A Cybersecurity Management System is the organisational machinery — policies, processes, roles, competence, and resources — through which a company governs cybersecurity risk across the full vehicle lifecycle: development, production, and post-production. ISO/SAE 21434 Clause 5 defines its content: a cybersecurity policy and organisation-specific rules, assigned responsibilities, competence and awareness management, a continual-improvement loop, and standing processes for risk management, information sharing, vulnerability handling, and incident response. Clause 6 makes each project instantiate the system through a Cybersecurity Plan, and Clause 7 extends it across the supply chain through Cybersecurity Interface Agreements that allocate activities between customer and supplier. UNECE R155 is what makes the CSMS mandatory: an approval authority or its technical service assesses the manufacturer's CSMS and issues a Certificate of Compliance valid for up to three years, and without a valid certificate no vehicle type can be approved in adopting markets. The obligation formally lands on the vehicle manufacturer, but it cascades in practice — an OEM can only evidence a working system if its suppliers run compatible processes, so Tier-1 and Tier-2 suppliers build ISO/SAE 21434-aligned CSMS capability to stay sourceable. The CSMS also has siblings: UNECE R156 requires the equivalent management system for software updates (SUMS), and suppliers in scope of the EU's NIS2 directive face organisational cybersecurity duties that overlap with, but do not replace, CSMS requirements. A CSMS is deliberately a management system, not a project artefact — the TARA, Cybersecurity Concept, and Cybersecurity Case each project produces are outputs of the system working, not substitutes for it.
Why it matters
The CSMS is the certificate everything else hangs from — no CSMS Certificate of Compliance, no type approval, no market entry. Building one is less about writing policies than about making risk management, vulnerability handling, and incident response actually run between assessments, with evidence that accumulates instead of being reconstructed. A 2–4 week gap analysis against ISO/SAE 21434 Clause 5 is the standard starting point for organisations that need a certification path.