Automotive Cybersecurity Level 2 (Professional) according to ISO/SAE 21434
Professional Training - Developed with SAE International
| | Disponible en Español | Also available in Spanish |
This advanced professional training provides participants with the knowledge and practical guidance required to implement automotive cybersecurity engineering activities according to ISO/SAE 21434 throughout the vehicle lifecycle.
Building upon the Automotive Cybersecurity Level 1 (Foundation) training, participants will learn how to plan, manage, develop, evaluate, and maintain cybersecurity activities across automotive projects and organizations. Through realistic case studies, practical examples, and instructor-led exercises, learners gain a deep understanding of cybersecurity governance, TARA, cybersecurity concepts, product development, verification and validation, post-development activities, and compliance assessment.
Upon completion of this course, participants will be able to:
- Explain the role of ISO/SAE 21434 within the automotive cybersecurity ecosystem.
- Apply cybersecurity governance principles, policies, processes, and competence management practices.
- Develop and manage cybersecurity plans throughout automotive projects.
- Define cybersecurity responsibilities and interfaces within distributed development environments.
- Create and evaluate Cybersecurity Interface Agreements (CS-IAs).
- Develop Item Definitions and identify cybersecurity-relevant assets.
- Perform and interpret Threat Analysis and Risk Assessment (TARA) activities.
- Define cybersecurity goals, claims, controls, and requirements.
- Develop and refine cybersecurity concepts aligned with cybersecurity objectives.
- Apply cybersecurity engineering activities during system, hardware, and software development.
- Establish cybersecurity verification and validation strategies.
- Evaluate cybersecurity test methods and their applicability.
- Understand cybersecurity case creation and maintenance.
- Implement cybersecurity monitoring, vulnerability management, and incident response processes.
- Distinguish between cybersecurity audits and cybersecurity assessments.
- Support organizational and project-level compliance with ISO/SAE 21434.
This course is intended for professionals involved in automotive cybersecurity, engineering, quality, safety, compliance, and project management activities, including:
- Cybersecurity Managers
- Cybersecurity Engineers
- Cybersecurity Specialists
- Systems Engineers
- Software Engineers
- Hardware Engineers
- Functional Safety Professionals
- Product Security Engineers
- Project Managers
- Program Managers
- Process Owners
- Quality Managers
- Auditors and Assessors
- Compliance Managers
- Production Managers
- Technical Leads
- OEM Personnel
- Tier-1, Tier-2 and Tier-3 Suppliers
- Consultants supporting automotive cybersecurity initiatives
This training provides knowledge regarding the implementation of automotive cybersecurity requirements according to ISO/SAE 21434.
- Standards and regulations
- Culture & Competence
- Automotive Cybersecurity Ecosystem & Planning
- Audits & Assessments, Distributed Development, Policies, as well as Rules & Processes, Tool Management
- Cybersecurity Case
- Post-development activities
- Item Definition, Goals & Claims
- Concept & Planning, Product Development, Validation & Verification, and Test Meth
The automotive industry is undergoing a rapid transformation driven by connected, automated, software-defined, and electrified vehicles. As connectivity and digitalization continue to expand, cybersecurity has become a critical requirement throughout the entire vehicle lifecycle. ISO/SAE 21434 provides the globally recognized framework for engineering cybersecurity into road vehicles and their components.
The Automotive Cybersecurity Level 2 (Professional) training provides advanced knowledge for professionals involved in developing, managing, assessing, or implementing automotive cybersecurity activities. Building on the concepts introduced in the Foundation level, this course focuses on the practical implementation of cybersecurity engineering processes according to ISO/SAE 21434.
Participants explore the complete cybersecurity lifecycle, including organizational cybersecurity management, cybersecurity culture and competence, project cybersecurity planning, distributed development, cybersecurity interface agreements, and cybersecurity governance. Special attention is given to Threat Analysis and Risk Assessment (TARA), Item Definition, cybersecurity goals, claims, requirements, and concept development.
The course further covers cybersecurity activities during system, hardware, and software development, cybersecurity verification and validation strategies, vulnerability analysis, cybersecurity testing methods, cybersecurity case creation, and post-development cybersecurity management. Participants learn how organizations can establish traceability and evidence to demonstrate compliance and support cybersecurity assurance.
A comprehensive automotive case study and practical exercises throughout the training enable learners to apply concepts in realistic project scenarios and develop the confidence required to support cybersecurity implementation within OEMs, suppliers, and related organizations across the automotive ecosystem.
Participants will benefit from:
- Comprehensive understanding of ISO/SAE 21434 implementation practices.
- Practical guidance for deploying cybersecurity engineering processes throughout the automotive lifecycle.
- Improved ability to plan and manage cybersecurity activities in automotive projects.
- Enhanced understanding of TARA and cybersecurity risk management.
- Knowledge of cybersecurity governance, organizational structures, culture, and competence requirements.
- Practical experience through realistic case studies and exercises.
- Understanding of cybersecurity concepts, controls, and requirements development.
- Insight into cybersecurity testing approaches, including vulnerability scanning, fuzz testing, and penetration testing.
- Improved capability to work with suppliers and customers in distributed development environments.
- Knowledge of cybersecurity monitoring, vulnerability management, and incident response activities.
- Preparation for cybersecurity audits and assessments.
- Increased readiness to support compliance with ISO/SAE 21434 and related automotive cybersecurity regulations.
This instructor-led training is delivered in a live classroom or virtual classroom environment.
The learning approach combines:
- Expert-led presentations
- Real-world automotive cybersecurity examples
- Interactive discussions
- Practical exercises
- Case study workshops
- Group activities
- Knowledge checks and quizzes
- Examination preparation
- Final certification examination
A comprehensive automotive case study is integrated throughout the course to reinforce practical application of the concepts covered.
Participants who attend at least 90% of the total training duration will receive an official Certificate of Attendance from TÜV SÜD Academy.
Participants complete a final examination at the end of the training.
Examination Details
- Exam format: Single-choice questions
- Number of questions: 40
- Examination duration: 60 minutes
- Passing score: 24 out of 40 points
- Reference materials: Not permitted
Participants who successfully pass the examination will receive the:
TÜV SÜD Certificate: Automotive Cybersecurity Professional
Participants receive:
- Comprehensive course training materials.
- Presentation slides and instructor-led content.
- Case study documentation and practical exercises.
- Supporting examples and implementation guidance.
- Examination preparation materials where applicable.
Participants must:
- Successfully completed the Automotive Cybersecurity Level 1 (Foundation) training.
- Successfully passed the Automotive Cybersecurity Level 1 (Foundation) examination.
Recommended:
- Basic understanding of automotive development processes.
- Familiarity with systems, software, hardware, or cybersecurity engineering concepts.
Is this course aligned with ISO/SAE 21434?
Yes. The course is based on ISO/SAE 21434 and focuses on practical implementation of cybersecurity engineering activities across the automotive lifecycle.
What is the difference between Level 1 and Level 2?
Level 1 provides foundational understanding of automotive cybersecurity and ISO/SAE 21434 concepts. Level 2 focuses on implementation, project execution, governance, engineering activities, compliance, and practical application.
Do I need to complete Level 1 before attending?
Yes. Successful completion of the Automotive Cybersecurity Level 1 (Foundation) training and examination is required.
Does the course cover TARA?
Yes. Participants learn the ISO/SAE 21434 risk assessment process, including asset identification, threat scenarios, attack path analysis, attack feasibility evaluation, risk determination, cybersecurity goals, and claims.
Does the course include practical exercises?
Yes. Practical exercises and a detailed automotive case study are integrated throughout the training.
Does the course address supplier and OEM collaboration?
Yes. Distributed development, supplier interaction, and Cybersecurity Interface Agreements (CS-IAs) are covered.
Does the course cover cybersecurity testing?
Yes. The course includes vulnerability scanning, fuzz testing, penetration testing, and cybersecurity verification and validation strategies.
Will I learn how to develop a Cybersecurity Case?
Yes. Participants learn the purpose, structure, evidence requirements, and lifecycle management of a Cybersecurity Case.
Are post-development activities covered?
Yes. The course covers monitoring, field incident handling, vulnerability management, cybersecurity information triage, and incident response.
Does the course discuss UN R155?
Yes. The relationship between ISO/SAE 21434 and UN Regulation No. 155 is discussed, including its role in cybersecurity compliance programs.
Do participants receive a certificate?
Yes. Participants who successfully pass the final examination receive the TÜV SÜD Automotive Cybersecurity Professional certificate.
Is the course suitable for both OEMs and suppliers?
Yes. The content is relevant for OEMs, Tier-1 suppliers, Tier-2 suppliers, engineering service providers, and consultants supporting automotive cybersecurity activities.
How long is the course?
The training is delivered over two days and concludes with a certification examination.
Is the course focused only on technical cybersecurity?
No. The course addresses both technical and organizational aspects of cybersecurity, including governance, processes, competence, planning, audits, assessments, and lifecycle management.
Dr. Peter Wilks, Technical Trainer, Functional Safety TÜV SÜD
Peter has a degree in Electronic Engineering and a doctorate in Biomedical Engineering. He has worked for many years in the automotive sector on projects with a significant safety component. In recent years, projects have increasingly included cybersecurity and autonomous requirements. In addition, Peter has worked on safety-critical projects in the industrial and medical sectors. Due to this, he brings a broad experience to the training he delivers for the Academy.
