What is a CSMS? The cybersecurity management system, end to end

A CSMS is a management system, not a document — here is what that means across the vehicle lifecycle

5 Aug 20264 min readAutoSifu

A management system, not a document

A CSMS — Cyber Security Management System — is the set of processes an organisation uses to manage vehicle cyber security risk across the whole lifecycle. The single most common misunderstanding is to treat it as a document. It is not. It is a management system in the same sense as a quality or environmental management system: defined processes, named owners, records, and a mechanism for continual improvement.

UN R155 requires the manufacturer to hold a Certificate of Compliance for the CSMS, valid for three years, before any vehicle type can be approved. India's aligned standard, AIS-189, follows the same structure for assessment inside India. In both regimes the CSMS certificate is issued to the organisation, separately from any individual vehicle type approval.

The distinction matters because of how it is assessed. An assessor does not just read your process manual. They ask for evidence that the process actually ran on a real programme. A CSMS that exists only on paper is the classic reason a first assessment stalls, a pattern we cover in the gaps that fail a first UN R155 CSMS assessment.

The processes a CSMS must run

A compliant CSMS demonstrates a defined, evidenced capability in each of the following areas.

Process area What it must do Evidence it produces
Governance Assign responsibility for cyber security, at a senior level Policy, roles, org accountability
Risk management Identify and treat cyber risks (TARA) and keep them current TARA records, risk treatment decisions
Supplier flow-down Impose and verify requirements on suppliers Interface agreements, supplier evidence
Verification Confirm mitigations work Test and verification records
Monitoring Watch the fleet and back-end after production Monitoring data, threat intelligence
Incident response Detect and respond to attacks and incidents Incident records, response actions

None of these is optional, and each must produce records. The table's right-hand column is where assessments are won or lost: a process description with no corresponding records is not a working process.

Across the whole lifecycle

The word "management" in CSMS carries a lot of weight because the system has to span three phases.

In development, the CSMS drives the engineering: item definition, threat analysis, cyber security goals and concept, secure architecture, and verification. This is where ISO/SAE 21434 supplies the method — the CSMS says that risk must be managed; 21434 says how, through its lifecycle clauses. We set that out in ISO/SAE 21434 explained.

In production, the CSMS reaches the plant. End-of-line programming, key handling and flashing stations are part of the attack surface, so the assembly line is in scope. A signed image or a protected key is only as good as the process that installs it.

In post-production, the obligation continues. R155 expects the manufacturer to monitor the fleet, respond to new threats, and update software where needed. Approval is not the end of the work; it is the start of the operational phase the CSMS also has to govern.

Why supplier flow-down is central

Almost no OEM builds its own connected stack end to end. The vehicle is assembled from Tier-1 and Tier-2 components, each with its own software and its own vulnerabilities. Yet the OEM carries the approval. That gap — accountability at the OEM, capability across the supply chain — is why supplier flow-down is not a side process but a core one.

The CSMS has to impose cyber security requirements on suppliers, and, just as importantly, verify that they were met with real evidence rather than assurances. A vulnerability in a Tier-2 component does not stop being the OEM's problem because it originated three tiers down. This is a large enough topic that we treat it separately, and it is worth reading alongside this piece.

Ownership and accountability

Because the certificate is issued to the organisation, the CSMS cannot belong to a single project. R155 expects clear governance with senior responsibility. In practice the system is usually anchored in a cyber security function with a defined owner, but it draws on engineering, production, procurement, IT and after-sales. Each of those must feed the system with its own records.

This is where organisational reality bites. A CSMS designed by one team and ignored by the rest of the business produces exactly the paper-only system that fails assessment. A working CSMS is one that other functions actually use — where the TARA is maintained because engineering relies on it, where supplier evidence is collected because procurement requires it, where monitoring runs because operations owns it.

The AutoSifu view

A CSMS fails when it is written as a document by one team and never becomes a system the business runs. AutoSifu builds the CSMS as one route — the processes, the 21434 engineering substance beneath them, the supplier flow-down, and the evidence pack — and takes it through to the Certificate of Compliance with our partner CIRT, a named test agency, engaged from the start. The system you operate and the system the assessor examines are then the same thing.

Questions

What is a CSMS?
A CSMS, or Cyber Security Management System, is the set of processes an organisation uses to manage vehicle cyber security risk across the whole lifecycle — development, production and post-production. It is required by UN R155 and by India's aligned AIS-189, which grant a Certificate of Compliance for the CSMS separately from any individual vehicle type approval. It is a management system in the ISO sense, with defined processes, owners, records and continual improvement, not a one-off document.
What processes must a CSMS have?
A CSMS must cover governance and responsibility for cyber security, risk management including threat analysis and risk assessment, requirements flow-down and verification across the supply chain, continual monitoring of the fleet after production, and detection of and response to attacks and incidents. These processes must run across development, production and post-production. Each must produce records, because the CSMS is assessed on evidence that the process ran, not only on its description.
Who owns the CSMS in an OEM?
The CSMS belongs to the manufacturer as an organisation, and R155 expects clear governance with named responsibility at a senior level. In practice it is typically anchored in a cyber security function with a defined owner, but it touches engineering, production, procurement, IT and after-sales, all of which must feed the system. The Certificate of Compliance is issued to the organisation, so accountability cannot sit with a single project team.

09 — Start here

Bring us the file you are least sure about.

Most conversations start with a gap assessment, or a type approval submission that is closer than it feels. Either is a good place to begin.

Direct

Jaipur · registered office

Plot No. 8, ABS Plaza, Chanakya PuriJagatpura, Jaipur – 302017, RajasthanAUTOSIFU Pvt Ltd · India

Required