ISO 21434 and CSMS Specialist
Implement and evidence a Cyber Security Management System that survives type approval.
- Duration
- 6 weeks
- Delivery format
- Hybrid
- Certification
- AutoSec Compliance Practitioner
Overview
What This Program Is For
Most organisations can quote ISO/SAE 21434. Far fewer can produce the evidence trail an assessor asks for. This program takes the standard from clause text to working process, using your own artefacts as the working material wherever confidentiality allows.
Take ISO/SAE 21434 from clause text to working process. Build the CSMS artefacts, interfaces and evidence trail that UNECE R155, R156 and the Indian AIS series require.
Who should attend
- Compliance and quality managers owning CSMS delivery
- Engineering leads preparing for UNECE R155 type approval
- Supplier-facing engineers negotiating cybersecurity interface agreements
- Anyone accountable for audit readiness under the Indian AIS series
Prerequisites
- Automotive Cybersecurity Foundations or equivalent experience
Curriculum
5 Modules Across 6 weeks
Every module is assessed. Durations are indicative for open cohorts and are compressed or extended for corporate delivery.
ISO/SAE 21434 clause walkthrough
1 weekCSMS design and governance
2 weeksUNECE R155 / R156 and AIS mapping
1 weekSupplier interface agreements
1 weekAudit preparation and evidence
1 week
Learning outcomes
What You Take Back to Your Programme
Capability you can demonstrate, not topics you have been exposed to.
What you will be able to do
- Structure a CSMS against ISO/SAE 21434 clauses
- Map R155, R156 and AIS obligations to internal processes
- Define supplier cybersecurity interface agreements
- Assemble an audit-ready evidence pack
Career outcomes
- Compliance Manager
- CSMS Owner
- Cybersecurity Programme Lead
Capability levels
- Compliance Practitioner
Tools and skills
- CSMS artefact templates
- Clause-to-process mapping matrix
- Supplier interface agreement model
- Evidence pack structure
Labs included
Hands-On Time on Real Hardware
Lab access is included with this program, and the exercises below are assessed rather than optional.
- Included lab2 assessed exercises
AutoSec TARA Lab
Model threats against real vehicle architectures
Objectives
- Define items and assets from a real vehicle architecture
- Derive attack paths and rate feasibility
- Produce cybersecurity goals and requirements
Practical exercises
- Central gateway TARAintermediate4 hours
Full assessment of a domain gateway including diagnostic and OTA interfaces.
- Telematics unit attack pathsadvanced3 hours
Derive and rate attack paths across cellular, Bluetooth and Wi-Fi interfaces.
Certification mapping
Where This Sits in the Framework
How the program maps to the AutoSec Automotive Cybersecurity Capability Framework™ and the certification ladder.
Capability Framework
Compliance Practitioner
Enable ISO 21434, UNECE R155/R156, AIS standards and CSMS implementation.
- ISO 21434 lifecycle requirements
- CSMS establishment and audit
- UNECE R155/R156 type approval
- AIS 189, 190 and 230 requirements
Certification
AutoSec Certified Compliance Practitioner
Evidences the ability to implement and audit a Cyber Security Management System against ISO/SAE 21434, UNECE R155/R156 and the Indian AIS series.
Exam preparation
- Format
- online proctored
- Duration
- 90 minutes
- Passing score
- 75%
- Valid for
- 3 years
- Hold the Foundation certification or demonstrate equivalent experience
- Complete ISO 21434 and CSMS Specialist
- Submit a CSMS artefact portfolio for review
Common questions
ISO 21434 and CSMS Specialist FAQ
What candidates and their managers ask before enrolling.
- Will this prepare us for an actual UNECE R155 assessment?
- It prepares the people. The program covers CSMS structure, evidence expectations and supplier interfaces, and includes a mock assessment exercise. Organisation-wide readiness is a longer engagement — that is what the corporate CSMS Readiness programme addresses.
- Does it cover the Indian AIS series as well as UNECE?
- Yes. AIS 189 and AIS 190 follow the structure UNECE R155 and R156 established, so the material treats them together and highlights where the process and submission obligations diverge for the Indian market.
- Can we bring our own CSMS documentation to work on?
- For corporate cohorts, yes — and it makes the program considerably more valuable. For open cohorts we use representative artefacts instead, since confidentiality prevents sharing customer material across organisations.
Ready to Start AutoSec Compliance Practitioner?
Enrol as an individual, or talk to us about running this program for your engineering team.