# CSMS (Cybersecurity Management System)

> A CSMS (Cybersecurity Management System) is the set of organisational processes with which a vehicle manufacturer manages cyber risk across development, production and post-production. UN Regulation No. 155 paragraph 7.2 defines what it must cover, from risk identification and treatment to testing, monitoring and incident response, and the approval authority certifies it with a Certificate of Compliance valid for at most three years. ISO/SAE 21434 is the standard most manufacturers use to implement it.

A CSMS is the system of processes UN R155 requires from a vehicle manufacturer: risk management, testing, monitoring and response over the vehicle lifecycle.

Source: https://auto-st.com/glossary/csms · Updated: 2026-10-07

## What is CSMS?

A Cybersecurity Management System (CSMS) is the organisation-wide framework of processes, responsibilities and tooling with which a vehicle manufacturer handles cyber risk for its vehicles, from the first concept through production and the years the vehicles are on the road. It is not a software system and not a product feature. It is the answer to the question "how does this company make sure its vehicles are and remain secure", written down, applied and audited.

## Where is it defined?

UN Regulation No. 155 defines the term and the requirements. Paragraph 7.2 states what the CSMS must demonstrate, and paragraph 7.2.2.2 lists the processes it must contain: processes to manage cybersecurity in the organisation, to identify risks to vehicle types, to assess, categorise and treat those risks, to verify that risks are appropriately managed, to test the security of the vehicle type, to keep the risk assessment current, to monitor, detect and respond to attacks, to analyse successful and attempted attacks, and to assess whether the measures remain effective in the light of new threats. Paragraphs 7.2.2.3 to 7.2.2.5 add the post-production phase, the data for forensic analysis and the management of supplier-related risks. Paragraph 6 covers the Certificate of Compliance for CSMS: issued by the approval authority after an assessment, valid for at most three years (6.8), and a precondition for vehicle type approval under paragraph 7.3.

ISO/SAE 21434 does not use the term CSMS, but its clauses 5 (organisational cybersecurity management), 6 (project-dependent cybersecurity management), 7 (distributed cybersecurity activities) and 8 (continual cybersecurity activities) describe the same processes, which is why the standard is the common way to build one.

## What it means in practice

For an engineering or test team the CSMS shows up as process obligations: every vehicle type needs a current risk assessment, every identified risk needs a treatment and a verification, every test needs to be documented and traceable, and findings from the field need a defined route back into development. The processes are audited on paper, but the auditor samples the evidence behind them, and security test reports are the evidence most often sampled.

In the CSMS work products we produced for an ADAS Tier-1 the hardest part was not writing the processes but closing the loop: proving that a test case exists for each risk treatment, that it was run on the delivered software version and that the finding went into a ticket with an owner. Unclear traceability between risk, requirement, test and result is what fails the sample.

## How AutoST tests it

AutoST does not run a CSMS and does not certify one. It supplies the "test the security of the vehicle type" and "verify that risks are appropriately managed" processes with repeatable evidence at ECU level: dated scans, findings with severity and fix, a Fix Plan whose tasks carry a reference to your requirement or ticket, risk acceptance that survives re-tests, and PDF and SARIF exports the auditor and your tracker can read.

## Common misunderstandings

A CSMS certificate does not mean a vehicle is secure; it means the manufacturer has working processes to manage security. And "we have ISO/SAE 21434" is not the same as having a CSMS certificate: the standard is the method, the certificate is the regulatory recognition, and only the approval authority issues it.

## FAQ

**Who needs a CSMS?**

The vehicle manufacturer, because the Certificate of Compliance is issued to the manufacturer and is a precondition for type approval under UN R155. Suppliers do not get their own certificate, but paragraph 7.2.2.5 requires the manufacturer to manage supplier-related risks, so OEMs push CSMS-shaped requirements down the chain.

**How long is a CSMS certificate valid?**

UN R155 paragraph 6.8 limits the Certificate of Compliance to a maximum of three years, after which it is renewed following a new assessment. Changes to the CSMS have to be reported to the approval authority in between.

**What does testing have to do with the CSMS?**

Paragraph 7.2.2.2 lists the processes a CSMS must contain, including processes to test the security of the vehicle type and to verify that the risks identified are appropriately managed. Repeatable, documented security tests are therefore part of the CSMS evidence, not separate from it.

## Sources

- [UN Regulation No. 155, Cyber security and cyber security management system, paragraphs 6 and 7.2](https://unece.org/transport/documents/2021/03/standards/un-regulation-no-155-cyber-security-and-cyber-security)
- [ISO/SAE 21434:2021 Road vehicles, Cybersecurity engineering, Clauses 5 to 8](https://www.iso.org/standard/70918.html)

## Related

- [UN R155 (UN Regulation No. 155, Cyber Security)](https://auto-st.com/glossary/un-r155)
- [ISO/SAE 21434](https://auto-st.com/glossary/iso-sae-21434)
- [TARA (Threat Analysis and Risk Assessment)](https://auto-st.com/glossary/tara)
- [VSOC (Vehicle Security Operations Center)](https://auto-st.com/glossary/vsoc)
- [UN R155 audits: what testers need to deliver](https://auto-st.com/insights/un-r155-audit-what-testers-need)
- [Evidence for your 21434 work, on tap.](https://auto-st.com/iso-21434-testing)

---
AutoST by Zyberum. Canonical page: https://auto-st.com/glossary/csms
