Knowledge base
Automotive OEM Vendor Cybersecurity Assessment: Control Families, Scoring and Standards Mapping
What an automotive vendor cybersecurity assessment covers, how it is scored, the evidence it asks for, and how each control family maps to ISO standards.
Neha Dvivedi · 2026 оны есдүгээр сарын 13
Suppliers to vehicle manufacturers in India are increasingly asked to complete a structured cybersecurity assessment as a condition of business. This reference guide explains what a vendor cybersecurity assessment format contains, how a supplier information security questionnaire of this kind is scored, what evidence it calls for, and how each area maps to recognised management system standards. It is written for quality, IT and operations managers at component manufacturers who have received such a request.
What a vendor cybersecurity assessment is
A vendor cybersecurity assessment is a customer-issued evaluation of a supplier’s information security posture. It is not a certification audit and not a regulatory inspection. It is a commercial assessment conducted by or on behalf of the customer, resulting in a score and a corrective action requirement.
Three features distinguish it. It is comparative, so suppliers are ranked against one another. It is weighted, so different checkpoints carry different marks. And it is usually owned by the customer’s supply chain or business continuity function rather than its IT department, which reflects the underlying concern: a supplier that cannot operate is a supply problem before it is a security problem.
Governance sits at the top, and carries the heaviest weight
Before the technical families, assessments test governance and culture. Is information security addressed by a documented policy. Are responsibilities defined and assigned to a named individual within the existing management structure. Is there a contact list. Is the policy reviewed and improved rather than written once and filed. Is there evidence of continuous improvement.
These carry among the highest weightings in the instrument, and the absence of a named accountable person is one of the most expensive single failures available. Governance is not the soft preamble to a cybersecurity assessment. It is where the marks are. This maps to ISO/IEC 27001 Clause 5 on leadership and Clause 10 on improvement, and the same logic applies whether an organisation is automotive or not.
The control families
The following describes each family, the evidence typically requested, and the standard it maps to. Annex A references use ISO/IEC 27001:2022 numbering. Terminology is often imported from other frameworks, which is why suppliers encounter checkpoints referring to Controlled Unclassified Information. The CUI meaning in supplier assessment documents is simply the customer’s confidential technical and commercial information.
- Access Control. Role-based access control or RBAC, segregation of duties, least privilege, session timeout, remote access, wireless access, mobile devices and removable storage. Generally the largest family. Annex A 5.15 to 5.18 and 8.1 to 8.5.
- Awareness and Training. Education at induction and periodically thereafter, role-specific responsibilities, and evidence that training is effective rather than merely delivered. Clause 7.2 and 7.3, Annex A 6.3.
- Audit and Accountability. Generation, protection, retention and review of logs, with actions attributable to individuals. Retention periods are commonly specified in months. Annex A 8.15 and 8.16.
- Configuration Management. Baseline configurations, change control with approval records, security impact analysis before implementation, removal of unnecessary functions and ports. Annex A 8.9, 8.19 and 8.32.
- Identification and Authentication. Asset and user inventories, authenticator management, multi-factor authentication, prohibition of shared accounts. Annex A 5.16, 5.17 and 8.5.
- Incident Response. Defined roles, documented procedures, and agreed responsibilities between customer and supplier where shared information is involved. Annex A 5.24 to 5.28.
- Maintenance of information security assets. Controlled maintenance, management of maintenance tools and diagnostic media, secure disposal. Annex A 7.10, 7.13 and 7.14.
- Media Protection. Inventory, marking, transport, protection and sanitisation of digital and physical media, including controls on items carried into and out of the premises. Annex A 7.10 and 8.10.
- Personnel Security. Background verification before access is granted, and defined action on termination or reassignment. Scope commonly extends to outside employees including temporary staff and contractors. Annex A 6.1, 6.2 and 6.5.
- Physical Protection. Controlled areas, visitor registration, access logging, issue and recovery of access devices, surveillance. Annex A 7.1 to 7.6.
- Risk Assessment. Operational impact assessment, vulnerability scanning and remediation within defined timelines. Clause 6.1, Annex A 8.8.
- Security Assessment. Evaluation of control effectiveness, plans of action with milestones, continuous monitoring. Clause 9.1 to 9.3.
- System and Communications Protection. Boundary protection, network segmentation, denial by default, cryptography and key management, protection of shared resources. Annex A 8.20 to 8.24.
- System and Information Integrity. Flaw remediation, malicious code protection, monitoring of security advisories, handling of customer personal information. Annex A 8.7, 8.8 and 8.16.
- Information Security Certifications. Identification of certifications held, with ISO/IEC 27001 commonly named. Usually a single checkpoint of modest weight and categorised as desirable rather than mandatory.
- Data Privacy. Identification and classification of personal data, distinction between sensitive and normal categories, safeguards, and clarity on whether the organisation acts as controller or processor. ISO/IEC 27701 and, in India, the Digital Personal Data Protection Act, 2023.
- Artificial Intelligence Security. Whether AI systems are used in operational or decision-making processes, whether any operate without human oversight, and whether the resulting risk has been formally assessed. Commonly categorised as mandatory. ISO/IEC 42001.
- Data Privacy on Cloud. Personal data processed or stored in cloud environments and approval of the services used. ISO/IEC 27017 and ISO/IEC 27018.
- Business Continuity. Documented continuity plan, recovery point and recovery time objectives expressed as RPO and RTO, disaster recovery capability, business impact analysis, drills and management review. ISO 22301. Commonly among the most heavily weighted families, which follows from the assessment being owned by a continuity function.
How scoring works
- Must Have and Good to Have. Checkpoints are separated into mandatory and desirable categories. Failure against a mandatory checkpoint carries materially greater consequence.
- Weightage. Each checkpoint carries a weight, so the score is not a count of passes. Equal numbers of gaps in two areas can produce very different results.
- Measures complete, measures underway, not implemented. A three-point basis. Full marks generally require the name of the internal regulation, the year it was established, and evidence of revision and adoption. Partial marks are available where work is underway with a stated status and scheduled completion date. Nothing is awarded where a control is absent.
- Not applicable. Available where a control genuinely does not apply, but a reason must be recorded. An unjustified not-applicable is normally treated as zero.
- Self-assessment score and validation score. The supplier’s own assessment is recorded separately from the assessor’s validated result. Self-declaration is tested against evidence, not accepted.
- Outside-in score. An independent assessment of externally observable posture, derived from scanning internet-facing infrastructure. Produced without the supplier’s participation and may differ substantially from the assessed score.
- Countermeasure plan and closure status. The supplier submits an improvement plan with implementation dates, then supporting evidence. Each observation is tracked to open, closed or partially closed. Submission windows are measured in weeks.
What evidence is actually requested
Assessments award marks for evidence rather than practice. The artefacts requested most consistently are:
- An approved information security policy with evidence of accessibility to staff
- An access control procedure and role-based access control matrix, commonly called an RBAC matrix
- A segregation of duties matrix
- A list of administrator accounts and their privileges
- Sample access request and approval records
- An acceptable use policy and a removable media policy
- A training calendar, attendance records and evidence of effectiveness
- Network and data flow diagrams carrying title, version, approval and review date
- A change management procedure with security impact analysis and an approved change log
- A defined log retention period and records of log review
- Non-disclosure agreements covering contractors and third party personnel
- A business continuity plan with recovery objectives, business impact analysis and a drill record
How this differs from other requirements
- Vendor cybersecurity assessment. Customer-issued, scored, contractual. No certificate is issued.
- ISO/IEC 27001 certification. Independent third party certification of an information security management system. Voluntary, but recognised in Indian law under the rules on reasonable security practices made under Section 43A of the Information Technology Act, 2000.
- TISAX. An automotive information security assessment mechanism governed by the ENX Association, based on the VDA Information Security Assessment catalogue. Widely required by European manufacturers. Draws on ISO/IEC 27001 but adds automotive-specific requirements, notably prototype protection and subcontractor management.
- AIS-189 and AIS-190. Indian automotive standards for cyber security management and software update management, connected to vehicle type approval. They apply to the vehicle manufacturer, but AIS-189 requires management of cybersecurity dependencies across the supply chain, which is how the requirement reaches suppliers.
Does ISO 27001 cover the manufacturing plant?
An ISO/IEC 27001 certificate scoped to corporate information technology does not cover the shop floor. Programmable logic controllers, supervisory control systems, human machine interfaces and plant networks fall outside such a scope. A supplier can hold a valid certificate and still score poorly against checkpoints reaching into the production environment.
Where operational technology is in scope, the relevant standards are IEC 62443-2-1 for the security programme and IEC 62443-3-3 for system security requirements and security levels. These address the security of the industrial automation and control system itself and should not be confused with ISO 26262 or ISO/SAE 21434, which govern the safety and cybersecurity of the vehicle as a product.
Frequently asked questions
Do automotive suppliers in India need ISO/IEC 27001 certification?
No Indian vehicle manufacturer has published a requirement making ISO/IEC 27001 certification mandatory for suppliers. Certification typically appears as one checkpoint among many, categorised as desirable rather than mandatory. However, the substance of a vendor assessment closely follows the structure of an information security management system, so a certified organisation is generally able to answer most of the instrument from existing documentation.
What happens if a supplier scores poorly?
A low score does not ordinarily terminate a supply relationship. It triggers a corrective action cycle with defined dates for an improvement plan and supporting evidence. Failure to respond within those dates, or repeated failure to close observations, is where commercial consequences arise.
What documents does a customer cybersecurity audit ask for?
Predominantly documents rather than technology. The list above covers the artefacts requested most consistently. Most can be produced without significant expenditure.
Does a supplier have statutory obligations of its own?
Yes. The Digital Personal Data Protection Act, 2023 applies to employee and customer personal data. The CERT-In Directions of April 2022 set incident reporting and log retention requirements. Section 43A of the Information Technology Act, 2000 and the associated rules on reasonable security practices remain in force. These exist independently of any customer requirement.
The nine documents that close most of the gap covers remediation, and the statutory obligations guide covers what applies regardless of any customer. MSCi supports automotive suppliers through this work. MSCi is a consulting organisation: we prepare organisations for assessment and certification, we do not issue certificates, and we are not an approved or empanelled assessor for any manufacturer. Start with the free readiness checklist.
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO/IEC 27001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- Automotive Vendor Cybersecurity Assessments Move from Advisory to Scored: What Indian Suppliers Are Now Being Measured On
Vehicle manufacturers in India now score suppliers on cybersecurity against weighted checklists, with corrective action deadlines. What is being measured.
2026 оны есдүгээр сарын 13
- Inside an Automotive OEM Vendor Cybersecurity Assessment: The 19 Control Families and What They Actually Ask For
The nineteen control families in an automotive vendor cybersecurity assessment, where the structure came from, and why good controls still score zero.
2026 оны есдүгээр сарын 13
- Why Auto Component Suppliers Score Poorly on OEM Cybersecurity Assessments, and the Nine Documents That Close Most of the Gap
Scored assessments award marks for documented evidence, not for practice. That is why secure suppliers score badly, and nine documents close most of the gap.
2026 оны есдүгээр сарын 13
