Contact

What are you looking for?

Automotive Cybersecurity Audits, Assessments and Certification

All the automotive cybersecurity audit, assessment and certification services you need to prove systems and components meet ISO/SAE 21434 standard.

An increase in vehicle connectivity and automated cars brings with it an increase in the risk and the potential of cyber-attacks. ISO/SAE 21434 is a cybersecurity-specific standard that provides a structured process to ensure cybersecurity is embedded into automotive products and their manufacture, throughout their lifetime.

To meet the requirements of ISO/SAE 21434, automotive manufacturers and suppliers must prove correct and complete implementation from development to the final product. As an accredited body for ISO/SAE 21434 we can assist with the following services:

  • Process audits

    A process audit reviews the development process by checking the existence of generic document templates, associated process descriptions, a cybersecurity management system (CSMS), an incident response process and a practiced security culture. The audit usually takes one to two days and will be guided by a process description review and is documented in an audit log. Anything that is found to be missing is then addressed, after which a technical report and, if required, a certificate is issued.

  • Product assessments

    This assesses the finished product’s capabilities to defend against cyberattacks through preventive measures, according to standard ISO/SAE 21434. All the required product documentation is recorded and reviewed, and the results are documented and made available to the customer. Once again, there is opportunity for any missing stages or documents to be addressed. After this, a technical report is issued which contains the final cybersecurity assessment. A product certificate can also be acquired if needed.

  • Certification

    Certification underlines your claim to have carried out a security evaluation with the greatest possible independence. At the same time, it enables your customers to see the achieved level of embedded cybersecurity at a glance. The certification is based on a technical report on the audit or the assessment and can be carried out for both. The Cybersecurity Assurance Level (CAL) is currently irrelevant, as its use is only considered informative according to ISO/SAE 21434.

  • Testing

    ISO/SAE 21434 also recommends that dedicated tests, such as penetration tests and fuzz tests, are carried out for a cybersecurity assessment. We are happy to offer these in our cyber labs if required.

SGS and cybersecurity for automotive
We are the global leader in testing and verification services, and we are at the forefront of cybersecurity and S4S standardization. As such, we are perfectly placed to perform all the audits, assessments and certification services you need for cybersecurity standards, including ISO/SAE 21434.

Related Services

More Services

News & Insights

  • SGS - China - Beijing

16th Floor, Block A, No.73 Fucheng Road, Century Yuhui Mansion, Haidian District, Beijing,

Beijing, Beijing Municipality,

China