Operating-model boundary. The “grey-box evidence package” is our recommended supplier-assurance operating model. ISO/SAE 21434 does not prescribe that exact bundle or use that label as a mandatory deliverable.

The evidence gap appears when time is shortest

A raw SBOM is useful, but it rarely answers the operational question by itself. When a vulnerability appears during a release or fleet decision, engineering needs affected-version mapping and exploitability context: is the vulnerable component present, reachable, configured in the vulnerable mode and exposed through the actual ECU architecture?

ISO/SAE 21434 explicitly spans OEMs and suppliers across the vehicle lifecycle. Auto-ISAC’s third-party risk guidance similarly treats supplier cybersecurity as an ongoing governance problem. The practical failure occurs when those principles have not been translated into evidence that can be delivered on an incident timeline.

Technically correct evidence delivered two weeks late can be operationally useless. RFQs, Cybersecurity Interface Agreements, SOWs and incident-response SLAs need to define not just what the supplier will produce, but how quickly it must arrive and who is accountable when the decision window is closing.

What this diagram shows

A grey-box supplier interface should reveal enough evidence to make a release decision without requiring unrestricted access to supplier IP.

Grey-box supplier evidenceThe customer needs enough evidence to decide, without requiring the supplier to disclose its entire implementation
Decision-grade evidence element Customer decision gate
01Affected-version mappingExact HW / SW / ECU scopeWhich delivered products are actually exposed?
02Exploitability rationaleVEX or equivalent technical argumentWhy is the vulnerability exploitable, mitigated or not applicable?
03TARA + verification deltaImpact on risk and controlsWhich cybersecurity claims changed and what evidence re-validates them?
04Timeline + mitigation stateDecision-grade incident evidenceWhen will containment, fix and verification be available?
Customer decision gate

Is the evidence sufficient to identify scope, exploitability, control impact and recovery timing?

YESRelease, contain or continue with an explicit residual-risk decision.
NOEscalate the evidence gap rather than substituting assurance with supplier confidence.

Define a grey-box evidence package before nomination

The answer is not unlimited access to supplier intellectual property. A useful grey-box package can stay bounded: affected-version mapping, VEX or equivalent exploitability rationale, vulnerability impact, TARA delta, verification evidence, mitigation state, incident timeline and enough cybersecurity-case support for the customer to make its own decision.

ISO/PAS 5112 explicitly addresses evidence in CSMS audits, which is a useful reminder that evidence quality, provenance and availability are governance concerns, not only technical artefacts.

The supplier should perform the first exploitability assessment for its component. The OEM or Tier 1 still owns the final vehicle or product risk decision. That division avoids both extremes: blindly accepting supplier assurance or forcing the customer to reverse-engineer every dependency under time pressure.

Supplier governance becomes a production-resilience control when evidence is needed to make a live product decision.
The decision
Specify the evidence needed to release, contain or continue operation before commercial nomination, not during the incident.
Operational checks
  • Require affected-version mapping, exploitability rationale and mitigation status.
  • Define minimum grey-box forensic evidence without unnecessary IP disclosure.
  • Attach response times and escalation contacts to evidence obligations.
  • Protect provenance, timestamp integrity and chain of custody for late-collected artefacts.
  • Make ownership of first assessment and final risk acceptance explicit.
Related episodeMissing Cybersecurity Evidence Can Delay ProductionLinkedInJoin the discussion
Source record

Sources & further reading

4 cited sourcesHow we source →
← Automotive IDPSNext: Rail patching →Companion episode →