USA | EN

Security of connected and automated vehicles (CAV)

Ensure your intelligent vehicles comply with cybersecurity regulations and standards.
Pictogram in .SVG for Automotive Cybersecurity 2

Security of connected and automated vehicles (CAV) is critical to ensure safe, reliable, and trustworthy operation in an increasingly connected environment. As vehicles exchange data internally and with external systems, cybersecurity protects safety critical functions from unauthorized access, manipulation, and disruption. CAV security encompasses both in-vehicle security, which protects onboard systems, and V2X security, which secures communications with the surrounding ecosystem. Together, these measures enable resilient, safe, and dependable connected and automated mobility.

In‑vehicle security

In‑vehicle security focuses on protecting the internal digital architecture where safety‑critical decisions are executed. Modern vehicles rely on interconnected electronic control units (ECUs), sensors, actuators, and software platforms communicating over in‑vehicle networks and gateways. Effective in‑vehicle security prevents unauthorized access, malicious code execution, data manipulation, and unintended control of vehicle functions. Key measures include secure ECU design, access control, secure boot and software integrity, network segmentation, intrusion detection, and continuous monitoring throughout the vehicle lifecycle. As vehicles become increasingly software‑defined, strong in‑vehicle cybersecurity is essential to preserve functional integrity and ensure safe operation.

V2X security

V2X security addresses the protection of communications between vehicles and their external environment, including vehicle‑to‑vehicle (V2V), vehicle‑to‑infrastructure (V2I), vehicle‑to‑pedestrian (V2P), and vehicle‑to‑network (V2N). These communications enable the real‑time exchange of safety‑critical information such as position, speed, traffic conditions, and hazard warnings, improving situational awareness and traffic efficiency. At the same time, they expand the attack surface, introducing risks such as spoofing, replay attacks, jamming, and denial‑of‑service. Robust V2X security relies on strong authentication, message integrity, encryption, certificate and key management, and resilience against communication failures, ensuring trusted and reliable cooperative driving.

TÜV SÜD’s AV cybersecurity assessment approach

The AV cybersecurity assessment approach

TÜV SÜD has developed a cybersecurity assessment methodology specifically for the AV approval process. Based on international cybersecurity standards and current industry best practices, the approach helps organizations identify risks, validate security controls, and support regulatory readiness throughout vehicle development.

1. Identify critical assets

The first step focuses on identifying critical vehicle assets and ensuring cybersecurity risks are properly understood and mitigated. This includes threat analysis and risk assessment (TARA), identification of critical components across the automotive ecosystem, evaluation of cybersecurity threats and risks, and development of cybersecurity concepts to address identified vulnerabilities.

2. Verify security measures

The second step verifies that critical vehicle systems implement effective cybersecurity controls. We review implemented security measures, perform deviation analysis, evaluate alignment between cybersecurity mechanisms and the cybersecurity concept, and provide technical guidance to help organization prepare documentation that meets approval requirements.

3. Validate through testing

The final step confirms that implemented cybersecurity measures perform as intended through testing and validation activities. We review security test results, validate cybersecurity mechanisms, and provides detailed technical reporting to support cybersecurity and roadworthiness evaluations. 

How TÜV SÜD's services help with CAV security

TÜV SÜD supports the automotive industry in securing connected and automated vehicles through independent, end-to-end cybersecurity audits and assessments across the vehicle lifecycle. Through cybersecurity assessments, system level verification, and Cybersecurity Management System (CSMS) evaluations, TÜV SÜD helps OEMs and suppliers identify risks, validate security controls, and demonstrate compliance with key regulations and standards such as UN R155 and ISO/SAE 21434. By combining deep automotive expertise with globally recognized conformity assessment services, TÜV SÜD enables safe deployment, regulatory readiness, and trusted operation of connected and automated vehicles worldwide.

Ready to take the next step in CAV security?

AV cybersecurity is essential for safe operation and compliance. Our assessment identifies risks early and validates controls against key standards.

    Frequently asked questions (FAQs)

    What is cybersecurity for connected and automated vehicles (CAV), and why is it important?

    Cybersecurity for CAV focuses on protecting both vehicle systems and external communications from cyber threats. As vehicles exchange data internally and with infrastructure, strong cybersecurity is essential to prevent unauthorized access, manipulation, or disruption of safety-critical functions.

    What is the difference between in-vehicle security and V2X security?
    In-vehicle security protects internal systems such as ECUs, sensors, and software from unauthorized access or manipulation, while V2X security focuses on securing communication between vehicles and external entities (e.g., other vehicles, infrastructure, and networks). Both are critical to ensuring safe and reliable vehicle operation. 
    How does TÜV SÜD assess cybersecurity for automated vehicles?
    TÜV SÜD follows a structured three-step approach: identifying critical assets, verifying implemented security measures, and validating those measures through testing. This ensures that cybersecurity risks are systematically addressed during vehicle development and approval.
    Can TÜV SÜD support prototype approval for autonomous vehicles?
    Yes, TÜV SÜD provides cybersecurity assessments tailored to the AV approval process and supports manufacturers in obtaining permits for both single vehicles and fleets. This includes validating security concepts and ensuring compliance with regulatory expectations. 
    Which standards and regulations are relevant for CAV cybersecurity?
    Key frameworks include UN Regulation No. 155 (UN R155) and ISO/SAE 21434. TÜV SÜD helps organizations align their development and validation processes with these globally recognized standards.
    Who should consider a CAV cybersecurity assessment?
    Automotive OEMs, suppliers, and mobility providers developing connected or automated vehicles should consider cybersecurity assessments to identify risks early, validate security controls, and demonstrate readiness for regulatory approval and safe deployment.

    Knowledge highlights

    Article

    #Service knowledge #Future insights #Cybersecurity #Automotive

    Cyber security threats of connected vehicles

    Article

    #Service knowledge #Automotive

    Keeping it connected: Wireless technology for automotive

    White paper

    #Service knowledge #Automotive

    Highly Automated Driving - An Overview of the Current State of Legislation