Automotive Cybersecurity Compliance: ISO/SAE 21434 & UN R155/R156
The vehicle cybersecurity regulatory regime: ISO/SAE 21434 engineering process, UN R155 CSMS type-approval, R156 software-update management, and what suppliers must produce to keep programs moving.
Get notified when this course is scheduled
One email when dates are set. Or skip the wait: run it as a private cohort, on-site at your plant.
- One email, no sequence
- Never shared
- Reply within one business day
Faculty
Faculty details for this seminar will be announced with the full schedule.
Fees
Early: $1,895 (payment 4+ weeks ahead)
Standard: $2,095 (check/ACH) · $2,165 (card)
Group discount: $200 off per attendee for 3+ from the same organization.
Also Available
- Corporate on-site delivery at your facility
- Private cohort sessions
- Digital curriculum licensing
Seminar Overview
UN R155 made cybersecurity a type-approval matter: no certified CSMS, no market access. This seminar teaches the supplier-side compliance stack: ISO/SAE 21434's engineering process (item definition, TARA, cybersecurity goals, verification), UN R155's CSMS certification requirements, and R156's software-update management system — taught for the component engineer who must produce the artifacts, not the policy student who must read them.
The TARA (threat analysis and risk assessment) gets workshop treatment: threat scenarios on a real component (a connector, a valve, a body controller), attack-path analysis, risk values, and the mitigation traceability into design requirements. The documentation half covers the work products R155 auditors and OEM customers actually request: cybersecurity interface agreements (IAs), the CSMS evidence pack, and the component-level cybersecurity case that rolls up into the vehicle's type approval.
Corpus grounding is direct: the ETS knowledge base holds UNECE R155/R156/R157 full text — taught from the regulation, not a summary of it.
Ideal Learner
- Component and system engineers facing R155/21434 obligations
- Cybersecurity engineers entering automotive
- Quality and program managers assembling CSMS evidence
- Supplier program leads signing cybersecurity interface agreements
Learning Objectives
- Explain the R155/R156/21434 stack and who owes what
- Build and defend a component-level TARA
- Assemble the CSMS evidence pack and interface agreements
- Integrate cybersecurity requirements into DVP&R and PPAP flow
- Manage the post-production (R156) update and monitoring obligations
Consulting Sessions
Seminar attendees can sign up for individual consulting sessions with the instructor. Sessions are free for registered attendees, first-come first-served — sign up when registering by calling 248-539-0473 or during the seminar.
Seminar Outline
- UN R155: CSMS certification and type approval
- UN R156: SUMS and update management
- ISO/SAE 21434: the engineering process underneath
- Who owes what: OEM vs. Tier-1 vs. Tier-2
- Item definition and threat scenarios
- Attack-path analysis on a real component
- Risk values and mitigation traceability
- From TARA to design requirements
- Cybersecurity interface agreements: reading and negotiating
- The CSMS evidence pack: what auditors request
- Component cybersecurity case roll-up
- Integration into DVP&R/PPAP documentation
- R156 update management for components
- Monitoring, incident response, and the feedback loop
- Field-monitoring data and its design feedback
- Full TARA on a supplied component
- Evidence-pack assembly drill
- Audit-simulation Q&A
More in Track J — Global Compliance & Aerospace Quality
- J-01 · FMVSS & U.S. Automotive Safety Standards — 3-day · Advanced
- J-02 · EU/UNECE Homologation & Global Regulations — 3-day · Advanced
- J-03 · AS9100 Aerospace Quality & First-Article Inspection — 3-day · Advanced