Automotive cybersecurity engineering for type approval and beyond.
ISO/SAE 21434, ISO 24089 and the Indian AIS 189 / AIS 190 requirements all point at the same thing: a demonstrable cybersecurity and software update management system, evidenced across the vehicle lifecycle. We help OEMs and suppliers build one that holds up under assessment.
- ISO/SAE 21434
- Cybersecurity engineering
- ISO 24089
- Software update engineering
- AIS 189 / 190
- India CSMS & SUMS
Standards in scope
ISO/SAE 21434
Road vehicles — Cybersecurity engineering
ISO 24089
Road vehicles — Software update engineering
AIS 189
Cyber security and Cyber Security Management System (India)
AIS 190
Software update and Software Update Management System (India)
One programme, four sets of requirements.
ISO/SAE 21434 and ISO 24089 give you the engineering process. AIS 189 and AIS 190 — India's CSMS and SUMS requirements, aligned with UN R155 and R156 — are what you are assessed against. We build the evidence once and map it across all four.
Road vehicles — Cybersecurity engineering
The cybersecurity lifecycle for road vehicle E/E systems: organisational governance, project-level activities, TARA, and continuous cybersecurity activities through production, operations and decommissioning.
How we support you
- Cybersecurity Management System (CSMS) design and rollout
- TARA methodology and item-level threat analysis & risk assessment
- Cybersecurity goals, claims, requirements and concept
- Cybersecurity interface agreements (CIA) with suppliers
- Cybersecurity case and assessment readiness
- Distributed development and supplier capability assessment
Road vehicles — Software update engineering
Requirements for engineering software updates safely and securely, covering the update campaign lifecycle, infrastructure, vehicle-side execution and the organisational processes behind them.
How we support you
- Software Update Management System (SUMS) process definition
- Update campaign design, risk analysis and release governance
- Update infrastructure and back-end security requirements
- Vehicle-side update integrity and rollback controls
- Compatibility, dependency and configuration management
- Evidence pack for update engineering activities
Cyber security and Cyber Security Management System (India)
The Indian automotive requirement for a CSMS covering vehicle cybersecurity across development, production and post-production — aligned in intent with UN Regulation No. 155.
How we support you
- Gap assessment against AIS 189 CSMS requirements
- Mapping of existing ISO/SAE 21434 evidence to AIS 189 clauses
- Process and documentation remediation plan
- Risk management and monitoring process for the vehicle fleet
- Testing agency submission pack preparation
- Internal readiness review before assessment
Software update and Software Update Management System (India)
The Indian automotive requirement for a SUMS, covering how software updates are recorded, validated, authorised and delivered to vehicles — aligned in intent with UN Regulation No. 156.
How we support you
- Gap assessment against AIS 190 SUMS requirements
- RXSWIN and software identification handling
- Update authorisation, traceability and record-keeping processes
- Mapping of ISO 24089 work products to AIS 190 clauses
- Type-approval documentation support
- Post-approval change and re-assessment guidance
From gap assessment to assessment-ready evidence.
The same seven services run across every practice, so you can compare scope without re-learning the menu.
Risk assessment
Structured risk assessment to identify what can actually go wrong, how likely it is, and what it would cost you.
Advisory & consulting
Strategy, governance and architecture guidance shaped around your operating model rather than a template.
VA-PT & security testing
Vulnerability assessment and penetration testing, scoped so that testing never threatens availability.
Compliance & audit readiness
Gap analysis, evidence assembly and internal audit so the first challenge to your evidence is not the assessor's.
Implementation support
Turning designs into deployed controls — segmentation, hardening, access control and monitoring.
Security operations
Continuous monitoring, detection and incident response support suited to the environment's constraints.
Training & capability
Building internal capability so the programme keeps running after the engagement ends.
Typical engagements.
Gap assessment
Where your current engineering process sits against ISO/SAE 21434, ISO 24089, AIS 189 and AIS 190 — with findings prioritised by approval risk, not volume.
TARA & risk analysis
Item definition, asset identification, threat scenarios, attack path analysis, impact and feasibility rating, and risk treatment decisions you can defend.
CSMS & SUMS build-out
Designing the management systems themselves — roles, process interfaces, work product templates and the governance that keeps them alive after go-live.
Product & ECU security
Security requirements for ECUs, gateways and connected platforms, secure boot and key management review, and verification against the cybersecurity concept.
Connected & OTA review
Back-end, telematics and OTA pipeline security review — how updates are signed, delivered, applied and rolled back without stranding a vehicle.
Assessment readiness
Cybersecurity case assembly, internal audit, and a dry-run assessment so the first time someone challenges the evidence, it isn't the testing agency.
Where we work
- Passenger vehicle and commercial vehicle OEM programmes
- Tier-1 and Tier-2 component suppliers
- ECUs, domain controllers and central gateways
- Telematics units, infotainment and connected services
- OTA and software update back-ends
- EV powertrain and charging interfaces
- Manufacturing plant OT supporting vehicle production
- Aftermarket and diagnostics interfaces
What you receive
- Gap assessment report with clause-level traceability across all four standards
- TARA register and supporting analysis work products
- Cybersecurity plan, concept and requirement specifications
- CSMS and SUMS process documentation and templates
- Cybersecurity case structured for assessment
- Remediation roadmap with owners, effort and sequencing
Preparing for AIS 189 / AIS 190 assessment?
Send us where you are — programme stage, existing ISO/SAE 21434 work and your target approval date — and we'll come back with a realistic path.