Skip to main content
Expert
Flagship program
Level 6 · Leader

Certified Automotive Cybersecurity Expert (CACE)

The complete practitioner pathway — compliance, design, implementation, validation and offence.

Duration
16 weeks
Delivery format
Hybrid
Certification
Certified Automotive Cybersecurity Expert

Overview

What This Program Is For

CACE is the complete practitioner pathway. Sixteen weeks that take an automotive engineer from regulatory fluency through architecture, implementation, validation and offensive testing, assessed by a supervised capstone on real vehicle hardware and defended before a board. It is the credential for people who will be accountable for cybersecurity across a programme, not one discipline within it.

The flagship AutoSec Academy programme. Sixteen weeks that take an automotive engineer from regulatory fluency to hands-on offensive and defensive capability, assessed through a supervised capstone on real hardware.

Who should attend

  • Senior engineers moving into cybersecurity leadership
  • Security engineers who need breadth across all five disciplines
  • Architects and technical leads accountable for programme-level security
  • Consultants who must hold their own in any room on the subject

Prerequisites

  • Automotive engineering background
  • Automotive Cybersecurity Foundations or equivalent

Curriculum

9 Modules Across 16 weeks

Every module is assessed. Durations are indicative for open cohorts and are compressed or extended for corporate delivery.

  1. Foundations

    1 week
  2. CSMS and ISO 21434

    2 weeks
  3. TARA

    2 weeks
  4. Secure Architecture

    2 weeks
  5. Secure ECU Development

    2 weeks
  6. Security Validation

    2 weeks
  7. Penetration Testing

    2 weeks
  8. Fuzz Testing

    1 week
  9. Capstone

    2 weeks

Learning outcomes

What You Take Back to Your Programme

Capability you can demonstrate, not topics you have been exposed to.

What you will be able to do

  • Lead CSMS implementation and type-approval readiness
  • Own TARA and security architecture for a vehicle programme
  • Implement and validate ECU-level security controls
  • Plan and execute offensive testing against vehicle systems
  • Present findings and capability gaps to engineering leadership
  • Career outcomes

    • Head of Product Security
    • Principal Security Architect
    • Cybersecurity Programme Lead
  • Capability levels

    • Cybersecurity Leader
  • Tools and skills

    • Full AutoSec lab toolchain
    • CSMS artefact templates
    • Threat modelling workbench
    • HSM firmware toolchain
    • Exploitation and fuzzing frameworks

Labs included

Hands-On Time on Real Hardware

Lab access is included with this program, and the exercises below are assessed rather than optional.

  • Included lab
    2 assessed exercises

    AutoSec TARA Lab

    Model threats against real vehicle architectures

    Objectives

    • Define items and assets from a real vehicle architecture
    • Derive attack paths and rate feasibility
    • Produce cybersecurity goals and requirements

    Practical exercises

    • Central gateway TARA
      intermediate
      4 hours

      Full assessment of a domain gateway including diagnostic and OTA interfaces.

    • Telematics unit attack paths
      advanced
      3 hours

      Derive and rate attack paths across cellular, Bluetooth and Wi-Fi interfaces.

  • Included lab
    2 assessed exercises

    AutoSec Secure Development Lab

    Harden ECU software on real hardware

    Objectives

    • Implement secure boot on an automotive microcontroller
    • Integrate an HSM-backed key hierarchy
    • Apply SecOC to a CAN communication matrix

    Practical exercises

    • Secure boot chain of trust
      advanced
      5 hours

      Build and verify a signed bootloader with rollback protection.

    • SecOC on a CAN bus
      advanced
      4 hours

      Add authentication and freshness to safety-relevant CAN frames.

  • Included lab
    2 assessed exercises

    AutoSec Crypto Lab

    Key management that survives production

    Objectives

    • Design a production key hierarchy
    • Provision keys securely at end of line
    • Operate certificate lifecycles for V2X and OTA

    Practical exercises

    • End-to-end key hierarchy
      advanced
      4 hours

      Model provisioning, rotation and revocation across supplier and OEM boundaries.

    • Cryptographic misuse hunt
      intermediate
      3 hours

      Identify weak modes, hardcoded keys and entropy failures in ECU firmware.

  • Included lab
    2 assessed exercises

    AutoSec Red Team Lab

    Attack the vehicle to defend it

    Objectives

    • Map the attack surface of a connected vehicle
    • Exploit diagnostic and bus-level weaknesses
    • Escalate from a wireless entry point to a safety-relevant domain

    Practical exercises

    • Diagnostic session takeover
      advanced
      4 hours

      Defeat weak seed-key authentication and reach a privileged UDS session.

    • Wireless entry to CAN pivot
      advanced
      5 hours

      Chain a wireless foothold into control of an in-vehicle network segment.

  • Included lab
    2 assessed exercises

    AutoSec Fuzz Testing Lab

    Break protocols before attackers do

    Objectives

    • Design a protocol fuzzing campaign
    • Instrument targets for crash detection
    • Triage and de-duplicate findings

    Practical exercises

    • UDS service fuzzing
      intermediate
      3 hours

      Fuzz diagnostic services and triage the resulting faults.

    • Automotive Ethernet stack fuzzing
      advanced
      4 hours

      Campaign against SOME/IP and DoIP handling with coverage feedback.

Certification mapping

Where This Sits in the Framework

How the program maps to the AutoSec Automotive Cybersecurity Capability Framework™ and the certification ladder.

Capability Framework

Cybersecurity Leader

Lead CSMS transformation, security governance and enterprise capability programmes.

  • CSMS governance and KPIs
  • Security organisation design
  • Supplier security management
  • Executive reporting and risk acceptance

Certification

AutoSec Certified Master — CACE

The terminal credential. Awarded on completion of the CACE capstone, it evidences end-to-end command of compliance, architecture, implementation, validation and offence.

Level 5 · Master

Exam preparation

Format
in person
Duration
2 days
Passing score
80%
Valid for
3 years
  • Hold the Expert certification
  • Complete the Certified Automotive Cybersecurity Expert programme
  • Pass the supervised capstone on real vehicle hardware
  • Present findings and a capability plan to an assessment board
See the full certification ladder

Common questions

Certified Automotive Cybersecurity Expert (CACE) FAQ

What candidates and their managers ask before enrolling.

Can I take CACE without the individual programs first?
Yes, and most candidates do — CACE covers the same ground in an integrated sequence rather than as separate courses. What it assumes is an automotive engineering background and Foundations-level literacy. Candidates without either find sixteen weeks extremely compressed.
What does the capstone involve?
A supervised project on real vehicle hardware spanning risk assessment, an implemented control, validation evidence and an offensive test of your own work — then a defence before an assessment board. It is the component candidates report as the most demanding and the most valuable.
Is CACE recognised outside AutoSec Academy?
It is an AutoSec Academy credential mapped to Level 6 of the AutoSec Automotive Cybersecurity Capability Framework™. It is not a regulatory qualification, and no training credential is — UNECE R155 approves management systems and vehicle types, not individuals. What it evidences is assessed capability across all five disciplines.
How much of the sixteen weeks is lab time?
Roughly half, rising through the programme. All five AutoSec labs are included, and the capstone is entirely hands-on.

Ready to Start Certified Automotive Cybersecurity Expert?

Enrol as an individual, or talk to us about running this program for your engineering team.