| OP-001 | ECU designation, variant and item definition for TARA | Confirm the exact ECU designation/variant and the agreed item definition and boundary used for the risk analysis (TARA). | Confirm the exact ECU designation/variant and the agreed item definition and boundary used for the risk analysis (TARA). | Proceed on the working ECA-ECU interpretation; flag every TARA-scope statement as assumption until confirmed. | OEM / Customer | Open | 9 |
| OP-002 | Diagnostic security role model and service authorization | Confirm the diagnostic role model, the authorized services per role, and which party owns the diagnostic authorization policy. | Confirm the diagnostic role model, the authorized services per role, and which party owns the diagnostic authorization policy. | Implement configurable session/security-access on the ECU and request the customer-confirmed service-to-role table. | Shared (OEM policy / Supplier ECU) | Open | 38 |
| OP-003 | Key and certificate ownership, provisioning and lifecycle | Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier. | Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier. | Provide ECU-side secure storage and provisioning hooks; require OEM confirmation of PKI ownership and the provisioning interface. | OEM / Customer (PKI) + Supplier (ECU) | Open | 19 |
| OP-004 | Secure software update / backend campaign responsibility | Confirm the update chain ownership (backend/campaign vs. ECU programming) and the authenticity/integrity scheme to be applied. | Confirm the update chain ownership (backend/campaign vs. ECU programming) and the authenticity/integrity scheme to be applied. | Implement authenticated, integrity-protected ECU programming with controlled boot/app state; require OEM update-chain definition. | Shared (OEM backend / Supplier ECU) | Open | 25 |
| OP-005 | Secure on-board communication (SecOC/SDT) signal allocation | Confirm which signals/PDUs require SecOC/SDT, the freshness scheme, and the key distribution for protected communication. | Confirm which signals/PDUs require SecOC/SDT, the freshness scheme, and the key distribution for protected communication. | Support SecOC/SDT in the platform and request the customer-confirmed protected-signal list and freshness policy. | OEM / Customer | Open | 24 |
| OP-009 | Cybersecurity work products, DIA and responsibility split | Confirm the DIA / responsibility (RASIC/CIA) split for each cybersecurity work product before supplier scope is fixed. | Confirm the DIA / responsibility (RASIC/CIA) split for each cybersecurity work product before supplier scope is fixed. | Deliver supplier-owned work products per concept; require a signed DIA/RASIC before treating shared items as supplier scope. | OEM / Customer + Supplier (DIA) | Open | 9 |
| OP-006 | Incident response and vulnerability management ownership | Confirm the split of monitoring, triage, vulnerability handling and field response between OEM PSIRT and supplier. | Confirm the split of monitoring, triage, vulnerability handling and field response between OEM PSIRT and supplier. | Define supplier vulnerability handling and field-fix capability; require OEM confirmation of monitoring/communication ownership. | OEM / Customer (fleet) + Supplier (ECU) | Open | 2 |
| OP-008 | Production, development and debug-interface hardening | Confirm production/debug hardening expectations (debug lock, secure end-of-line, developer-access policy). | Confirm production/debug hardening expectations (debug lock, secure end-of-line, developer-access policy). | Apply debug lock and secured production access; request the customer-confirmed production-security and EOL requirements. | Shared (OEM process / Supplier ECU) | Open | 5 |
| OP-011 | Document-specific scope and responsibility confirmation | Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline. | Decide whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context. | Carry the items as customer-confirmation dependencies and review them in the next clarification workshop. | OEM / Customer | Open | 202 |