Automaker Security Standards
OEM Cybersecurity Requirements for Dealers (GM, Mercedes-Benz and More)
Automakers now set their own security standards for the stores that carry their badge. Here’s what GM and Mercedes-Benz USA ask for, and how to find out what your brand expects.

OEM cybersecurity requirements for dealerships are the security standards an automaker sets for its franchised stores. GM publishes them in its Dealer Infrastructure and Security Guidelines. Mercedes-Benz USA asks for ISO 27001 or TISAX Level 2 certification.
Last updated: October 10, 2026
Washington set the floor. Your automaker is building on top of it.
Every dealer that finances or leases already answers to the FTC Safeguards Rule requirements. That’s the floor. What changed is who else is asking. After the June 2024 CDK Global attack disrupted about 15,000 dealerships and left stores writing repair orders by hand, automakers stopped taking a dealer’s word for it and started asking to see the evidence.
Helion Technologies maps these standards for stores through its dealership cybersecurity program, and the pattern holds across brands. An automaker writes a standard, ties it to the dealer agreement or a deadline, and then asks for proof, which means a document, a log or an audit report that somebody outside your store can check without calling you first. Promises don’t count.
We covered why this shift is happening in Why Automakers Are Raising the Dealership Cybersecurity Bar. This is the practical half. What each automaker asks for, and what to have ready when they ask.
Mercedes-Benz USA Wants a Certificate, Not a Checklist
Mercedes-Benz USA’s Cyber Security Guidelines for Dealers set a harder test than GM does. As Helion reported in January, dealers have to prove an information security program is in place and working, through ISO/IEC 27001 or TISAX Level 2 certification. The deadline was September 30, 2026. It’s passed.
The guidelines reach dealers through Mercedes-Benz channels and aren’t published. Check your copy. Both paths end the same way, with an outside party reviewing how your store actually runs security instead of how a questionnaire says it does, which is why a policy binder nobody follows won’t survive either one. Our ISO 27001 vs TISAX comparison sets the two side by side. Not certified yet? Ask your Mercedes-Benz USA contact in writing where your store stands and what timeline they’ll accept. Then start. Our guide to the Mercedes-Benz dealer ISO 27001 and TISAX requirement after the deadline covers the next steps.
An audit. Not a form.
ISO/IEC 27001
The international standard for an information security management system. An accredited certification body audits your store. The certificate runs three years, with a surveillance audit each year in between.
Broad, and recognized outside automotive.
TISAX Level 2
The auto industry’s own assessment, governed by the ENX Association and built on the VDA’s ISA catalogue. At Level 2 an approved audit provider checks your self-assessment and your evidence, usually remotely. Labels last three years.
Built for automotive, shared through the ENX portal.
Brand by brand
OEM Cybersecurity Requirements by Automaker
Automakers send these standards through dealer portals and field reps, and they revise them. Versions change. Treat this table as a starting map, then get the current copy from your brand.
| Automaker | What it asks for | What to have ready |
|---|---|---|
| General Motors | Follow the Dealer Infrastructure and Security Guidelines, which GM ties to Article 5.6 of its dealer agreement. Report a confirmed security incident to GM within 72 hours. | An incident response plan with GM’s reporting steps in it, MFA records, a network diagram that shows segmentation and proof that endpoint monitoring is running. |
| Mercedes-Benz USA | Prove a working information security program through ISO/IEC 27001 or TISAX Level 2 certification. The deadline was September 30, 2026. | The certificate or TISAX label, the scope it covers and the evidence file behind it. |
| Other brands | It varies, and most of it isn’t public. Standards arrive through the dealer portal, the brand’s IT guidelines or the dealer agreement itself. | A written answer from your field rep on which security standard applies, which version is current and whether proof is due by a date. |
| Every dealer that finances or leases | The FTC Safeguards Rule. A written security program, a qualified individual in charge, risk assessments, MFA, encryption, testing and an incident response plan. | The written program, the latest risk assessment and the yearly report to your board or owners. |
GM details from the GM Dealer Infrastructure and Security Guidelines, April 2026 version. Mercedes-Benz USA details as reported in Helion’s January 2026 article, since the guidelines aren’t public. Federal requirements from 16 CFR 314.4. Checked October 2026.
Inside GM’s guidelines
Six Things GM’s Dealer Security Guidelines Ask For
GM’s guidelines run 19 pages and cover everything from PC specs to Wi-Fi. Security gets three of them. One part is written as mandatory, the incident reporting process. The rest GM calls the minimum set of controls that should be in place. Read both.
Want to know how your stores measure up? Request a complimentary IT and cybersecurity assessment.

Where Helion fits
Helion runs the controls these standards describe for dealerships. That’s 24/7 monitoring, endpoint detection and response, multi-factor authentication and staff training.
GM security guidelines check April 2026 version
1 The incident clock
Email GM’s Cyber Incident Center after a confirmed security incident, preferably within 24 hours and no later than 72, and if GM spots the problem first, expect to start your own investigation within 24 hours of hearing from them. A written summary is due two weeks after the investigation ends. The FTC runs its own clock, covered in our guide to the Safeguards Rule notification requirement. Two clocks. Know both.
Put GM’s steps in your incident response plan now.
2 MFA in three places
GM’s list is specific. It names multi-factor authentication for all privileged accounts, for remote access such as a VPN, and for every user of an internet-facing application. No exceptions listed.
Email counts. So does a cloud DMS.
3 One person, one login
Each user account belongs to one individual. Shared logins at the parts counter or the service desk fail this line, and they fail it quietly, because nobody notices until an investigator asks who was signed in at 4:10 on a Tuesday afternoon and the honest answer is five people.
Remove access the day someone leaves.
4 Endpoint detection with a long memory
GM wants endpoint detection and response on every computer and server, watched around the clock, with activity logged to a SIEM and kept for a rolling 400 days. That’s over a year.
Antivirus alone doesn’t meet this.
5 Guest Wi-Fi kept apart
Guest traffic, financial data and the dealership network must be separated through VLANs or a separate internet connection. GM adds a warning. A different Wi-Fi name doesn’t separate anything.
Test it from the customer lounge.
6 Backups you’ve restored
Regular backups, restore tests and a disaster recovery plan that gets tested too. Test the restore. GM also expects operating systems to stay current, and its guidelines dropped support for Windows 10 on October 14, 2025. The same controls sit in the Safeguards Rule, which our FTC Safeguards compliance service documents for dealers.
A backup nobody has restored is a guess.
What Helion Brings to OEM Cybersecurity Requirements
Helion has worked only with automotive and heavy truck dealerships since 1997. Its security team watches client stores around the clock, and when Helion runs both IT and security for a store, one team owns the fix and the record of it, so the dealer isn’t stuck between two vendors pointing at each other while an automaker waits on an answer. That matters at audit time.
How to Get Ready for an OEM Cybersecurity Review
-
1
Collect every standard
Pull the current security document for each brand you sell, plus the Safeguards Rule and your cyber insurance application. Get all of them.
-
2
Build one control list
These documents overlap heavily. Line them up side by side and work from the strictest version of each control.
-
3
Close the big gaps first
Shared logins, missing multi-factor authentication, flat networks and untested backups go to the top of the list. Start there.
-
4
Keep the proof current
Save reports, logs and screenshots as you go. A control you can’t show is a control you don’t have.
Common Questions

Selling more than one brand?
Bring each brand’s security document to a complimentary IT and cybersecurity assessment. We’ll show you where your stores stand against them.
What are OEM cybersecurity requirements for dealerships?
Does GM require dealers to follow its security guidelines?
How fast do we have to tell GM about a security incident?
What did Mercedes-Benz USA require by September 30, 2026?
Is TISAX easier than ISO 27001 for a dealership?
Do other automakers have cybersecurity requirements for dealers?
Does meeting the FTC Safeguards Rule cover our automaker’s requirements?
Your automaker will ask for proof. Find out what your stores could show today.
Request a Complimentary Assessment →