Dealership cybersecurity non-compliance does not look like somebody walking in and taking your sign off the wall. It looks like a written notice, a portal that stops working the way it used to, and a line item that follows your store into every renewal conversation for years.
That is a less dramatic answer than the one most dealer principals expect, and in some ways it is a worse one. A sudden shutdown would at least be over. A documented, uncured non-compliance just sits there, compounding.
Mercedes-Benz USA requires its dealers to evidence a qualified information security program through ISO 27001 or TISAX Level 2 by September 30, 2026. In this article, we will walk through exactly what happens if you do not, in the order you would actually experience it, so you can have this conversation with your ownership group using facts rather than rumors.
Verify with your factory representative.
OEM cybersecurity guidelines are issued through dealer channels rather than published publicly, and requirements and dates can change. Confirm the standard your manufacturer accepts and the date it applies in writing before you budget against it.
The Consequence Nobody Mentions Is Already Live
Before the OEM deadline enters the picture at all, your store carries a federal obligation that has been in force for three years.
The FTC Safeguards Rule has applied to US auto dealers since June 2023. It classifies dealerships as financial institutions under the Gramm-Leach-Bliley Act, and it requires a written information security program, a named qualified individual accountable for it, multi-factor authentication, encryption of customer data, monitoring, vendor oversight, and staff training.
Federal civil penalties reach $53,088 per violation, per day, and the FTC has treated each affected customer as a separate violation. That exposure exists whether or not you ever hear from your factory representative.
This matters for two reasons:
- The work is not optional either way. Strip Mercedes out of the picture entirely and you still owe most of the same controls under federal law.
- It changes the internal conversation. This is not “an OEM is asking us for something extra.” It is “we are behind on a federal rule, and the OEM has now given us a deadline to catch up.”
You can read the FTC’s own guidance in What Your Business Needs to Know.
The Escalation Ladder, in Order
Here is the sequence in the order a dealership actually meets it. Each rung stays open until you close it, and each one makes the next easier for the manufacturer to reach for.
| When | What happens | How it feels day to day |
| Already | FTC Safeguards Rule exposure, up to $53,088 per violation per day | Invisible until an incident or a complaint makes it visible |
| October 1, 2026 | Documented non-compliance against your dealer agreement and a notice to cure | A letter, and a date by which you must respond |
| Weeks after | Friction on OEM programs, portals, and data feeds that depend on the attestation | Your GM loses a week to workarounds |
| Next renewal | An open item in every conversation about term renewal, add points, and open point applications | Leverage you no longer have |
| If left uncured | Good cause termination or non-renewal proceedings | A legal process with a paper trail against you |
| If you are breached | The fact pattern that turns an incident into a lawsuit and a declined insurance claim | The worst week of your professional life |
Let’s look at the rungs that dealers most often misjudge.
1. The Notice to Cure Is the Real Trigger
Missing the deadline does not terminate anything. It creates a documented material non-compliance with the security provisions of your dealer agreement, and it starts a notice-to-cure clock.
What makes this consequential is not the letter. It is that the issue moves from being a matter of opinion, which you can discuss with your factory rep, to being a matter of record, which follows the store through ownership changes, buy-sell diligence, and every subsequent dispute.
2. Operational Friction Arrives Before Any Formal Action
In practice, the first real cost is not legal. Programs and systems that depend on a security attestation become harder to keep, and the effect shows up in portal access, data feeds, and program eligibility rather than in a formal letter.
This is the part that quietly consumes management attention. Nobody sends you a notice saying access has been reduced; things just start requiring extra steps.
3. Franchise Termination Is Real but Slow
Here is where the rumor and the reality diverge sharply, and it is worth being precise because your ownership group will ask.
State franchise laws protect you from an overnight shutdown. Dealer protection statutes exist in every US state and generally require good cause, written notice, and a cure period before a manufacturer can terminate or refuse to renew a franchise. The specifics vary considerably, with statutory cure periods ranging from 10 days to more than 90 depending on the state, so check your own. Either way, nobody is walking into your showroom on October 1.
What those statutes do not protect you from is a documented, repeatedly uncured material breach. That is precisely the fact pattern that supports good cause, and the manufacturer will hold the entire paper trail. Termination is not the first consequence; it is the last one, and it only becomes available because you let the earlier ones sit.
4. Insurance and Litigation Exposure Compounds Quietly
Cyber insurers increasingly ask, on the renewal application, whether you hold a recognized security certification and whether you comply with applicable regulatory requirements. Answering no affects pricing, coverage terms, and sometimes appetite.
The harder problem is what happens after an incident. A written OEM requirement, a federal rule already in force, and no program in place is the combination plaintiffs’ counsel looks for, because it converts “we were unlucky” into “you were on notice.” Our incident response team has seen how much the presence of a documented program changes the shape of the days after a breach.
The Precedent Every Dealer Principal Already Remembers
In June 2024, the dealer management system provider CDK Global was hit by ransomware attributed to the BlackSuit group. Roughly 15,000 dealer locations across North America went offline for about two weeks.
Deals were written on paper. Warranty claims stopped. Parts ordering stopped. Financing stopped. Anderson Economic Group estimated the cost to dealers at $1.02 billion across the three weeks from June 19 to July 5, 2024, with $605 million incurred in the first two weeks alone.
Not one of those dealers had made a mistake. The breach happened at a vendor. That is exactly why manufacturers stopped taking a dealer’s word for it on security, and it is the reason a September 2026 deadline exists at all.
Divided across the affected rooftops, the average store lost more in that fortnight than a full TISAX program costs.
Four Things Dealers Believe That Are Not True
Here are the misconceptions we hear most often, and what is actually the case:
- “They will pull my franchise on October 1.” They will not. State dealer laws generally require good cause, written notice, and a cure period, though the specifics vary by state. This is a breach-and-cure situation. It only becomes a termination conversation if you leave it uncured through multiple cycles.
- “Everyone is behind, so I am fine.” Most US dealers have not started, which is not cover. There is a limited pool of ENX-accredited assessors in North America, and every month you wait puts you further back in a queue that only lengthens.
- “My MSP handles all of this.” Your MSP may run the tools, and that is genuinely valuable. Somebody still has to write the management system, gather and organize the evidence, and sit across the table from the assessor. That is a different job with a different skill set.
- “We can just buy the certificate.” You cannot. A TISAX assessment must be performed by an independent ENX-accredited audit provider, and ISO 27001 certificates are issued only by accredited certification bodies. Any firm implying it can hand you a label is telling you something that is not true.
What You Can Realistically Do Now
If you are reading this close to the deadline, the honest position is that no dealership starting from a standing start will hold a label by September 30. Eight to twelve months is the real timeline. So the goal changes.
Here is what a defensible position looks like on the deadline date:
- Ask your factory representative, in writing, what they will accept as evidence of progress. A written answer you can plan against beats a rumor from the twenty group.
- Complete a readiness check. Two weeks and typically $7,500 fixed produces a documented scope, a gap assessment, and a ranked roadmap. It is also the first artifact you can actually show someone.
- Register with ENX and book an accredited assessor. Your place in the queue is worth more than it sounds.
- Close the assessment blockers first. Multi-factor authentication everywhere, shared logins eliminated, same-day offboarding, and documented vendor access. Our identity and access management and third-party risk assessment work targets exactly these.
- Keep evidence as you go. The single most common cause of a failed or delayed assessment is not missing controls. It is controls that exist with nothing written down to prove it.
A dealer who arrives on September 30 registered, scoped, gap-assessed, funded, and visibly remediating is in an entirely different conversation than a dealer with nothing on paper. That difference costs two weeks and a fixed fee.
Frequently Asked Questions
Can a manufacturer terminate a dealership for cybersecurity non-compliance?
Not immediately. Dealer franchise protection laws exist in every US state and generally require good cause, written notice, and an opportunity to cure before a manufacturer can terminate or refuse to renew. A missed cybersecurity deadline creates a documented material non-compliance and starts a notice-to-cure process. Termination becomes a realistic risk only if the non-compliance remains uncured over an extended period.
What is the FTC Safeguards Rule penalty for a car dealership?
Federal civil penalties under the FTC Act reach $53,088 per violation, per day, and the FTC has treated each affected customer as a separate violation. The Safeguards Rule has applied to US auto dealers since June 2023 and requires a written security program, a named qualified individual, multi-factor authentication, encryption, monitoring, and vendor oversight, independently of any manufacturer requirement.
What happens to OEM portal access if a dealership is non-compliant?
Programs and systems that depend on a security attestation typically become harder to maintain, and the effect shows up first in portal access, data feeds, and program eligibility rather than in a formal notice. In practice, this is the consequence dealerships feel earliest, because it consumes management time immediately rather than escalating through a legal process.
Does cyber insurance still cover a dealership that is not compliant?
Coverage is not automatically void, but non-compliance affects it in two ways. Cyber insurers increasingly ask on renewal applications whether you hold a recognized security certification and comply with applicable regulatory requirements, and the answer affects pricing, terms, and appetite. After an incident, a documented failure to meet a known requirement can also support a coverage dispute or a negligence claim.
Is it too late for a dealership to start before September 30, 2026?
It is too late to hold a full label by that date, because a program from a standing start takes eight to twelve months. It is not too late to be registered with ENX, scoped, gap-assessed, booked with an accredited assessor, and visibly remediating, which is a materially stronger position than having nothing documented. TISAX also allows a temporary label valid for up to nine months where an assessment finds only minor non-conformities.
Which manufacturers require TISAX or ISO 27001 from dealers?
Mercedes-Benz USA has set the clearest requirement for US dealers, with a September 30, 2026 deadline for ISO 27001 or TISAX Level 2. TISAX is already an established requirement across the supply chains of Volkswagen Group, BMW, Audi, Porsche, Daimler Truck, and Stellantis, and the requirement is progressively moving down to the dealer level. Confirm your own obligations directly with each manufacturer you represent.
Close the Gap with CyberGlobal by Your Side
None of this is a comfortable read, and we would rather tell you the honest version than the reassuring one. The consequences of dealership cybersecurity non-compliance are slow, cumulative, and entirely avoidable, which is the best news in this article.
Our GRC team builds these programs for a living; our Security Operations Center covers the monitoring requirement, and our penetration testing engineers handle the annual test where continuous monitoring is not in place. We have supported enterprise clients including Mercedes-Benz, and behind every framework and acronym there are real people who will translate this into plain English for your team.
We are not your assessor, and that is deliberate. Our only job is to get you ready and stand beside you through every audit interaction. Let us be your ally on this one. Reach out today!
Secure Your Dealership With CyberGlobal
Two weeks, a fixed price, and you go from having nothing on paper to having a scope, a gap report, and a defensible plan.