Certifications
Automotive Cybersecurity Certifications
Five assessed levels, from foundational literacy to the Master-level CACE. Every credential is earned through examined work and maps to a level of the AutoSec Automotive Cybersecurity Capability Framework™.
Certification framework
What an AutoSec Credential Means
A certificate is only worth the rigour behind it. These are the four commitments that sit behind every level of the ladder.
Assessed, not attended
Attendance earns nothing. Every level is granted on examined work — written papers, supervised practicals and reviewed deliverables.
Graded by practitioners
Assessments are marked by engineers who run type-approval assessments and vehicle penetration tests for a living.
Mapped to capability
Each credential corresponds to a level of the AutoSec Automotive Cybersecurity Capability Framework™, so it means the same thing across every team.
Valid for three years
Regulation moves. Credentials carry a three-year validity period and are renewed against the current standards, not the ones in force when you sat the exam.
The ladder
Foundation to Master
Each level builds on the one before it. Progression is cumulative — you cannot skip to Expert without evidencing the capability beneath it.
Foundation
AutoSec Certified Foundation
4 weeks
Practitioner
AutoSec Certified Compliance Practitioner
6 weeks
Professional
AutoSec Certified Professional
8 weeks
Expert
AutoSec Certified Expert
10 weeks
Master
AutoSec Certified Master — CACE
16 weeks
- Foundation
AutoSec Certified Foundation
Proves working literacy in automotive cybersecurity: attack surfaces, in-vehicle networks and the regulatory landscape that governs every production programme.
Requirements
- Complete Automotive Cybersecurity Foundations
- Pass the foundation assessment
- Exam
- online proctored · 60 minutes · pass 70%
- Typical duration
- 4 weeks
Contributing programs
- Automotive Cybersecurity Foundations
- Practitioner
AutoSec Certified Compliance Practitioner
Evidences the ability to implement and audit a Cyber Security Management System against ISO/SAE 21434, UNECE R155/R156 and the Indian AIS series.
Requirements
- Hold the Foundation certification or demonstrate equivalent experience
- Complete ISO 21434 and CSMS Specialist
- Submit a CSMS artefact portfolio for review
- Exam
- online proctored · 90 minutes · pass 75%
- Typical duration
- 6 weeks
Contributing programs
- ISO 21434 and CSMS Specialist
- TARA Specialist
- Professional
AutoSec Certified Professional
Confirms hands-on capability to design and build secure vehicle systems — architecture segregation, secure boot, HSM-backed key handling and SecOC.
Requirements
- Hold the Practitioner certification
- Complete Secure ECU Developer or Secure Automotive Architect
- Pass a supervised practical assessment on lab hardware
- Exam
- hybrid · 3 hours · pass 75%
- Typical duration
- 8 weeks
Contributing programs
- Secure ECU Developer
- Secure Automotive Architect
- TARA Specialist
- Expert
AutoSec Certified Expert
Recognises independent offensive and validation capability: penetration testing against real ECU hardware, fuzzing campaigns and defensible findings.
Requirements
- Hold the Professional certification
- Complete Automotive Penetration Testing Expert or Automotive Fuzz Testing Expert
- Deliver a full engagement report assessed by a practitioner panel
- Exam
- hybrid · 6 hours · pass 80%
- Typical duration
- 10 weeks
Contributing programs
- Automotive Penetration Testing Expert
- Automotive Fuzz Testing Expert
- Master
AutoSec Certified Master — CACE
The terminal credential. Awarded on completion of the CACE capstone, it evidences end-to-end command of compliance, architecture, implementation, validation and offence.
Requirements
- Hold the Expert certification
- Complete the Certified Automotive Cybersecurity Expert programme
- Pass the supervised capstone on real vehicle hardware
- Present findings and a capability plan to an assessment board
- Exam
- in person · 2 days · pass 80%
- Typical duration
- 16 weeks
Contributing programs
- Certified Automotive Cybersecurity Expert (CACE)
Capability mapping
Capability Levels, Programs and Credentials
The relationship between what an organisation needs (capability levels), how it is built (programs and labs) and how it is evidenced (certifications).
- Level 1Awareness
Cybersecurity Awareness
Introduce automotive attack surfaces, the regulatory landscape and security-by-design principles to engineers joining a cybersecurity programme.
What this level covers
- Threat landscape overview
- Connected vehicle architecture basics
- Introduction to ISO 21434 and UNECE regulations
- Programs
- Automotive Cybersecurity Foundations
- Certification
- Foundation
- Level 2Compliance
Compliance Practitioner
Implement and audit compliance frameworks across the automotive product lifecycle, from CSMS establishment through type-approval evidence.
What this level covers
- ISO 21434 lifecycle requirements
- CSMS establishment and audit
- UNECE R155/R156 type approval
- AIS 189, 190 and 230 requirements
- Programs
- ISO 21434 and CSMS SpecialistTARA Specialist
- Certification
- Practitioner
- Labs
- AutoSec TARA Lab
- Level 3Secure Developer
Secure Developer
Develop production-grade secure automotive software and embedded systems, with a verifiable chain of trust from boot to communication.
What this level covers
- Secure ECU development lifecycle
- Automotive crypto stack
- Secure Boot, HSM, SecOC and Secure Flash
- Hardware security features of automotive microcontrollers
- Programs
- Secure ECU DeveloperSecure Automotive Architect
- Certification
- Professional
- Labs
- AutoSec Secure Development LabAutoSec Crypto Lab
- Level 4Validation
Security Validation Specialist
Validate security controls through systematic testing, threat analysis and architecture assessment that stands up to independent review.
What this level covers
- Security validation methodologies
- Automotive TARA execution
- Architecture security review
- Fuzz testing fundamentals
- Programs
- TARA SpecialistAutomotive Fuzz Testing ExpertSecure Automotive Architect
- Certification
- ProfessionalExpert
- Labs
- AutoSec TARA LabAutoSec Fuzz Testing Lab
- Level 5Offensive
Offensive Security Expert
Conduct authorised offensive security assessments on automotive systems, from wireless entry points through to hardware-level exploitation.
What this level covers
- Automotive penetration testing
- CAN and Automotive Ethernet attack vectors
- Red team operations
- Hardware-based exploitation
- Programs
- Automotive Penetration Testing ExpertAutomotive Fuzz Testing Expert
- Certification
- Expert
- Labs
- AutoSec Red Team LabAutoSec Fuzz Testing Lab
- Level 6Leader
Cybersecurity Leader
Own automotive cybersecurity strategy, governance and organisational capability, with the technical depth to hold engineering to account.
What this level covers
- CSMS governance and KPIs
- Security organisation design
- Supplier security management
- Executive reporting and risk acceptance
- Programs
- Certified Automotive Cybersecurity Expert (CACE)ISO 21434 and CSMS Specialist
- Certification
- Master
- Labs
- AutoSec TARA LabAutoSec Secure Development LabAutoSec Crypto LabAutoSec Red Team LabAutoSec Fuzz Testing Lab
Common questions
Certification FAQ
Straight answers to the questions engineering managers and candidates ask most often.
- What is automotive cybersecurity?
- Automotive cybersecurity is the engineering discipline that protects vehicles and their supporting backends from malicious interference. It covers the in-vehicle networks (CAN, LIN, Automotive Ethernet), the ECUs on them, wireless entry points such as Bluetooth, Wi-Fi and cellular telematics, over-the-air update paths, and the manufacturer processes that govern all of it. Unlike IT security, decisions are constrained by functional safety, real-time timing budgets, a fifteen-year service life and vehicles that cannot simply be patched overnight.
- What is ISO/SAE 21434?
- ISO/SAE 21434 is the international standard for road vehicle cybersecurity engineering. It defines cybersecurity activities across the full product lifecycle — concept, development, production, operations, maintenance and decommissioning — including Threat Analysis and Risk Assessment (TARA), cybersecurity goals and requirements, supplier interface agreements, and the evidence a manufacturer must retain. It is the engineering backbone that a Cyber Security Management System is built on, and it underpins type approval under UNECE R155.
- What is the CACE certification?
- CACE is the Certified Automotive Cybersecurity Expert credential, the Master level of the AutoSec ladder. It is awarded on completion of the sixteen-week flagship program and a supervised capstone performed on real vehicle hardware, then defended before an assessment board. Holders have demonstrated end-to-end command of compliance, secure architecture, ECU implementation, security validation and offensive testing — not just one of them.
- Do programs include labs?
- Yes. Lab access is included with every program, and lab work is assessed rather than optional. Depending on the program you will work in the TARA Lab, Secure Development Lab, Crypto Lab, Red Team Lab or Fuzz Testing Lab, on production-representative ECUs and the tooling used in real engineering programmes. The flagship CACE program includes all five.
- How do certifications relate to the Capability Framework?
- The five certification levels and the six Capability Framework levels are two views of the same progression. Certifications are what an individual earns; framework levels are how an organisation measures and plans capability. Foundation maps to Level 1 Awareness, Practitioner to Level 2 Compliance, Professional to Levels 3 and 4, Expert to Levels 4 and 5, and Master to Level 6 Leadership.
- Are the certifications suitable for corporate rollout?
- Yes. The framework was designed for exactly that. Teams are assessed against a capability level, enrolled on the programs that close the gap and re-assessed on completion — giving engineering leadership a defensible view of readiness against ISO 21434, UNECE R155/R156 and the Indian AIS series. Delivery can be onsite, remote or hybrid.
Become an Automotive Cybersecurity Expert
Start at the level that matches your experience and work up the ladder to CACE.