Cybersecurity That Clears Type Approval

For an OEM, cybersecurity isn't just engineering any more. It decides whether a vehicle can be sold at all. We help you build, prove and maintain the CSMS and SUMS that UN R155/R156 and AIS-189/190 require, from concept all the way to fleet.

No Approved CSMS, No Market

Under UN R155/R156, you can't get type approval for a new vehicle without an approved Cybersecurity Management System (CSMS). AIS-189/190 puts the same gate in front of the Indian market. Miss it, and the vehicle simply can't be sold.

That turns cybersecurity from an engineering line item into a board-level launch risk. The question leadership is really asking isn't “are we secure?” It's “will this clear homologation, on time, in every market we sell in?”

Cybersecurity is now a homologation gate. We treat it as one, mapping the CSMS and SUMS work onto your type-approval timeline, so it clears the assessment instead of holding up the launch.

Everything an OEM Needs, Across the Vehicle Lifecycle

Secure-by-Design & TARA

Security built in from concept, with ISO/SAE 21434-aligned threat analysis for each vehicle type.

Explore TARA

Vehicle-Level Security Testing

Our own penetration and fuzz testing across ECUs, gateways, telematics, V2X and OTA.

Explore testing

CSMS & SUMS Implementation

We stand up the management systems UN R155/R156 require and map them to how you already work.

UN R155 / R156

AIS-189/190 for India

India-specific CSMS/SUMS readiness, run in step with your global UN R155/R156 programme.

AIS-189/190

Threat Intelligence & Vulnerability Monitoring

24/7 monitoring and response after launch, meeting UN R155/R156's duty to watch the vehicle for life.

Explore Monitoring

security.core Platform

Automated testing, threat intelligence and SBOM monitoring, all in one place.

Explore the platform

From Concept to Type Approval, and Beyond

  1. Assess

    TARA plus a CSMS/SUMS gap analysis for the vehicle programme, so you know where you stand.

  2. Build

    Security requirements, architecture, and the management-system processes auditors will look for.

  3. Test

    Penetration and fuzz testing at vehicle and component level, with the evidence captured as you go.

  4. Certify

    Audit prep and hands-on support through the technical service assessment for type approval.

  5. Monitor

    Continuous monitoring and response across the vehicle's working life.

    Never stops

Built to Stand Up in the Boardroom and the Audit

Trusted by leading automotive manufacturers and suppliers.

OEM Cybersecurity, Common Questions

No. Under UN R155/R156, an approved Cybersecurity Management System is a precondition for type approval, and AIS-189/190 sets the same bar for the Indian market.
They're separate approvals, but most of the CSMS work overlaps. We run them together so you're not doing the same work twice for different markets.
With continuous monitoring. Our 24/7 monitoring and response, backed by threat.core, puts UN R155/R156's duty to detect and respond across the vehicle's life into practice.
Yes. We test at vehicle and component level, and help you pass ISO/SAE 21434 expectations down to your supply chain.

Make Cybersecurity Your Launch Enabler, Not Your Blocker

Start with a gap assessment. We measure your programme against UN R155/R156, AIS-189/190 and ISO/SAE 21434, and you walk away with a prioritised, board-ready roadmap to type approval.