Consulting · Automotive

Automotive cybersecurity engineering for type approval and beyond.

ISO/SAE 21434, ISO 24089 and the Indian AIS 189 / AIS 190 requirements all point at the same thing: a demonstrable cybersecurity and software update management system, evidenced across the vehicle lifecycle. We help OEMs and suppliers build one that holds up under assessment.

ISO/SAE 21434
Cybersecurity engineering
ISO 24089
Software update engineering
AIS 189 / 190
India CSMS & SUMS

Standards in scope

  • ISO/SAE 21434

    Road vehicles — Cybersecurity engineering

  • ISO 24089

    Road vehicles — Software update engineering

  • AIS 189

    Cyber security and Cyber Security Management System (India)

  • AIS 190

    Software update and Software Update Management System (India)

Standards

One programme, four sets of requirements.

ISO/SAE 21434 and ISO 24089 give you the engineering process. AIS 189 and AIS 190 — India's CSMS and SUMS requirements, aligned with UN R155 and R156 — are what you are assessed against. We build the evidence once and map it across all four.

ISO/SAE 21434

Road vehicles — Cybersecurity engineering

The cybersecurity lifecycle for road vehicle E/E systems: organisational governance, project-level activities, TARA, and continuous cybersecurity activities through production, operations and decommissioning.

How we support you

  • Cybersecurity Management System (CSMS) design and rollout
  • TARA methodology and item-level threat analysis & risk assessment
  • Cybersecurity goals, claims, requirements and concept
  • Cybersecurity interface agreements (CIA) with suppliers
  • Cybersecurity case and assessment readiness
  • Distributed development and supplier capability assessment
ISO 24089

Road vehicles — Software update engineering

Requirements for engineering software updates safely and securely, covering the update campaign lifecycle, infrastructure, vehicle-side execution and the organisational processes behind them.

How we support you

  • Software Update Management System (SUMS) process definition
  • Update campaign design, risk analysis and release governance
  • Update infrastructure and back-end security requirements
  • Vehicle-side update integrity and rollback controls
  • Compatibility, dependency and configuration management
  • Evidence pack for update engineering activities
AIS 189

Cyber security and Cyber Security Management System (India)

The Indian automotive requirement for a CSMS covering vehicle cybersecurity across development, production and post-production — aligned in intent with UN Regulation No. 155.

How we support you

  • Gap assessment against AIS 189 CSMS requirements
  • Mapping of existing ISO/SAE 21434 evidence to AIS 189 clauses
  • Process and documentation remediation plan
  • Risk management and monitoring process for the vehicle fleet
  • Testing agency submission pack preparation
  • Internal readiness review before assessment
AIS 190

Software update and Software Update Management System (India)

The Indian automotive requirement for a SUMS, covering how software updates are recorded, validated, authorised and delivered to vehicles — aligned in intent with UN Regulation No. 156.

How we support you

  • Gap assessment against AIS 190 SUMS requirements
  • RXSWIN and software identification handling
  • Update authorisation, traceability and record-keeping processes
  • Mapping of ISO 24089 work products to AIS 190 clauses
  • Type-approval documentation support
  • Post-approval change and re-assessment guidance
Services

From gap assessment to assessment-ready evidence.

The same seven services run across every practice, so you can compare scope without re-learning the menu.

Risk assessment

Structured risk assessment to identify what can actually go wrong, how likely it is, and what it would cost you.

Advisory & consulting

Strategy, governance and architecture guidance shaped around your operating model rather than a template.

VA-PT & security testing

Vulnerability assessment and penetration testing, scoped so that testing never threatens availability.

Compliance & audit readiness

Gap analysis, evidence assembly and internal audit so the first challenge to your evidence is not the assessor's.

Implementation support

Turning designs into deployed controls — segmentation, hardening, access control and monitoring.

Security operations

Continuous monitoring, detection and incident response support suited to the environment's constraints.

Training & capability

Building internal capability so the programme keeps running after the engagement ends.

Where we get involved

Typical engagements.

Gap assessment

Where your current engineering process sits against ISO/SAE 21434, ISO 24089, AIS 189 and AIS 190 — with findings prioritised by approval risk, not volume.

TARA & risk analysis

Item definition, asset identification, threat scenarios, attack path analysis, impact and feasibility rating, and risk treatment decisions you can defend.

CSMS & SUMS build-out

Designing the management systems themselves — roles, process interfaces, work product templates and the governance that keeps them alive after go-live.

Product & ECU security

Security requirements for ECUs, gateways and connected platforms, secure boot and key management review, and verification against the cybersecurity concept.

Connected & OTA review

Back-end, telematics and OTA pipeline security review — how updates are signed, delivered, applied and rolled back without stranding a vehicle.

Assessment readiness

Cybersecurity case assembly, internal audit, and a dry-run assessment so the first time someone challenges the evidence, it isn't the testing agency.

Environments

Where we work

  • Passenger vehicle and commercial vehicle OEM programmes
  • Tier-1 and Tier-2 component suppliers
  • ECUs, domain controllers and central gateways
  • Telematics units, infotainment and connected services
  • OTA and software update back-ends
  • EV powertrain and charging interfaces
  • Manufacturing plant OT supporting vehicle production
  • Aftermarket and diagnostics interfaces
Work products

What you receive

  • Gap assessment report with clause-level traceability across all four standards
  • TARA register and supporting analysis work products
  • Cybersecurity plan, concept and requirement specifications
  • CSMS and SUMS process documentation and templates
  • Cybersecurity case structured for assessment
  • Remediation roadmap with owners, effort and sequencing
Consulting enquiries

Preparing for AIS 189 / AIS 190 assessment?

Send us where you are — programme stage, existing ISO/SAE 21434 work and your target approval date — and we'll come back with a realistic path.

Raise an enquiry otfuriouswarrior@svratechcyber.com