An independent overview from DQS, an accredited certification body.

ENX VCS (Vehicle Cyber Security) is the automotive industry’s assessment scheme for evaluating an organization’s Cybersecurity Management System (CSMS) for vehicles and their components. Developed by the ENX Association – the same body that operates TISAX® – ENX VCS provides a globally standardized test basis through which suppliers can demonstrate that they implement a CSMS in line with ISO/SAE 21434 and the guidance of ISO/PAS 5112, and that supports compliance with the regulatory expectations of UNECE Regulation No. 155 (UN R155).

ENX VCS is relevant to organizations along the automotive value chain whose products, components, software, or services contribute to vehicle cybersecurity. This includes OEMs, tier 1 suppliers of electronic control units and connected components, software and platform providers, and engineering service providers. Customers – particularly OEMs subject to UN R155 type-approval obligations – increasingly require their suppliers to demonstrate a CSMS that is independently assessed.

ENX VCS was launched in June 2024 and has progressively expanded since. Free registration during the early phase ran through the end of 2024, with the broader rollout continuing in 2025 and 2026. ENX VCS adds to the ENX scheme portfolio alongside TISAX, with a current TISAX label generally serving as a prerequisite for ENX VCS audits.

One of the key differentiators of ENX VCS compared to ISO/SAE 21434 are the strictly regulated qualification requirements for the assessment team. In particular, each assessment team must include a VCS expert with demonstrated practical experience in automotive cybersecurity and the Vehicle Cyber Security (VCS) domain.

While these qualification requirements inevitably increase the cost of a VCS assessment, they also provide significant value to the customer. The involvement of experienced VCS experts helps ensure a technically sound and consistent assessment, enables more meaningful discussions during the interviews, and allows customers to benefit from the assessors’ practical experience with real-world cybersecurity implementations in the automotive industry.

Clients can obtain one or more of three VCS labels for their VCS-related locations: “VCS Development”, “VCS Production”, and “VCS Operations and Maintenance.” These labels allow organizations to demonstrate their specific cybersecurity capabilities to customers and other interested parties, depending on the VCS activities for which they are contractually responsible.

UN R155 entered into force in January 2021. However, the dates on which compliance became mandatory differ by jurisdiction. In the European Union, UN R155 has applied to all newly approved vehicle types since July 2022 and to all newly produced vehicles since July 2024. China has introduced its own national cybersecurity regulation, GB 44495:2024, which is broadly aligned with the objectives of UN R155 but constitutes a separate regulatory framework. It applies to newly approved vehicle types from January 2026 and to all newly produced vehicles from January 2028.

Already operating a cybersecurity management system for automotive products?

If your organization supplies the automotive industry and you are preparing for an ENX VCS assessment, our dedicated assessment page has everything you need – from process overview to a personalized quote.

Go to ENX VCS As­sess­ment with DQS

What is ENX VCS, from a certification body’s perspective?

From a certification body’s perspective, ENX VCS is the automotive industry assessment scheme through which an audit provider approved by the ENX Association evaluates an organization’s CSMS against the requirements of ISO/SAE 21434, the guidance of ISO/PAS 5112, and ENX VCS scheme requirements. The assessment results in an ENX VCS audit result exchanged via the ENX Portal – comparable in concept to the TISAX label exchange – rather than an ISO-style certificate.

ENX VCS sits alongside TISAX as part of the ENX scheme portfolio: TISAX focuses on information security at the supplier’s site; ENX VCS focuses on the supplier’s CSMS for the vehicle and its components. A current TISAX label and established QMS are generally  prerequisites for ENX VCS audits. Third-party assessment by an approved audit provider is the recognized industry-wide way to demonstrate a CSMS, and the audit result is accepted by participating OEM customers through the ENX exchange mechanism.

As a certification body, DQS assesses conformity – it does not design or implement your cybersecurity management system. That independence is what gives an ENX VCS audit result its value: the organization builds and runs the CSMS, and an approved audit provider verifies it against the scheme’s requirements.

Key Facts about ENX VCS at a Glance

Full TitleENX Vehicle Cyber Security (ENX VCS)
Published byENX Association (the same body that operates TISAX), in coordination with the automotive industry.
First PublishedLaunched June 2024
Current VersionENX VCS scheme requirements as maintained by the ENX Association; the assessment basis is ISO/SAE 21434 and the guidance of ISO/PAS 5112, aligned with UN R155.
Management System TypeCybersecurity Management System (CSMS) for vehicles and their components.
Applicable toOEMs, tier 1 and tier 2 suppliers of electronic and software components, software and platform providers, and engineering service providers contributing to vehicle cybersecurity.
CertifiableENX VCS is an assessment scheme rather than a certification scheme. The assessment results in an ENX VCS audit result exchanged via the ENX Portal; it is not an ISO-style certificate.
StructureAssessment based on ISO/SAE 21434 (Road vehicles – Cybersecurity engineering) and ISO/PAS 5112 (Guidelines for auditing cybersecurity engineering), complemented by ENX VCS scheme requirements; a current TISAX label and established QMS are generally prerequisites.
Related StandardsTISAX® (information security at the supplier site, prerequisite); ISO/SAE 21434 (cybersecurity engineering reference standard); ISO/IEC 27001 (information security management).

 

Context and Drivers for ENX VCS

UN R155 and Vehicle-Type Approval

UNECE Regulation No. 155 establishes uniform provisions for the approval of vehicles with regard to cybersecurity and cybersecurity management systems. Vehicle manufacturers must demonstrate that they operate a CSMS that addresses cybersecurity throughout the development, production, and post-production life cycle. OEMs are required to flow CSMS expectations down to their suppliers, who in turn need an effective and demonstrable CSMS.

ISO/SAE 21434 and ISO/PAS 5112

ISO/SAE 21434 (Road vehicles – Cybersecurity engineering) is the technical reference standard for cybersecurity engineering across the automotive product life cycle. ISO/PAS 5112 (Guidelines for auditing cybersecurity engineering) provides guidance on auditing CSMS implementations. ISO/SAE 21434 alone is not sufficient to meet all UN R155 requirements; UN R155 references the standard but adds further regulatory expectations. ENX VCS uses these documents as the assessment basis while implementing the scheme procedures that make audit results comparable and exchangeable across the industry.

Mutual Recognition and Reduction of Duplicate Audits

Automotive suppliers are increasingly subject to multiple cybersecurity audits from different OEM customers. ENX VCS is designed around mutual recognition: an organization commissions one assessment and shares the result via the ENX Portal, reducing duplication. The combination of TISAX and ENX VCS gives OEMs a complete picture – information security at the supplier’s site, plus cybersecurity engineering for vehicle products and components.

 

Core Requirements for ENX VCS

Cybersecurity Governance and Organizational Context

Establishment of a cybersecurity culture, governance roles, policies, and management commitment. The CSMS must be embedded within the organization’s broader governance and integrate with quality, information security, and functional safety management.

Cybersecurity Risk Management (TARA)

Systematic Threat Analysis and Risk Assessment (TARA) following ISO/SAE 21434, applied to vehicle assets and their cybersecurity-relevant interfaces. Identified risks are evaluated and treated through documented controls and design decisions.

Cybersecurity in the Product Life Cycle

Cybersecurity activities across concept, product development, post-development (production, operations, maintenance, decommissioning), and supporting processes – including requirements management, design, integration, verification, and validation.

Continuous Cybersecurity Activities

Cybersecurity monitoring, vulnerability management, incident response, and post-production support are ongoing activities throughout the vehicle lifecycle. UN R155 explicitly requires that the capabilities of the Cybersecurity Management System (CSMS) be maintained on a continuous basis. Accordingly, ENX VCS assesses not only the initial maturity of these processes but also the organization’s ability to sustain them over time.

The requirement to maintain valid TISAX labels complements this objective by providing assurance that the organization’s information security posture remains effective against evolving IT threats that could impact its vehicle cybersecurity activities.–.

Supplier and Distributed Development Management

Management of cybersecurity in the supply chain: requirements flow-down to suppliers, supplier capability assessment, interface agreements, and joint cybersecurity activities. ENX VCS supports OEMs in evidencing supplier cybersecurity capability across their supply base.

Audit Process and Exchange

Assessments are conducted by audit providers approved by the ENX Association. Findings are documented and classified, and the assessment results are shared through the ENX Portal with participating customers in accordance with the supplier’s consent and the rules of the ENX VCS scheme.

Interested parties can register as ENX participants to obtain real-time visibility into the current VCS label status of their suppliers. This enables the ENX Portal to serve as an effective supplier management tool, allowing organizations to verify and continuously monitor the cybersecurity assessment status of their supply chain.

 

Target Groups and Application Areas for ENX VCS

ENX VCS is intended for organizations whose products, components, software, or services contribute to vehicle cybersecurity. Typical scope includes OEMs (preparing for and maintaining UN R155 type approvals), tier 1 suppliers of electronic control units (ECUs), telematics units, gateways, infotainment systems, and connected components, tier 2 suppliers of semiconductors, embedded software, and hardware modules with cybersecurity relevance, providers of in-vehicle and back-end software/infrastructure platforms, and engineering service providers undertaking development on behalf of OEMs and tier 1 suppliers.

OEMs and tier 1 customers use ENX VCS audit results – together with TISAX labels – as the basis for supplier qualification and ongoing supplier management. The scheme supports informed sourcing decisions by procurement, cybersecurity, and engineering functions in customer organizations and reduces the audit burden on suppliers serving multiple OEMs.

Organizations outside the automotive ecosystem typically rely on ISO/IEC 27001 or other sector-specific information security and cybersecurity frameworks rather than ENX VCS. Where a supplier serves both automotive and adjacent industries (e.g. industrial control, medical devices), parallel certifications and assessments are often maintained.

 

Standards Related to ENX VCS

Relationship to TISAX®

TISAX is the information security assessment scheme for the automotive industry and focuses on the supplier’s site-level information security management system. ENX VCS focuses on the supplier’s cybersecurity management system for vehicles and their components. A current TISAX label is generally a prerequisite for an ENX VCS audit. The two schemes are complementary parts of the ENX portfolio and are not interchangeable.

ISO/SAE 21434 – the Reference Engineering Standard

ISO/SAE 21434 is the international standard for road vehicle cybersecurity engineering and is the technical basis of ENX VCS. ISO/SAE 21434 is not, on its own, sufficient to meet all UN R155 requirements. ENX VCS uses ISO/SAE 21434 and ISO/PAS 5112 within a structured assessment scheme that supports OEM and supplier alignment with UN R155.

UN R155 and Regulatory Context

UN R155 is a UNECE regulation establishing approval requirements for vehicles with respect to cybersecurity and CSMS. UN R155 is regulatory law in many jurisdictions following national adoption. ENX VCS supports demonstration of a CSMS aligned with UN R155 expectations, but ENX VCS audit results do not by themselves constitute UN R155 type approval – which remains the responsibility of competent type-approval authorities.

ISO/IEC 27001 and Information Security Management

ISO/IEC 27001 is the certifiable international management system standard for information security. While its scope is broader than automotive cybersecurity, ISO/IEC 27001 is structurally aligned with the management-system thinking that underpins ISO/SAE 21434 and ENX VCS. Many automotive suppliers maintain ISO/IEC 27001 certification in parallel with TISAX labels and ENX VCS audit results.

Your organization develops vehicle components, software, or systems and you are now preparing for an ENX VCS assessment?

Learn more on our dedicated ENX VCS page.

ENX VCS As­sess­ment with DQS

About DQS as a certification body

This article is part of the DQS Knowledge Center, a resource on management system standards and certification processes. For context on who produced it:

  • One of Germany’s first management system certifiers – DQS issued its first certificate in 1986 and has audited and certified management systems for over 40 years.
  • Operates from more than 80 offices in 60 countries with a worldwide network of more than 3,000 auditors.
  • Approved by the ENX Association as an audit provider for ENX VCS and TISAX, and accredited for related standards including ISO/IEC 27001 and IATF 16949 – so automotive organizations can be served across vehicle cybersecurity, information security, and quality management certification from a single provider.
  • Member of IQNet, the international certification network, supporting cross-border recognition of DQS certificates.

The articles in this Knowledge Center are written and reviewed by DQS specialists working with these standards in audit practice. Where applicable, content is verified against the current version of the standard, the issuing body’s official publications, and recent regulatory or accreditation guidance. This article was last reviewed on 3 June 2026.

Frequently Asked Questions about ENX VCS

Is ENX VCS mandatory?

ENX VCS is a voluntary assessment scheme. However, UN R155 makes a vehicle CSMS effectively mandatory for OEMs seeking type approval, and OEMs flow CSMS expectations down to their suppliers. Many automotive customers therefore require – or strongly prefer – ENX VCS audit results from their suppliers, particularly for components with cybersecurity relevance.

Is ENX VCS a certification?

No. ENX VCS is an assessment scheme, not a certification scheme. A successful assessment results in an ENX VCS audit result exchanged via the ENX Portal, rather than an ISO-style certificate. The design follows the ENX mutual-recognition model used for TISAX.

What standards does ENX VCS use as its assessment basis?

ENX VCS uses ISO/SAE 21434 (Road vehicles – Cybersecurity engineering) as the technical basis and ISO/PAS 5112 (Guidelines for auditing cybersecurity engineering) as guidance for auditors. ENX VCS scheme requirements add the procedural rules that make audit results comparable across the industry. The combination is aligned with UN R155 expectations.

Is a TISAX® label required for ENX VCS?

Yes, generally. A current TISAX label is a prerequisite for an ENX VCS audit. The two schemes are designed to operate together within the ENX scheme portfolio.

How does ENX VCS relate to UN R155?

UN R155 is a UNECE regulation establishing approval requirements for vehicles with respect to cybersecurity and CSMS. ENX VCS provides an industry-wide assessment scheme through which suppliers demonstrate a CSMS aligned with UN R155 expectations – using ISO/SAE 21434 and ISO/PAS 5112 – but ENX VCS audit results do not by themselves constitute UN R155 type approval, which remains the responsibility of competent type-approval authorities.

From when does UN R155 apply?

UN R155 applies to all new vehicle types from January 2026 and to all vehicle types from January 2028 in jurisdictions that have adopted the regulation. National transposition timelines vary; organizations should verify the regulatory status in each market they serve.