EU UN R155/156 & India AIS-189/190 Compliance Experts

Securing the
Software-Defined Vehicle
Globally & Regionally.

Expert technical regulatory interpretation, ECU penetration testing, ISO/SAE 21434 lifecycles, and type-approval support across European (UN R155/R156) and Indian (AIS-189/AIS-190) homologation frameworks.

Automotive Cybersecurity Multi-Layered Defense Concept

Regulatory

UN R155 / AIS-189

Verification

ECU Pen Testing

Our Mission

To empower automotive OEMs and Tier-1 suppliers with world-class engineering and regulatory solutions that bridge the gap between innovation and global compliance—ensuring vehicles are secure by design, safe by default, and fully certified.

Our Vision

To be the global benchmark in automotive safety, penetration testing, and cybersecurity regulatory interpretation—setting the standard for secure mobility across European, Indian, and international automotive markets.

Navigating Global & Regional Regulations

ISO/SAE 21434

Cybersecurity Engineering

UN R155 / UN R156

EU CSMS & SUMS Approval

AIS-189 / AIS-190

Indian Homologation Mandates

ISO 26262

Functional Safety

ASPICE

Process Maturity

Homologation & Type Approval

EU & India Regulatory Interpretation Support

Guiding automotive OEMs and Tier-1 suppliers through technical requirements, audit evidence compilation, and type-approval validation across European UN regulations and Indian AIS standards.

European Union Regulations

UN R155 (CSMS) & UN R156 (SUMS) Type Approval

  • CSMS Certificate of Compliance: Structuring organizational processes to pass Certificate of Compliance audits from Technical Services (e.g., KBA, TÜV, RDW, UTAC).
  • UN R155 Annex 5 Threat Mapping: Direct mapping of all 70+ threat scenarios and mandatory mitigations to your ISO/SAE 21434 TARA and architecture work products.
  • UN R156 Software Updates (SUMS): Guidance on software update management system compliance, RXSWIN identification architecture, and secure OTA deployment verification.

India Automotive Homologation

AIS-189 (Cybersecurity) & AIS-190 (Software Updates)

  • AIS-189 Implementation: Technical interpretation of Indian cybersecurity regulations for M, N, and L category vehicle architectures, including 2-wheeler and 3-wheeler EV platforms.
  • Test Agency Audit Preparation: Compiling technical audit dossiers and supporting demonstration during evaluation by Indian test agencies (ARAI, ICAT, CIRT).
  • AIS-190 SUMS & OTA Safety: Operationalizing software update mechanisms and vulnerability response channels for vehicles deployed across the Indian subcontinent.
Compliance Framework

End-to-End Automotive Cybersecurity Lifecycle (ISO 21434 & UN R155)

UN R155 requires a certified Cybersecurity Management System (CSMS) spanning the entire vehicle lifecycle, while ISO/SAE 21434 dictates engineering rigor from concept to decommissioning. Here is how we guide your teams through each phase.

Phase 1

Organizational & Governance Setup

UN R155 / AIS-189 (CSMS) & ISO/SAE 21434 Clause 5

Core Activities

Defining corporate cybersecurity policies, setting up roles and responsibilities, ensuring cybersecurity competence management across the supply chain, and establishing a CSMS framework.

How Our Consultants Help

We author tailor-made CSMS manuals, define supplier interface agreements (CIA/DIA), conduct maturity audits, and prepare your organization for type-approval certification with authorities (e.g., KBA, TÜV, ARAI, ICAT).

Phase 2

Concept & Risk Assessment (TARA)

ISO/SAE 21434 Clauses 9 & 10

Core Activities

Item definition, asset identification, Threat Analysis and Risk Assessment (TARA), attack path analysis, impact rating, and deriving cybersecurity goals.

How Our Consultants Help

We lead collaborative TARA workshops, build robust attack tree frameworks, calculate risk levels systematically, and draft formal Cybersecurity Concepts for your ECUs.

Phase 3A

Product Development & Architecture

ISO/SAE 21434 Clause 11

Core Activities

Secure hardware and software architecture design, cryptographic implementations (HSM, SecOC), secure boot, and secure flashing protocols across ECU platforms.

How Our Consultants Help

We design robust security mechanisms, integrate AUTOSAR crypto stacks, and ensure hardware-software security interfaces meet strict automotive requirements.

Phase 3B

Cybersecurity Verification

ISO/SAE 21434 Clause 12

Core Activities

Vulnerability analysis, static/dynamic code analysis, interface testing, and verification of security requirements implementation against the target architecture.

How Our Consultants Help

We execute rigorous verification test cases, evaluate evidence against cybersecurity goals, and generate ISO 21434-compliant verification work products.

Phase 3C

Penetration Testing

ISO/SAE 21434 Clause 13

Core Activities

Offensive security evaluations, black/gray/white box testing, bus fuzzing (CAN/CAN-FD, Ethernet, LIN), and diagnostic interface (UDS) attack simulations.

How Our Consultants Help

We perform advanced ECU penetration testing, uncover exploitable flaws before production, and deliver comprehensive vulnerability remediation reports.

Phase 4

Production, Operation & SUMS

UN R155 / R156, AIS-189 / 190 & ISO 21434 Clauses 14 & 15

Core Activities

Post-SOP vulnerability monitoring, threat intelligence gathering, incident response handling, and secure software over-the-air (OTA) updates (SUMS / UN R156 / AIS-190).

How Our Consultants Help

We establish continuous vulnerability tracking workflows, build operational Incident Response playbooks, and ensure seamless compliance for vehicle fleet monitoring and software updates.

Offensive Security Verification

Automotive Penetration Testing Services

Validating ECU security controls, embedded software defenses, and vehicle attack surfaces through real-world offensive security assessments before SOP.

In-Vehicle Network Testing

Fuzzing and protocol analysis for CAN, CAN-FD, LIN, Automotive Ethernet, and FlexRay to uncover communication stack vulnerabilities.

ECU Hardware & Debug Testing

Analyzing physical interfaces, JTAG/SWD debugging ports, side-channel attacks, and memory dumping on microcontroller units.

Wireless & Infotainment Testing

Evaluating Bluetooth, Wi-Fi, cellular, NFC, and telematics units (TCUs) along with companion mobile apps and cloud backend APIs.

Diagnostic Interface (UDS) Assessment

Penetration testing on Unified Diagnostic Services (ISO 14229), security access routines, session control, and routine control commands.

Our Core Offerings

Comprehensive Engineering & Regulatory Consultation

We provide end-to-end support for the automotive supply chain, ensuring your products are secure by design, safe by default, and fully compliant with global regulations.

EU & India Regulatory Support

UN R155/R156 & AIS-189/190 Homologation.

  • UN R155 CSMS Audit Preparation
  • AIS-189 & AIS-190 Homologation Files
  • Annex 5 Threat Mitigation Mapping
  • Test Agency Audit Support (ARAI / TÜV)

Cybersecurity & Pen Testing

ISO/SAE 21434 Lifecycle & Offensive Security.

  • TARA (Threat Analysis & Risk Assessment)
  • ECU Hardware & Firmware Pen Testing
  • CAN / Ethernet Bus Fuzzing
  • Vulnerability Management & Incident Response

Functional Safety

ISO 26262 ASIL Compliance.

  • HARA & ASIL Determination
  • Functional & Technical Safety Concepts
  • Safety Analysis (FMEA, FTA, FMEDA)
  • Safety Case Development

Automotive SPICE

ASPICE Process Assessment.

  • Process Gap Analysis (V-Model)
  • ASPICE Assessment Preparation
  • Cybersecurity SPICE Integration
  • Process Coaching & Training

Start Your Compliance Journey

Reach out to our experts to discuss your specific requirements for Cybersecurity, Functional Safety, or ASPICE assessments.

Headquarters

Electronic City, Tech Park, Bangalore, India

Email Us

contact@esditechnosol.com

Call Us

+91 973 995 7336

Send us a message