Skip to main content

ESCRYPT Supplier governance

Risk management for your supplier ecosystem

The ESCRYPT Supplier governance service by ETAS provides you with tools to reliably and efficiently assess, monitor, and successfully manage your supply chain cyber risks. This enables you to fulfill a key requirement of a cybersecurity management system (CSMS) as demanded by UN regulations and standards such as ISO/SAE 21434.

Team reviewing supplier cybersecurity risk assessment data during a governance workshop

Your benefits

Strategic

Risk classification of your suppliers and derivation of target maturity levels.

Digitalized

Manage supplier risks in Alyne GRC with automated audits and supplier benchmarking.

Integrated

Part of the ESCRYPT PROOF framework to strengthen cyber maturity across your supply chain.

Regulations demand comprehensive cyber risk management of the supplier network

Professional working on a laptop while reviewing supplier cybersecurity governance data in an office environment

UN regulation 155: cybersecurity and cybersecurity management system

The vehicle manufacturer shall

  • be required to demonstrate how their cybersecurity management system will manage dependencies that may exist with contracted suppliers, service providers or manufacturer’s sub-organizations in regards of the requirements of paragraph 7.2.2.2. [7.2.2.5.].
  • identify and manage, for the vehicle type being approved, supplier-related risks. [7.3.2.].

ISO/SAE 21434: road vehicles – cybersecurity engineering

[…] the capability of the considered supplier, to develop and, if applicable, perform post-development activities according to this document shall be evaluated. [RQ-15-01].

Your roadmap to CSMS certification

A graphic showing the different layers for cybersecurity risk management

Automotive-specific regulations make it critical for OEMs and suppliers to set up adequate cybersecurity management systems with greatest efficiency. Our ESCRYPT Product security organization framework PROOF helps you cover cybersecurity development in five domains: governance, risk management, concept & development, production & operation, and ecosystem. Your advantage: a structured, traceable approach to achieving cybersecurity in accordance with the legal and standard requirements.

18,000
An automotive OEM may have more than 18,000 suppliers involved in its production process.

Digitalize your supplier risk management

Graphics showcasing the target maturity of an organization

Digitalize your supplier risk management

Take your supplier risk management to the next level and realize smart cybersecurity with the ESCRYPT PROOF maturity framework – now also available on the Alyne GRC platform. This integration enables a digitalized supplier risk management including efficient audit, evaluation, and benchmarking. Take advantage of higher maturity levels and continuously guide your supply chain to your organization’s target maturity. Close the plan-do-check-act loop with follow-up delta audits and hints for continuous improvement.

Knowledge base

Practical guidance and expertise– our Knowledge Base is your central hub for in-depth insights into automotive software and engineering and provides you with practical information for your success.

Is your Off-Highway business geared for cyber resilience?

The cover of an ETAS brochure titled "Navigating the Cyber Resilience Act in the off-highway industry.

Is your Off-Highway business geared for cyber resilience?

The regulatory landscape for Off-Highway vehicles is changing. Learn how to leverage best practises and avoid unnecessary costs with our expert approach to securing your Off-Highway product for the long haul.

The Diagnostic Dilemma: Cybersecurity & Right-to-Repair Explained

YouTube

Loading the video requires your consent. If you agree by clicking on the Play icon, the video will load and data will be transmitted to Google as well as information will be accessed and stored by Google on your device. Google may be able to link these data or information with existing data.

The Diagnostic Dilemma: Cybersecurity & Right-to-Repair Explained

Learn how manufacturers can strike the right balance between protecting connected products and enabling fair and reasonable access for operators, service technicians, independent repair providers, and other legitimate users.

Simplify vehicle diagnostics with ActiveSchematics

YouTube

Loading the video requires your consent. If you agree by clicking on the Play icon, the video will load and data will be transmitted to Google as well as information will be accessed and stored by Google on your device. Google may be able to link these data or information with existing data.

Simplify vehicle diagnostics with ActiveSchematics

ActiveSchematics automatically generates the schematic information technicians need based on a specific VIN, function, fault code, or symptom. This helps reduce time spent searching through static diagrams and enables technicians to focus on diagnosing and repairing the vehicle.

Illustration of people using phone, email and laptop channels to contact ETAS experts.

Contact us

Do you have any questions? Get in touch with us!