Skip to main content

Certifications

Automotive Cybersecurity Certifications

Five assessed levels, from foundational literacy to the Master-level CACE. Every credential is earned through examined work and maps to a level of the AutoSec Automotive Cybersecurity Capability Framework™.

Certification framework

What an AutoSec Credential Means

A certificate is only worth the rigour behind it. These are the four commitments that sit behind every level of the ladder.

  • Assessed, not attended

    Attendance earns nothing. Every level is granted on examined work — written papers, supervised practicals and reviewed deliverables.

  • Graded by practitioners

    Assessments are marked by engineers who run type-approval assessments and vehicle penetration tests for a living.

  • Mapped to capability

    Each credential corresponds to a level of the AutoSec Automotive Cybersecurity Capability Framework™, so it means the same thing across every team.

  • Valid for three years

    Regulation moves. Credentials carry a three-year validity period and are renewed against the current standards, not the ones in force when you sat the exam.

The ladder

Foundation to Master

Each level builds on the one before it. Progression is cumulative — you cannot skip to Expert without evidencing the capability beneath it.

  1. Foundation

    AutoSec Certified Foundation

    4 weeks

  2. Practitioner

    AutoSec Certified Compliance Practitioner

    6 weeks

  3. Professional

    AutoSec Certified Professional

    8 weeks

  4. Expert

    AutoSec Certified Expert

    10 weeks

  5. Master

    AutoSec Certified Master — CACE

    16 weeks

  1. Foundation

    AutoSec Certified Foundation

    Proves working literacy in automotive cybersecurity: attack surfaces, in-vehicle networks and the regulatory landscape that governs every production programme.

    Requirements

    • Complete Automotive Cybersecurity Foundations
    • Pass the foundation assessment
    Exam
    online proctored · 60 minutes · pass 70%
    Typical duration
    4 weeks

    Contributing programs

    • Automotive Cybersecurity Foundations
  2. Practitioner

    AutoSec Certified Compliance Practitioner

    Evidences the ability to implement and audit a Cyber Security Management System against ISO/SAE 21434, UNECE R155/R156 and the Indian AIS series.

    Requirements

    • Hold the Foundation certification or demonstrate equivalent experience
    • Complete ISO 21434 and CSMS Specialist
    • Submit a CSMS artefact portfolio for review
    Exam
    online proctored · 90 minutes · pass 75%
    Typical duration
    6 weeks

    Contributing programs

    • ISO 21434 and CSMS Specialist
    • TARA Specialist
  3. Professional

    AutoSec Certified Professional

    Confirms hands-on capability to design and build secure vehicle systems — architecture segregation, secure boot, HSM-backed key handling and SecOC.

    Requirements

    • Hold the Practitioner certification
    • Complete Secure ECU Developer or Secure Automotive Architect
    • Pass a supervised practical assessment on lab hardware
    Exam
    hybrid · 3 hours · pass 75%
    Typical duration
    8 weeks

    Contributing programs

    • Secure ECU Developer
    • Secure Automotive Architect
    • TARA Specialist
  4. Expert

    AutoSec Certified Expert

    Recognises independent offensive and validation capability: penetration testing against real ECU hardware, fuzzing campaigns and defensible findings.

    Requirements

    • Hold the Professional certification
    • Complete Automotive Penetration Testing Expert or Automotive Fuzz Testing Expert
    • Deliver a full engagement report assessed by a practitioner panel
    Exam
    hybrid · 6 hours · pass 80%
    Typical duration
    10 weeks

    Contributing programs

    • Automotive Penetration Testing Expert
    • Automotive Fuzz Testing Expert
  5. Master

    AutoSec Certified Master — CACE

    The terminal credential. Awarded on completion of the CACE capstone, it evidences end-to-end command of compliance, architecture, implementation, validation and offence.

    Requirements

    • Hold the Expert certification
    • Complete the Certified Automotive Cybersecurity Expert programme
    • Pass the supervised capstone on real vehicle hardware
    • Present findings and a capability plan to an assessment board
    Exam
    in person · 2 days · pass 80%
    Typical duration
    16 weeks

    Contributing programs

    • Certified Automotive Cybersecurity Expert (CACE)

Capability mapping

Capability Levels, Programs and Credentials

The relationship between what an organisation needs (capability levels), how it is built (programs and labs) and how it is evidenced (certifications).

  1. Level 1
    Awareness

    Cybersecurity Awareness

    Introduce automotive attack surfaces, the regulatory landscape and security-by-design principles to engineers joining a cybersecurity programme.

    What this level covers

    • Threat landscape overview
    • Connected vehicle architecture basics
    • Introduction to ISO 21434 and UNECE regulations
    Programs
    Automotive Cybersecurity Foundations
    Certification
    Foundation
  2. Level 2
    Compliance

    Compliance Practitioner

    Implement and audit compliance frameworks across the automotive product lifecycle, from CSMS establishment through type-approval evidence.

    What this level covers

    • ISO 21434 lifecycle requirements
    • CSMS establishment and audit
    • UNECE R155/R156 type approval
    • AIS 189, 190 and 230 requirements
    Programs
    ISO 21434 and CSMS SpecialistTARA Specialist
    Certification
    Practitioner
    Labs
    AutoSec TARA Lab
  3. Level 3
    Secure Developer

    Secure Developer

    Develop production-grade secure automotive software and embedded systems, with a verifiable chain of trust from boot to communication.

    What this level covers

    • Secure ECU development lifecycle
    • Automotive crypto stack
    • Secure Boot, HSM, SecOC and Secure Flash
    • Hardware security features of automotive microcontrollers
    Programs
    Secure ECU DeveloperSecure Automotive Architect
    Certification
    Professional
    Labs
    AutoSec Secure Development LabAutoSec Crypto Lab
  4. Level 4
    Validation

    Security Validation Specialist

    Validate security controls through systematic testing, threat analysis and architecture assessment that stands up to independent review.

    What this level covers

    • Security validation methodologies
    • Automotive TARA execution
    • Architecture security review
    • Fuzz testing fundamentals
    Programs
    TARA SpecialistAutomotive Fuzz Testing ExpertSecure Automotive Architect
    Certification
    ProfessionalExpert
    Labs
    AutoSec TARA LabAutoSec Fuzz Testing Lab
  5. Level 5
    Offensive

    Offensive Security Expert

    Conduct authorised offensive security assessments on automotive systems, from wireless entry points through to hardware-level exploitation.

    What this level covers

    • Automotive penetration testing
    • CAN and Automotive Ethernet attack vectors
    • Red team operations
    • Hardware-based exploitation
    Programs
    Automotive Penetration Testing ExpertAutomotive Fuzz Testing Expert
    Certification
    Expert
    Labs
    AutoSec Red Team LabAutoSec Fuzz Testing Lab
  6. Level 6
    Leader

    Cybersecurity Leader

    Own automotive cybersecurity strategy, governance and organisational capability, with the technical depth to hold engineering to account.

    What this level covers

    • CSMS governance and KPIs
    • Security organisation design
    • Supplier security management
    • Executive reporting and risk acceptance
    Programs
    Certified Automotive Cybersecurity Expert (CACE)ISO 21434 and CSMS Specialist
    Certification
    Master
    Labs
    AutoSec TARA LabAutoSec Secure Development LabAutoSec Crypto LabAutoSec Red Team LabAutoSec Fuzz Testing Lab

Common questions

Certification FAQ

Straight answers to the questions engineering managers and candidates ask most often.

What is automotive cybersecurity?
Automotive cybersecurity is the engineering discipline that protects vehicles and their supporting backends from malicious interference. It covers the in-vehicle networks (CAN, LIN, Automotive Ethernet), the ECUs on them, wireless entry points such as Bluetooth, Wi-Fi and cellular telematics, over-the-air update paths, and the manufacturer processes that govern all of it. Unlike IT security, decisions are constrained by functional safety, real-time timing budgets, a fifteen-year service life and vehicles that cannot simply be patched overnight.
What is ISO/SAE 21434?
ISO/SAE 21434 is the international standard for road vehicle cybersecurity engineering. It defines cybersecurity activities across the full product lifecycle — concept, development, production, operations, maintenance and decommissioning — including Threat Analysis and Risk Assessment (TARA), cybersecurity goals and requirements, supplier interface agreements, and the evidence a manufacturer must retain. It is the engineering backbone that a Cyber Security Management System is built on, and it underpins type approval under UNECE R155.
What is the CACE certification?
CACE is the Certified Automotive Cybersecurity Expert credential, the Master level of the AutoSec ladder. It is awarded on completion of the sixteen-week flagship program and a supervised capstone performed on real vehicle hardware, then defended before an assessment board. Holders have demonstrated end-to-end command of compliance, secure architecture, ECU implementation, security validation and offensive testing — not just one of them.
Do programs include labs?
Yes. Lab access is included with every program, and lab work is assessed rather than optional. Depending on the program you will work in the TARA Lab, Secure Development Lab, Crypto Lab, Red Team Lab or Fuzz Testing Lab, on production-representative ECUs and the tooling used in real engineering programmes. The flagship CACE program includes all five.
How do certifications relate to the Capability Framework?
The five certification levels and the six Capability Framework levels are two views of the same progression. Certifications are what an individual earns; framework levels are how an organisation measures and plans capability. Foundation maps to Level 1 Awareness, Practitioner to Level 2 Compliance, Professional to Levels 3 and 4, Expert to Levels 4 and 5, and Master to Level 6 Leadership.
Are the certifications suitable for corporate rollout?
Yes. The framework was designed for exactly that. Teams are assessed against a capability level, enrolled on the programs that close the gap and re-assessed on completion — giving engineering leadership a defensible view of readiness against ISO 21434, UNECE R155/R156 and the Indian AIS series. Delivery can be onsite, remote or hybrid.

Become an Automotive Cybersecurity Expert

Start at the level that matches your experience and work up the ladder to CACE.