Skip to main content

Programs

Automotive Cybersecurity Programs

Eight programs covering the full arc of automotive cybersecurity — regulatory compliance, secure architecture and development, validation, and offensive testing — each mapped to a certification and a Capability Framework level.

Full catalog

Choose Your Program

Every program includes lab time on production-representative hardware and contributes to at least one certification level.

  • Foundation
    Level 1 · Awareness

    Automotive Cybersecurity Foundations

    The threat landscape, vehicle architecture and regulatory context every automotive engineer needs.

    Duration
    4 weeks
    Certification
    AutoSec Foundation

    Learning outcomes

    • Describe the connected vehicle attack surface
    • Explain ISO/SAE 21434 and UNECE R155 in engineering terms
    • Identify security-relevant assets in a vehicle architecture
  • Intermediate
    Level 2 · Compliance

    ISO 21434 and CSMS Specialist

    Implement and evidence a Cyber Security Management System that survives type approval.

    Duration
    6 weeks
    Certification
    AutoSec Compliance Practitioner

    Learning outcomes

    • Structure a CSMS against ISO/SAE 21434 clauses
    • Map R155, R156 and AIS obligations to internal processes
    • Define supplier cybersecurity interface agreements
  • Intermediate
    Level 4 · Validation

    TARA Specialist

    Run defensible Threat Analysis and Risk Assessments on production architectures.

    Duration
    5 weeks
    Certification
    AutoSec TARA Practitioner

    Learning outcomes

    • Produce complete item definitions and asset lists
    • Construct and rate attack paths
    • Derive cybersecurity goals and requirements
  • Advanced
    Level 3 · Secure Developer

    Secure Automotive Architect

    Design zonal and domain architectures with defence in depth built in from the start.

    Duration
    8 weeks
    Certification
    AutoSec Security Architect

    Learning outcomes

    • Design segregated zonal and domain architectures
    • Specify gateway and firewall policy for vehicle networks
    • Architect secure OTA update paths to R156
  • Advanced
    Level 3 · Secure Developer

    Secure ECU Developer

    Build ECU software with secure boot, HSM-backed keys and hardened diagnostics.

    Duration
    8 weeks
    Certification
    AutoSec Secure Developer

    Learning outcomes

    • Implement a verified secure boot chain
    • Integrate an HSM-backed key hierarchy
    • Apply SecOC to a production communication matrix
  • Expert
    Level 5 · Offensive

    Automotive Penetration Testing Expert

    Run full-scope offensive engagements against vehicles and their backends.

    Duration
    10 weeks
    Certification
    AutoSec Offensive Expert

    Learning outcomes

    • Map and prioritise a vehicle attack surface
    • Exploit bus, diagnostic and wireless weaknesses
    • Chain findings into realistic attack scenarios
  • Expert
    Level 4 · Validation

    Automotive Fuzz Testing Expert

    Design and operate fuzzing campaigns that fit a real validation programme.

    Duration
    6 weeks
    Certification
    AutoSec Validation Expert

    Learning outcomes

    • Design protocol fuzzing campaigns with coverage feedback
    • Instrument targets for reliable crash detection
    • Triage and de-duplicate findings at scale
  • Expert
    Level 6 · Leader

    Certified Automotive Cybersecurity Expert (CACE)

    The complete practitioner pathway — compliance, design, implementation, validation and offence.

    Duration
    16 weeks
    Certification
    Certified Automotive Cybersecurity Expert

    Learning outcomes

    • Lead CSMS implementation and type-approval readiness
    • Own TARA and security architecture for a vehicle programme
    • Implement and validate ECU-level security controls

Capability mapping

How Programs Map to the Capability Framework

Awareness, compliance, development, validation, offensive security and leadership — each level names the programs, labs and credential that build it.

  1. Level 1
    Awareness

    Cybersecurity Awareness

    Introduce automotive attack surfaces, the regulatory landscape and security-by-design principles to engineers joining a cybersecurity programme.

    What this level covers

    • Threat landscape overview
    • Connected vehicle architecture basics
    • Introduction to ISO 21434 and UNECE regulations
    Programs
    Automotive Cybersecurity Foundations
    Certification
    Foundation
  2. Level 2
    Compliance

    Compliance Practitioner

    Implement and audit compliance frameworks across the automotive product lifecycle, from CSMS establishment through type-approval evidence.

    What this level covers

    • ISO 21434 lifecycle requirements
    • CSMS establishment and audit
    • UNECE R155/R156 type approval
    • AIS 189, 190 and 230 requirements
    Programs
    ISO 21434 and CSMS SpecialistTARA Specialist
    Certification
    Practitioner
    Labs
    AutoSec TARA Lab
  3. Level 3
    Secure Developer

    Secure Developer

    Develop production-grade secure automotive software and embedded systems, with a verifiable chain of trust from boot to communication.

    What this level covers

    • Secure ECU development lifecycle
    • Automotive crypto stack
    • Secure Boot, HSM, SecOC and Secure Flash
    • Hardware security features of automotive microcontrollers
    Programs
    Secure ECU DeveloperSecure Automotive Architect
    Certification
    Professional
    Labs
    AutoSec Secure Development LabAutoSec Crypto Lab
  4. Level 4
    Validation

    Security Validation Specialist

    Validate security controls through systematic testing, threat analysis and architecture assessment that stands up to independent review.

    What this level covers

    • Security validation methodologies
    • Automotive TARA execution
    • Architecture security review
    • Fuzz testing fundamentals
    Programs
    TARA SpecialistAutomotive Fuzz Testing ExpertSecure Automotive Architect
    Certification
    ProfessionalExpert
    Labs
    AutoSec TARA LabAutoSec Fuzz Testing Lab
  5. Level 5
    Offensive

    Offensive Security Expert

    Conduct authorised offensive security assessments on automotive systems, from wireless entry points through to hardware-level exploitation.

    What this level covers

    • Automotive penetration testing
    • CAN and Automotive Ethernet attack vectors
    • Red team operations
    • Hardware-based exploitation
    Programs
    Automotive Penetration Testing ExpertAutomotive Fuzz Testing Expert
    Certification
    Expert
    Labs
    AutoSec Red Team LabAutoSec Fuzz Testing Lab
  6. Level 6
    Leader

    Cybersecurity Leader

    Own automotive cybersecurity strategy, governance and organisational capability, with the technical depth to hold engineering to account.

    What this level covers

    • CSMS governance and KPIs
    • Security organisation design
    • Supplier security management
    • Executive reporting and risk acceptance
    Programs
    Certified Automotive Cybersecurity Expert (CACE)ISO 21434 and CSMS Specialist
    Certification
    Master
    Labs
    AutoSec TARA LabAutoSec Secure Development LabAutoSec Crypto LabAutoSec Red Team LabAutoSec Fuzz Testing Lab

Certification alignment

Which Programs Contribute to Which Credential

Certifications are earned across programs. This is the exact contribution path from Foundation through to the Master-level CACE.

  1. Foundation

    AutoSec Certified Foundation

    Proves working literacy in automotive cybersecurity: attack surfaces, in-vehicle networks and the regulatory landscape that governs every production programme.

    Requirements

    • Complete Automotive Cybersecurity Foundations
    • Pass the foundation assessment
    Exam
    online proctored · 60 minutes · pass 70%
    Typical duration
    4 weeks

    Contributing programs

    • Automotive Cybersecurity Foundations
  2. Practitioner

    AutoSec Certified Compliance Practitioner

    Evidences the ability to implement and audit a Cyber Security Management System against ISO/SAE 21434, UNECE R155/R156 and the Indian AIS series.

    Requirements

    • Hold the Foundation certification or demonstrate equivalent experience
    • Complete ISO 21434 and CSMS Specialist
    • Submit a CSMS artefact portfolio for review
    Exam
    online proctored · 90 minutes · pass 75%
    Typical duration
    6 weeks

    Contributing programs

    • ISO 21434 and CSMS Specialist
    • TARA Specialist
  3. Professional

    AutoSec Certified Professional

    Confirms hands-on capability to design and build secure vehicle systems — architecture segregation, secure boot, HSM-backed key handling and SecOC.

    Requirements

    • Hold the Practitioner certification
    • Complete Secure ECU Developer or Secure Automotive Architect
    • Pass a supervised practical assessment on lab hardware
    Exam
    hybrid · 3 hours · pass 75%
    Typical duration
    8 weeks

    Contributing programs

    • Secure ECU Developer
    • Secure Automotive Architect
    • TARA Specialist
  4. Expert

    AutoSec Certified Expert

    Recognises independent offensive and validation capability: penetration testing against real ECU hardware, fuzzing campaigns and defensible findings.

    Requirements

    • Hold the Professional certification
    • Complete Automotive Penetration Testing Expert or Automotive Fuzz Testing Expert
    • Deliver a full engagement report assessed by a practitioner panel
    Exam
    hybrid · 6 hours · pass 80%
    Typical duration
    10 weeks

    Contributing programs

    • Automotive Penetration Testing Expert
    • Automotive Fuzz Testing Expert
  5. Master

    AutoSec Certified Master — CACE

    The terminal credential. Awarded on completion of the CACE capstone, it evidences end-to-end command of compliance, architecture, implementation, validation and offence.

    Requirements

    • Hold the Expert certification
    • Complete the Certified Automotive Cybersecurity Expert programme
    • Pass the supervised capstone on real vehicle hardware
    • Present findings and a capability plan to an assessment board
    Exam
    in person · 2 days · pass 80%
    Typical duration
    16 weeks

    Contributing programs

    • Certified Automotive Cybersecurity Expert (CACE)

Learning journey

Assess, Learn, Practise, Certify

The same four-step model runs through every program, whether you enrol as an individual or roll it out across an engineering organisation.

  • 1 — Assess

    Establish where the individual or team sits on the Capability Framework, and which regulatory obligations apply to your programme.

  • 2 — Learn

    Practitioner-led instruction built around the standard you must satisfy, not a generic security syllabus.

  • 3 — Practise

    Apply every concept in the labs — real ECUs, real buses, real tooling — until the technique is repeatable under pressure.

  • 4 — Certify

    Earn a credential through assessed work: written exams, supervised practicals and, at Master level, a capstone before a review board.

Find the Right Program for Your Team

Tell us where your engineers are today and we will map them onto the Capability Framework and recommend a pathway.