— Insights
The referencelibrary.
The reference for homologation managers at OEMs, Tier-1s and Tier-2s: clause-precise, dated writing on UN R155, UN R156, AIS-189, AIS-190, ISO/SAE 21434 and the EU CRA — the mechanics no one else documents. Plus the coverage of the work, and the sources behind every claim on this site.
— Writing
Everything we publish.
Grouped by regulation and by practice. Filter, or open a topic hub.
- India — AIS-189 & AIS-190AIS-190 explained: India's software update standardAIS-190 is India's SUMS standard for over-the-air and workshop software updates — here is what it asks for
- India — AIS-189 & AIS-190AIS-189 vs UN R155: a clause-level comparisonWhere India's AIS-189 follows UN R155 and where the Indian route differs — for teams carrying both files
- India — AIS-189 & AIS-190AIS-190 vs UN R156: what's the same, what's notA side-by-side of India's software-update standard and its UNECE parent
- India — AIS-189 & AIS-190AIS-189 clause 5.3.1: why being on the Rule 126 list isn't enoughThe clause that separates a named test agency from one that actually holds cybersecurity competence
- India — AIS-189 & AIS-190Rule 124, Rule 126 and CIRT: who type-approves AIS-189/190 in IndiaFor homologation managers: the CMVR test agencies, and where the AIS-189/190 cybersecurity assessment is actually granted
- EU Cyber Resilience ActThe EU Cyber Resilience Act for automotive: what changesHow the CRA lands on connected-vehicle products, and what it adds on top of UN R155
- India — AIS-189 & AIS-190India's automotive cybersecurity timeline: the draft dates, and what's still openThe June 2026 MoRTH draft proposes a phased AIS-189/190 timeline — here is what it says, and why it is a draft, not a deadline
- EU Cyber Resilience ActCRA vs UN R155: overlap, gaps and double duty for Indian exportersWhere the CRA and UN R155 overlap, where they do not, and what an exporter to the EU must do about both
- India — AIS-189 & AIS-190An AIS-189/190 readiness checklist for Indian OEMsA practical, sequenced checklist to get a CSMS and SUMS to an assessable state
- India — AIS-189 & AIS-190CIRT, ARAI, ICAT: how an Indian type approval actually gets assessedThe submission-to-certificate workflow no one documents — and where cybersecurity fits into it
- EU Cyber Resilience ActThe EU CRA timeline: (EU) 2024/2847 dates and the reporting clockThe dates that matter — including the vulnerability-reporting obligation that starts 11 September 2026
- UN R155 & the CSMSUN R155 Annex 5, decoded: the automotive threat catalogueAnnex 5 read as a checklist — the threats, the vulnerabilities, and the mitigations a CSMS must address
- UN R155 & the CSMSUN R155 explained: the CSMS in plain termsThe UN cyber security regulation, what a CSMS is, and what an approval authority checks
- UN R155 & the CSMSRxSWIN explained: the software identifier UN R155 and R156 rely onWhat RxSWIN is, what it must cover, who generates it, and when it changes
- UN R155 & the CSMSWhat is a CSMS? The cybersecurity management system, end to endA CSMS is a management system, not a document — here is what that means across the vehicle lifecycle
- UN R155 & the CSMSThe UN R155 audit: what evidence the assessor actually opensThe dossier an assessor reads — and the difference between describing a process and proving it ran
- UN R155 & the CSMSUN R155 and the supply chain: flow-down to Tier-1s and Tier-2sA CSMS is only as strong as its suppliers — how R155 obligations flow down the chain
- UN R155 & the CSMSUN R155 type-approval timeline: new types vs all vehiclesThe dates that already bit, market by market — and what 'new type' versus 'all vehicles' means for a programme
- UN R155 & the CSMSThe vehicle SOC (VSOC) and UN R155 post-approval monitoringApproval is not the finish line — R155 expects monitoring of the fleet after the certificate
- UN R155 & the CSMSThe gaps that fail a first UN R155 CSMS assessmentThe recurring reasons a first assessment stalls — and how to close them before the assessor arrives
- UN R155 & the CSMSHow much does UN R155 / AIS-189 cost, and how long does it take?An honest answer to the two questions every programme asks first — with the variables that move them
- UN R156 & software updatesA secure OTA update workflow under UN R156From build to vehicle: the integrity, authorisation and record-keeping an OTA campaign needs
- UN R156 & software updatesUN R156 explained: the SUMS and why OTA needs its own regulationThe software-update regulation, the SUMS, and what changes once a vehicle can update itself
- UN R156 & software updatesGenerating and managing RxSWIN for UN R156A practical walkthrough of what an RxSWIN must cover and how to keep it correct across updates
- UN R156 & software updatesRollback, recovery and integrity: UN R156 and ISO 24089What happens when an update fails — and how R156 and ISO 24089 expect you to handle it
- UN R156 & software updatesUN R156 for non-OTA vehicles: what still appliesYou do not need over-the-air updates for R156 to apply — here is the part that always does
- UN R156 & software updatesThe SUMS documentation UN R156 expectsThe records and processes a Software Update Management System has to hold to pass assessment
- UN R156 & software updatesISO 24089 explained: software update engineeringThe engineering standard beneath UN R156 — what ISO 24089:2023 covers and how it is used
- ISO/SAE 21434ISO/SAE 21434 explained: the cybersecurity lifecycleThe engineering standard the regulations lean on — the lifecycle from concept to decommissioning
- ISO/SAE 21434TARA, step by step: threat analysis and risk assessmentThe method at the centre of ISO/SAE 21434 — asset, threat, attack path, impact, risk, treatment
- ISO/SAE 21434The ISO/SAE 21434 V-model, and where coverage breaksHow the left leg (concept) and right leg (verification) connect — and the gap most vendors leave
- ISO/SAE 21434Cybersecurity Assurance Level (CAL) explainedWhat a CAL is in ISO/SAE 21434, how it is derived, and how it shapes rigour
- ISO/SAE 21434Goals, claims and requirements: ISO/SAE 21434 clauses 9.3–9.5The concept-phase clauses that turn a TARA into engineering requirements
- ISO/SAE 21434ISO/SAE 21434 vs UN R155: how the standard supports the regulationOne is a regulation you must pass; the other is the engineering that makes passing possible
- EU Cyber Resilience ActSBOMs under the CRA: what a software bill of materials must carryThe SBOM is moving from good practice to obligation — here is what it has to contain and why
- EU Cyber Resilience ActVulnerability handling and disclosure under the CRACoordinated disclosure, reporting timelines, and the process the CRA expects a manufacturer to run
- Practice — labs, VSOC & communityIT/OT convergence in automotive manufacturing securityThe plant, the backend and the vehicle are one attack surface — securing them as three silos is the gap
- Practice — labs, VSOC & communityIEC 62443 for the vehicle plant: securing production OTThe industrial security standard that governs the factory where the ECU is built and flashed
- Practice — labs, VSOC & communityWhy the assembly line is in scope for a CSMSEnd-of-line is where an unsigned image or a loose key enters the fleet — and why the CSMS has to cover it
- Practice — labs, VSOC & communityBuilding an automotive VSOC: architecture to detectionWhat a vehicle security operations centre is, how it differs from an IT SOC, and how to stand one up
- Practice — labs, VSOC & communityCAN bus attacks explained: fuzzing, injection and spoofingHow the in-vehicle network is attacked, why the CAN protocol is exposed, and what mitigates it
- Practice — labs, VSOC & communityUDS diagnostics security: the 0x27 SecurityAccess problemHow diagnostic security access works, where it is weak, and what a hardened UDS stack looks like
- Practice — labs, VSOC & communityAutomotive PKI and key management for OTAThe public-key infrastructure that lets a vehicle trust an update — and the lifecycle that keeps it safe
- Practice — labs, VSOC & communityPenetration testing a vehicle: scope, method, deliverablesWhat a vehicle pentest covers, how it is run against representative benches, and what a good report contains
- Practice — labs, VSOC & communityThe instrument cluster attack: how a dashboard liesA worked example — crafted CAN messages change what the cluster shows, with no fault raised
- Practice — labs, VSOC & communityCar-hacking villages and why Indian OEMs should careThe community that finds vehicle bugs first — and why building that capability in India matters
- Practice — labs, VSOC & communityV2X security and the C-ITS ecosystemHow vehicles trust messages from other vehicles and infrastructure — and the PKI that makes it possible
- Practice — labs, VSOC & communityEV charging security: ISO 15118 and Plug & ChargeHow an EV and a charger authenticate each other — and the attack surface at the charging inlet
- Practice — labs, VSOC & communityBuilding an automotive cybersecurity career in IndiaThe roles, the skills, and the routes in — for engineers moving into vehicle security
— Watch
The conversation, unedited.
— In the press
On the record.
Every link here was verified as live and genuinely names AutoSifu or the CIRT × AutoSifu partnership.
— Sources
The documents themselves.
Coverage that ran without a stable public link — shown here as the scans we hold, not linked to an address that may not resolve.


— In the room
The events.


09 — Start here
Bring us the file you are least sure about.
Most conversations start with a gap assessment, or a type approval submission that is closer than it feels. Either is a good place to begin.
Direct
- Email[email protected]
- Phone+91 98672 75102
- Book a callcalendly.com/contact-autosifu
Jaipur · registered office
Plot No. 8, ABS Plaza, Chanakya PuriJagatpura, Jaipur – 302017, RajasthanAUTOSIFU Pvt Ltd · India