Cybersecurity Audit and Assessment
UNECE Regulation 155 addresses the rising number of cyberattacks and demands for verifiable cybersecurity along the supply chain - from OEM to system, software and hardware supplier - as a basis for homologation. Cybersecurity must be demonstrated by means of Cybersecurity Management System (CSMS) Audits, focusing on the Cybersecurity Process definition, as well as Cybersecurity Assessments, focusing on the cybersecurity of individual products.
Together reproduceable cybersecurity can be proven across the entire lifecycle - from concept and development through production and maintenance to decommissioning.
Cybersecurity Audit and Assessment
CSMS Audit
A CSMS Audit focusses on the Cybersecurity Process definition in organizations across the supply chain. Based on ISO/PAS 5112:2022 and ISO 19011:2018, a CSMS Audit evaluates the achievement of the objectives of ISO/SAE 21434:2021.
The CSMS Audit thereby focuses on the process implementation as well as the process effectiveness, which are evaluation by document review and interview sessions. The Audit result is summarized in an Audit report stating the audit approach, evaluated evidence, as well as identified strengths and weaknesses.
A successful CSMS Audit leads to a CSMS Audit Certificate, which can be used as evidence in the supply chain.


Cybersecurity Assessment
A Cybersecurity Assessment focusses on the Cybersecurity of specific products, based on the requirements of ISO/SAE 21434:2021.
The Cybersecurity Assessment thereby focusses on the compliance to the individual requirements as well as on the achieved cybersecurity of the product, which are evaluated by document review and interview sessions based. The Assessment result is summarized in an Assessment report stating the assessment approach, evaluated evidence, as well as identified strength and weaknesses.
A successful Cybersecurity Assessment leads to a recommendation for acceptance for this product, which can be used as evidence in the supply chain.


Vector Consulting offering
With over twenty years of experience in cybersecurity, Vector Consulting supports you with:
- CSMS Audit according to ISO/PAS/5112:2022 including CSMS Audit Report and Certificate
- Cybersecurity Assessment according to ISO/SAE 21434:2021 including Assessment Report
- Iterative approach with Pre-Audit before the final CSMS Audit and Cybersecurity Gap-Analysis before the final Cybersecurity Assessment provides predictability
- Our ISO 19011 qualified Auditors and Assessors have extensive cybersecurity experience across domains
- Cybersecurity Audits and Assessments can be conducted onsite, virtual as well as hybrid setup
- Cybersecurity Audit and Assessments results contain systematic ratings, risks and recommendations for improvements
Reference Project: CSMS Audit
Identification of status quo of CSMS implementation and definition of improvement measures
Reference Project: Cybersecurity Assessment
Identification of status quo of ISO21434 compliance and cybersecurity implementation in specific product and definition of improvement measures

