Skip to content

GUIDE · Product security

The cybersecurity management system (CSMS)

Most first-time UN R155 audits are not lost on technical analysis. They are lost on organisational evidence that the project never produced because nobody owned it.

LAST REVIEWED

What a CSMS has to cover

AreaWhat it governsTypical evidence
Governance and policyCybersecurity policy, roles, accountabilityPolicy documents, role assignments, management review records
Risk managementHow cybersecurity risk is identified, assessed and treatedTARA method definition, risk register, treatment decisions with rationale
Competence and awarenessThat people doing the work are qualifiedCompetence framework, training records
Supplier managementAssurance flowed down the supply chainCybersecurity interface agreements, supplier assessments
Tool and configuration managementConfidence in the tools and baselines usedTool qualification records, configuration baselines
Monitoring and responseDetection and handling of new threats in the fieldMonitoring process, triage records, incident and update history
The organisational areas an audited CSMS is expected to cover, and the evidence each produces.

Why the organisational layer is the hard part

Project teams naturally produce engineering artefacts: analyses, requirements, test results. A CSMS asks for something different — evidence that the organisation consistently governs cybersecurity across projects, over time. That means operating history: monitoring records, triage decisions, management reviews, competence records, supplier assessments. A policy written the month before an audit, with no operating history behind it, is a predictable finding.

Post-production monitoring

The monitoring obligation is where automotive cybersecurity most closely resembles the CRA's vulnerability handling expectations. It requires a defined intake for new cybersecurity information and vulnerabilities, triage criteria, a route into the risk assessment, and the ability to deliver an update to fielded units — which for type-approved vehicles connects to the software update management system required by UN Regulation No. 156.

Under-resourced areas

  • Supplier assurance below Tier 1, where interface agreements often exist on paper only.
  • Tool management, which teams treat as an engineering detail until an assessor asks how tool output is trusted.
  • Competence evidence for engineers performing threat analysis.
  • Management review, which is the clearest available evidence that the system is actually operating.
  • The handover from project cybersecurity case to post-production monitoring, which frequently has no named owner.

Frequently asked questions

What does CSMS stand for?

CSMS stands for cybersecurity management system: the organisational processes, governance and records through which a manufacturer manages cybersecurity risk across a product's lifecycle, including post-production monitoring and incident response.

Is a CSMS mandatory?

For vehicle manufacturers seeking type approval in markets applying UN Regulation No. 155, a certified CSMS is mandatory. For other product manufacturers it is not mandated by that regulation, though comparable organisational obligations arise under the Cyber Resilience Act and IEC 62443-4-1.

How is a CSMS certified?

Under UN Regulation No. 155 an approval authority or its technical service assesses the manufacturer's cybersecurity management system and issues a certificate of compliance, which is then a precondition for vehicle type approval. The assessment examines processes and operating evidence, not only documentation.

What is the difference between a CSMS and a TARA?

A TARA is a project-level technical analysis producing risk values and cybersecurity requirements for a specific system. A CSMS is the organisational framework that defines how TARAs are performed, reviewed, maintained and fed by field monitoring across all projects.

How does a CSMS relate to the CRA?

The CRA does not use the term, but its requirements for a documented risk assessment, vulnerability handling process, coordinated disclosure and support-period updates describe an equivalent organisational capability for products with digital elements outside vehicle type approval.