
About
Özer Koray Akdemir
Product cybersecurity architect · Gothenburg, Sweden
Özer Koray Akdemir works where regulation meets engineering: turning a legal requirement into an architecture, into requirements suppliers can build to, and into evidence an assessor will accept. He set up the product cybersecurity function for a new electric vehicle platform, starting with no team and no processes, and took the platform through UNECE R155 type approval. It was among the first vehicle platforms worldwide to be approved under the regulation. The work covered the cybersecurity management system, threat analysis and risk assessment (TARA), supplier requirements and the evidence for the type-approval audit. He also designed the PKI and secure update chain for over-the-air software updates under UNECE R156, and later worked as a vehicle cybersecurity architect on heavy-duty vehicle platforms. Before automotive, he spent many years on cryptographic systems and secure communications.
Why the kit exists
The CRA asks manufacturers of connected products for much of what R155 asked of carmakers: a risk-based process, security designed in, vulnerability handling, incident reporting and a documented trail an authority can follow. Most companies now facing the CRA have never had to produce that trail. The kit is the structure he would hand a team on its first day: the documents in the order they are needed, each linked to the article it supports.
Principles
- Every template maps to an article of the regulation.
- Standards are cited by number only; no standard text is reproduced.
- No legal promises: the kit structures the work; it does not certify it.
Background
- M.Sc. in Electronics and Multimedia Signal Processing, Tampere University of Technology, Finland.
- B.Sc. in Electrical and Electronics Engineering, Bilkent University, Türkiye.
- Works with UNECE R155 and R156, ISO/SAE 21434, IEC 62443, ISO 27001 and NIS2.