About the Author and Research
This research was authored by Matvieiev, Yevhenii Viacheslavovych (Матвєєв, Євгеній Вячеславович), a Ukrainian researcher specializing in national technical regulation frameworks for vehicle cybersecurity. Published on arXiv in 2023—one of the world's largest preprint academic platforms hosting over 2.2 million papers—this study occupies a unique position at the intersection of engineering standards and national regulatory policy.
The author's central contribution is a systematic analysis of how ISO 21434:2021, the international standard for road vehicle cybersecurity engineering, can be translated into actionable national technical regulation. The research reviews core concepts and requirements of the standard, cross-references multiple international cybersecurity documents including UNECE WP.29 frameworks, and proposes a methodology for improving national connected vehicle security systems. While the study focuses on Ukraine's regulatory landscape, its methodological approach and identified structural gaps carry direct relevance for any manufacturing nation—including Taiwan—navigating the transition from international standards adoption to verifiable compliance.
Core Research Findings: The Three-Layer Translation Challenge
The research's central finding is that simply adopting ISO 21434:2021 as a reference standard is insufficient. Effective national regulatory frameworks must achieve alignment across three distinct layers, each presenting different implementation challenges.
Finding 1: Full Lifecycle Coverage Exposes Regulatory Blind Spots
ISO 21434:2021 mandates cybersecurity management across the entire vehicle lifecycle—from concept design through development, production, post-production monitoring, and end-of-life decommissioning. The author's analysis reveals that most existing national vehicle regulations focus narrowly on pre-market type approval, leaving quantifiable regulatory gaps in post-production vulnerability management (Chapter 13 of ISO 21434:2021) and incident response (Chapter 14). This structural gap directly undermines the security assurance of connected vehicles during their operational lifetime in the market. UNECE WP.29 Regulation 155, which became mandatory for new vehicle types in the EU from July 2022, requires OEMs to establish a Cybersecurity Management System (CSMS) precisely to address this lifecycle management gap.
Finding 2: Verifiability, Not Documentation, Is the True Compliance Metric
The author establishes that effective standard-to-regulation translation requires three hierarchical levels of correspondence: conceptual consistency (terminology alignment with international standards), process executability (converting functional requirements into auditable concrete measures), and systemic regulatory integration (embedding vehicle cybersecurity within existing type approval frameworks). For Taiwan's automotive suppliers, this means that claiming "ISO 21434 compliance" without demonstrable, auditable evidence across all three levels will fail under TISAX Level 2 or Level 3 on-site assessments. The distinction between documented compliance and verifiable compliance is the single most important insight this research provides for Taiwan's supply chain practitioners.
Implications for Taiwan's Automotive Cybersecurity Practice
Taiwan's automotive supply chain is experiencing convergent regulatory pressure that directly mirrors the challenges analyzed in this research. Since UNECE WP.29 R155 became mandatory for new vehicle types in the EU in July 2022, global OEMs have progressively required suppliers to provide ISO/SAE 21434-compliant cybersecurity engineering documentation. Several major Tier 1 customers have already incorporated TISAX certification as a mandatory supplier qualification criterion.
Three specific implications stand out for Taiwan enterprises:
Post-Production Monitoring Remains Taiwan's Weakest Link. Based on Winners Consulting Services Co. Ltd.'s advisory experience with Taiwan's automotive supply chain, the most pervasive compliance gap is not in design-phase Threat Analysis and Risk Assessment (TARA), where significant improvements have been made, but in the post-production mechanisms required by ISO 21434:2021 Chapters 13 and 14. Vulnerability disclosure processes, CVE monitoring for automotive components, and structured incident response workflows are absent in the majority of Taiwan's Tier 2 and Tier 3 suppliers.
Supply Chain Security Requirements Cannot Be Ignored. ISO 21434:2021 Chapter 7 places explicit cybersecurity obligations on organizations regarding their own suppliers' security capabilities. For Taiwan's SME-heavy supply chain, this creates a cascading compliance requirement: Tier 1 suppliers cannot achieve genuine ISO 21434 compliance without ensuring their component vendors meet baseline cybersecurity standards. This supply chain dimension is consistently underestimated in initial compliance planning.
CSMS Certification Timelines Are Longer Than Expected. The Ukrainian research analysis indicates that even technically mature manufacturing economies require an average of 18 months or more to establish a CSMS meeting UNECE WP.29 R155 requirements. Taiwan suppliers targeting EU market entry in 2025-2026 should consider that their compliance preparation window is already constrained.
Winners Consulting Services Co. Ltd.: Actionable Framework for Taiwan Suppliers
Winners Consulting Services Co. Ltd. (積穗科研股份有限公司) assists Taiwan's automotive supply chain in achieving TISAX certification, implementing vehicle cybersecurity standards under ISO/SAE 21434, and meeting UNECE WP.29 regulatory requirements. Drawing directly from the three-layer translation framework identified in this research, we recommend the following structured action plan:
- [Months 1-2] Conduct ISO 21434 Gap Analysis: Map existing documentation, processes, and technical controls against all 15 major chapters of ISO 21434:2021, with priority focus on Chapters 7 (Distributed cybersecurity activities), 13 (Vulnerability management), and 14 (Incident response). Simultaneously establish a TISAX requirement traceability matrix to identify which gaps carry the highest audit risk.
- [Months 3-6] Build an Auditable Cybersecurity Management System (CSMS): Design and implement management mechanisms that are explicitly structured for verifiability—not just documentation. This includes standardizing TARA processes, establishing post-production vulnerability monitoring workflows, defining supplier cybersecurity requirements (ISO 21434:2021 Chapter 7 compliance), and creating incident response procedures that can be demonstrated in a TISAX on-site evaluation.
- [Months 7-12] Execute TISAX Assessment and Build Internal Capability: Conduct at least two internal mock audits with findings remediation cycles. Complete TISAX assessment application, on-site evaluation, and label issuance. Critically, establish an annual review mechanism to maintain ongoing compliance—TISAX certification is a continuous commitment, not a one-time achievement. Ensure all relevant personnel can articulate their cybersecurity responsibilities and provide execution evidence independently.
Winners Consulting Services Co. Ltd. provides a complimentary Automotive Cybersecurity Mechanism Diagnostic, helping Taiwan enterprises establish TISAX-compliant management systems within 7 to 12 months.
Explore Automotive Cybersecurity (AUTO) Services → Request Free Diagnostic →Frequently Asked Questions
- What is the practical difference between ISO 21434:2021 compliance and UNECE WP.29 R155 CSMS certification for Taiwan suppliers?
- ISO 21434:2021 is a technical engineering standard that specifies how cybersecurity should be integrated throughout the vehicle development lifecycle. UNECE WP.29 R155 is an international regulation that mandates OEMs to demonstrate an organizational Cybersecurity Management System (CSMS) as a prerequisite for vehicle type approval in the EU. For Taiwan suppliers, ISO 21434 provides the engineering methodology framework, while CSMS certification (aligned with TISAX) provides the auditable organizational evidence that OEM customers require. Since R155 became mandatory for new vehicle types in July 2022, Taiwan Tier 1 suppliers exporting to EU markets must ensure their OEM partners' CSMS references their own cybersecurity engineering practices. In practical terms, ISO 21434 compliance without CSMS/TISAX documentation leaves suppliers unable to provide the verifiable evidence OEMs need for their own regulatory submissions.
- What are the most common TISAX assessment failures for Taiwan automotive suppliers?
- Based on Winners Consulting Services Co. Ltd.'s advisory experience, Taiwan suppliers most frequently encounter findings in three areas during TISAX Level 2 on-site assessments. First, documentation-practice gaps: written procedures exist but actual workflows do not follow them—on-site interviews immediately surface this disconnect. Second, post-production mechanism absence: ISO 21434:2021 Chapter 13 (vulnerability management) and Chapter 14 (incident response) mechanisms are either missing or exist only as paper policies without operational implementation evidence. Third, supplier security management gaps: Chapter 7 requirements for managing cybersecurity obligations within the supply chain are rarely implemented with traceable evidence. Addressing these three areas before the formal TISAX assessment is the single most impactful preparation investment.
- How should Taiwan suppliers choose between TISAX Assessment Levels 1, 2, and 3?
- TISAX provides three assessment levels with increasing rigor: Level 1 (self-assessment only), Level 2 (remote or on-site assessment by an accredited TISAX assessment provider), and Level 3 (high-protection-needs assessment for sensitive intellectual property). The majority of Tier 1 automotive suppliers are required by OEM customers to achieve Level 2. Level 3 is typically required for suppliers handling highly confidential vehicle development data or prototype information. Preparation timelines are approximately 3-4 months for Level 1, 6-9 months for Level 2, and 9-12+ months for Level 3. Winners Consulting recommends confirming the specific customer requirement in writing before committing to an assessment level, as over-preparation for Level 3 when Level 2 is sufficient creates unnecessary resource expenditure.
- What is the realistic resource investment for a Taiwan mid-sized Tier 1 supplier to achieve TISAX Level 2 certification?
- For a typical Taiwan Tier 1 supplier with 200-500 employees starting from a low cybersecurity maturity baseline, achieving TISAX Level 2 certification typically requires 2-3 dedicated internal personnel, external consulting support, and a 9-12 month implementation timeline. The effort distribution is approximately: gap analysis and mechanism design (30%), documentation and staff training (40%), internal audit and remediation (20%), and formal assessment preparation (10%). From a return-on-investment perspective, TISAX certification typically unlocks German OEM supplier qualification opportunities. For most Taiwan suppliers, the first qualifying contract secured as a result of TISAX certification recovers the full implementation investment. Winners Consulting's engagement model maximizes knowledge transfer to internal teams, reducing long-term external advisory dependency.
- Why engage Winners Consulting Services Co. Ltd. for Automotive Cybersecurity (AUTO) matters?
- Winners Consulting Services Co. Ltd. (積穗科研股份有限公司) is Taiwan's specialized automotive cybersecurity consultancy with integrated competencies across ISO/SAE 21434 engineering implementation, TISAX certification advisory, and UNECE WP.29 CSMS compliance planning. Our consultants hold both automotive engineering credentials and information security qualifications, enabling support at both the technical level (TARA execution, ECU security design, OTA security architecture) and the management system level (CSMS establishment, supply chain security governance). Compared to general information security consultancies, our differentiated value lies in deep familiarity with automotive development processes (ASPICE, AUTOSAR ecosystems), practical understanding of Taiwan's supply chain resource realities, and a structured 7-12 month engagement model with clearly defined deliverables at each phase. Contact us to request a complimentary cybersecurity mechanism diagnostic.
日本語版
積穗科研股份有限公司(Winners Consulting Services Co. Ltd.)は、2023年に発表されたウクライナの研究論文に注目しています。この研究は、ISO 21434:2021に基づくコネクテッドカーの国家技術規制整備について体系的に分析しており、台湾の自動車サプライチェーンがTISAX認証取得とUNECE WP.29コンプライアンス達成に向けた比較的視点のフレームワークを提供しています。特に「国際標準を実行可能な国家規制フレームワークに転換する方法」という核心的課題は、台湾が現在最も解決を必要としている問題と一致しています。
論文出典:Технічне регулювання України щодо кібербезпеки підключеного автомобіля на відповідність вимогам ISO 21434:2021(Матвєєв, Євгеній Вячеславович,arXiv,2023)
原文リンク:https://core.ac.uk/download/572918967.pdf
Source Paper
Технічне регулювання України щодо кібербезпеки підключеного автомобіля на відповідність вимогам ISO 21434:2021(Матвєєв, Євгеній Вячеславович,arXiv,2023)
Read Original Paper →Was this article helpful?
Related Services & Further Reading
Related Services
Want to apply these insights to your enterprise?
Get a Free Assessment