Cybersecurity evidence through the supply chain
Tier-1 suppliers contractually pass their OEM customer’s UN-R155 CSMS obligations down to Tier-2 and Tier-3. Anyone delivering automotive software without a documented ISO/SAE 21434-conformant engineering process — TARA, threat catalog, vulnerability management, secure development lifecycle — fails supplier audits. The evidence is not a “nice to have” certificate, it is a precondition for the next framework agreement. Equally demanded: a TISAX assessment level (AL2 or AL3, valid three years) covering information security of the development environment itself.