2026-09-21 · Équipe éditoriale KeXinMaterials
IATF 16949:2025 Édition 2 + AIAG-VDA FMEA + Cybersécurité + AI/ML + ESG + Résilience Chaîne Approvisionnement Mises à jour B2B Guide
IATF 16949:2025 Édition 2 (en développement, attendue 2025-2026) intègre mises à jour majeures: AI/ML per ISO 42001 + cybersécurité per UN R155 + ISO 21434 + IEC 62443 + ESG per ISO 14001 + CSRD + ESRS + résilience chaîne approvisionnement per ISO 28000 + ISO 20243 + EU NIS 2 + US EO 14028 + SBOM + SLSA.
IATF 16949:2025 Edition 2 Major Updates
IATF 16949:2025 Edition 2 expected 2025-2026. Major updates: cybersecurity + AI/ML + ESG + supply chain resilience + risk management + SDV + BIM + OEM cost program.
IATF 16949:2025 Edition 2: Currently in Draft / Public Consultation stage. Expected publication 2025-2026. Major update of automotive QMS for global automotive supply chain.
IATF 16949:2025 transition timeline: Draft 2024-2025 + Final publication 2025-2026 + Transition period 2026-2028 + Mandatory 2029-2030.
IATF 16949:2025 cybersecurity updates: Per UN R155 + ISO 21434 + IEC 62443 + ISO 27001 + ISO 27002 + SOC 2 + EN 18031 (RED 3.3(d)). Cyber Security Management System (CSMS) + Software Update Management System (SUMS).
IATF 16949:2025 AI/ML updates: Per ISO 42001 + ISO/IEC TR 5469 + ISO/IEC 23053 + ISO/IEC 42005. AI risk assessment + AI governance + AI transparency + AI robustness + AI safety. Required for AI machine learning in automotive.
IATF 16949:2025 ESG updates: Per ISO 14001 + ISO 14090 + ISO 14097 + CSRD + ESRS + EU CBAM + EU Battery Regulation + SBTi + CDP + GRI. Environmental + social + governance. Mandatory sustainability reporting.
IATF 16949:2025 supply chain resilience updates: Per ISO 28000 + ISO 20243 + EU NIS 2 + US EO 14028 + SBOM + SLSA + NIST SP 800-161 + NIST SP 800-218 + EN 18031. Software supply chain + hardware supply chain + counterfeit detection + tamper evident + provenance + traceability.
IATF 16949:2025 risk management updates: Per ISO 31000 + ISO 31010 + Enterprise Risk Management (ERM). Risk-based thinking + opportunity assessment + risk treatment + residual risk + effectiveness monitoring.
IATF 16949:2025 software-defined vehicles (SDV) updates: Per ISO 26262 + ISO 21448 (SOTIF) + SAE J1739 + ASPICE + ISO 24089 (ROTS) + ISO 21434 + UN R155 + UN R156 + UL 4600 (autonomy). SDV requires continuous software delivery + OTA updates + cybersecurity + functional safety + SOTIF.
IATF 16949:2025 OEM cost program updates: Per VW Group PMC (purchasing + management) + Toyota ASES (Achieving Supply Excellence System) + GM BIQS (Built-In Quality Supply) + Ford Q-Spec + Hyundai SQ Mark. Tier 1/2/3 supplier cost reduction + value engineering + design-to-cost.
IATF 16949:2025 BIM (Built-In Quality) updates: Per Toyota + GM BIQS + Ford Q-Spec. Quality built-in at every process step + defect prevention + zero defects + operator authority + Andon system.
IATF 16949:2025 traceability + documentation updates: Per IATF 16949:2016 + IATF 16949:2025. Digital thread + MBSE + Smart Manufacturing + Industry 4.0 + Industrial Internet of Things (IIoT) + Industrial Edge + Cloud Manufacturing.
B2B relevance: For B2B automotive cases, IATF 16949:2025 Edition 2 is procurement requirement for tier 1/2/3 suppliers. Major updates impact cybersecurity + AI/ML + ESG + supply chain resilience + SDV + BIM.
Cybersecurity + AI/ML + ESG + Supply Chain Updates Detail
IATF 16949:2025 detailed updates: UN R155 + ISO 21434 + ISO 42001 + CSRD + ISO 28000 + SBOM + SLSA + UN R156 + SOTIF + ISO 24089.
UN R155 + ISO 21434 + IEC 62443 per IATF 16949:2025: Cyber Security Management System (CSMS) for OEM + EV + EVSE + supplier + service. ISO 21434 for automotive cybersecurity engineering + ISO 24089 (Road vehicles — Software update engineering). IEC 62443 SL 1-4 for OT cybersecurity.
ISO 42001 + AI/ML per IATF 16949:2025: AI Management System (AIMS). AI risk assessment + AI transparency + AI explainability + AI robustness + AI safety + AI ethics. ISO/IEC TR 5469 (AI functional safety). ISO/IEC 23053 (AI use cases framework).
AI/ML in automotive: ADAS (Advanced Driver Assistance Systems) + AD (Autonomous Driving) + driver monitoring + voice assistant + predictive maintenance + quality inspection + generative AI for design + autonomous vehicle.
EU AI Act (2024/1689): EU regulation on artificial intelligence. Risk-based approach: prohibited + high risk + limited risk + minimal risk. Automotive AI typically high risk.
ISO 14001 + ISO 14090 + CSRD + ESRS + EU Battery Regulation 2023/1542 per IATF 16949:2025: Environmental management + climate change adaptation + ESRS + Battery carbon footprint declaration + Battery passport + recycled content + lithium footprint + supply chain due diligence.
EU CSRD per Directive (EU) 2022/2464: Corporate Sustainability Reporting Directive. ESRS (European Sustainability Reporting Standards). ESRS E1 (Climate Change) + ESRS E5 (Resource Use + Circular Economy) + ESRS S (Social) + ESRS G (Governance). Required for global automotive supply chain.
EU Battery Regulation 2023/1542: Battery carbon footprint declaration + recycled content + battery passport + state of health + lithium footprint + supply chain due diligence. Replaces Battery Directive 2006/66/EC. Effective August 2024.
EU CBAM (Carbon Border Adjustment Mechanism) per Regulation (EU) 2023/956: Carbon tariff on imports. Scope: cement + iron + steel + aluminium + fertilisers + electricity + hydrogen. Transition October 2023 - December 2025. Definitive January 2026.
ISO 28000 + ISO 20243 + EU NIS 2 + SBOM + SLSA per IATF 16949:2025: Supply chain security management + ISO 20243 O-TTPS supply chain integrity + EU NIS 2 supply chain security + Software Bill of Materials (SBOM) + SLSA framework.
NIST SP 800-161r1 (2022) C-SCRM: Cyber Supply Chain Risk Management. 12 control families. Aligned with ISO/IEC 20243 O-TTPS + EU NIS 2.
NIST SP 800-218 SSDF: Secure Software Development Framework. 12 practices. SBOM + software composition analysis + vulnerability handling + security update + provenance + integrity + attestation.
Executive Order 14028 (May 2021): US federal government software supply chain security. SBOM + secure development + SLSA Level 1-4.
SLSA (Supply chain Levels for Software Artifacts): Per Google + Linux Foundation. SLSA 1 (basic) + SLSA 2 (build provenance) + SLSA 3 (hardened build) + SLSA 4 (two-party review + hermetic + reproducible).
UN R156 SUMS (Software Update Management System): Per UN R156. OTA software update management. Required for automotive OEMs + EV.
ISO 24089 (Road vehicles — Software update engineering): Engineering requirements for software updates. Per ISO 24089:2023.
ISO 21448 (SOTIF) per IATF 16949:2025: Safety of the Intended Functionality. AI + autonomous driving + ADAS + edge cases + performance limitation + triggering condition.
B2B relevance: For B2B automotive cases, IATF 16949:2025 with cybersecurity + AI/ML + ESG + supply chain resilience + SDV + BIM + EU regulations + US regulations is procurement requirement for tier 1/2/3 suppliers.
Points clés
- IATF 16949:2025 Edition 2 in development. Expected 2025-2026. Transition 2026-2028. Mandatory 2029-2030.
- IATF 16949:2025 major updates: cybersecurity (UN R155 + ISO 21434 + IEC 62443) + AI/ML (ISO 42001) + ESG (ISO 14001 + CSRD + ESRS) + supply chain resilience (ISO 28000 + ISO 20243 + EU NIS 2 + SBOM + SLSA).
- Risk management per ISO 31000 + ISO 31010. Software-defined vehicles per ISO 26262 + SOTIF + SAE J1739 + ASPICE + ISO 24089.
- UN R156 SUMS + EU Battery Regulation 2023/1542 + EU CBAM (EU) 2023/956 + CSRD + ESRS + EU AI Act 2024/1689. Multi-regulatory compliance.
- BIM (Built-In Quality) per Toyota + GM BIQS + Ford Q-Spec. Quality built-in at every process step + defect prevention + zero defects.
- B2B recommendation: For B2B automotive cases, prepare for IATF 16949:2025 + cybersecurity + AI/ML + ESG + supply chain resilience + BIM + SDV + ISO 31000 + UN R155 + ISO 42001.
FAQ
q
a
q
a
q
a
q
a
q
a
q
a