Overview
This three-day course is designed to build practical knowledge and application of ISO/SAE 21434:2021—the international standard for cybersecurity in road vehicles. SRES instructors lead this training as senior industry practitioners with experience implementing safety and security processes across global OEM and supplier development programs. Participants will learn how to embed cybersecurity throughout the lifecycle of electrical and electronic systems, from concept development to decommissioning.
This live training includes lectures, interactive discussions, and practical exercises. An optional certificate exam to become a Certified Automotive Cybersecurity Professional (CACSP, SGS-TÜV Saar) is offered on the afternoon of Day 3.
Intended Audience
This training is intended for engineers, managers, and technical leaders involved in automotive product development, cybersecurity, or regulatory compliance. It is particularly relevant for:
- Systems, software, hardware, and cybersecurity engineers working on road-vehicle electrical and electronic systems
- Product cybersecurity managers, security architects, and professionals responsible for Cybersecurity Management Systems (CSMS)
- Engineering managers and technical leads overseeing cybersecurity activities across the vehicle lifecycle
- Professionals conducting or reviewing Threat Analysis and Risk Assessment (TARA)
- Quality, compliance, and assessment professionals supporting ISO/SAE 21434 or UNECE R155 implementation
- Automotive OEM and supplier personnel responsible for cybersecurity interfaces, requirements, and assurance activities
Objectives
By the end of this course, participants will be able to:
- Understand the scope and goals of ISO/SAE 21434:2021
- Implement key elements of a Cybersecurity Management System (CSMS)
- Perform and evaluate TARA techniques
- Integrate cybersecurity into each phase of the vehicle development lifecycle
- Compare ISO/SAE 21434 with functional safety and other automotive standards
Agenda
Below you will find an outline of the training course schedule.
DAY 1 — Foundations of Automotive Cybersecurity & Regulatory Standards
- Introduction to Automotive Cybersecurity
- Current Threat Landscape
- Security motivation in connected vehicle systems
- Core concepts and terminology
- Assets, threats and damage scenarios
- Security properties
- Threat modeling and risk foundations
- STRIDE-based threat modeling
- Attack path analysis
- CVSS and vulnerability classification
- Introduction to ISO/SAE 21434
- Scope, structure, and objectives of the standard
- Relationship to functional safety
DAY 2 — Cybersecurity Management and Development Lifecycle
- Cybersecurity Management Systems (CSMS)
- Cybersecurity governance, culture & information sharing
- Supporting systems: configuration, update, requirements & tool management
- Cybersecurity audits: planning and execution
- Security Development Lifecycle (SDL) – Part 1
- Initiation phase: relevance check, plan tailoring, reuse analysis
- Concept phase: item definition, TARA, cybersecurity concept
DAY 3 — From Design to Operations: Implementation & Compliance
- Security Development Lifecycle (SDL) – Part 2
- Design phase: Cybersecurity specification and architectural design
- Verification & validation
- Cybersecurity case
- Post-Development Activities
- Securing production, operations and maintenance
- Incident response management & secure software updates
- Supplier Collaboration & Continuous Activities
- Cybersecurity Interface Agreement and role distribution
- Continuous monitoring, event evaluation, vulnerability management
- Optional deep-dive modules
- UN/ECE R-155 – Type approval and regulatory requirements
- Automotive SPICE for Cybersecurity
- CACSP Certificate Exam (Optional – Afternoon)

