Back to Frameworks

Automotive SPICE for Cybersecurity PAM v2.0

International (VDA QMC, Germany; automotive supply chain)
v2.0 (2025-03-28), supplement to Automotive SPICE 4.0
3 domains
31 controls

The VDA's cybersecurity supplement to Automotive SPICE: six processes (ACQ.2, MAN.7, SEC.1 to SEC.4) whose 31 base practices an intacs assessor rates, from supplier selection and TARA-based risk management through cybersecurity goals, requirements, implementation, verification and validation, every leaf read in the complete free VDA document.

Verified

Automotive SPICE for Cybersecurity PAM v2.0 is a compliance framework from International (VDA QMC, Germany; automotive supply chain) with 3 domains and 31 controls. The largest domains are Cybersecurity Engineering Process Group (SEC) – Automotive SPICE for Cybersecurity PAM v2.0 (20 controls), Management Process Group (MAN) – Automotive SPICE for Cybersecurity PAM v2.0 (7 controls), Acquisition Process Group (ACQ) – Automotive SPICE for Cybersecurity PAM v2.0 (4 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard Blokdyk

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (3)

Acquisition Process Group (ACQ) – Automotive SPICE for Cybersecurity PAM v2.0

4 controls
Controls in the Acquisition Process Group (ACQ) – Automotive SPICE for Cybersecurity PAM v2.0 domain of Automotive SPICE for Cybersecurity PAM v2.04 controls
CodeTitle
automotive-spice-for-cybersecurity-pam-v2-0::ACQ.2.BP1ACQ.2.BP1 Establish supplier evaluation criteria
automotive-spice-for-cybersecurity-pam-v2-0::ACQ.2.BP2ACQ.2.BP2 Evaluate potential suppliers
automotive-spice-for-cybersecurity-pam-v2-0::ACQ.2.BP3ACQ.2.BP3 Prepare and issue a request for quotation
automotive-spice-for-cybersecurity-pam-v2-0::ACQ.2.BP4ACQ.2.BP4 Negotiate and award the commitment or agreement

Cybersecurity Engineering Process Group (SEC) – Automotive SPICE for Cybersecurity PAM v2.0

20 controls
Controls in the Cybersecurity Engineering Process Group (SEC) – Automotive SPICE for Cybersecurity PAM v2.0 domain of Automotive SPICE for Cybersecurity PAM v2.020 controls
CodeTitle
automotive-spice-for-cybersecurity-pam-v2-0::SEC.1.BP1SEC.1.BP1 Specify cybersecurity goals and cybersecurity requirements
automotive-spice-for-cybersecurity-pam-v2-0::SEC.1.BP2SEC.1.BP2 Ensure consistency and establish bidirectional traceability
automotive-spice-for-cybersecurity-pam-v2-0::SEC.1.BP3SEC.1.BP3 Communicate agreed cybersecurity requirements
automotive-spice-for-cybersecurity-pam-v2-0::SEC.2.BP1SEC.2.BP1 Refine the details of the architecture
automotive-spice-for-cybersecurity-pam-v2-0::SEC.2.BP2SEC.2.BP2 Ensure consistency and establish bidirectional traceability for cybersecurity requirements
automotive-spice-for-cybersecurity-pam-v2-0::SEC.2.BP3SEC.2.BP3 Select cybersecurity controls
automotive-spice-for-cybersecurity-pam-v2-0::SEC.2.BP4SEC.2.BP4 Analyze architecture for weaknesses
automotive-spice-for-cybersecurity-pam-v2-0::SEC.2.BP5SEC.2.BP5 Refine the detailed design
automotive-spice-for-cybersecurity-pam-v2-0::SEC.2.BP6SEC.2.BP6 Ensure consistency and establish bidirectional traceability for architecture and detailed design
automotive-spice-for-cybersecurity-pam-v2-0::SEC.2.BP7SEC.2.BP7 Communicate agreed results of cybersecurity implementation
automotive-spice-for-cybersecurity-pam-v2-0::SEC.3.BP1SEC.3.BP1 Specify risk treatment verification measures
automotive-spice-for-cybersecurity-pam-v2-0::SEC.3.BP2SEC.3.BP2 Select verification measures
automotive-spice-for-cybersecurity-pam-v2-0::SEC.3.BP3SEC.3.BP3 Perform risk treatment verification activities
automotive-spice-for-cybersecurity-pam-v2-0::SEC.3.BP4SEC.3.BP4 Ensure consistency and establish bidirectional traceability
automotive-spice-for-cybersecurity-pam-v2-0::SEC.3.BP5SEC.3.BP5 Summarize and communicate results
automotive-spice-for-cybersecurity-pam-v2-0::SEC.4.BP1SEC.4.BP1 Specify risk treatment validation measures
automotive-spice-for-cybersecurity-pam-v2-0::SEC.4.BP2SEC.4.BP2 Select validation measures
automotive-spice-for-cybersecurity-pam-v2-0::SEC.4.BP3SEC.4.BP3 Perform risk treatment validation activities
automotive-spice-for-cybersecurity-pam-v2-0::SEC.4.BP4SEC.4.BP4 Ensure consistency and establish bidirectional traceability
automotive-spice-for-cybersecurity-pam-v2-0::SEC.4.BP5SEC.4.BP5 Summarize and communicate results

Management Process Group (MAN) – Automotive SPICE for Cybersecurity PAM v2.0

7 controls
Controls in the Management Process Group (MAN) – Automotive SPICE for Cybersecurity PAM v2.0 domain of Automotive SPICE for Cybersecurity PAM v2.07 controls
CodeTitle
automotive-spice-for-cybersecurity-pam-v2-0::MAN.7.BP1MAN.7.BP1 Identify cybersecurity risk management scope
automotive-spice-for-cybersecurity-pam-v2-0::MAN.7.BP2MAN.7.BP2 Identify cybersecurity events
automotive-spice-for-cybersecurity-pam-v2-0::MAN.7.BP3MAN.7.BP3 Analyze risks
automotive-spice-for-cybersecurity-pam-v2-0::MAN.7.BP4MAN.7.BP4 Define risk treatment options
automotive-spice-for-cybersecurity-pam-v2-0::MAN.7.BP5MAN.7.BP5 Define and perform risk treatment activities
automotive-spice-for-cybersecurity-pam-v2-0::MAN.7.BP6MAN.7.BP6 Monitor risks
automotive-spice-for-cybersecurity-pam-v2-0::MAN.7.BP7MAN.7.BP7 Take corrective action

What is Automotive SPICE for Cybersecurity PAM v2.0 and who does it apply to?

Automotive SPICE for Cybersecurity PAM v2.0 is a compliance framework from International (VDA QMC, Germany; automotive supply chain) with 3 domains and 31 controls. The VDA's cybersecurity supplement to Automotive SPICE: six processes (ACQ.2, MAN.7, SEC.1 to SEC.4) whose 31 base practices an intacs assessor rates, from supplier selection and TARA-based risk management through cybersecurity goals, requirements, implementation, verification and validation, every leaf read in the complete free VDA document. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does Automotive SPICE for Cybersecurity PAM v2.0 actually require?

Automotive SPICE for Cybersecurity PAM v2.0 has 31 controls organised across 3 domains. The largest domains are Cybersecurity Engineering Process Group (SEC) – Automotive SPICE for Cybersecurity PAM v2.0 (20 controls), Management Process Group (MAN) – Automotive SPICE for Cybersecurity PAM v2.0 (7 controls), Acquisition Process Group (ACQ) – Automotive SPICE for Cybersecurity PAM v2.0 (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of Automotive SPICE for Cybersecurity PAM v2.0 do I already cover?

Automotive SPICE for Cybersecurity PAM v2.0 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I implement Automotive SPICE for Cybersecurity PAM v2.0?

Start your Automotive SPICE for Cybersecurity PAM v2.0 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Automotive SPICE for Cybersecurity PAM v2.0 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 31 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.

Get Started Free →

Free forever — no credit card required