Cybersecurity management system audit
Required for type approval of new vehicle types since 2022; all new vehicles since 2024-07. The CSMS itself is the artefact under audit.
One orchestrator for ISO/SAE 21434, UN R155, EU CRA, ISO/IEC 27001 and NIST CSF. Deterministic TARA, evidence with provenance, and audit-grade traceability - across nine domains, in one operating model.
Type-approval clocks are running. UN R155 already requires a certified CSMS for new vehicle types. The EU CRA enters full enforcement in December 2027 - with a 24-hour reporting window for actively-exploited vulnerabilities that starts ticking now. Meanwhile your TARAs, SBOMs, audits, incidents, evidence and decisions live in eight different tools.
CSMS Orchestrator is the management-system layer that ties them together: deterministic risk derivation, content-addressed evidence, branched editing, and a process engine that actually runs. Use it alongside the tools you already have - or as your standalone CSMS - on day one.
Required for type approval of new vehicle types since 2022; all new vehicles since 2024-07. The CSMS itself is the artefact under audit.
Conformity assessment, technical documentation, secure-by-design, security-update policy, vulnerability handling. 24h / 72h reporting windows precede the main obligations.
Damage scenarios, threat scenarios, attack feasibility, risk values, treatment. Every override carries a rationale; every snapshot is reproducible.
The orchestrator is built in deliberate layers: a canonical data model at the foundation, deterministic engines per domain above it, a coordination module that resolves interdependencies and runs the event bus, and an editorial UI on top. [FR-ENG]
Standards are data, not code. Adopting UN R155 or the CRA is a row in a catalog that derives obligations, applicable risk methods, required evidence and downstream workflows into every domain that needs them. Un-adopt and they gracefully fall to not-applicable - your tenant work is preserved. [STD-021]
Each domain is a real engine with real records - not a tab. Foundational domains (Governance, Asset/Product) carry the others; operational domains hard-depend on them so cross-domain rollups always work.
Select your standards and regions. The orchestrator derives obligations, policy requirements, applicable risk methods, required evidence types and downstream workflows - into every domain that consumes them. No code change.
Author processes in the orchestrator's flow editor. They compile to an n8n workflow that actually runs - schedules, webhooks, triggers, the lot. Executions mirror back as real ProcessRuns with per-step traceability.
Every governed artefact - policy, process, method, risk model, decision - is content-addressed and branchable. Edit in a per-user draft, open a branch, compare with a tagged release, restore at any commit. Audit-grade out of the box.
Industry-agnostic by design. The catalog covers automotive, software, industrial, healthcare, energy and ICT regulation across the EU, US, UK, Japan and China - and grows with each tenant. Each catalog entry materialises as an external_framework row with its clauses as external_requirement rows; applicability is decided per scope (organisation, product, release, supplier, asset) and rolled up into a compliance case.
Mock-mode out of the box
Talk to us about live tenants
Pricing on request
All tiers include the full data model, content-addressed evidence ledger, and the OpenAPI 3.0 surface. Annual prepay only on Team and above. Public-sector / academic discounts available.
We'll spin up a tenant pre-loaded with your industry, region and standards selection, then walk through a real TARA, a real audit pack, and a real n8n-executed process - in your domain.
Book a demo via emailBerlin / Detroit / Tokyo