Skip to content
AutoST by Zyberum GmbH
Menu
ComparisonsTesting strategy

In-House ECU Security Testing vs an External Test Lab

Testing ECUs on your own bench gives speed and control; an external lab brings independence, specialists and hardware. Which fits a supplier or OEM, and how both combine.

Updated This page as Markdown

In short

In-house ECU security testing means your own engineers run the tests on your own bench, as often as the release cycle needs, with the results in your hands. An external test lab brings independent assessors, specialist tools and hardware you do not own, and a report that carries weight with an OEM or an assessor. The lab is the better choice for independence and for the first look at a new platform; the in-house bench is the better choice for everything that has to happen on every build.

What is the difference?

In-house testing means the ECU, the bench and the engineer are yours. You decide when a test runs, you see the result the same afternoon, and nothing about the firmware or the diagnostic description leaves the building. The limits are expertise and independence: your team knows your ECU but may not know what attackers do to other people’s ECUs, and a supplier assessing its own product is not what an OEM means by validation.

An external test lab is independent by construction. It brings people who test ECUs from many suppliers all year, hardware you do not own (climate chambers, bus analysers for every transport, side-channel and fault-injection rigs where needed) and a report that an OEM or assessor accepts as third-party evidence. The limits are time and cost: a lab engagement is a project with a scope, a start date and a deliverable, and the ECU you send is a snapshot. Six weeks later there is a new firmware and the report describes the old one.

Side by side

In-house testingExternal test lab
What it findsEverything your tools and people cover, on every build: diagnostic surface, SecurityAccess weaknesses, robustness under fuzzing, Ethernet exposure, IVI hardening, regressionsEverything an experienced outsider finds on a snapshot: the above plus firmware-level weaknesses, chained attacks, hardware attacks, comparison with what other suppliers do
What it missesBlind spots of a team that knows the product too well; the independence an assessor wants for validationRegressions after the report; your internal context; anything out of scope or outside the booked weeks
Who does itYour test and QA engineers, ideally with one security-minded ownerThe lab’s security engineers, under an agreement with scope and rules of engagement
Bench timeMinutes to hours per run, whenever a build is readyTwo to six weeks per engagement including the report, plus shipping the samples
CostBench hardware you mostly have, engineer time, a tool licence per componentProject price per engagement; ECU penetration tests typically 20,000 to 45,000 euros in Germany and the EU, not an offer
Fits a release cycleYes, this is the point of itNo; once per platform generation, before start of production and after major changes
Required byISO/SAE 21434 Clause 10.4.2 verification is the supplier’s own job; UN R155 CSMS asks the manufacturer to manage testing along the supply chainIndependence for validation (Clause 11) is asked for by many OEM requirement sets and by type-approval assessors in practice
OutputScan history, PDF and SARIF per run, a Fix Plan your engineers work throughA signed report with method, findings, reproduction and recommendations; a presentation and a retest

Choose in-house testing when

  • You release firmware more than once a year or ship an ECU in several variants. Each release needs the same checks, and a lab cannot be booked every sprint.
  • Confidentiality is strict. ODX and CDD files, pre-series firmware and seed/key material stay on your own servers; nothing has to be shipped or uploaded.
  • You want findings fixed while the developer still remembers the change. A result the same day is worth more than a better result in six weeks.
  • Your team should learn. Engineers who run enumeration and read negative response codes every week become the people who design the next ECU better.
  • The checks are the repeatable kind: sessions, services, DIDs, SecurityAccess counters, fuzzing robustness, DoIP routing, SOME/IP exposure. Tools do these well and a lab would use tools too.

Choose an external test lab when

  • Independence is the requirement. A supplier’s own report rarely satisfies an OEM’s validation clause, and an assessor for UN R155 type approval will ask who tested.
  • The platform is new and nobody in-house has attacked one like it. A first external pentest sets the baseline the in-house suite later protects.
  • You need hardware or skills you will not build up for one project: firmware extraction from a locked microcontroller, fault injection, side channels, environmental testing.
  • You have no bench yet. A lab engagement is also a way to learn what a bench for this ECU should look like.

Both together

The combination that works: an external lab tests each new platform once, deeply and independently, before start of production. The in-house bench runs the repeatable suite on every build from then on and keeps the lab’s findings from coming back. When the next lab engagement is due, the tester gets the in-house scan history and spends the days on what automation cannot see.

AutoST serves both sides of this. Suppliers and OEMs run it on their own benches; test labs run it on their customers’ ECUs to make the repeatable part consistent across engagements and hand over PDF and SARIF with the report. Zyberum’s own penetration testers are a lab in this sense, and we are clear that AutoST is the tool they use for the first day, not a replacement for the following weeks.

FAQ

Frequently asked questions

Does an OEM accept in-house test results?

For verification evidence during development, usually yes, provided the method and the results are traceable: what was tested, with which tool version, when, and what happened to each finding. For validation of the cybersecurity goals, many OEM requirement sets ask for an independent test, which is where the lab comes in. Check the cybersecurity interface agreement; ISO/SAE 21434 Clause 7 is where this split is documented.

What does a lab engagement cost compared to an in-house setup?

A lab charges per project: an ECU penetration test is typically 20,000 to 45,000 euros, a typical market range for Germany and the EU, not an offer, plus hardware or environmental testing if needed. An in-house setup costs the bench you mostly have, your engineers time and a tool licence. The lab is cheaper for one test; the bench is cheaper from the second firmware release.

Can a test lab use AutoST?

Yes. Labs use it to run the repeatable part (enumeration, SecurityAccess, fuzzing, DoIP, SOME/IP, IVI) on every customer ECU in a consistent way and spend their experts time on the manual part. The report and SARIF export go into the lab deliverable.

Sources

Related pages

See it on your ECU

Not sure what your ECU programme needs?

Describe your ECUs, your bench and your release cadence in a 15-minute call. You get a clear recommendation, whether or not it involves AutoST.

  • A recommendation, not a sales pitch
  • What to automate and what to leave to a pentest
  • Free and without obligation
Tom Zaubermann

Your demo is withTom ZaubermannFounder of Zyberum, ex-lead of the VW InCar Security Testing Lab

Already trusted by Tier 1, Tier 2 suppliers and OEMs. References on request.

Call us: +49 176 439 17074automotive@zyberum.com

Or send us a message

We reply within one business day.

Call usGet a recommendation

Pick a time that suits you

Open in a new tab