CSMS (Cyber Security Management System)
A CSMS (Cyber Security Management System) bundles the processes, roles and responsibilities with which a vehicle manufacturer identifies, assesses and treats cybersecurity risks across the entire lifecycle. UNECE R155 makes an audited CSMS a prerequisite for type approval — without a CSMS, no market access for new vehicles in the EU.
What belongs in a CSMS?
A CSMS is not a single document, but a management system put into practice. It must cover the phases of development, production and operation in the field, and essentially comprises:
- Risk processes: procedures to identify, assess and treat cybersecurity risks — the central method for this is the threat analysis and risk assessment (TARA).
- Monitoring: continuous observation of new threats, vulnerabilities and attacks on one’s own vehicle types, including after sale.
- Incident response: defined procedures to react to security incidents and newly discovered vulnerabilities.
- Supply chain: evidence that cybersecurity risks are also managed at suppliers and service providers — typically governed via the Cybersecurity Interface Agreement.
- Organization: clear roles, responsibilities and sufficient cybersecurity competence within the company.
CSMS audit and type approval: two separate assessments
R155 assesses on two levels that are easily confused:
| CSMS assessment | Type approval | |
|---|---|---|
| Subject | The manufacturer’s organization | A specific vehicle type |
| Core question | Are processes in place and are they lived? | Are the risks of this type identified and treated? |
| Typical evidence | Process documentation, roles, monitoring and response procedures | Documented TARA, implemented measures, test results |
| Result | CSMS certificate of compliance (time-limited, to be renewed regularly) | Type approval for the vehicle type |
The CSMS certificate is a prerequisite for every type approval — but it does not replace the technical evidence per vehicle type. Both must be in place.
Building a CSMS: ISO/SAE 21434 as the framework
R155 describes what a CSMS must deliver, but not how to build it. For this, ISO/SAE 21434 is the recognized technical framework: it defines the organizational requirements, the risk-based engineering process and the required work products. Those who set up their CSMS along the standard provide the R155 evidence on a robust, auditable foundation.
CSMS in practice
The most common mistake when building a CSMS is treating it as a documentation project: processes are described for the audit, but not integrated into everyday development. A CSMS only holds up when the risk analyses actually live — when a new CVE in an installed component automatically triggers the question of whether an attack path has changed, and when this reassessment is documented and retrievable. Precisely this consistency across many vehicle types, variants and years is, in practice, the real challenge — not the first audit.


