Skip to main content

CSMS (Cyber Security Management System)

A CSMS (Cyber Security Management System) bundles the processes, roles and responsibilities with which a vehicle manufacturer identifies, assesses and treats cybersecurity risks across the entire lifecycle. UNECE R155 makes an audited CSMS a prerequisite for type approval — without a CSMS, no market access for new vehicles in the EU.

What belongs in a CSMS?

A CSMS is not a single document, but a management system put into practice. It must cover the phases of development, production and operation in the field, and essentially comprises:

  • Risk processes: procedures to identify, assess and treat cybersecurity risks — the central method for this is the threat analysis and risk assessment (TARA).
  • Monitoring: continuous observation of new threats, vulnerabilities and attacks on one’s own vehicle types, including after sale.
  • Incident response: defined procedures to react to security incidents and newly discovered vulnerabilities.
  • Supply chain: evidence that cybersecurity risks are also managed at suppliers and service providers — typically governed via the Cybersecurity Interface Agreement.
  • Organization: clear roles, responsibilities and sufficient cybersecurity competence within the company.

CSMS audit and type approval: two separate assessments

R155 assesses on two levels that are easily confused:

CSMS assessmentType approval
SubjectThe manufacturer’s organizationA specific vehicle type
Core questionAre processes in place and are they lived?Are the risks of this type identified and treated?
Typical evidenceProcess documentation, roles, monitoring and response proceduresDocumented TARA, implemented measures, test results
ResultCSMS certificate of compliance (time-limited, to be renewed regularly)Type approval for the vehicle type

The CSMS certificate is a prerequisite for every type approval — but it does not replace the technical evidence per vehicle type. Both must be in place.

Building a CSMS: ISO/SAE 21434 as the framework

R155 describes what a CSMS must deliver, but not how to build it. For this, ISO/SAE 21434 is the recognized technical framework: it defines the organizational requirements, the risk-based engineering process and the required work products. Those who set up their CSMS along the standard provide the R155 evidence on a robust, auditable foundation.

CSMS in practice

The most common mistake when building a CSMS is treating it as a documentation project: processes are described for the audit, but not integrated into everyday development. A CSMS only holds up when the risk analyses actually live — when a new CVE in an installed component automatically triggers the question of whether an attack path has changed, and when this reassessment is documented and retrievable. Precisely this consistency across many vehicle types, variants and years is, in practice, the real challenge — not the first audit.

Frequently asked questions

Who needs a CSMS?
Directly obliged are vehicle manufacturers applying for type approval under UNECE R155. Suppliers are affected indirectly: the OEM must demonstrate that risks are managed across the entire supply chain, and therefore passes the requirements on contractually to tier 1 and tier 2 suppliers.
Is a CSMS the same as an ISMS according to ISO 27001?
No. An ISMS protects the information assets and IT systems of one’s own organization. A CSMS relates to the product: the cybersecurity of the vehicles and their components across the entire lifecycle — from development through production to operation in the field.
How are CSMS and TARA related?
The TARA is the central analysis method within the CSMS: it provides the documented risk decisions for a specific system. The CSMS ensures at organizational level that TARAs are systematically created, maintained and translated into measures.

Related terms

Reviewed by Dirk Leopold, Executive Vice President Digital Engineering on July 20, 2026