GUIDE · Product security
The cybersecurity management system (CSMS)
Most first-time UN R155 audits are not lost on technical analysis. They are lost on organisational evidence that the project never produced because nobody owned it.
LAST REVIEWED
What a CSMS has to cover
| Area | What it governs | Typical evidence |
|---|---|---|
| Governance and policy | Cybersecurity policy, roles, accountability | Policy documents, role assignments, management review records |
| Risk management | How cybersecurity risk is identified, assessed and treated | TARA method definition, risk register, treatment decisions with rationale |
| Competence and awareness | That people doing the work are qualified | Competence framework, training records |
| Supplier management | Assurance flowed down the supply chain | Cybersecurity interface agreements, supplier assessments |
| Tool and configuration management | Confidence in the tools and baselines used | Tool qualification records, configuration baselines |
| Monitoring and response | Detection and handling of new threats in the field | Monitoring process, triage records, incident and update history |
Why the organisational layer is the hard part
Project teams naturally produce engineering artefacts: analyses, requirements, test results. A CSMS asks for something different — evidence that the organisation consistently governs cybersecurity across projects, over time. That means operating history: monitoring records, triage decisions, management reviews, competence records, supplier assessments. A policy written the month before an audit, with no operating history behind it, is a predictable finding.
Post-production monitoring
The monitoring obligation is where automotive cybersecurity most closely resembles the CRA's vulnerability handling expectations. It requires a defined intake for new cybersecurity information and vulnerabilities, triage criteria, a route into the risk assessment, and the ability to deliver an update to fielded units — which for type-approved vehicles connects to the software update management system required by UN Regulation No. 156.
Under-resourced areas
- Supplier assurance below Tier 1, where interface agreements often exist on paper only.
- Tool management, which teams treat as an engineering detail until an assessor asks how tool output is trusted.
- Competence evidence for engineers performing threat analysis.
- Management review, which is the clearest available evidence that the system is actually operating.
- The handover from project cybersecurity case to post-production monitoring, which frequently has no named owner.
Frequently asked questions
What does CSMS stand for?
CSMS stands for cybersecurity management system: the organisational processes, governance and records through which a manufacturer manages cybersecurity risk across a product's lifecycle, including post-production monitoring and incident response.
Is a CSMS mandatory?
For vehicle manufacturers seeking type approval in markets applying UN Regulation No. 155, a certified CSMS is mandatory. For other product manufacturers it is not mandated by that regulation, though comparable organisational obligations arise under the Cyber Resilience Act and IEC 62443-4-1.
How is a CSMS certified?
Under UN Regulation No. 155 an approval authority or its technical service assesses the manufacturer's cybersecurity management system and issues a certificate of compliance, which is then a precondition for vehicle type approval. The assessment examines processes and operating evidence, not only documentation.
What is the difference between a CSMS and a TARA?
A TARA is a project-level technical analysis producing risk values and cybersecurity requirements for a specific system. A CSMS is the organisational framework that defines how TARAs are performed, reviewed, maintained and fed by field monitoring across all projects.
How does a CSMS relate to the CRA?
The CRA does not use the term, but its requirements for a documented risk assessment, vulnerability handling process, coordinated disclosure and support-period updates describe an equivalent organisational capability for products with digital elements outside vehicle type approval.