Skip to content
Zyberum Cyber Security Firm
Menu
GlossaryAutomotiveCompliance

CSMS (Cybersecurity Management System)

A CSMS is the organisational process framework UN R155 requires from vehicle manufacturers. What it must cover, how it is audited, and what suppliers deliver to it.

Updated This page as Markdown

In short

A CSMS (Cybersecurity Management System) is the set of processes, roles and evidence with which a vehicle manufacturer manages cybersecurity across development, production and the post-production phase. UN Regulation No. 155 makes a certified CSMS a precondition for vehicle type approval; ISO/SAE 21434 describes the processes that fill it. The CSMS belongs to the OEM, but suppliers deliver work products into it.

What is a CSMS?

A CSMS is the management system with which a vehicle manufacturer organises cybersecurity: who is responsible, how risks to a vehicle type are identified and treated, how the vehicle is tested, how attacks in the field are detected and answered, and how all of that is documented. UN Regulation No. 155 defines it in paragraph 2.3 as “a systematic risk-based approach defining organisational processes, responsibilities and governance to treat risk associated with cyber threats to vehicles and protect them from cyber-attacks”.

The key word is process. A CSMS is not a product, not a security architecture and not a one-off assessment. It is the proof that the organisation does cybersecurity repeatably, for every vehicle type and over the whole lifecycle.

Where is it defined?

Paragraph 7.2 of UN R155 lists what the CSMS must cover. It applies to the development, production and post-production phases (7.2.2.1) and must include processes for managing cybersecurity in the organisation, identifying and assessing risks to vehicle types, treating them, verifying that treatment, testing the vehicle type, keeping the risk assessment current, monitoring, detecting and responding to attacks, and analysing attempted or successful attacks (7.2.2.2). Paragraph 7.2.2.3 adds the management of dependencies on suppliers, and 7.2.2.4 the ability to react to new threats within a reasonable time frame.

The approval authority or its technical service assesses the CSMS and issues a certificate of compliance, valid for up to three years. Only then can vehicle types be approved under paragraph 7.3. ISO/SAE 21434:2021 provides the engineering processes behind it, in particular Clause 5 (organisational cybersecurity management), Clause 6 (project-dependent management), Clause 7 (distributed activities with suppliers) and Clause 8 (continual activities such as monitoring and vulnerability management).

What it means in practice

For an OEM the CSMS audit is a document and interview exercise: policies, role descriptions, a cybersecurity plan template, the TARA method, test strategies, the incident and vulnerability handling process, and evidence that all of it has been applied to real projects. For a supplier the CSMS arrives as a stack of contractual requirements plus a cybersecurity interface agreement (CIA) that says which work products the supplier owes.

When we build CSMS work products with a Tier-1, most of the effort goes into three places. First, making the TARA method concrete enough that two engineers get comparable results. Second, defining what “cybersecurity validation” means for the component, because a test plan that only says “penetration test” will not survive the audit. Third, the post-production part: who watches for new vulnerabilities in the software bill of materials, who decides whether an update is needed, and how fast.

Common misunderstandings

A certified CSMS does not mean a vehicle is secure; it means the manufacturer has working processes to manage security. The vehicle type approval under paragraph 7.3 is the separate step where the results for a specific vehicle are checked. And a CSMS is not finished after certification: the processes have to run, the evidence has to grow, and the certificate is renewed at the latest every three years.

FAQ

Frequently asked questions

Does a supplier need its own CSMS?

Not under UN R155, which addresses the vehicle manufacturer. In practice OEMs pass the obligation down by contract: paragraph 7.2.2.3 requires the manufacturer to manage supplier dependencies, so suppliers are asked for ISO/SAE 21434-conformant processes, a TARA, test evidence and an interface agreement. Many Tier-1s run an internal management system for exactly that reason.

Who certifies a CSMS?

The type approval authority of a contracting state or a technical service it has designated, for example the KBA in Germany with services such as TÜV or DEKRA. The certificate of compliance is valid for a maximum of three years. Zyberum is not a certification body; we prepare the work products and the evidence, we do not issue the certificate.

Is a CSMS the same as ISO/SAE 21434 conformance?

No. The CSMS is a regulatory requirement from UN R155 and is audited. ISO/SAE 21434 is a standard that describes how cybersecurity engineering is done; it is the accepted way to show that the CSMS processes exist and work. You can follow the standard without an approval, and in theory build a CSMS without it, but nobody does.

Sources

Related pages

Get started

A term that applies to your product?

In 15 minutes we tell you what it means for you in practice, which requirement follows from it and what the sensible next step is.

  • Direct answer from a security engineer
  • Which standard or law applies to you
  • Free and without obligation
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usAsk a security engineer

Pick a time that suits you

Open in a new tab