Skip to content
Zyberum Cyber Security Firm
Menu
ComparisonsCompliance

ISO/SAE 21434 vs IEC 62443: Vehicle or Plant, and What If Your Product Is Both?

ISO/SAE 21434 covers cybersecurity engineering for vehicles and ECUs, IEC 62443 covers industrial automation. Differences, overlaps and products that sit in between.

Updated This page as Markdown

In short

ISO/SAE 21434 is the cybersecurity engineering standard for road vehicles: it defines how OEMs and suppliers run a TARA, develop, validate and maintain ECUs, and it is the backbone of the CSMS that UN R155 demands. IEC 62443 is the standard family for industrial automation: zones and conduits, Security Levels, system and component requirements and a secure development lifecycle for suppliers. Both ask for risk assessment, secure development and vulnerability management, with different vocabulary, roles and evidence. Vehicles follow 21434, plants and machines follow 62443, and charging infrastructure or off-highway machinery often needs both.

What is the difference?

ISO/SAE 21434 is written for one product class, road vehicles and the ECUs and software inside them; IEC 62443 is written for one environment, industrial automation and control systems and the components they are built from. The automotive standard describes the engineering lifecycle: organisational cybersecurity management (clause 5), project management (6), distributed activities between OEM and supplier (7), continual activities such as monitoring and vulnerability management (8), concept and TARA (9 and 15), product development and validation (10 and 11), production, operations and end of support (12 to 14). It does not contain technical requirements like “the ECU shall authenticate diagnostic sessions”; it tells you how to derive them from your own TARA.

IEC 62443 does contain technical requirements. 62443-3-3 lists system requirements per foundational requirement and Security Level, 4-2 does the same for components, and 3-2 gives the risk method with zones and conduits. 4-1 covers the development process, which is the part closest to 21434. Where 21434 says “derive your goals from the threat scenarios”, 62443 says “a component at SL 2 shall provide these capabilities”. That makes 62443 easier to specify in a purchase order and 21434 easier to apply to a product nobody has threat-modelled before.

Side by side

ISO/SAE 21434IEC 62443
What it coversCybersecurity engineering of road vehicles, their systems, ECUs and software across the lifecycle: TARA, concept, development, validation, production, operations, decommissioning; the process side of the UN R155 CSMSSecurity of industrial automation and control systems: operator programmes (2-1), service providers (2-4), risk assessment with zones and conduits (3-2), system requirements (3-3), development lifecycle (4-1), component requirements (4-2)
What it does not coverPrescriptive technical requirements or security levels; the plant or factory that builds the car; back-end and charging infrastructure outside the vehicle’s item definitionVehicles and type approval; the OEM-supplier interface agreements that 21434 clause 7 formalises; attacker models with physical access to a mass-produced unit at home
Who is addressedOEMs and their suppliers of ECUs, software and components; indirectly the type-approval authority through UN R155Asset owners of plants, system integrators, and product suppliers of PLCs, drives, HMIs, machines and industrial software
DurationA TARA for one ECU two to six weeks; a complete set of work products for a component project several months alongside developmentA plant risk assessment two to three months; bringing a development process to 4-1 and a product to a 4-2 Security Level one to two years
Typical costTARA and cybersecurity concept for an ECU 10,000 to 30,000 euros; ECU penetration test and fuzzing 20,000 to 45,000; typical ranges for Germany and the EU, not an offerOT risk assessment and penetration test 12,000 to 25,000 euros per site; 4-1 process and 4-2 component evaluations often five-figure sums per product; not an offer
Recurring dutiesContinual monitoring, vulnerability management and incident response for the support period (clause 8 and 13); updates to TARA on changesPatch and vulnerability management (2-3, 4-1 practice DM), reassessment of zones after changes, re-evaluation of components after major releases
Required byUN R155 for type approval in the EU and 60 plus contracting states; OEM contracts and cybersecurity interface agreements; UN R156 for software updates alongsideOEM and operator specifications for machines and components; NIS2 for plant operators in practice; Machinery Regulation and CRA via harmonised standards for industrial products
OutputItem definition, TARA, cybersecurity goals and concept, specifications, verification and validation reports, cybersecurity case, release for post-developmentZone and conduit model with target SLs, requirement traceability per 3-3 or 4-2, process evidence per 4-1, optional certificates per product or process from accredited bodies

Choose ISO/SAE 21434 when

  • Your product goes into a road vehicle: car, truck, bus, trailer with electronics, motorcycle. The OEM’s type approval depends on UN R155, and the OEM will cascade 21434 work products to you via a cybersecurity interface agreement.
  • You are an OEM building a CSMS. UN R155 does not name a standard, but 21434 is what the authorities and technical services expect to see behind it.
  • The threat picture is the automotive one: an attacker owns a unit, has unlimited time with it, and attacks via OBD, CAN, UDS, Bluetooth, cellular and the back end. The TARA method of clause 15 is built for that.

Choose IEC 62443 when

  • Your product is a controller, drive, HMI, machine, robot or industrial software, or you run a plant. The buyer wants a Security Level and 4-1 process evidence, not a TARA in automotive vocabulary.
  • Availability and safety of a running process dominate the risk. The zone and conduit method and the foundational requirements of 62443 express that; 21434 has no equivalent for segmentation of a plant.
  • The CRA and the Machinery Regulation are your route to market. For industrial products the harmonised standards will build on 62443, not on 21434.

Both together

Products in between need both, and that is more common than it looks: EV charging stations (vehicle protocols on one side, grid and building automation on the other), agricultural and construction machinery with road-approved variants, and factory equipment built on automotive-grade controllers. The efficient approach is one risk assessment that produces both a 21434 TARA and a 62443-3-2 zone model, one development process documented against clause 10 of 21434 and 62443-4-1 with a mapping table, and one vulnerability-management process that serves UN R155, the CRA and plant customers.

Zyberum does TARAs and ISO/SAE 21434 work products for OEMs and suppliers, IEC 62443 risk assessments and 4-1 and 4-2 gap analyses for machine builders, and penetration tests and fuzzing of ECUs and industrial controllers. We do not issue CSMS certificates or IEC 62443 certificates; those come from type-approval authorities and accredited bodies. If your product sits in between, we map the two standards once so that you do not pay for two processes.

FAQ

Frequently asked questions

Our ECU is used in trucks and in agricultural machines. Which standard applies?

Both, and the split follows the vehicle. In the truck the ECU is part of a type-approved vehicle under UN R155, so the OEM will demand ISO/SAE 21434 work products: TARA, cybersecurity concept, verification evidence, vulnerability management for the support period. In the agricultural machine, if it is not a road vehicle under R155, the machine falls under the Machinery Regulation and the CRA, and the buyer will more likely ask for IEC 62443-4-1 process evidence and 4-2 component requirements. Do one TARA and one development process that produce both sets of evidence.

Is a Security Level the same as a CAL?

No. An IEC 62443 Security Level (SL 1 to 4) describes the attacker capability a zone or component must withstand, and it translates into concrete technical requirements per foundational requirement. A Cybersecurity Assurance Level in the informative Annex E of ISO/SAE 21434 describes how much rigour the engineering activities need. One is about the product, the other about the process; mapping one onto the other is possible for a project but not defined by either standard.

Does a CSMS certificate under UN R155 count for IEC 62443?

Not formally. The CSMS certificate of compliance is issued to the vehicle manufacturer by the type-approval authority and covers its processes. A machine buyer or an industrial operator has no obligation to recognise it. In practice a supplier with a mature 21434 process is close to IEC 62443-4-1 and can close the gap with a mapping and a few additions, which is cheaper than two processes.

Sources

Related pages

Get started

Not sure which test you need?

Describe your product or environment in a 15-minute call. You get a clear recommendation and, if you want one, a fixed-price offer.

  • A recommendation, not a sales pitch
  • Scope and effort estimate on the spot
  • Free and without obligation
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usGet a recommendation

Pick a time that suits you

Open in a new tab