{"id":34587,"date":"2026-08-10T05:00:00","date_gmt":"2026-08-10T03:00:00","guid":{"rendered":"https:\/\/sii.pl\/blog\/?p=34587"},"modified":"2026-08-05T14:12:27","modified_gmt":"2026-08-05T12:12:27","slug":"the-cybersecurity-interface-agreement-cia-and-why-you-need-one","status":"publish","type":"post","link":"https:\/\/sii.pl\/blog\/en\/the-cybersecurity-interface-agreement-cia-and-why-you-need-one\/","title":{"rendered":"The Cybersecurity Interface Agreement (CIA) and why you need one"},"content":{"rendered":"\n<p>Long past are the days when a single organization developed the electronic control units (ECUs) for a vehicle program in complete isolation, with cybersecurity just an afterthought.<\/p>\n\n\n\n<p>Nowadays, vehicle architectures are inherently distributed, with cybersecurity-relevant assets, interfaces, and responsibilities spanning the OEM, tier-one suppliers, and tier-two suppliers providing hardware and software.<\/p>\n\n\n\n<p>The <strong>ISO\/SAE 21434<\/strong> standard explicitly recognizes this and introduces the Cybersecurity Interface Agreement (CIA) as a mechanism to manage cybersecurity dependencies across organizational boundaries.<\/p>\n\n\n\n<p>More than being just a compliance exercise, the CIA is one of the most important steps to get right at the beginning of an ISO\/SAE 21434-compliant automotive project. As the Tier-one supplier, which is the role of many practitioners, you are often nestled between the OEM with their vehicle-level cybersecurity concept, requirements, and process expectations, and your Tier-two suppliers with their ECU hardware, base software, and technical IP. Hence, it is critical that you coordinate a robust CIA between all three parties, since you all have a hand in securing the end ECU product in the vehicle.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong><strong>The CIA in ISO\/SAE 21434<\/strong><\/strong><\/h2>\n\n\n\n<p>The Cybersecurity Interface Agreement is defined within <strong>Clause 7 (Distributed Cybersecurity Activities)<\/strong> of ISO\/SAE 21434, with <strong>Clause 7.4.3<\/strong> specifying the requirements for establishing and maintaining a CIA.<\/p>\n\n\n\n<p>This clause describes how to manage the distribution of cybersecurity activities across organizational boundaries for the development of items and components. It covers the interactions and interfaces between a customer and a supplier, and these roles can be at different levels, e.g., customer OEM&lt;-&gt;supplier tier-one, customer tier-one &lt;-&gt; supplier tier-two. All phases of the project, including post-development, vulnerability management, and end-of-life, should be covered in the CIA.<\/p>\n\n\n\n<p>The standard also mentions that internal suppliers can be managed using the CIA in the same way as external suppliers, though this is not typically done in most organizations. This could be an option if your organization is very siloed in its operations.<\/p>\n\n\n\n<p>Each customer&lt;-&gt;supplier interface in the CIA should be unique and bidirectional.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong><strong>Practice<\/strong><\/strong><\/h3>\n\n\n\n<p>Meaning that if the project involves one OEM, one tier-one supplier, and two tier-two suppliers, you may be tempted to include them all in a single CIA template. DON\u2019T! You should always maintain a one-to-one relationship for each CIA and use multiple, separate, one-to-one CIA&#8217;s when multiple parties are involved.<\/p>\n\n\n\n<p>In the example, there would be three CIAs:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>OEM \u2194 Tier 1<\/li>\n\n\n\n<li>Tier 1 \u2194 Tier 2A<\/li>\n\n\n\n<li>Tier 1 \u2194 Tier 2B<\/li>\n<\/ul>\n\n\n\n<p>This will greatly reduce the risk of ambiguity, disagreement, and conflict down the road and increase the document&#8217;s clarity. Especially since this will be a contractual agreement, it makes sense to make it between only two parties.<\/p>\n\n\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6a79445d552bd&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6a79445d552bd\" class=\"wp-block-image size-full wp-lightbox-container\"><img decoding=\"async\" width=\"1024\" height=\"1024\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/sii.pl\/blog\/wp-content\/uploads\/2026\/08\/image1.png\" alt=\"Example CIA Interfaces\" class=\"wp-image-34580\" srcset=\"https:\/\/sii.pl\/blog\/wp-content\/uploads\/2026\/08\/image1.png 1024w, https:\/\/sii.pl\/blog\/wp-content\/uploads\/2026\/08\/image1-300x300.png 300w, https:\/\/sii.pl\/blog\/wp-content\/uploads\/2026\/08\/image1-150x150.png 150w, https:\/\/sii.pl\/blog\/wp-content\/uploads\/2026\/08\/image1-768x768.png 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\taria-label=\"Enlarge\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.imageButtonRight\"\n\t\t\tdata-wp-style--top=\"state.imageButtonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><figcaption class=\"wp-element-caption\">Fig. 1 Example CIA Interfaces<\/figcaption><\/figure>\n\n\n\n<p>Another option when multiple parties are involved is that you can have one overall document for the CIA for the project with multiple CIA pages within it, using a separate page for each one-to-one CIA relationship, and then have all parties sign off on the overall CIA document. Otherwise, it is highly recommended to maintain a unique, separate CIA for each interface. Especially as the tier-one, as the OEM will hold you accountable even when it is the tier-two&#8217;s responsibility.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong><strong>Example CIA template content<\/strong><\/strong><\/h2>\n\n\n\n<p>In <strong>Appendix C<\/strong> of the ISO\/SAE Standard, an example CIA template is provided. This can be a good starting point for your organization and can easily be adapted to your spreadsheet program. Some organizations have even started using their own database tools to manage and standardize their CIAs.<\/p>\n\n\n\n<p>Overall, though, the tool is not as important as the content that it contains. The participating organizations must document in the CIA their agreement on responsibilities (typically using an RASIC), the level of information disclosure, and the level of achievement for each milestone (as well as the milestones themselves).<\/p>\n\n\n\n<p>The CIA should also include the contact details for all parties involved (OEM, tier-one, and tier-two suppliers), as well as space for them to sign off on the document to establish it as a formal contract. This is a critical step because, as the project progresses over multiple years, you will often find yourselves referring back to the CIA to see what was agreed to be delivered, by whom, and at which milestone. So, it is very important that the parties knowingly agree and sign off on this.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong><strong>Key elements<\/strong><\/strong><\/h3>\n\n\n\n<p>Other key elements that should be included for each line item in your CIA template are:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Phase<\/strong>: the phase of the project, e.g., Concept, Product Development, etc., in which the cybersecurity activity will be performed.<\/li>\n\n\n\n<li><strong>Work<\/strong> <strong>Product<\/strong>: the actual work product from ISO\/SAE 21434 (see Appendix A for the full list) to be delivered as part of the cybersecurity activity.<\/li>\n\n\n\n<li><strong>Reference<\/strong>: a link to the clause and requirements from the ISO\/SAE 21434 standard relevant to the cybersecurity activity.<\/li>\n\n\n\n<li><strong>Supplier<\/strong><strong>RASIC<\/strong>: supplier responsibilities for the cybersecurity activity and work product.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong><strong>Customer<\/strong> <strong>RASIC<\/strong><\/strong><\/h3>\n\n\n\n<p>Customer responsibilities for the cybersecurity activity and work product:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>R (responsible): the organization that is responsible for conducting the activity.<\/li>\n\n\n\n<li>A (accountable): the organization that has the authority to approve the activity.<\/li>\n\n\n\n<li>S (supporting): the organization that will assist the organization responsible for the activity.<\/li>\n\n\n\n<li>I (informed): the organization that is informed of the progress of the activity and any decision being made.<\/li>\n\n\n\n<li>C (consulted): the organization that offers advice or guidance but does not actively work on the activity.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Level of Confidentiality<\/strong><\/h3>\n\n\n\n<p>The organizations involved agree to the confidentiality of the work product. Example levels of confidentiality could be:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Highly Confidential: Only the organization that created the work product is allowed to access it.<\/li>\n\n\n\n<li>Confidential: Both customer and supplier are allowed to access the work product.<\/li>\n\n\n\n<li>Confidential with Third Parties: This work product is allowed to be shared with external Parties.<\/li>\n\n\n\n<li>Public: the work product can be shared without any restrictions.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong><strong>Other elements<\/strong><\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Deliverable<\/strong>: a description of the actual work product to be delivered, in what format, and how it shall be transmitted, and if any reviews or verification steps are required.<\/li>\n\n\n\n<li><strong>Tailoring<\/strong>: Describe the rationale for the joint tailoring of any of the cybersecurity activities<\/li>\n\n\n\n<li><strong>Exchange<\/strong> <strong>Scope<\/strong>: What level of the work product shall be shared, e.g., delivered fully, an extract, onsite review only, or not delivered.<\/li>\n\n\n\n<li><strong>Exchange<\/strong> <strong>Direction<\/strong>: whether the work product is delivered from supplier to customer or vice versa<\/li>\n\n\n\n<li><strong>Milestones<\/strong>: The target milestone for completing each activity and delivering the work product<\/li>\n\n\n\n<li><strong>Comment<\/strong>: any additional information concerning the discussion and state of agreement for the cybersecurity activity.<\/li>\n<\/ul>\n\n\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6a79445d561cf&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6a79445d561cf\" class=\"wp-block-image size-large wp-lightbox-container\"><img decoding=\"async\" width=\"1024\" height=\"218\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/sii.pl\/blog\/wp-content\/uploads\/2026\/08\/image2-1024x218.png\" alt=\"Example CIA Template\" class=\"wp-image-34582\" srcset=\"https:\/\/sii.pl\/blog\/wp-content\/uploads\/2026\/08\/image2-1024x218.png 1024w, https:\/\/sii.pl\/blog\/wp-content\/uploads\/2026\/08\/image2-300x64.png 300w, https:\/\/sii.pl\/blog\/wp-content\/uploads\/2026\/08\/image2-768x164.png 768w, https:\/\/sii.pl\/blog\/wp-content\/uploads\/2026\/08\/image2.png 1393w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\taria-label=\"Enlarge\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.imageButtonRight\"\n\t\t\tdata-wp-style--top=\"state.imageButtonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><figcaption class=\"wp-element-caption\">Fig.\u00a0 2 Example CIA Template<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong><strong>When to establish the CIA?<\/strong><\/strong><\/h2>\n\n\n\n<p>Since the CIA covers the entire lifecycle of cybersecurity activities for the component from the concept phase extending through post-production, it is very important and most effective to establish the CIA as early as possible in the project timeline. Ideally, before any project work starts, but at least before the Threat Analysis and Risk Assessment (TARA) is performed.<\/p>\n\n\n\n<p>Many of the cybersecurity activities specified in the CIA will need to be quoted by tier-one and tier-two suppliers; thus, clear ownership of these activities needs to be defined and agreed upon upfront. In addition, activities involving third-party costs, such as external cybersecurity assessments and penetration tests, need to be captured in the CIA so they can be budgeted for in project plans.<\/p>\n\n\n\n<p>Without an early CIA, tier-one and two suppliers often encounter cybersecurity requirements and expectations that are discovered too late or incorrectly allocated, leading to cost overruns and project delays. Putting the CIA together often takes months of back-and-forth and lengthy meetings to resolve and document all the necessary cybersecurity activities, requirements, and processes. So be prepared and plan for this time investment at the beginning of your projects.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong><strong>The Threat Model<\/strong><\/strong><\/h2>\n\n\n\n<p>Another key element of the CIA to be established upfront is who will perform the TARA and at what level. In practice, TARAs are most often performed at the vehicle or system level by the OEM, with resulting cybersecurity requirements allocated to the components.<\/p>\n\n\n\n<p>However, ISO\/SAE 21434 allows, and in some cases requires, TARAs at lower levels where interfaces or responsibilities are unclear.<\/p>\n\n\n\n<p>This should be clearly established in the CIA between the OEM and the tier-one supplier so that it is clear whether the OEM will perform the TARA themselves and only share the resulting component-level cybersecurity requirements, or whether they also require the tier-one to also perform a TARA at the sub-system or component level, depending on where the interface boundaries are.<\/p>\n\n\n\n<p>Tier-two suppliers typically won&#8217;t need to perform a TARA. They should mainly focus on the technical implementation of cybersecurity controls in hardware and software during the product development phase. So the CIA should clearly define where its cybersecurity responsibilities start and end.<\/p>\n\n\n\n<p>Especially for production, post-production, and vulnerability and incident management, as these are important cybersecurity activities that may be overlooked because they fall outside the technical implementation of the product development phase. All of these items need to be clarified and documented in the CIA so that each side is clear on their individual responsibilities.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong><strong>Vulnerability Management and Incident Response<\/strong><\/strong><\/h2>\n\n\n\n<p>Two key areas in the CIA that are often overlooked, as they don&#8217;t relate to core product development activities, are cybersecurity vulnerability management and incident response. Depending on where in the process and at what stage in the product lifecycle these are discovered, they often necessitate a coordinated effort between OEM and suppliers to resolve satisfactorily.<\/p>\n\n\n\n<p>Hence, to avoid future &#8220;finger-pointing,&#8221; it is critical to define upfront in the CIA how vulnerabilities and incidents will be managed across the organizational boundaries.<\/p>\n\n\n\n<p>Key things to consider are what information needs to be shared, levels of confidentiality for the information shared, vulnerability disclosure timelines, response times for responding to information requests and providing fixes and updates, and key contacts within the security organizations for all sides involved to ensure speedy communication, incident escalation paths, and overall roles and responsibilities for managing vulnerabilities and incidents. Often, the contacts for incident response are different than those used for normal product development.<\/p>\n\n\n\n<p>A well-defined CIA ensures that incident response is not improvised under pressure but is executed according to agreed-upon rules that align with both the OEM&#8217;s vehicle\u2011level response strategy and the technical capabilities of the suppliers involved.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong><strong><strong>Artificial Intelligence and the CIA<\/strong><\/strong><\/strong><\/h2>\n\n\n\n<p>Of course, one cannot talk about anything related to technology these days without at least mentioning Artificial Intelligence (AI). Throughout the project, AI can be a valuable tool for modeling threats, identifying attack paths, performing vulnerability analysis, detecting intrusions, etc.<\/p>\n\n\n\n<p>There are many areas where it can be applied. But the important thing not to lose sight of is that the CIA is an engineering contract, and the work still needs to be done and checked by humans, even if assisted by AI; AI cannot guarantee security. So it is important to document upfront in the CIA any areas where AI will be explicitly used, so that both parties are aware and can make appropriate judgments about its efficacy and who will ultimately be accountable for the cybersecurity activity involving AI. &nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong><strong>Practical recommendations for Tier\u2011One suppliers<\/strong><\/strong><\/h2>\n\n\n\n<p>Based on experience across multiple projects, several practical recommendations can be provided for tier-one suppliers on completing the CIA:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Start the CIA before TARA finalization \u2013 the CIA should inform the TARA, not be retrofitted afterward.<\/li>\n\n\n\n<li>Separate CIAs but align OEM and tier\u2011two CIAs \u2013 each serves a different purpose, but they must be consistent.<\/li>\n\n\n\n<li>Document assumptions explicitly \u2013 unstated assumptions are the most common root cause of failure.<\/li>\n\n\n\n<li>Demand evidence early \u2013 do not wait until integration to request cybersecurity work products from tier\u2011two suppliers. Especially to build the cybersecurity case.<\/li>\n\n\n\n<li>Integrate CIA management into change control; any architectural or supplier change should trigger a CIA review.<\/li>\n<\/ol>\n\n\n<div class=\"nsw-o-blogersii-banner\">\n            <picture>\n            <source srcset=\"https:\/\/sii.pl\/blog\/wp-content\/uploads\/2026\/04\/Blog-CybersecDesktop_.jpg\" media=\"(min-width: 992px)\" >\n            <source srcset=\"https:\/\/sii.pl\/blog\/wp-content\/uploads\/2026\/04\/Blog-Cybersec-Mob_.jpg\" media=\"(min-width: 300px)\" >            <img decoding=\"async\" src=\"https:\/\/sii.pl\/blog\/wp-content\/uploads\/2026\/04\/Blog-CybersecDesktop_.jpg\" alt=\"\"  class=\"\"  >\n        <\/picture>\n        <div class=\"cnt\">\n                    <div class=\"nsw-m-title-block -h3 -invert  -has-title-margin-bottom-0 -has-title-font-weight-bold\">\n                                <h2 class=\"nsw-m-title-block__title\">Cybersecurity<\/h2>\n                <\/div>\n                            <p class=\"has-nsw-p-4-font-size has-invert-color\">\n                We protect your data and IT environment with modern solutions and services \u2013 audits, penetration testing, continuous monitoring and incident response.\n            <\/p>\n                            <a  href=\"https:\/\/sii.pl\/en\/what-we-offer\/cybersecurity\/\" class=\"nsw-a-button -ghost -banner-button\"   >\n        <span>Cybersecurity offering<\/span>\n    <\/a>\n            <\/div>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\"><strong><strong>Conclusion<\/strong><\/strong><\/h2>\n\n\n\n<p>For a tier-one supplier operating in the complex world of automotive cybersecurity and ISO\/SAE 21434 compliance, a CIA is neither optional nor a bureaucratic exercise. Still, it is a necessary exercise to protect all parties involved and to set the project up for success in securing your product in the vehicle.<\/p>\n\n\n\n<p>By establishing clear CIAs with both OEMs and tier\u2011two suppliers at the very beginning of a project, as a tier\u2011one organization, you can reduce ambiguity, manage risk proactively, and avoid costly rework late in the lifecycle. Proactively initiating this step also positions you as a mature cybersecurity partner whom you can trust to deliver on your cybersecurity commitments. It is well worth the initial investment of time and effort, as cybersecurity failures down the road can halt production, trigger recalls, and easily damage your company&#8217;s reputation.<\/p>\n\n\n\n<p>Not everything can be foreseen in the world of cybersecurity, but a good, solid CIA can go a long way to protecting your company, your product, and your customer.<\/p>\n\n\n<div class=\"kk-star-ratings kksr-auto kksr-align-left kksr-valign-bottom\"\n    data-payload='{&quot;align&quot;:&quot;left&quot;,&quot;id&quot;:&quot;34587&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;0&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;0&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;2&quot;,&quot;greet&quot;:&quot;&quot;,&quot;legend&quot;:&quot;0\\\/5&quot;,&quot;size&quot;:&quot;30&quot;,&quot;title&quot;:&quot;The Cybersecurity Interface Agreement (CIA) and why you need one&quot;,&quot;width&quot;:&quot;0&quot;,&quot;_legend&quot;:&quot;{score}\\\/5&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}'>\n            \n<div class=\"kksr-stars\">\n    \n<div class=\"kksr-stars-inactive\">\n            <div class=\"kksr-star\" data-star=\"1\" style=\"padding-right: 2px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 30px; height: 30px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" data-star=\"2\" style=\"padding-right: 2px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 30px; height: 30px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" data-star=\"3\" style=\"padding-right: 2px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 30px; height: 30px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" data-star=\"4\" style=\"padding-right: 2px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 30px; height: 30px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" data-star=\"5\" style=\"padding-right: 2px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 30px; height: 30px;\"><\/div>\n        <\/div>\n    <\/div>\n    \n<div class=\"kksr-stars-active\" style=\"width: 0px;\">\n            <div class=\"kksr-star\" style=\"padding-right: 2px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 30px; height: 30px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" style=\"padding-right: 2px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 30px; height: 30px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" style=\"padding-right: 2px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 30px; height: 30px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" style=\"padding-right: 2px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 30px; height: 30px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" style=\"padding-right: 2px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 30px; height: 30px;\"><\/div>\n        <\/div>\n    <\/div>\n<\/div>\n                \n\n<div class=\"kksr-legend\" style=\"font-size: 24px;\">\n            <span class=\"kksr-muted\"><\/span>\n    <\/div>\n    <\/div>\n","protected":false},"excerpt":{"rendered":"<p>Long past are the days when a single organization developed the electronic control units (ECUs) for a vehicle program in &hellip; <a class=\"continued-btn\" href=\"https:\/\/sii.pl\/blog\/en\/the-cybersecurity-interface-agreement-cia-and-why-you-need-one\/\">Continued<\/a><\/p>\n","protected":false},"author":813,"featured_media":34585,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_editorskit_title_hidden":false,"_editorskit_reading_time":0,"_editorskit_is_block_options_detached":false,"_editorskit_block_options_position":"{}","inline_featured_image":false,"footnotes":""},"categories":[1319],"tags":[15077,9980,2132,1817,1655,1651],"class_list":["post-34587","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-soft-development","tag-artificial-intelligence-en-2","tag-automotive-en","tag-norms-en","tag-iso-en","tag-cybersecurity-en-2","tag-guidebook-en"],"acf":[],"aioseo_notices":[],"republish_history":[],"featured_media_url":"https:\/\/sii.pl\/blog\/wp-content\/uploads\/2026\/08\/Cybersecurity.jpg","category_names":["Soft development"],"_links":{"self":[{"href":"https:\/\/sii.pl\/blog\/en\/wp-json\/wp\/v2\/posts\/34587","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sii.pl\/blog\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sii.pl\/blog\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sii.pl\/blog\/en\/wp-json\/wp\/v2\/users\/813"}],"replies":[{"embeddable":true,"href":"https:\/\/sii.pl\/blog\/en\/wp-json\/wp\/v2\/comments?post=34587"}],"version-history":[{"count":1,"href":"https:\/\/sii.pl\/blog\/en\/wp-json\/wp\/v2\/posts\/34587\/revisions"}],"predecessor-version":[{"id":34589,"href":"https:\/\/sii.pl\/blog\/en\/wp-json\/wp\/v2\/posts\/34587\/revisions\/34589"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sii.pl\/blog\/en\/wp-json\/wp\/v2\/media\/34585"}],"wp:attachment":[{"href":"https:\/\/sii.pl\/blog\/en\/wp-json\/wp\/v2\/media?parent=34587"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sii.pl\/blog\/en\/wp-json\/wp\/v2\/categories?post=34587"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sii.pl\/blog\/en\/wp-json\/wp\/v2\/tags?post=34587"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}