Skip to main content
Intermediate
Level 2 · Compliance

ISO 21434 and CSMS Specialist

Implement and evidence a Cyber Security Management System that survives type approval.

Duration
6 weeks
Delivery format
Hybrid
Certification
AutoSec Compliance Practitioner

Overview

What This Program Is For

Most organisations can quote ISO/SAE 21434. Far fewer can produce the evidence trail an assessor asks for. This program takes the standard from clause text to working process, using your own artefacts as the working material wherever confidentiality allows.

Take ISO/SAE 21434 from clause text to working process. Build the CSMS artefacts, interfaces and evidence trail that UNECE R155, R156 and the Indian AIS series require.

Who should attend

  • Compliance and quality managers owning CSMS delivery
  • Engineering leads preparing for UNECE R155 type approval
  • Supplier-facing engineers negotiating cybersecurity interface agreements
  • Anyone accountable for audit readiness under the Indian AIS series

Prerequisites

  • Automotive Cybersecurity Foundations or equivalent experience

Curriculum

5 Modules Across 6 weeks

Every module is assessed. Durations are indicative for open cohorts and are compressed or extended for corporate delivery.

  1. ISO/SAE 21434 clause walkthrough

    1 week
  2. CSMS design and governance

    2 weeks
  3. UNECE R155 / R156 and AIS mapping

    1 week
  4. Supplier interface agreements

    1 week
  5. Audit preparation and evidence

    1 week

Learning outcomes

What You Take Back to Your Programme

Capability you can demonstrate, not topics you have been exposed to.

What you will be able to do

  • Structure a CSMS against ISO/SAE 21434 clauses
  • Map R155, R156 and AIS obligations to internal processes
  • Define supplier cybersecurity interface agreements
  • Assemble an audit-ready evidence pack
  • Career outcomes

    • Compliance Manager
    • CSMS Owner
    • Cybersecurity Programme Lead
  • Capability levels

    • Compliance Practitioner
  • Tools and skills

    • CSMS artefact templates
    • Clause-to-process mapping matrix
    • Supplier interface agreement model
    • Evidence pack structure

Labs included

Hands-On Time on Real Hardware

Lab access is included with this program, and the exercises below are assessed rather than optional.

  • Included lab
    2 assessed exercises

    AutoSec TARA Lab

    Model threats against real vehicle architectures

    Objectives

    • Define items and assets from a real vehicle architecture
    • Derive attack paths and rate feasibility
    • Produce cybersecurity goals and requirements

    Practical exercises

    • Central gateway TARA
      intermediate
      4 hours

      Full assessment of a domain gateway including diagnostic and OTA interfaces.

    • Telematics unit attack paths
      advanced
      3 hours

      Derive and rate attack paths across cellular, Bluetooth and Wi-Fi interfaces.

Certification mapping

Where This Sits in the Framework

How the program maps to the AutoSec Automotive Cybersecurity Capability Framework™ and the certification ladder.

Capability Framework

Compliance Practitioner

Enable ISO 21434, UNECE R155/R156, AIS standards and CSMS implementation.

  • ISO 21434 lifecycle requirements
  • CSMS establishment and audit
  • UNECE R155/R156 type approval
  • AIS 189, 190 and 230 requirements

Certification

AutoSec Certified Compliance Practitioner

Evidences the ability to implement and audit a Cyber Security Management System against ISO/SAE 21434, UNECE R155/R156 and the Indian AIS series.

Level 2 · Practitioner

Exam preparation

Format
online proctored
Duration
90 minutes
Passing score
75%
Valid for
3 years
  • Hold the Foundation certification or demonstrate equivalent experience
  • Complete ISO 21434 and CSMS Specialist
  • Submit a CSMS artefact portfolio for review
See the full certification ladder

Common questions

ISO 21434 and CSMS Specialist FAQ

What candidates and their managers ask before enrolling.

Will this prepare us for an actual UNECE R155 assessment?
It prepares the people. The program covers CSMS structure, evidence expectations and supplier interfaces, and includes a mock assessment exercise. Organisation-wide readiness is a longer engagement — that is what the corporate CSMS Readiness programme addresses.
Does it cover the Indian AIS series as well as UNECE?
Yes. AIS 189 and AIS 190 follow the structure UNECE R155 and R156 established, so the material treats them together and highlights where the process and submission obligations diverge for the Indian market.
Can we bring our own CSMS documentation to work on?
For corporate cohorts, yes — and it makes the program considerably more valuable. For open cohorts we use representative artefacts instead, since confidentiality prevents sharing customer material across organisations.

Ready to Start AutoSec Compliance Practitioner?

Enrol as an individual, or talk to us about running this program for your engineering team.