Knowledge base
Automotive OEM Vendor Cybersecurity Assessment: Controls, Scoring and ISO Standards Mapping
What does an automotive vendor cybersecurity assessment cover?
Neha Dvivedi · September 13, 2026
Automotive suppliers are increasingly being asked by vehicle manufacturers to complete cybersecurity assessments before or during a business relationship. These assessments check how well a supplier protects information, systems, data and business operations.
This guide explains:
• What a vendor cybersecurity assessment is
• What areas are assessed
• How the assessment is scored
• What documents and evidence are normally required
• How the controls relate to ISO standards
It is mainly intended for quality, IT, information security and operations managers at automotive component manufacturers.
1. What is a Vendor Cybersecurity Assessment?
A vendor cybersecurity assessment is an evaluation conducted by a customer to understand how well its supplier manages cybersecurity and information security.
It is not an ISO certification audit, and it is not a government regulatory inspection.
Instead, it is usually a customer or business requirement. The supplier completes an assessment, provides supporting evidence, receives a score and may be required to address identified gaps.
Three things are important:
1. It is comparative
Suppliers may be assessed using the same criteria so that the customer can understand their relative level of cybersecurity readiness.
2. It is weighted
Not every question has the same importance. Some controls carry more marks than others.
3. It focuses on business continuity as well as security
The assessment is often linked to supply-chain, risk or business-continuity functions. The concern is not only whether a supplier can protect information, but also whether a cyber incident could stop the supplier from delivering products or services.
2. Governance and Management Responsibility
Before looking at technical controls, the assessment normally checks whether cybersecurity is properly managed by the organisation.
For example:
• Is there an approved information security policy?
• Are security responsibilities clearly defined?
• Is someone specifically responsible for information security?
• Is there a list of important contacts?
• Is the policy reviewed regularly?
• Is there evidence that the organisation improves its security controls over time?
These areas can carry significant weight.
Having a responsible person, documented policies and evidence of continuous improvement can therefore make a major difference to the assessment result.
This area closely relates to ISO/IEC 27001 Clause 5 on Leadership and Clause 10 on Improvement.
3. Main Cybersecurity Control Families
The following are the major areas normally covered in a vendor cybersecurity assessment, along with typical evidence and related ISO standards.
Access Control
This checks whether only authorised people can access systems and information.
It may include:
• Role-Based Access Control (RBAC)
• Least-privilege access
• Separation of duties
• Remote access
• Wireless access
• Mobile devices
• Removable storage
• Session timeout
This is often one of the largest control areas.
ISO/IEC 27001:2022: Annex A 5.15–5.18 and 8.1–8.5.
Awareness and Training
Employees should understand their cybersecurity responsibilities.
The assessment may check:
• Security training during joining
• Periodic awareness training
• Role-specific training
• Training records
• Evidence that employees understood the training
ISO/IEC 27001: Clauses 7.2 and 7.3; Annex A 6.3.
Audit and Accountability
This area checks whether important activities can be tracked back to the people or systems that performed them.
It normally covers:
• Security logs
• Log protection
• Log retention
• Regular log review
• Traceability of activities
ISO/IEC 27001:2022: Annex A 8.15 and 8.16.
Configuration Management
Systems should have secure and approved configurations.
The assessment may check:
• Standard system configurations
• Change management
• Approval of changes
• Security impact analysis
• Removal of unnecessary services and ports
ISO/IEC 27001:2022: Annex A 8.9, 8.19 and 8.32.
Identification and Authentication
This area checks how users and assets are identified and authenticated.
It may include:
• Asset inventory
• User inventory
• Password and authenticator management
• Multi-factor authentication (MFA)
• Prevention of shared accounts
ISO/IEC 27001:2022: Annex A 5.16, 5.17 and 8.5.
Incident Response
The organisation should know what to do when a cybersecurity incident occurs.
The assessment may check:
• Incident response procedures
• Defined responsibilities
• Incident response teams
• Communication procedures
• Responsibilities between the customer and supplier
ISO/IEC 27001:2022: Annex A 5.24–5.28.
Maintenance of Information Security Assets
This checks whether maintenance activities are properly controlled.
It may include:
• Maintenance procedures
• Control of maintenance tools
• Diagnostic equipment and media
• Secure disposal of equipment and information
ISO/IEC 27001:2022: Annex A 7.10, 7.13 and 7.14.
Media Protection
Both digital and physical media should be protected.
The assessment may cover:
• Media inventory
• Labelling
• Transportation
• Protection
• Secure disposal or sanitisation
• Controls over media entering or leaving the premises
ISO/IEC 27001:2022: Annex A 7.10 and 8.10.
Personnel Security
This area focuses on employees, contractors and other people who have access to company information.
It may include:
• Background verification
• Security responsibilities
• Access before employment
• Access removal after termination
• Access changes after transfer or reassignment
• Controls for temporary employees and contractors
ISO/IEC 27001:2022: Annex A 6.1, 6.2 and 6.5.
Physical Security
Cybersecurity also depends on protecting physical locations and equipment.
The assessment may check:
• Restricted areas
• Visitor registration
• Access records
• Access cards and keys
• Recovery of access devices
• CCTV and surveillance
ISO/IEC 27001:2022: Annex A 7.1–7.6.
Risk Assessment
This area checks how the organisation identifies and manages cybersecurity risks.
It may include:
• Business and operational impact assessment
• Vulnerability scanning
• Risk treatment
• Defined timelines for fixing vulnerabilities
ISO/IEC 27001: Clause 6.1 and Annex A 8.8.
Security Assessment
Organisations should regularly check whether their security controls are actually working.
This can include:
• Control effectiveness reviews
• Action plans
• Target completion dates
• Continuous monitoring
• Management review
ISO/IEC 27001: Clauses 9.1–9.3.
System and Communications Protection
This area focuses on network and communication security.
It may include:
• Network boundaries
• Network segmentation
• Firewall controls
• Default-deny principles
• Encryption
• Cryptographic key management
• Protection of shared resources
ISO/IEC 27001:2022: Annex A 8.20–8.24.
System and Information Integrity
This checks whether systems and information are protected from vulnerabilities, malware and other security threats.
It may include:
• Vulnerability and patch management
• Malware protection
• Security monitoring
• Monitoring security advisories
• Protection of customer personal information
ISO/IEC 27001:2022: Annex A 8.7, 8.8 and 8.16.
Information Security Certifications
The assessment may ask whether the organisation already holds recognised information security certifications.
ISO/IEC 27001 is commonly included.
Certification may be treated as a desirable requirement rather than an absolute mandatory requirement.
Data Privacy
This area focuses on how personal information is handled.
The assessment may check:
• Identification of personal data
• Data classification
• Sensitive and non-sensitive information
• Security safeguards
• Data processing responsibilities
• Whether the organisation acts as a controller or processor
Relevant frameworks include:
• ISO/IEC 27701
• Digital Personal Data Protection Act, 2023, in India
Artificial Intelligence Security
Where an organisation uses AI, the assessment may ask:
• Where AI is being used
• Whether AI is involved in business or operational decisions
• Whether AI operates without human oversight
• Whether AI-related risks have been assessed
ISO/IEC 42001 is the relevant management system standard for AI.
Data Privacy in Cloud Environments
This area checks how personal data is protected when cloud services are used.
It may include:
• Personal data stored in the cloud
• Personal data processed through cloud services
• Approval of cloud service providers
• Cloud security controls
Relevant standards include:
• ISO/IEC 27017
• ISO/IEC 27018
Business Continuity
The organisation should be able to continue critical operations during and after a disruption.
The assessment may check:
• Business continuity plan
• Business Impact Analysis (BIA)
• Recovery Point Objective (RPO)
• Recovery Time Objective (RTO)
• Disaster recovery arrangements
• Business continuity drills
• Management review
ISO 22301 is the main standard associated with this area.
Business continuity can receive significant weight because a cyber incident can directly affect the supplier's ability to continue production and deliveries.
4. How Does the Scoring Work?
Mandatory and Desirable Requirements
Assessment questions are generally divided into:
• Must Have / Mandatory
• Good to Have / Desirable
Failure to meet a mandatory requirement can have a greater impact on the overall score.
Weightage
Each question or control may have a different weight.
Therefore, the score is not simply based on the number of questions passed.
For example, two suppliers may have the same number of gaps but receive different overall scores because the gaps relate to controls with different weightings.
Complete, In Progress and Not Implemented
Controls are often assessed using three levels:
Complete
The control is fully implemented and supported by evidence.
Evidence may include:
• Policy or procedure name
• Date or year of implementation
• Approval records
• Review records
• Implementation evidence
In Progress
The organisation has started implementing the control but has not completed it.
A planned completion date and current status may be required.
Not Implemented
The control does not currently exist or there is no supporting evidence.
In such cases, no marks are normally awarded.
Not Applicable
A control may be marked Not Applicable if it genuinely does not apply to the organisation.
However, the supplier should provide a clear reason.
An unsupported or unjustified "Not Applicable" response may be treated as a gap.
Self-Assessment vs. Validation
The supplier may first complete a self-assessment.
The customer or assessor can then validate the answers by reviewing supporting evidence.
Therefore, simply declaring that a control exists is generally not enough. Evidence is important.
Outside-In Assessment
Some assessments also look at the supplier from an external perspective.
Internet-facing systems may be scanned to identify issues that can be observed from outside the organisation.
This score can be different from the internal assessment because it is based on externally visible systems and does not necessarily depend on information provided by the supplier.
Corrective Action and Closure
When gaps are identified, the supplier may need to prepare a corrective action or countermeasure plan.
This normally includes:
• Identified gap
• Corrective action
• Responsible person
• Target completion date
• Supporting evidence
Observations may then be marked as:
• Open
• Partially closed
• Closed
The customer may specify a particular period for submitting the corrective action and evidence.
5. What Evidence Is Normally Required?
Cybersecurity assessments generally require documented evidence, not just verbal confirmation.
Commonly requested documents include:
1. Approved Information Security Policy
2. Access Control Procedure
3. Role-Based Access Control (RBAC) Matrix
4. Segregation of Duties Matrix
5. Administrator Account and Privilege List
6. Access Request and Approval Records
7. Acceptable Use Policy
8. Removable Media Policy
9. Security Awareness Training Calendar and Attendance Records
10. Evidence of Training Effectiveness
11. Network and Data Flow Diagrams
12. Change Management Procedure
13. Security Impact Analysis
14. Approved Change Records
15. Log Retention Policy and Log Review Records
16. Non-Disclosure Agreements for contractors and third parties
17. Business Continuity Plan
18. Business Impact Analysis
19. RPO and RTO information
20. Business Continuity Drill Records
The exact evidence required will depend on the customer's assessment questionnaire.
6. How Is a Vendor Cybersecurity Assessment Different from Other Requirements?
Vendor Cybersecurity Assessment
• Customer-driven
• Usually contractual or commercial
• Scored
• Focused on supplier cybersecurity and business risk
• No certification is issued
ISO/IEC 27001 Certification
• Independent third-party certification
• Evaluates an Information Security Management System (ISMS)
• Based on a defined certification scope
• Results in an ISO/IEC 27001 certificate when certification requirements are met
TISAX
TISAX is an automotive information security assessment mechanism managed by the ENX Association and based on the VDA Information Security Assessment approach.
It is widely used in the automotive sector, particularly in Europe.
It builds on information security principles and includes automotive-specific areas such as prototype protection and supplier/subcontractor management.
AIS-189 and AIS-190
These are Indian automotive cybersecurity and software-update related standards connected with vehicle type approval.
Their primary focus is on vehicle manufacturers, but cybersecurity requirements can extend into the supply chain.
7. Does ISO/IEC 27001 Automatically Cover the Manufacturing Plant?
Not necessarily.
An ISO/IEC 27001 certificate only covers the activities, locations, systems and information included within its defined scope.
For example, if a company's ISO/IEC 27001 scope only covers corporate IT systems, it may not automatically cover:
• Production networks
• Programmable Logic Controllers (PLCs)
• Supervisory Control and Data Acquisition (SCADA) systems
• Human-Machine Interfaces (HMIs)
• Industrial control systems
Therefore, a supplier can have a valid ISO/IEC 27001 certificate and still have gaps when a customer assesses cybersecurity controls inside the manufacturing environment.
For operational technology and industrial control environments, IEC 62443 is particularly relevant.
Examples include:
• IEC 62443-2-1 — Security program requirements
• IEC 62443-3-3 — System security requirements and security levels
These should not be confused with:
• ISO 26262, which focuses on automotive functional safety
• ISO/SAE 21434, which focuses on cybersecurity of road vehicles
8. Frequently Asked Questions
Do automotive suppliers in India need ISO/IEC 27001 certification?
Not necessarily.
ISO/IEC 27001 certification may appear as one requirement within a customer cybersecurity assessment, but it is not automatically mandatory for every automotive supplier.
However, many assessment controls are similar to the practices expected within an Information Security Management System.
As a result, an organisation with a properly implemented ISO/IEC 27001 system may already have many of the policies, procedures and records needed to respond to a vendor cybersecurity assessment.
What happens if a supplier receives a low score?
A low score does not necessarily mean that the supplier relationship will immediately end.
Typically, the customer may require the supplier to:
1. Identify the gaps
2. Prepare a corrective action plan
3. Set completion dates
4. Implement the required controls
5. Submit supporting evidence
6. Close the identified observations
Commercial consequences may arise if the supplier does not respond within the required timeline or repeatedly fails to close important gaps.
What documents does a customer cybersecurity assessment usually ask for?
The assessment is often heavily documentation based.
Typical requirements include:
• Security policies
• Procedures
• Access control records
• Training records
• Network diagrams
• Change management records
• Log review records
• Business continuity documents
• Risk assessment records
Many of these documents can be developed using existing organisational processes and records.
Does a supplier have its own legal and regulatory responsibilities?
Yes.
Customer requirements are separate from the organisation's own statutory and regulatory responsibilities.
Depending on the organisation's activities and circumstances, relevant Indian requirements may include:
• Digital Personal Data Protection Act, 2023
• CERT-In Directions
• Information Technology Act, 2000
• Applicable rules relating to reasonable security practices
These requirements can apply independently of any specific customer cybersecurity questionnaire.
9. Closing the Gap
For automotive suppliers, preparing for a cybersecurity assessment is not only about installing more technology.
A large part of the assessment focuses on having:
• Clear policies
• Defined responsibilities
• Documented procedures
• Access controls
• Employee awareness
• Risk assessments
• Incident response
• Business continuity
• Evidence of implementation
• Regular reviews and improvement
The key is to identify the customer's requirements early, understand the gaps, prepare the required documentation, implement the controls and maintain evidence.
MSCI supports automotive suppliers in preparing for cybersecurity assessments and certification requirements. MSCI is a consulting organisation and does not issue certificates. It is also not an approved or empanelled assessor for any vehicle manufacturer.
Start with the free readiness checklist to understand where your organisation currently stands and which areas may require improvement.
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO/IEC 27001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- Automotive Suppliers Face Stricter Cybersecurity Assessments
Cybersecurity is becoming a key part of supplier evaluations in the automotive industry. Vehicle manufacturers now check how suppliers protect data and systems alongside quality, cost, and delivery.
September 13, 2026
- Inside an Automotive OEM Vendor Cybersecurity Assessment: The 19 Control Families and What They Actually Ask For
The nineteen control families in an automotive vendor cybersecurity assessment, where the structure came from, and why good controls still score zero.
September 13, 2026
- Why Auto Component Suppliers Score Poorly on OEM Cybersecurity Assessments, and the Nine Documents That Close Most of the Gap
Scored assessments award marks for documented evidence, not for practice. That is why secure suppliers score badly, and nine documents close most of the gap.
September 13, 2026
