The evidence gap appears when time is shortest
A raw SBOM is useful, but it rarely answers the operational question by itself. When a vulnerability appears during a release or fleet decision, engineering needs affected-version mapping and exploitability context: is the vulnerable component present, reachable, configured in the vulnerable mode and exposed through the actual ECU architecture?
ISO/SAE 21434 explicitly spans OEMs and suppliers across the vehicle lifecycle. Auto-ISAC’s third-party risk guidance similarly treats supplier cybersecurity as an ongoing governance problem. The practical failure occurs when those principles have not been translated into evidence that can be delivered on an incident timeline.
Technically correct evidence delivered two weeks late can be operationally useless. RFQs, Cybersecurity Interface Agreements, SOWs and incident-response SLAs need to define not just what the supplier will produce, but how quickly it must arrive and who is accountable when the decision window is closing.
A grey-box supplier interface should reveal enough evidence to make a release decision without requiring unrestricted access to supplier IP.
Is the evidence sufficient to identify scope, exploitability, control impact and recovery timing?
Define a grey-box evidence package before nomination
The answer is not unlimited access to supplier intellectual property. A useful grey-box package can stay bounded: affected-version mapping, VEX or equivalent exploitability rationale, vulnerability impact, TARA delta, verification evidence, mitigation state, incident timeline and enough cybersecurity-case support for the customer to make its own decision.
ISO/PAS 5112 explicitly addresses evidence in CSMS audits, which is a useful reminder that evidence quality, provenance and availability are governance concerns, not only technical artefacts.
The supplier should perform the first exploitability assessment for its component. The OEM or Tier 1 still owns the final vehicle or product risk decision. That division avoids both extremes: blindly accepting supplier assurance or forcing the customer to reverse-engineer every dependency under time pressure.
- Require affected-version mapping, exploitability rationale and mitigation status.
- Define minimum grey-box forensic evidence without unnecessary IP disclosure.
- Attach response times and escalation contacts to evidence obligations.
- Protect provenance, timestamp integrity and chain of custody for late-collected artefacts.
- Make ownership of first assessment and final risk acceptance explicit.
