Cyber risk assessment using TARA methodology has been an established standard in the global automotive industry and vehicle development for years, anchored in ISO/SAE 21434. The tooling to support it has long been a challenge: enterprise pricing, lengthy sales cycles, complex onboarding. The market has moved on. Speed matters. Affordability matters. And compliance cannot be compromised. That is exactly why we built CYMETRIS Lite, the world’s first self-service TARA platform.
Philipp Veronesi
For years, professional TARA tooling has followed a single commercial model: large contracts, long sales cycles, enterprise pricing, layered onboarding. For the customers that model was built for, it makes sense. OEMs, large Tier-1 suppliers, organizations with procurement departments, legal review cycles, and dedicated software budgets — those environments require everything to fit together across departments.
But across the automotive industry and its complex supply chain, a different kind of customer is becoming increasingly common.
No procurement manager involved. No supplier evaluation to run. No board meeting to wait for. Just everyday situations where specialists need to get a TARA done.
For example:
- A cybersecurity engineer at a mobility startup who just received an OEM TARA requirement for a new partnership project, with a four-week deadline.
- A freelance automotive security consultant three weeks out from a project deadline.
- A Tier-3 supplier with one security-minded engineer on staff and a compliance gap that needs to close now.
- A technology provider developing EV charging infrastructure (or similar) who needs to demonstrate UN R155 readiness to close a deal, without the time or budget for a months-long enterprise evaluation.
These situations are no longer edge cases. They represent the majority of the market.
Time to shake things up in the TARA tooling space.
Here is what we are launching:
Introducing CYMETRIS Lite: The World’s First Self-Service TARA Platform
CYMETRIS Lite extends the CYMETRIS product line with a new option: a self-service offering that lets teams get started immediately.
Not a stripped-down version. Not a trial. Not a feature-limited freemium tier designed to push users toward an upgrade through frustration.
CYMETRIS Lite is a standalone SaaS product, built for teams who know what they need, understand TARA methodology, and want to get to work. No sales conversations standing between them and the tool.
The full methodological core of the CYMETRIS TARA platform is included: the guided ISO/SAE 21434 workflow, automatic consistency checks, attack path visualization, AI-powered features via MCP integration, and state-of-the-art TARA exports for ISO/SAE 21434 and UN R155.
If you know CYMETRIS, have already evaluated it, or simply know what a professional TARA process looks like: you are ready to go.
Who Is CYMETRIS Lite Built For?
CYMETRIS Lite is made for cybersecurity engineers and teams who need to complete professional TARA work without Excel workarounds and without an enterprise procurement process. From the many evaluation conversations we have had around CYMETRIS Enterprise, three recurring situations emerged that CYMETRIS Lite is built to address.- Teams that are ready to buy but not ready for an enterprise process. Teams that have already explored the platform, perhaps worked through the interactive tours of the actual software interface in the Platform Overview↗, and now want to start their own TARA project right away. CYMETRIS Lite is the fastest path from decision to first TARA.
- Organizations where enterprise licensing simply does not fit right now. A specialized cybersecurity consultancy. A startup in the ADAS, e-mobility, or connected vehicle space. A Tier-2 or Tier-3 supplier receiving ISO/SAE 21434 requirements from their OEM customer but without a dedicated tooling budget. For these teams, CYMETRIS Lite is not a compromise. It is the right product.
- The many individual practitioners: automotive consultants, external functional safety and cybersecurity experts who carry TARA responsibility personally. The senior security engineer who is simultaneously team lead, compliance owner, and the audit point of contact. The consultant who delivers TARAs for clients and needs a practical tool that is professional enough to stand up in front of an OEM. CYMETRIS Lite was built specifically for these practitioners.
Regulatory Cybersecurity Pressure Has Reached the Long Tail
The regulatory case for taking TARA work seriously has been building globally for several years. Systematic completion of the TARA work products required by ISO/SAE 21434:2021 compliance now receives significantly higher priority than in the early days of vehicle cybersecurity engineering standards. UN R155, mandatory for new vehicle types since July 2022 and applicable to all newly registered vehicles since July 2024, does not limit its cybersecurity expectations to the OEM or the Tier-1 supplier. OEMs must demonstrate that their cybersecurity management extends throughout their entire supply chain. In practice, that requirement lands on every supplier whose component carries a security-relevant interface. ISO/SAE 21434, and therefore the TARA, is the de-facto engineering standard in OEM supplier requirements, regardless of whether the supplier is formally a Tier-1 or sits several tiers deeper in the chain. The methodology is the same. Audit expectations are the same. And they are tightening globally, as the Korean Vehicle Cybersecurity Regulation makes clear. At the same time, it is no longer only E/E components and systems that go directly into vehicles that are affected. The EU Cyber Resilience Act (see also our overview of CRA vs. ISO/SAE 21434) is pulling far more organizations and their products into the scope of systematic cyber risk assessment. IoT manufacturers, industrial systems developers, embedded hardware producers, and many others now face structured cybersecurity risk assessment requirements for the first time. The regulatory surface has expanded. The tooling available to smaller teams has not kept pace. CYMETRIS Lite addresses that gap directly.What CYMETRIS Lite Includes
The guided TARA workflow per ISO/SAE 21434 is fully included in CYMETRIS Lite. A complete TARA is possible without restriction: asset identification, threat scenario definition, attack path analysis, damage scenario assessment, risk determination, and risk treatment. The intuitive structure of the TARA modeling environment allows first-time users to produce a methodologically correct TARA without knowing in advance what the output should look like. That is a fundamental advantage over an Excel sheet. Automatic consistency and logic checks run continuously as the TARA is built. Attack paths are visualized interactively. Once the analysis is complete, the state-of-the-art export function generates evidence packages for ISO/SAE 21434 and UN R155. Every CYMETRIS Lite subscription includes a pre-built demo project: a realistic, fully assembled TARA that can be explored, copied, and adapted. The first login does not lead to a blank screen. (Note: Demo projects are expected to be available from August 2026.)When CYMETRIS Enterprise Is the Right Choice
CYMETRIS Lite covers the full methodological core of a complete TARA. For many smaller teams and straightforward use cases, that is exactly what is needed today. There are situations, however, that go beyond a standalone TARA, and that typically come with different organizational conditions: larger security teams, more complex development environments, formalized tooling workflows and processes, and a positioning of product security at the department or company level. Credit card checkout is usually not how software gets procured in these environments. CYMETRIS Enterprise is built for those scenarios. Here is what Enterprise adds beyond CYMETRIS Lite:- Vertical TARA integration for multi-layer TARAs across organizational boundaries, with damage scenarios as the structured handoff point between OEM and supplier analysis (also ideal for variant management). (Read also: Hey, Vertical TARA Integration!)
- Continuous vulnerability management throughout the product lifecycle, matching CVE findings natively and continuously against the TARA rather than as a separate manual process.
- Cross-organizational review access: external partners, auditors, or OEM contacts can be invited with read-only access, allowing them to view and comment (feature in finalization) without editing rights and without consuming a user seat.
- Toolchain integrations to Jira, Codebeamer, Enterprise Architect, and additional environments, plus API access for PLM, ALM, and MBSE connections.
- Import of organization-specific catalogs and customization for company-wide standards, ideal for custom TARAs rather than generic templates.
- Unlimited users and projects and a dedicated proof-of-concept process for complex deployment scenarios.



