Automotive SPICE for Cybersecurity PAM v2.0
The VDA's cybersecurity supplement to Automotive SPICE: six processes (ACQ.2, MAN.7, SEC.1 to SEC.4) whose 31 base practices an intacs assessor rates, from supplier selection and TARA-based risk management through cybersecurity goals, requirements, implementation, verification and validation, every leaf read in the complete free VDA document.
Automotive SPICE for Cybersecurity PAM v2.0 is a compliance framework from International (VDA QMC, Germany; automotive supply chain) with 3 domains and 31 controls. The largest domains are Cybersecurity Engineering Process Group (SEC) – Automotive SPICE for Cybersecurity PAM v2.0 (20 controls), Management Process Group (MAN) – Automotive SPICE for Cybersecurity PAM v2.0 (7 controls), Acquisition Process Group (ACQ) – Automotive SPICE for Cybersecurity PAM v2.0 (4 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (3)
Acquisition Process Group (ACQ) – Automotive SPICE for Cybersecurity PAM v2.0
| Code | Title |
|---|---|
| automotive-spice-for-cybersecurity-pam-v2-0::ACQ.2.BP1 | ACQ.2.BP1 Establish supplier evaluation criteria |
| automotive-spice-for-cybersecurity-pam-v2-0::ACQ.2.BP2 | ACQ.2.BP2 Evaluate potential suppliers |
| automotive-spice-for-cybersecurity-pam-v2-0::ACQ.2.BP3 | ACQ.2.BP3 Prepare and issue a request for quotation |
| automotive-spice-for-cybersecurity-pam-v2-0::ACQ.2.BP4 | ACQ.2.BP4 Negotiate and award the commitment or agreement |
Cybersecurity Engineering Process Group (SEC) – Automotive SPICE for Cybersecurity PAM v2.0
| Code | Title |
|---|---|
| automotive-spice-for-cybersecurity-pam-v2-0::SEC.1.BP1 | SEC.1.BP1 Specify cybersecurity goals and cybersecurity requirements |
| automotive-spice-for-cybersecurity-pam-v2-0::SEC.1.BP2 | SEC.1.BP2 Ensure consistency and establish bidirectional traceability |
| automotive-spice-for-cybersecurity-pam-v2-0::SEC.1.BP3 | SEC.1.BP3 Communicate agreed cybersecurity requirements |
| automotive-spice-for-cybersecurity-pam-v2-0::SEC.2.BP1 | SEC.2.BP1 Refine the details of the architecture |
| automotive-spice-for-cybersecurity-pam-v2-0::SEC.2.BP2 | SEC.2.BP2 Ensure consistency and establish bidirectional traceability for cybersecurity requirements |
| automotive-spice-for-cybersecurity-pam-v2-0::SEC.2.BP3 | SEC.2.BP3 Select cybersecurity controls |
| automotive-spice-for-cybersecurity-pam-v2-0::SEC.2.BP4 | SEC.2.BP4 Analyze architecture for weaknesses |
| automotive-spice-for-cybersecurity-pam-v2-0::SEC.2.BP5 | SEC.2.BP5 Refine the detailed design |
| automotive-spice-for-cybersecurity-pam-v2-0::SEC.2.BP6 | SEC.2.BP6 Ensure consistency and establish bidirectional traceability for architecture and detailed design |
| automotive-spice-for-cybersecurity-pam-v2-0::SEC.2.BP7 | SEC.2.BP7 Communicate agreed results of cybersecurity implementation |
| automotive-spice-for-cybersecurity-pam-v2-0::SEC.3.BP1 | SEC.3.BP1 Specify risk treatment verification measures |
| automotive-spice-for-cybersecurity-pam-v2-0::SEC.3.BP2 | SEC.3.BP2 Select verification measures |
| automotive-spice-for-cybersecurity-pam-v2-0::SEC.3.BP3 | SEC.3.BP3 Perform risk treatment verification activities |
| automotive-spice-for-cybersecurity-pam-v2-0::SEC.3.BP4 | SEC.3.BP4 Ensure consistency and establish bidirectional traceability |
| automotive-spice-for-cybersecurity-pam-v2-0::SEC.3.BP5 | SEC.3.BP5 Summarize and communicate results |
| automotive-spice-for-cybersecurity-pam-v2-0::SEC.4.BP1 | SEC.4.BP1 Specify risk treatment validation measures |
| automotive-spice-for-cybersecurity-pam-v2-0::SEC.4.BP2 | SEC.4.BP2 Select validation measures |
| automotive-spice-for-cybersecurity-pam-v2-0::SEC.4.BP3 | SEC.4.BP3 Perform risk treatment validation activities |
| automotive-spice-for-cybersecurity-pam-v2-0::SEC.4.BP4 | SEC.4.BP4 Ensure consistency and establish bidirectional traceability |
| automotive-spice-for-cybersecurity-pam-v2-0::SEC.4.BP5 | SEC.4.BP5 Summarize and communicate results |
Management Process Group (MAN) – Automotive SPICE for Cybersecurity PAM v2.0
| Code | Title |
|---|---|
| automotive-spice-for-cybersecurity-pam-v2-0::MAN.7.BP1 | MAN.7.BP1 Identify cybersecurity risk management scope |
| automotive-spice-for-cybersecurity-pam-v2-0::MAN.7.BP2 | MAN.7.BP2 Identify cybersecurity events |
| automotive-spice-for-cybersecurity-pam-v2-0::MAN.7.BP3 | MAN.7.BP3 Analyze risks |
| automotive-spice-for-cybersecurity-pam-v2-0::MAN.7.BP4 | MAN.7.BP4 Define risk treatment options |
| automotive-spice-for-cybersecurity-pam-v2-0::MAN.7.BP5 | MAN.7.BP5 Define and perform risk treatment activities |
| automotive-spice-for-cybersecurity-pam-v2-0::MAN.7.BP6 | MAN.7.BP6 Monitor risks |
| automotive-spice-for-cybersecurity-pam-v2-0::MAN.7.BP7 | MAN.7.BP7 Take corrective action |
What is Automotive SPICE for Cybersecurity PAM v2.0 and who does it apply to?
Automotive SPICE for Cybersecurity PAM v2.0 is a compliance framework from International (VDA QMC, Germany; automotive supply chain) with 3 domains and 31 controls. The VDA's cybersecurity supplement to Automotive SPICE: six processes (ACQ.2, MAN.7, SEC.1 to SEC.4) whose 31 base practices an intacs assessor rates, from supplier selection and TARA-based risk management through cybersecurity goals, requirements, implementation, verification and validation, every leaf read in the complete free VDA document. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does Automotive SPICE for Cybersecurity PAM v2.0 actually require?
Automotive SPICE for Cybersecurity PAM v2.0 has 31 controls organised across 3 domains. The largest domains are Cybersecurity Engineering Process Group (SEC) – Automotive SPICE for Cybersecurity PAM v2.0 (20 controls), Management Process Group (MAN) – Automotive SPICE for Cybersecurity PAM v2.0 (7 controls), Acquisition Process Group (ACQ) – Automotive SPICE for Cybersecurity PAM v2.0 (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of Automotive SPICE for Cybersecurity PAM v2.0 do I already cover?
Automotive SPICE for Cybersecurity PAM v2.0 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I implement Automotive SPICE for Cybersecurity PAM v2.0?
Start your Automotive SPICE for Cybersecurity PAM v2.0 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Automotive SPICE for Cybersecurity PAM v2.0 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 31 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.
Get Started Free →Free forever — no credit card required