Skip to content
Zyberum Cyber Security Firm
Menu
GlossaryAutomotiveStandards

ISO/SAE 21434

ISO/SAE 21434:2021 is the standard for cybersecurity engineering of road vehicles. Its clauses, how it relates to UN R155, and what it asks from OEMs and suppliers.

Updated This page as Markdown

In short

ISO/SAE 21434:2021 "Road vehicles, Cybersecurity engineering" specifies how cybersecurity is managed and engineered for electrical and electronic systems in road vehicles, from organisational processes and the concept phase through development, validation, production and operations to decommissioning. It is the standard behind the CSMS that UN Regulation No. 155 requires, and the common language between OEMs and suppliers.

What is ISO/SAE 21434?

ISO/SAE 21434 is the international standard for cybersecurity engineering of road vehicles. It was developed jointly by ISO and SAE International, published in August 2021, and replaces the SAE J3061 guidebook from 2016. It covers the whole lifecycle of electrical and electronic systems in series-production vehicles: how an organisation sets up cybersecurity governance, how a project plans and performs cybersecurity activities, how risks are analysed, how requirements are derived, implemented, verified and validated, and what happens after start of production.

The standard tells you what has to be done and documented. It does not prescribe specific technologies, protocols or security levels, and it does not contain a list of controls. Those come from the TARA for the product in question.

Where is it defined?

The standard is sold by ISO and SAE. Its structure in short: Clause 5 organisational cybersecurity management (policy, roles, culture, information sharing, management systems, tooling), Clause 6 project-dependent cybersecurity management (cybersecurity plan, tailoring, reuse, component out of context, off-the-shelf components, cybersecurity case, assessment, release for post-development), Clause 7 distributed cybersecurity activities (supplier capability, request for quotation, cybersecurity interface agreement), Clause 8 continual activities (monitoring, event evaluation, vulnerability analysis and management), Clause 9 concept (item definition, cybersecurity goals, cybersecurity concept), Clause 10 product development, Clause 11 cybersecurity validation, Clause 12 production, Clause 13 operations and maintenance (incident response, updates), Clause 14 end of cybersecurity support and decommissioning, and Clause 15 the TARA methods. Annexes give a cybersecurity interface agreement example, guidance on component out of context and a TARA example.

What it means in practice

For a supplier, ISO/SAE 21434 shows up as a list of work products the OEM expects with the quotation and at each milestone: a cybersecurity plan, the item definition, the TARA, cybersecurity goals and concept, cybersecurity specifications at system, hardware and software level, verification reports, a validation report and a cybersecurity case that ties it together. The cybersecurity interface agreement (Clause 7) decides who does which of them.

What we see when we come in as testers or as authors of the work products: the engineering is often fine, but the traceability is missing. A cybersecurity requirement exists in a document but no test case references it, or the TARA assumes secure diagnostics and the UDS implementation accepts security access with a constant seed. Clause 10 and Clause 11 exist to close exactly these gaps, and a penetration test or fuzzing campaign on the ECU is the fastest way to find them before the OEM does.

Common misunderstandings

ISO/SAE 21434 does not make a product secure and does not replace UN R155; the regulation decides whether a vehicle may be sold, the standard describes how to do the engineering behind it. It also does not cover IT security of the enterprise (that is ISO/IEC 27001 or TISAX) or industrial control systems (IEC 62443). And it does not say how often to test or how deep: that is a decision you document in the cybersecurity plan, based on the TARA.

FAQ

Frequently asked questions

Is ISO/SAE 21434 mandatory?

The standard itself is not law. UN Regulation No. 155 is binding for type approval in the EU, Japan, Korea and other contracting states, and it requires a CSMS and risk management without naming a method. ISO/SAE 21434 is the accepted way to show that, so OEMs require it from suppliers by contract. For most people in the supply chain it is mandatory in effect.

Can I get certified against ISO/SAE 21434?

Some technical services and certification bodies offer process assessments or certificates against the standard, but the standard itself does not define a certification scheme and UN R155 certifies the CSMS, not ISO conformance. Zyberum does not certify. We write the work products, run the TARA and the tests, and prepare you for the assessment.

What does ISO/SAE 21434 say about penetration testing?

Clause 11 (cybersecurity validation) requires that the cybersecurity goals and claims are validated on the item at vehicle level, and Clause 10 asks for verification of the cybersecurity specifications during development, with penetration testing named as one method. The standard does not prescribe depth or duration; the TARA and the cybersecurity plan should.

Sources

Related pages

Get started

A term that applies to your product?

In 15 minutes we tell you what it means for you in practice, which requirement follows from it and what the sensible next step is.

  • Direct answer from a security engineer
  • Which standard or law applies to you
  • Free and without obligation
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usAsk a security engineer

Pick a time that suits you

Open in a new tab