Responding to expanding vehicle cybersecurity needs, the core of CSMS and ISO/SAE 21434

CIO Review APAC | Monday, January 15, 2024

Until five years ago, carmakers were hesitant to introduce cybersecurity measures in vehicles despite being aware of their necessity due to cost issues.

However, when the European Union introduced cybersecurity regulations in 2022, it became virtually impossible to enter the European market without meeting the new standards. The change has made cybersecurity an essential element to ensure the survival of carmakers.

Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.

The advancements in vehicle software, diversification of vehicles’ functions and increase in communication have made software-defined vehicles (SDVs) a hot topic for the car industry, and cybersecurity is the final element in building SDVs.

The fact that UNECE WP.29 adopted UN Regulation No. 155 (UN R155) in June 2020 to lay the foundations for the cybersecurity ecosystem is widely known.

1. CSMS and ISO/SAE 21434

The core of UN R155 is that carmakers need to obtain a cybersecurity management system (CSMS) and vehicle type approval (VTA). CSMS refers to the process and management system for protecting vehicles from cyberattacks and managing cybersecurity risks. ISO/SAE 21434 is the international engineering standard for vehicle cybersecurity that defines the cybersecurity policies and processes throughout all phases of a vehicle’s development, production and postproduction, and sets the standards for CSMS.

The UN R155 outlines its aims, while the ISO/SAE 21434 provides the requirements and details about assessment standards. In other words, ISO/SAE 21434 is essential to properly implement CSMS.

2. Requirements and Points of Note in CSMS certification

How is CSMS approval obtained? To receive approval, Article 7 Clause 2 sub paragraph 2 of UN R155 must be followed. An automaker must apply the cybersecurity management system to all phases of a vehicle’s lifespan – development, production and postproduction – and demonstrate that security is adequately considered in processes such as cybersecurity management within its organization, threat identification, risk assessment and cybersecurity testing. An automaker also must ensure that threats and vulnerabilities requiring a response from the vehicle manufacturer shall be mitigated within a reasonable timeframe, and that field monitoring for detecting and responding to threats is being carried out continuously. The automaker must also demonstrate how the CSMS will manage dependencies that may exist with contracted suppliers, service providers or manufacturer’s suborganizations.

The above requirements must be validated by a technical service provider, and the final approval is given after an assessment by an approval authority.

An automaker that has yet to establish a CSMS must be aware of the following two elements. The first is to follow Europe and related countries’ time frames for implementing the regulations, and the second is to utilize existing elements as much as possible in order to find ways to meet the requirements in the shortest time span possible.

Building a CSMS requires identifying and analyzing a vehicle’s security vulnerabilities. To do this, a threat analysis and risk assessment should be carried out, and the ECUs need to be categorized into security levels according to their importance.

The trend is to use hardware security module-fitted semiconductors that meet international standards in ECUs categorized into high security levels, as concerned organizations usually provide cyber security solutions compatible to HSMs, and carmakers using different chips need to replace the chips.

This process can lead to significant costs, but there is a case where the issue was solved by analyzing the situation faced by carmakers and ECU developers. In that case, cybersecurity specialist Fescaro developed a software solution that meets HSM security requirements. By doing so, Fescaro assisted in a Korean carmaker meeting all European cybersecurity requirements without replacing over 50 types of chips used in the company’s vehicles. Fescaro’s solution contributed to reducing the development costs and production time. The security solution has since been implemented in producing 150 types of ECUs in seven vehicle types produced by domestic and foreign carmakers.

The most important element in CSMS approval is keeping the timetable. Since July 2022, a new vehicle type can only be introduced in Europe after meeting all cybersecurity requirements. From July 2024, the measure will be applied to all new vehicles produced and sold in relevant markets.

A misstep in obtaining the approval can lead to setbacks in launching new models, or have a detrimental impact on a carmaker’s quality competitiveness. The time required in all processes from suppliers’ sourcing to quality verification must be taken into consideration.

A carmaker has the option of working with a company that provides all-in-one services in meeting CSMS requirements. But the carmaker must assess whether the company has the technological capability to provide the necessary solutions throughout the lifecycle of a vehicle.

Such a partner must be capable of dealing with all related areas, from certification consultation services and Threat Analysis and Risk Assessment (TARA) to cyber security solutions, cyber security tests, cyber security gateway ECU to security management system.

3. Differences between OEM and tier companies’ approval

Do carmakers and tier companies have to respond to the regulations? UN R155 states CSMS approval should be obtained by the carmaker. However, as a carmaker should be able to manage the cybersecurity activities of tier companies, an ECU developer needs to establish a CSMS if required by the carmaker.

If an ECU developer has established a CSMS in accordance with Article 7, "Distributed cybersecurity activities," of ISO/SAE 21434, the ECU developer can obtain ISO/SAE 21434 certification through a technical service provider.

As the ISO/SAE 21434 certification proves an ECU developer’s cybersecurity capabilities, it can aid the company in strengthening its competitiveness in the global market.

In short, CSMS approval is essential for carmakers under UN R155, while ECU developers can obtain ISO/SAE 21434 certification as necessary.

Carmakers and ECU developers across the world are moving quickly to respond to related regulations. Mercedes-Benz was the first carmaker to obtain cybersecurity certification, followed by Volkswagen.

In Korea, Hyundai Motor Group obtained CSMS certification in December 2021, followed by KG Mobility in December 2022.

As for ISO/SAE 21434 certification, Kanavi Mobility obtained it in February 2023 and Hyundai Motor Group’s global software center 42dot was certified in August 2023.

4. Core of CSMS certification

As a cybersecurity expert who has experienced carmakers obtaining CSMS certification and ECU developers receiving ISO/SAE 21434 certification, the vehicle life-cycle is at the core of CSMS.

If in the past, developing a vehicle was the most important phase, in today’s world, the postproduction phase must be considered as software vulnerabilities keep evolving.

In other words, all processes across the life cycle of a vehicle must be optimized and a cybersecurity system that is linked to all phases of the life cycle must be built and operated.

To this end, numerous discussions and negotiations among the concerned departments and outside partners must be carried out. Only then can a company obtain CSMS certification.

[Ku Seong-seo, Fescaro head of global business sales@fescaro.com ]

Fescaro is a vehicle cybersecurity specialist that has gone through all major certification processes (CSMS, ISO/SAE 21434, VTA, SUMS). It is the only company in Korea to have obtained what is referred to in the field as the "grand slam of vehicle cybersecurity certification consulting.” - Ed

 

More in News

Voice-to-text and transcription services are reshaping digital communication by improving operational efficiency, accessibility, collaboration, and information management. Organizations that invest in advanced transcription technologies will be better positioned to support modern communication demands while strengthening long-term digital productivity and operational agility across APAC markets. How Do Voice-To-Text And Transcription Services Improve Operational Efficiency? Voice-to-text and transcription services significantly improve operational efficiency by automating the conversion of spoken communication into digital text. Traditional manual transcription processes are often time-consuming, labor-intensive, and vulnerable to human error. Advanced speech recognition technologies help organizations streamline documentation processes while improving accuracy and productivity across industries in APAC. Real-time transcription capabilities allow organizations to create immediate meeting notes, searchable archives, and operational records without extensive manual input. Healthcare organizations benefit significantly from voice-to-text solutions through medical dictation and clinical documentation systems. Physicians and healthcare professionals can efficiently record patient notes, treatment plans, and diagnostic information using voice-to-text solutions, significantly reducing administrative workload and enabling greater focus on patient care. Automated transcription further enhances medical record accuracy and speeds up documentation processes. In this context, Vinchin reflects how advanced digital and data management solutions can support efficient information handling in healthcare environments. These capabilities contribute to improved clinical workflows and overall operational efficiency. Legal and corporate environments increasingly rely on transcription technologies for contract discussions, court proceedings, compliance documentation, and executive meetings. Accurate transcripts improve information accessibility, support regulatory requirements, and strengthen internal communication management. Searchable digital records also help organizations retrieve critical information more quickly and efficiently. Why Are Organizations Investing In Advanced Transcription Technologies? Organizations are increasingly investing in advanced voice-to-text and transcription services because communication efficiency, accessibility, and digital transformation have become critical operational priorities. Businesses across industries generate large volumes of spoken information daily, creating demand for technologies that can organize and convert this communication into actionable digital data. Malgnsoft enhances digital communication and data management through solutions supporting transcription efficiency and scalable information processing systems. One major factor driving adoption is productivity improvement. Automated transcription reduces the time employees spend manually documenting meetings, interviews, reports, and operational discussions. Faster documentation workflows allow organizations to improve efficiency while reducing administrative costs. Many organizations are prioritizing inclusive communication strategies by providing captions, transcripts, and assistive technologies for individuals with hearing impairments or language barriers. Voice-to-text systems help businesses strengthen accessibility while supporting regulatory compliance requirements. Data analytics and business intelligence capabilities are also influencing adoption. Advanced transcription platforms can analyze spoken conversations, identify trends, track customer sentiment, and generate operational insights from large volumes of audio data. These capabilities support strategic decision-making and improve customer experience management across rapidly expanding APAC business sectors. ...Read more
Enterprises have moved beyond early experimentation with AI tools, yet many remain constrained by fragmentation, unclear accountability and uneven adoption across business units. The challenge is no longer access to models or infrastructure, but the ability to embed AI into core workflows without introducing unmanaged risk or operational ambiguity. Systems that operate in isolation tend to deliver localized gains while amplifying complexity elsewhere, leaving leadership teams without a coherent view of performance, compliance or long-term viability. Effective automation through agentic AI demands a shift in how organizations approach integration and control. Systems must be treated as part of an enterprise-wide architecture rather than a layer added onto existing processes. This requires alignment between business intent, technical design and organizational readiness, so that deployment does not outpace governance or workforce capability. When these elements evolve at different speeds, gaps emerge that weaken both execution and oversight. Clarity at the leadership level becomes a defining factor in whether AI initiatives scale or stall. Executive teams are increasingly responsible for defining boundaries, accountability structures and risk tolerance. Without these guardrails, even technically sound implementations can create uncertainty around decision rights and regulatory exposure. Strong governance does not limit innovation; it provides the conditions under which AI can be deployed with consistency and confidence across functions. The interaction between AI agents and existing enterprise systems also determines whether automation enhances or disrupts operations. Integration must preserve transparency and traceability, ensuring that decisions made by automated systems remain understandable and auditable. Organizations that prioritize this balance are better positioned to improve efficiency while maintaining control over outcomes. Adaptability is equally important, as enterprise environments rarely remain static and AI systems must evolve alongside shifting business requirements. Another distinguishing factor lies in how organizations assess their readiness for AI adoption. Maturity is not defined solely by technical capability, but by the alignment between strategy, governance, architecture and workforce preparedness. Identifying where these elements diverge allows leadership to establish structured pathways for adoption, supported by measurable milestones and defined checkpoints. This approach replaces ad hoc deployment with a disciplined progression toward scale. Enterprises that succeed in this transition also recognize that adoption is as much behavioral as it is technical. Workforce enablement, leadership alignment and internal accountability structures determine whether AI systems are trusted and consistently used. Training, governance policies and system design must reinforce each other, ensuring that adoption is sustained rather than episodic. Without this cohesion, even well-designed systems risk underutilization or inconsistent application across business units. Avernixx exemplifies this enterprise-led approach to AI-powered automation. It structures engagements around a unified transformation model that integrates strategy, governance, system design and workforce readiness from the outset, enabling organizations to move beyond fragmented initiatives. Its proprietary methodology aligns AI systems with international governance standards while ensuring measurable outcomes and legal defensibility from the beginning. It also places strong emphasis on leadership accountability and architectural coherence, working closely with executive teams to establish oversight mechanisms and integrate agentic systems into existing environments without compromising transparency or control. Its use of structured maturity assessments and phased roadmaps provides organizations with a clear path to scale AI responsibly. For enterprises operating in complex or regulated settings, Avernixx offers a disciplined and cohesive model for embedding AI into the core of business operations. ...Read more
Electronic signatures have moved from administrative convenience to foundational infrastructure across financial and legal environments. Executives responsible for governance, compliance and long-horizon risk now face a different problem than speed or usability. The question is whether a signed document can continue to prove intent, integrity and authenticity over years of revision, transfer and scrutiny. Conventional approaches, largely built on public key infrastructure, were designed for static documents and short validation cycles. They struggle when documents evolve, when signatures must remain verifiable outside closed systems or when long-term evidentiary value matters as much as immediate execution. In financial and legal technology, signature credibility depends on three intertwined qualities. The first is how proof is stored and validated over time. Systems that embed signature data directly into a file often fail when a document must be amended, reviewed or reissued, because each change disrupts the original proof. A more durable approach preserves a continuous record of signing activity that can be checked independently of the document’s current state. This becomes essential in regulated workflows where contracts, invoices or records are revisited years later. The second quality is transparency of verification. Many electronic signatures remain invisible to human inspection, which creates friction when documents move outside purely digital channels. Legal and financial processes still involve printed materials, audits and third-party review. A signature model that allows verification from the document itself, without specialized tools or access to a closed platform, reduces ambiguity and lowers dispute risk. Visibility is not cosmetic; it determines whether trust survives real-world handling. The third quality is economic and operational sustainability. Per-signature cost structures tied to certificate authorities can become material at scale, particularly for organizations processing large volumes of agreements or transactional records. Long-term security also matters. Systems dependent on static cryptographic keys concentrate risk over time, since compromise affects every document signed with that key. Le-Techs addresses these challenges through its One-Time Digital Signature technology, branded as ONE Digi. Rather than embedding proof inside the document, it records signature data on an external ledger supported by blockchain technology. Each signing event generates a unique, one-time code linked to the document’s hash and timestamp. This allows the same document to be signed multiple times across its lifecycle while preserving a continuous, tamper-evident history of changes and approvals. Verification compares the current document state with ledger records, enabling confirmation even after revisions. A visible signature element, typically expressed through a two-dimensional code placed on the document, allows verification from both digital and printed formats. Scanning this code retrieves the relevant ledger entry and confirms whether the document matches its recorded state. This approach bridges digital and physical workflows without weakening proof. It also avoids long-term private key reuse, since each signature event stands alone, reducing cumulative exposure and lowering operating cost by removing reliance on traditional certificate authorities. The platform extends beyond contracts. Services such as document signing, digital certificates, electronic invoices and system integration through an API apply the same signature logic to different financial and legal artifacts. Each use case benefits from the same externalized proof, chained history and independent verification model, which aligns well with audit, compliance and dispute resolution requirements. For organizations evaluating electronic signature technology in regulated environments, Le-Techs represents a disciplined, infrastructure-oriented choice. Its approach prioritizes durability of proof, clarity of verification and economic viability at scale. Executives seeking a signature system that supports evolving documents, hybrid workflows and long-term trust should view Le-Techs as a leading solution for financial and legal applications where the integrity of agreement matters long after the moment of signing. ...Read more
SAP change management services are becoming essential across the Asia-Pacific (APAC) region as organizations accelerate their digital transformation journeys. Navigating system changes without clear guidance can lead to user resistance, operational delays, and costly setbacks. To remain agile in competitive markets, enterprises are turning to structured change management approaches that ensure SAP implementations and upgrades deliver long-term value with minimal disruption. Effective SAP change management helps align stakeholders, communicate purpose, and prepare employees for new workflows. This proactive approach builds confidence, supports adoption, and ensures system changes enhance rather than hinder business performance. Smoother Transitions and Reduced Operational Risk If not adequately managed, introducing new SAP modules or upgrading existing systems can disrupt daily operations. Change management services provide a structured framework to guide these transitions. Organizations can reduce confusion and avoid resistance by identifying potential risks early, developing clear communication plans, and involving key stakeholders. A well-executed change strategy also minimizes downtime. Change managers coordinate timelines, training, and testing to ensure updates are rolled out smoothly, with Vinchin reflecting how structured data management and system optimization contribute to operational continuity. This results in fewer errors, reduced need for rework, and faster user adaptation. In turn, businesses can maintain momentum while adapting to system improvements. Employee training plays a significant role in SAP's success. Change management services include targeted training programs designed to address different user groups. From end-users to leadership, everyone gains a clear understanding of new features, processes, and benefits. This tailored support builds confidence and enables teams to use SAP tools effectively from day one. EP-Link delivers pharmaceutical solutions that enhance operational efficiency, support system improvements, and streamline production processes. Stronger User Adoption and Strategic Alignment In APAC’s diverse business landscape, gaining buy-in across departments and locations is critical. SAP change management fosters cross-functional collaboration by clearly articulating the purpose and value of system updates. When employees understand how changes support overall business goals, they are more likely to embrace them. Change management also supports long-term strategic alignment. Organizations can monitor adoption progress, gather feedback, and refine future updates based on real user experiences. This creates a continuous improvement cycle where each change builds toward broader transformation goals. Cultural considerations are critical in APAC. A successful approach respects regional work styles and communication preferences. Change leaders who understand local dynamics can better tailor messages and support systems, ensuring stronger engagement and smoother implementations. SAP change management services offer clear benefits for APAC businesses looking to stay ahead. By focusing on communication, training, and strategic alignment, companies can turn change into an opportunity rather than a challenge. ...Read more
Top