The ENX Association's Vehicle Cybersecurity (VCS) audit program focuses on standardized audits for cybersecurity management systems (CSMS) in the automotive sector, based on ISO/PAS 5112 and ISO/SAE 21434, and offers certification via the ENX platform upon successful testing by providers such as TÜV NORD.
Request Offer
As digitalisation and networking in the automotive sector progresses, the risk of cyberattacks is growing. As a result, increased requirements for the cyber security of electrical and electronic (E/E) systems for vehicles are characterising the entire automotive industry supply chain. This development is being driven by the increasing use of digital technologies in vehicle systems, including automated driving and the connectivity of vehicles with the road infrastructure, other vehicles or data centres.
Vehicle Cybersecurity (VCS) is a new audit programme from the ENX Association aimed at cybersecurity in the automotive sector. It aims at standardised audits for Cybersecurity Management Systems (CSMS) and implements ISO/PAS 5112 in the context of ISO/SAE 21434, using the existing and established audit framework of the ENX Association.
Upon successful verification by participating audit providers, such as TÜV NORD, ENX issues a VCS certification on its exchange platform.
The ENX VCS audit programme was primarily designed for automotive suppliers involved in the development, production or maintenance of electrical and electronic systems for road vehicles. The requirements for a cybersecurity management system are set out in particular in UNECE Regulation No. 155 (R 155), which applies to automotive manufacturers (OEMs) and their suppliers.
UNECE Regulation No. 155 (R 155) is an international regulation aimed at ensuring the cybersecurity of road vehicles. It requires all motor vehicle manufacturers (OEMs) to provide evidence of the successful assessment of their cybersecurity management system in the form of a Certificate of Compliance (CoC). In this regard, OEMs rely on support from their suppliers, as the security of the components is transferred to the vehicle. Only by securing the supply chain can a cyber-secure vehicle be produced. Suppliers must therefore also provide evidence to the OEMs. Since 2023, OEMs have been requiring their suppliers to provide evidence that a cybersecurity management system has been implemented.
Here at TÜV NORD CERT, we have extensive expertise and experience in the field of automotive cybersecurity. Do you have any questions about the audit programme? If so, please do not hesitate to contact us.
With TISAX®, ENX has already established a cross-company assessment and exchange procedure for information security in the automotive industry. The proven processes and experience gained from the TISAX® assessment were integrated into the development of the new VCS audit programme. The award of the ENX VCS certification confirms that the highest cyber security requirements are met. This includes the requirements of standards such as ISO/SAE 21434 and ISO/PAS 5112 as well as the UNECE regulation.
An effective cybersecurity management system covers all relevant phases of the vehicle life cycle. Depending on the type and area of application of a product, system or component, different scope categories may be relevant. Identifying the relevant phases and implementing the corresponding cybersecurity requirements are crucial for successful ENX VCS certification.
Scope differentiation is carried out in accordance with the guidelines of ENX VCS certification and is based on the requirements of ISO/SAE 21434. Organisations can seek certification for individual phases or for the entire life cycle in order to safeguard their processes and areas of responsibility.
The scope differentiation corresponds to the audit objectives of an ENX VCS certification. These correspond to the phases of the vehicle life cycle as defined in ISO/SAE 21434.
A distinction is made between three key scope categories:
In principle, every product (or ‘Protection Object’, as ENX terms it) goes through these phases. However, implementation varies depending on the type of product. In some cases, an organisation may carry out only one of these phases before handing the protection object over to the next organisation for further processing. These transition phases are particularly critical for cybersecurity and are therefore scrutinised closely.
Our experts are available to answer any questions you may have regarding the relevant scope categories and requirements of ENX VCS certification.
TÜV NORD is a renowned service provider for a large number of national and international audit and certification programmes. We have been accredited for IATF 16949 and ISO 27001 for many years and are a long-standing audit provider for TISAX®.
Note: TÜV NORD CERT GmbH is authorised by ENX to offer VCS audit services. The brands and trademarks associated with the VCS audit programme or TISAX® and the associated intellectual property belong to ENX.
No. Upon successful verification by participating audit providers, such as TÜV NORD, a VCS certification is issued by ENX Association - the administrator of the VCS audit programme - in its database.
TÜV NORD CERT was involved in the development of the ENX VCS programme from the very beginning and carries out the corresponding audits. Valuable experience gained during the global pilot phase is therefore incorporated into the application of the audit programme.
The prerequisite for an ENX VCS audit is a TISAX® label with assessment level 2 or 3.
In principle, UNECE Regulation R 155 applies to all new vehicle types that are developed from July 2022 and produced and placed on the market in the EU from July 2024.
ISO/SAE 21434 is an international standard that defines requirements for cybersecurity management in the automotive industry. It sets out how risks relating to vehicle cybersecurity should be identified and managed throughout a vehicle’s entire life cycle.
The ENX VCS audit programme builds on the requirements of ISO/SAE 21434 and verifies whether organisations are effectively implementing this standard within their processes and structures. Whilst ISO/SAE 21434 forms the basis for a cybersecurity management system, the ENX VCS audit serves as evidence to OEMs and regulatory authorities that the requirements of UNECE R 155 are being met.
In summary:
ISO/SAE 21434: sets out the cybersecurity requirements for the automotive industry
ENX VCS: assesses and confirms the implementation of these requirements through an audit
Further information on ISO/SAE 21434 can be found here.
A combined audit of both standards makes it possible to meet all the requirements of international OEMs. Our sales team will be happy to explain the relevant options and procedural steps to you.
TÜV NORD CERT is an internationally recognised and reliable partner for testing and certification services. Our experts and auditors possess in-depth knowledge and are all permanently employed by TÜV NORD. This ensures independence, neutrality and continuity in the support we provide to our clients. The benefit for you is clear: our auditors guide and support the development of your business and provide you with objective feedback.