International (VDA QMC, Germany; automotive supply chain)

Automotive SPICE for Cybersecurity PAM v2.0

44 controls. 0 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

44 controls 0 frameworks share controls with it International (VDA QMC, Germany; automotive supply chain) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

No measured overlap with another framework in the corpus.

Every control

CodeControlAlso in
ACQAcquisition Process Group0
ACQ.2ACQ.2 Supplier Request and Selection0
ACQ.2.BP1ACQ.2.BP1 Establish supplier evaluation criteria0
ACQ.2.BP2ACQ.2.BP2 Evaluate potential suppliers0
ACQ.2.BP3ACQ.2.BP3 Prepare and issue a request for quotation0
ACQ.2.BP4ACQ.2.BP4 Negotiate and award the commitment or agreement0
FRAMEWORKStatement of compliance, process capability determination and the measurement framework0
MANManagement Process Group0
MAN.7MAN.7 Cybersecurity Risk Management0
MAN.7.BP1MAN.7.BP1 Identify cybersecurity risk management scope0
MAN.7.BP2MAN.7.BP2 Identify cybersecurity events0
MAN.7.BP3MAN.7.BP3 Analyze risks0
MAN.7.BP4MAN.7.BP4 Define risk treatment options0
MAN.7.BP5MAN.7.BP5 Define and perform risk treatment activities0
MAN.7.BP6MAN.7.BP6 Monitor risks0
MAN.7.BP7MAN.7.BP7 Take corrective action0
MODELAutomotive SPICE for Cybersecurity PAM v2.0: what it is and what is held0
RELATION-21434Relation to ISO/SAE 21434 and the core model's coverage of cybersecurity management0
SECCybersecurity Engineering Process Group0
SEC.1SEC.1 Cybersecurity Requirements Elicitation0
SEC.1.BP1SEC.1.BP1 Specify cybersecurity goals and cybersecurity requirements0
SEC.1.BP2SEC.1.BP2 Ensure consistency and establish bidirectional traceability0
SEC.1.BP3SEC.1.BP3 Communicate agreed cybersecurity requirements0
SEC.2SEC.2 Cybersecurity Implementation0
SEC.2.BP1SEC.2.BP1 Refine the details of the architecture0
SEC.2.BP2SEC.2.BP2 Ensure consistency and establish bidirectional traceability for cybersecurity requirements0
SEC.2.BP3SEC.2.BP3 Select cybersecurity controls0
SEC.2.BP4SEC.2.BP4 Analyze architecture for weaknesses0
SEC.2.BP5SEC.2.BP5 Refine the detailed design0
SEC.2.BP6SEC.2.BP6 Ensure consistency and establish bidirectional traceability for architecture and detailed design0
SEC.2.BP7SEC.2.BP7 Communicate agreed results of cybersecurity implementation0
SEC.3SEC.3 Risk Treatment Verification0
SEC.3.BP1SEC.3.BP1 Specify risk treatment verification measures0
SEC.3.BP2SEC.3.BP2 Select verification measures0
SEC.3.BP3SEC.3.BP3 Perform risk treatment verification activities0
SEC.3.BP4SEC.3.BP4 Ensure consistency and establish bidirectional traceability0
SEC.3.BP5SEC.3.BP5 Summarize and communicate results0
SEC.4SEC.4 Risk Treatment Validation0
SEC.4.BP1SEC.4.BP1 Specify risk treatment validation measures0
SEC.4.BP2SEC.4.BP2 Select validation measures0
SEC.4.BP3SEC.4.BP3 Perform risk treatment validation activities0
SEC.4.BP4SEC.4.BP4 Ensure consistency and establish bidirectional traceability0
SEC.4.BP5SEC.4.BP5 Summarize and communicate results0
STATUSEdition status: 2.0 (March 2025) current on Automotive SPICE 4.0; assessed with the core model0

Tell me when Automotive SPICE for Cybersecurity PAM v2.0 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What this page is

A control-level reference for Automotive SPICE for Cybersecurity PAM v2.0, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition