Automaker Security Standards

OEM Cybersecurity Requirements for Dealers (GM, Mercedes-Benz and More)

Automakers now set their own security standards for the stores that carry their badge. Here’s what GM and Mercedes-Benz USA ask for, and how to find out what your brand expects.

Dealership general manager and an IT security consultant reviewing a binder of printed security policies at a showroom desk, with unbranded sedans behind them

OEM cybersecurity requirements for dealerships are the security standards an automaker sets for its franchised stores. GM publishes them in its Dealer Infrastructure and Security Guidelines. Mercedes-Benz USA asks for ISO 27001 or TISAX Level 2 certification.

Last updated: October 10, 2026

FTC Safeguards Rule
GM’s security guidelines
Mercedes-Benz USA guidelines
Your dealer agreement
Cyber insurance questions
One security program, with proof

Washington set the floor. Your automaker is building on top of it.

Every dealer that finances or leases already answers to the FTC Safeguards Rule requirements. That’s the floor. What changed is who else is asking. After the June 2024 CDK Global attack disrupted about 15,000 dealerships and left stores writing repair orders by hand, automakers stopped taking a dealer’s word for it and started asking to see the evidence.

Helion Technologies maps these standards for stores through its dealership cybersecurity program, and the pattern holds across brands. An automaker writes a standard, ties it to the dealer agreement or a deadline, and then asks for proof, which means a document, a log or an audit report that somebody outside your store can check without calling you first. Promises don’t count.

We covered why this shift is happening in Why Automakers Are Raising the Dealership Cybersecurity Bar. This is the practical half. What each automaker asks for, and what to have ready when they ask.

Mercedes-Benz USA Wants a Certificate, Not a Checklist

Mercedes-Benz USA’s Cyber Security Guidelines for Dealers set a harder test than GM does. As Helion reported in January, dealers have to prove an information security program is in place and working, through ISO/IEC 27001 or TISAX Level 2 certification. The deadline was September 30, 2026. It’s passed.

The guidelines reach dealers through Mercedes-Benz channels and aren’t published. Check your copy. Both paths end the same way, with an outside party reviewing how your store actually runs security instead of how a questionnaire says it does, which is why a policy binder nobody follows won’t survive either one. Our ISO 27001 vs TISAX comparison sets the two side by side. Not certified yet? Ask your Mercedes-Benz USA contact in writing where your store stands and what timeline they’ll accept. Then start. Our guide to the Mercedes-Benz dealer ISO 27001 and TISAX requirement after the deadline covers the next steps.

An audit. Not a form.

ISO/IEC 27001

The international standard for an information security management system. An accredited certification body audits your store. The certificate runs three years, with a surveillance audit each year in between.

Broad, and recognized outside automotive.

TISAX Level 2

The auto industry’s own assessment, governed by the ENX Association and built on the VDA’s ISA catalogue. At Level 2 an approved audit provider checks your self-assessment and your evidence, usually remotely. Labels last three years.

Built for automotive, shared through the ENX portal.

Brand by brand

OEM Cybersecurity Requirements by Automaker

Automakers send these standards through dealer portals and field reps, and they revise them. Versions change. Treat this table as a starting map, then get the current copy from your brand.

AutomakerWhat it asks forWhat to have ready
General MotorsFollow the Dealer Infrastructure and Security Guidelines, which GM ties to Article 5.6 of its dealer agreement. Report a confirmed security incident to GM within 72 hours.An incident response plan with GM’s reporting steps in it, MFA records, a network diagram that shows segmentation and proof that endpoint monitoring is running.
Mercedes-Benz USAProve a working information security program through ISO/IEC 27001 or TISAX Level 2 certification. The deadline was September 30, 2026.The certificate or TISAX label, the scope it covers and the evidence file behind it.
Other brandsIt varies, and most of it isn’t public. Standards arrive through the dealer portal, the brand’s IT guidelines or the dealer agreement itself.A written answer from your field rep on which security standard applies, which version is current and whether proof is due by a date.
Every dealer that finances or leasesThe FTC Safeguards Rule. A written security program, a qualified individual in charge, risk assessments, MFA, encryption, testing and an incident response plan.The written program, the latest risk assessment and the yearly report to your board or owners.

GM details from the GM Dealer Infrastructure and Security Guidelines, April 2026 version. Mercedes-Benz USA details as reported in Helion’s January 2026 article, since the guidelines aren’t public. Federal requirements from 16 CFR 314.4. Checked October 2026.

Inside GM’s guidelines

Six Things GM’s Dealer Security Guidelines Ask For

GM’s guidelines run 19 pages and cover everything from PC specs to Wi-Fi. Security gets three of them. One part is written as mandatory, the incident reporting process. The rest GM calls the minimum set of controls that should be in place. Read both.

Want to know how your stores measure up? Request a complimentary IT and cybersecurity assessment.

IT technician checking a patch cable at an open network cabinet in a car dealership back office while holding a printed checklist on a clipboard

Where Helion fits

Helion runs the controls these standards describe for dealerships. That’s 24/7 monitoring, endpoint detection and response, multi-factor authentication and staff training.

GM security guidelines check April 2026 version

1 The incident clock

Email GM’s Cyber Incident Center after a confirmed security incident, preferably within 24 hours and no later than 72, and if GM spots the problem first, expect to start your own investigation within 24 hours of hearing from them. A written summary is due two weeks after the investigation ends. The FTC runs its own clock, covered in our guide to the Safeguards Rule notification requirement. Two clocks. Know both.

Put GM’s steps in your incident response plan now.

2 MFA in three places

GM’s list is specific. It names multi-factor authentication for all privileged accounts, for remote access such as a VPN, and for every user of an internet-facing application. No exceptions listed.

Email counts. So does a cloud DMS.

3 One person, one login

Each user account belongs to one individual. Shared logins at the parts counter or the service desk fail this line, and they fail it quietly, because nobody notices until an investigator asks who was signed in at 4:10 on a Tuesday afternoon and the honest answer is five people.

Remove access the day someone leaves.

4 Endpoint detection with a long memory

GM wants endpoint detection and response on every computer and server, watched around the clock, with activity logged to a SIEM and kept for a rolling 400 days. That’s over a year.

Antivirus alone doesn’t meet this.

5 Guest Wi-Fi kept apart

Guest traffic, financial data and the dealership network must be separated through VLANs or a separate internet connection. GM adds a warning. A different Wi-Fi name doesn’t separate anything.

Test it from the customer lounge.

6 Backups you’ve restored

Regular backups, restore tests and a disaster recovery plan that gets tested too. Test the restore. GM also expects operating systems to stay current, and its guidelines dropped support for Windows 10 on October 14, 2025. The same controls sit in the Safeguards Rule, which our FTC Safeguards compliance service documents for dealers.

A backup nobody has restored is a guess.

What Helion Brings to OEM Cybersecurity Requirements

82 sec Average time to reach a support agent
98% Client retention rate
2,000+ Automotive and heavy truck dealerships
1997 Working only with dealerships since

Helion has worked only with automotive and heavy truck dealerships since 1997. Its security team watches client stores around the clock, and when Helion runs both IT and security for a store, one team owns the fix and the record of it, so the dealer isn’t stuck between two vendors pointing at each other while an automaker waits on an answer. That matters at audit time.

How to Get Ready for an OEM Cybersecurity Review

  1. 1

    Collect every standard

    Pull the current security document for each brand you sell, plus the Safeguards Rule and your cyber insurance application. Get all of them.

  2. 2

    Build one control list

    These documents overlap heavily. Line them up side by side and work from the strictest version of each control.

  3. 3

    Close the big gaps first

    Shared logins, missing multi-factor authentication, flat networks and untested backups go to the top of the list. Start there.

  4. 4

    Keep the proof current

    Save reports, logs and screenshots as you go. A control you can’t show is a control you don’t have.

Common Questions

Dealer principal and office manager going through printed audit paperwork and a binder at a conference table in a dealership office

Selling more than one brand?

Bring each brand’s security document to a complimentary IT and cybersecurity assessment. We’ll show you where your stores stand against them.

What are OEM cybersecurity requirements for dealerships?
They’re security standards an automaker sets for the franchised stores that sell its vehicles. Some sit in a guidelines document tied to the dealer agreement, like GM’s. Others call for outside certification, like Mercedes-Benz USA’s. They add to federal law. They don’t replace it.
Does GM require dealers to follow its security guidelines?
Yes. GM’s guidelines state that under Article 5.6 of the Dealer Sales and Service Agreement, the dealer has agreed to comply with them. The incident reporting process is written as mandatory, while the base security controls are described as the minimum that should be in place and working across the dealership.
How fast do we have to tell GM about a security incident?
72 hours at the outside. GM’s guidelines ask for an email to its Cyber Incident Center promptly after a confirmed incident, preferably within 24 hours and no later than 72, unless the law requires otherwise. Updates continue until the investigation closes. Don’t wait.
What did Mercedes-Benz USA require by September 30, 2026?
Proof, in the form of certification. Mercedes-Benz USA’s Cyber Security Guidelines for Dealers call for ISO/IEC 27001 or TISAX Level 2 certification showing that an information security program is in place. Missed the date? Ask your Mercedes-Benz USA contact what happens next, and get the answer in writing.
Is TISAX easier than ISO 27001 for a dealership?
It can be the lighter path, but it isn’t a shortcut. A TISAX Level 2 assessment checks your self-assessment and evidence, usually remotely, while ISO 27001 means a full certification audit with yearly follow-ups. Underneath, both expect the same thing. A security program that runs every day. We put ISO 27001 and TISAX side by side for dealers.
Do other automakers have cybersecurity requirements for dealers?
Many set IT and security expectations for their dealers, but few publish them. We haven’t confirmed a public standard for every brand, so we won’t guess here. Ask your field rep which document applies to your store, which version is current and whether proof is due. It’s worth the email.
Does meeting the FTC Safeguards Rule cover our automaker’s requirements?
No, though it gets you most of the way. The Safeguards Rule and the automaker standards overlap on multi-factor authentication, access control, monitoring and incident response, so a store that already runs a real Safeguards program has done much of the work before an automaker ever sends a letter. Automakers add their own pieces, like GM’s 72-hour notice or Mercedes-Benz USA’s outside certification. Check each one. Our FTC Safeguards Rule checklist is a good base to work from.

Your automaker will ask for proof. Find out what your stores could show today.

Request a Complimentary Assessment →