Stellantis, the parent company of Chrysler, Jeep, Dodge and Ram, has joined GlobalPlatform’s Automotive Task Force, signaling a major step toward synchronized cybersecurity standards for software-defined vehicles (SDVs). As part of the move, Bill Mazzara, North American regulatory lead and technical fellow for product cybersecurity at Stellantis, has been appointed co-chair of the task force.
The collaboration promotes standardized, certified hardware and software components — such as Secure Elements (SEs) and Trusted Execution Environments (TEEs) — while will allow collision repair shops to streamline workflows, minimize re-certification overhead, and manage ADAS or cybersecurity calibration processes more effectively.
“GlobalPlatform’s Automotive Task Force is helping the industry converge on a platform of secure, scalable foundations for software-defined vehicles,” said Mazzara. “Our engagement is focused on harmonizing security standards and fostering cross-industry collaboration to meet evolving regulatory and operational requirements and ultimately our customers' expectations.”
A cornerstone of the task force’s progress includes full alignment of GlobalPlatform specifications with the SAE J3101-5 addendum to the J3101 Hardware Protected Security Environment standard. This milestone enables suppliers adhering to GlobalPlatform protocols to automatically meet J3101 requirements, ensuring automakers — and by extension, collision-repair facilities — can trust embedded components without repeated cybersecurity validation.
Furthermore, the task force has engineered a protection profile using the SESIP evaluation methodology, meaning certified components can be reused across multiple platforms, greatly reducing costs, evaluation time and complexity across the supply chain.
GlobalPlatform reports that as of 2023, more than 192 million SEs and 100 million TEEs compliant with its standards are already deployed in vehicles. The pressing nature of automotive cybersecurity is underscored by a dramatic rise in vulnerabilities, from just six a decade ago to more than 500 published in 2024, with estimated SDV cyberattack costs surging to $22.5 billion from $1 billion in 2022.
GlobalPlatform’s Automotive Task Force — which now counts Stellantis alongside Cariad (Volkswagen), Woven by Toyota, Renesas, DEKRA and others — focuses on defining secure hardware and services, aligning with SAE, AUTOSAR and Car Connectivity Consortium (CCC) frameworks, and coordinating industry-wide compliance and interoperability.