EFS Consulting
Looking for US-specific information? Visit our US site for content tailored to the US market.
08/14/2026

ENX Vehicle Cyber Security Audit (VCS Audit): Cybersecurity Certification for the Automotive Industry

As the digitalisation, connectivity and software integration of modern vehicles continue to increase, so do the requirements for cybersecurity in the automotive industry. To address these requirements, companies operate a Cyber Security Management System (CSMS) to systematically manage risks relating to vehicle software, electronic control units and production systems. This insight provides an overview of the ENX Vehicle Cyber Security Audit (ENX VCS), a standardised audit process with an assessment catalogue for Cyber Security Management Systems based on automotive standards and highlights its strategic benefits.

Table of contents

Key Takeaways  

  • The ENX Association is a trusted organisation that promotes standardised information security requirements and helps reduce redundant supplier audits in the automotive industry.
  • The ENX Vehicle Cyber Security Audit assesses the effectiveness of a CSMS and its ability to address cybersecurity risks affecting vehicle communication systems.
  • ISO/SAE 21434 defines requirements for a vehicle CSMS, while ISO/PAS 5112 describes the corresponding audit approach. ENX VCS is based on both standards for its requirements and audit methodology.

  • TISAX® is an internationally recognised information security assessment scheme in the automotive industry, based on ISO 27001. A TISAX® assessment is a prerequisite and serves as a foundation for ENX VCS.

 

Foundations of the ENX Vehicle Cyber Security Audit

The increasing connectivity of modern vehicles expands the attack surface for cyber threats and presents manufacturers and suppliers with new challenges. Cybersecurity must therefore be systematically addressed throughout the entire vehicle lifecycle, from development and production through to operation and maintenance.

In response to these requirements, Vehicle Cybersecurity Management Systems (V-CSMS) have become a fundamental part of vehicle cybersecurity. A V-CSMS defines the organisational and technical processes used by companies to identify, assess, mitigate and continuously monitor cyber risks.

With the introduction of UNECE R155 and R156, Cyber Security Management Systems (CSMS) and Software Update Management Systems (SUMS) became regulatory requirements for the first time. In addition, ISO/SAE 21434 defines requirements for the implementation of vehicle cybersecurity processes, while ISO/PAS 5112 provides guidelines for auditing a V-CSMS.

In practice, however, different audit approaches and assessment methods have made the consistent and comparable verification of cybersecurity requirements more difficult. In response to these challenges, the ENX Association, together with experts from OEMs (Original Equipment Manufacturers), suppliers and service providers, developed ENX VCS. The goal of this framework is to assess cybersecurity processes across the automotive supply chain in a standardised, transparent and comparable manner.

ENX VCS focuses on the implementation of vehicle cybersecurity, risk management and governance structures and is generally conducted every three years. As part of the audit, a company’s organisational and technical cybersecurity processes are assessed against standardised criteria.

Benefits of ENX VCS

Building on these foundations, ENX VCS provides a standardised certification for a V-CSMS that meets the requirements of ISO/SAE 21434. The audit process is conducted in accordance with ISO/PAS 5112 and systematically assesses the implementation and effectiveness of the CSMS.

Benefits of ENX VCS:

  • Standardised cybersecurity evidence: demonstrates compliance with ISO/SAE 21434 for the V-CSMS.
  • Support with type approval under UN R155: provides evidence that a CSMS has been implemented as a prerequisite for vehicle approval.
  • Reduced costs and effort: reduces redundant audits and different proprietary certification schemes.
  • Reduced burden on OEMs: OEMs no longer need to maintain their own lists of accepted cybersecurity assessments.
  • Governance and quality assurance: ENX manages a pool of approved audit service providers and monitors audit quality.

Who needs ENX VCS?

ENX VCS is aimed at companies within the automotive supply chain that are involved in developing, manufacturing or maintaining vehicle functions with cybersecurity relevance. Typical target groups include:

  • Automotive manufacturers (OEMs): vehicle manufacturers are primarily responsible for vehicle security and require standardised, reliable proof of an effective Cybersecurity Management System from their suppliers.
  • Automotive suppliers: companies that develop or manufacture vehicle components, systems or software and therefore have an impact on vehicle cybersecurity.
  • IT and software service providers: providers of digital services, software or technical support for vehicle functions or their development.

 

Regulatory Requirements & Standards

The automotive industry is increasingly aligning its development and production processes with cybersecurity standards and regulatory requirements. A key regulation in this context is UN R155 (2021), which is applied internationally. It requires manufacturers to implement a CSMS and demonstrate its effectiveness to obtain vehicle type approval. The goal is to embed cybersecurity throughout the vehicle lifecycle and promote the continuous improvement of security.

ISO/SAE 21434 (2021) offers comprehensive guidance for the management of cybersecurity risks and supports the practical implementation of regulatory requirements. This standard outlines how manufacturers can establish a CSMS, systematically identify, evaluate, and minimise risks, and thereby facilitate compliance with UN R155.

More information on the topic of CSMS can be found in the EFS Consulting Whitepaper “Secure vehicles through UNECE R155 & ISO/SAE 21434”.

Additionally, UN R156 (2021) regulates the Software Update Management System, which includes secure over-the-air updates, patch management, and the continuous protection of vehicle software. This ensures that connected vehicles remain protected even after delivery.

ISO/SAE 24089 (2023) serves as a supporting standard for implementing these requirements. It provides detailed guidance for SUMS, including processes, roles, validation and traceability throughout the vehicle lifecycle.

ISO/PAS 5112 (2022) complements these standards with requirements for auditing a CSMS within the supply chain. It defines the structure and organisation of audit programmes, auditor qualifications and the documentation of evidence, thereby ensuring that CSMS implementation can be audited and verified in a transparent and traceable manner.

Another important tool is TISAX® (2017), an industry-wide information security assessment and exchange scheme. A valid TISAX® label confirms that an Information Security Management System (ISMS) has been implemented and that sensitive information, such as vehicle prototypes or production plans, is handled securely.

Differentiation from Related Standards & Audits

To understand the role of ENX VCS in the context of international standards and regulatory requirements, it is important to distinguish it from existing standards and assessments.

ENX VCS provides standardised proof that a CSMS has been implemented, thereby supporting manufacturers and suppliers in meeting the requirements of UN R155 for vehicle type approval. At the same time, ENX VCS assesses whether the CSMS meets the requirements of ISO/SAE 21434 and whether cybersecurity risk management processes within the supply chain have been appropriately implemented.

UN R156 goes beyond the scope of ENX VCS, as it defines specific requirements for SUMS. ENX VCS can support as a preparatory foundation, as it requires the implementation of a CSMS on which a SUMS can be built. The requirements of ISO 24089 are not assessed by ENX VCS, as the audit focuses on the CSMS rather than software update management systems.

The audit process itself is based on ISO/PAS 5112, ensuring a standardised approach, qualified auditors and traceable documentation. ENX VCS also builds on TISAX®: development locations must have a successful TISAX® assessment, while VCS assesses the implementation of the CSMS in accordance with ISO/SAE 21434 and thereby going beyond traditional information security.

Overall, ENX VCS positions itself as a binding, standardised audit mechanism that supports suppliers in implementing regulatory requirements and standards, meeting the requirements for vehicle type approval under UN R155, and demonstrating cybersecurity across the entire supply chain in a transparent and traceable manner.

 

Step by Step Audit process

Preparation & Objectives

Before a company registers for ENX VCS, preparatory steps must be completed to ensure that all relevant sites and activities are fully identified, so the audit can be properly planned.

  • Scope definition: The company defines which sites and areas carry out VCS-relevant activities and therefore need to be included in the audit. This includes all units directly or indirectly involved in processes relating to the security of vehicle components or data subject to confidentiality, integrity and availability requirements.
  • Audit Objective: The company determines which VCS activities are to be assessed. The requirements differ based on the chosen Objective:
    • VCS Development: concept and product development, integration and validation.
    • VCS Production: production of VCS components, including SecOC keys, Secure Boot and TLS certificates.
    • VCS Operations & Maintenance: monitoring, vulnerability analysis, updates and secure disposal of keys and certificates.

Each activity has specific audit criteria to ensure that the relevant processes have been properly implemented.

  • Valid TISAX® label: All locations within the defined scope must have a valid TISAX® label at the time of the audit. This ensures that information security is appropriately addressed across the company and allows the ENX VCS requirements to be assessed efficiently.

Companies should also consider the effort required for ENX VCS, including preparation, self-assessment, documentation, coordination with the audit service provider and the actual audit phases. Depending on the size of the organisation, number of sites and scope of the audit, significant time, personnel and resources may be required. Early planning and allocation of resources help ensure that the audit process is conducted efficiently and on schedule.

Audit Phases

The ENX Vehicle Cyber Security Audit consists of four consecutive phases, starting with preparation and self-assessment, and ending with the audit and completion. This ensures that all relevant locations, activities and evidence are comprehensively assessed:

Phase 1 Preparation:

The VCS scope is defined, i.e. which sites and VCS activities (Development, Production or Operations & Maintenance) are included. It is then verified that all sites within the scope have a valid TISAX® label, after which an external, approved audit service provider is selected. Once the scope, TISAX® prerequisites and audit service provider have been established, the audit registration takes place.

Phase 2 Self-assessment:

First, the central CSMS is assessed against the VCS catalogue. The required evidence and documentation are then prepared and provided to the audit team. Where necessary, measures are implemented based on the self-assessment to close identified gaps before the actual audit.

Phase 3 Audit:

The external auditor first reviews the documentation provided. The central CSMS is then audited, followed by the selection and assessment of a risk-based sample of VCS projects to verify that the CSMS requirements have been implemented.

Phase 4 Completion:

Any deviations identified during the audit are documented in the interim report and corrective measures are agreed. Where necessary, these measures are implemented within a defined period and their effectiveness is verified. Once completed, the final results and the ENX VCS label are published in the ENX Portal.

Audit Requirements

The following examples provide a general overview of the requirements assessed as part of ENX VCS:

Vehicle Cybersecurity Management System:

A V-CSMS must be in place and comprehensively documented. Evidence for the V-CSMS must document responsible individuals, the risk management process and continuous improvement.

Sample question: What process ensures that changes made at short notice to security-critical functions are immediately incorporated into the cybersecurity risk assessment?

System Architecture:

System architecture must be sufficiently documented and secured. Communication interfaces and architecture diagrams can serve as evidence.

Sample question: How are security-critical communication interfaces between electronic control units documented and secured?

Secure Development:

To ensure the security of the vehicle and individual software and hardware components, established processes must be implemented during the development phase. These include source code reviews and vulnerability scanning.

Sample question: How are open-source components assessed for vulnerabilities and how are they managed?

Supply Chain Management:

Suppliers are assessed and evaluated based on proven compliance with cybersecurity guidelines, such as TISAX® or ENX VCS. The resulting processes, such as supplier risk assessments, must be documented.

Sample question: How is it ensured that suppliers pass on cybersecurity requirements to their own sub-suppliers?

Incident Response:

An incident response plan based on UN R155 must be in place, documenting escalation paths, reporting obligations and communication plans.

Sample question: How are cybersecurity incidents classified and prioritised?

Testing and Validation:

Regular security testing must be carried out. This includes, among other things, penetration tests, code test cases and software integration tests. Test reports are reviewed and validated as part of the audit.

Sample question: Which test reports are available and which methods were used?

Labels & Results

Following a successful audit, the company receives the VCS label. This confirms that the audit has been passed and serves as evidence of the company’s high CSMS standards.

If the overall audit result contains a minor nonconformity, temporary VCS labels may be issued. A prerequisite is an agreed improvement plan with the audit partner, which is documented in the audit report.

Temporary VCS labels are valid for nine months from the closing meeting of the initial audit. Once all corrective measures have been implemented, a follow-up audit must be conducted in order to obtain the final VCS labels.

Audit results and VCS labels are uploaded and centrally stored in the ENX VCS Portal by the certification body. Companies retain control over their visibility and can decide whether to publish their results to all portal participants, share them selectively with individual business partners, or combine both approaches. This allows the CSMS audit to be used efficiently and selectively with relevant partners without unintentionally disclosing sensitive information.

 

Strategic Benefits for Companies

Risk Reduction & Compliance

Protection against cyberattacks and supply chain risks: An ENX VCS-compliant CSMS protects vehicle software, connected electronic control units and production facilities against cyberattacks while specifically reducing risks arising from disruptions within the automotive supply chain. At the same time, it ensures that industry-specific security and compliance requirements, such as ISO/SAE 21434, are systematically addressed.

Competitive Advantage through the ENX VCS Label

– Proof of Trust towards OEMs & partners: The ENX VCS label enables automotive manufacturers and suppliers to quickly identify whether a company operates a certified CSMS and meets high standards in automotive cybersecurity.

Integration into Corporate Strategy

– Synergies with ISMS, BCM & risk management: The CSMS is integrated into the company’s overall strategy and leverages synergies with ISMS, Business Continuity Management and risk management to manage security risks in vehicle development and production, support contingency planning and continuously improve processes.

 

Experience of EFS Consulting: Success Factors & Challenges

Top 3 Success Factors

1. Early Gap Analysis

An early gap analysis helps determine the current maturity of the CSMS and identify measures needed to meet the requirements of the ENX Vehicle Cyber Security Audit. Providers can support companies with gap analyses to establish priorities and initiate appropriate measures at an early stage.

2. Integration into the ISMS

Integrating CSMS processes directly into the existing ISMS helps ensure consistent processes. Existing evidence from TISAX® assessments or similar audits can be referenced or reused to avoid redundancies and improve traceability.

3. Transparent Communication between OEMs & Suppliers

Clear communication and reporting processes ensure that risks across the supply chain are managed transparently and that responsibilities are clearly defined. Structured information flows and documented incident-handling processes make it easier to provide audit evidence and avoid misunderstandings.

Top 3 Challenges

1. Heterogeneous Development Processes across Different Product Lines

Companies with multiple product lines often have development processes that differ in structure and maturity, due to their historical evolution. This makes the consistent implementation and documentation of cybersecurity requirements more challenging. A key challenge is ensuring that processes, tools and responsibilities are presented consistently and transparently during the audit.

2. Unclear Roles and Responsibilities within the CSMS

An effective CSMS requires clearly defined responsibilities across different areas of the organisation. If responsibilities for cybersecurity activities, decision-making processes or approvals are unclear, this can result in missing evidence and delays during the audit.

3. Insufficient Supply Chain Transparency

ENX VCS requires traceable evidence of cybersecurity measures throughout the supply chain. A lack of transparency or unclear responsibilities among suppliers can therefore put the success of the audit at risk.

 

Conclusion

ENX VCS establishes a standardised approach to demonstrating the effectiveness of CSMS in the automotive industry. From preparation and self-assessment through to the audit and award of the VCS label, the process provides a structured framework for assessing cybersecurity measures. Early preparation and transparent collaboration across the automotive supply chain are key to a successful audit.

EFS Consulting supports you on your journey towards the ENX VCS label. We analyse your existing V-CSMS, identify areas for improvement and support you throughout the audit process.

From defining the audit scope and conducting internal assessments to working with authorised audit providers, EFS Consulting helps ensure that your organisation is optimally prepared for the requirements of ENX VCS and can leverage the long-term benefits of the certification.

FAQs

What is the ENX Vehicle Cyber Security Audit (VCS)?

The ENX Vehicle Cyber Security Audit (VCS) is an audit process developed by ENX for CSMS in the automotive industry. It supports the demonstration of conformity with ISO/SAE 21434 and provides evidence for type approval under UN R155. It is based on the established TISAX® approach to information security.

Is VCS mandatory?

ENX VCS is not mandatory, but it is increasingly required or recommended by OEMs and suppliers as evidence of an ISO/SAE 21434-compliant CSMS. The standard is becoming increasingly important as an industry-wide approach to vehicle cybersecurity.

What is the difference between VCS and TISAX®?

TISAX® assesses information security across the automotive supply chain, while the ENX VCS Audit specifically assesses vehicle cybersecurity and an ISO/SAE 21434-compliant V-CSMS. A TISAX®-compliant ISMS is a prerequisite for ENX VCS.

Who provides ENX VCS audits?

Audits are conducted by audit providers specifically authorised by ENX, such as TÜV SÜD Management Service GmbH, DEKRA Certification GmbH and DQS GmbH.

Audit preparation is separate from the audit itself and can be supported by EFS Consulting through close collaboration with your organisation.

Sources

https://enx.com/en-US/VCS/

https://www.tuev-nord.de/en/dienstleistungen/auditierung-und-zertifizierung/enx-vcs/

https://www.tuvsud.com/de-de/dienstleistungen/produktpruefung-und-produktzertifizierung/zertifizierung-nach-iso-sae-21434

https://www.iso.org/standard/80840.html

More about this Business Area
Information Security