ISO/SAE 21434
ISO/SAE 21434:2021 is the standard for cybersecurity engineering of road vehicles. Its clauses, how it relates to UN R155, and what it asks from OEMs and suppliers.
Updated This page as Markdown
In short
ISO/SAE 21434:2021 "Road vehicles, Cybersecurity engineering" specifies how cybersecurity is managed and engineered for electrical and electronic systems in road vehicles, from organisational processes and the concept phase through development, validation, production and operations to decommissioning. It is the standard behind the CSMS that UN Regulation No. 155 requires, and the common language between OEMs and suppliers.
What is ISO/SAE 21434?
ISO/SAE 21434 is the international standard for cybersecurity engineering of road vehicles. It was developed jointly by ISO and SAE International, published in August 2021, and replaces the SAE J3061 guidebook from 2016. It covers the whole lifecycle of electrical and electronic systems in series-production vehicles: how an organisation sets up cybersecurity governance, how a project plans and performs cybersecurity activities, how risks are analysed, how requirements are derived, implemented, verified and validated, and what happens after start of production.
The standard tells you what has to be done and documented. It does not prescribe specific technologies, protocols or security levels, and it does not contain a list of controls. Those come from the TARA for the product in question.
Where is it defined?
The standard is sold by ISO and SAE. Its structure in short: Clause 5 organisational cybersecurity management (policy, roles, culture, information sharing, management systems, tooling), Clause 6 project-dependent cybersecurity management (cybersecurity plan, tailoring, reuse, component out of context, off-the-shelf components, cybersecurity case, assessment, release for post-development), Clause 7 distributed cybersecurity activities (supplier capability, request for quotation, cybersecurity interface agreement), Clause 8 continual activities (monitoring, event evaluation, vulnerability analysis and management), Clause 9 concept (item definition, cybersecurity goals, cybersecurity concept), Clause 10 product development, Clause 11 cybersecurity validation, Clause 12 production, Clause 13 operations and maintenance (incident response, updates), Clause 14 end of cybersecurity support and decommissioning, and Clause 15 the TARA methods. Annexes give a cybersecurity interface agreement example, guidance on component out of context and a TARA example.
What it means in practice
For a supplier, ISO/SAE 21434 shows up as a list of work products the OEM expects with the quotation and at each milestone: a cybersecurity plan, the item definition, the TARA, cybersecurity goals and concept, cybersecurity specifications at system, hardware and software level, verification reports, a validation report and a cybersecurity case that ties it together. The cybersecurity interface agreement (Clause 7) decides who does which of them.
What we see when we come in as testers or as authors of the work products: the engineering is often fine, but the traceability is missing. A cybersecurity requirement exists in a document but no test case references it, or the TARA assumes secure diagnostics and the UDS implementation accepts security access with a constant seed. Clause 10 and Clause 11 exist to close exactly these gaps, and a penetration test or fuzzing campaign on the ECU is the fastest way to find them before the OEM does.
Common misunderstandings
ISO/SAE 21434 does not make a product secure and does not replace UN R155; the regulation decides whether a vehicle may be sold, the standard describes how to do the engineering behind it. It also does not cover IT security of the enterprise (that is ISO/IEC 27001 or TISAX) or industrial control systems (IEC 62443). And it does not say how often to test or how deep: that is a decision you document in the cybersecurity plan, based on the TARA.
FAQ
Frequently asked questions
Is ISO/SAE 21434 mandatory?
The standard itself is not law. UN Regulation No. 155 is binding for type approval in the EU, Japan, Korea and other contracting states, and it requires a CSMS and risk management without naming a method. ISO/SAE 21434 is the accepted way to show that, so OEMs require it from suppliers by contract. For most people in the supply chain it is mandatory in effect.
Can I get certified against ISO/SAE 21434?
Some technical services and certification bodies offer process assessments or certificates against the standard, but the standard itself does not define a certification scheme and UN R155 certifies the CSMS, not ISO conformance. Zyberum does not certify. We write the work products, run the TARA and the tests, and prepare you for the assessment.
What does ISO/SAE 21434 say about penetration testing?
Clause 11 (cybersecurity validation) requires that the cybersecurity goals and claims are validated on the item at vehicle level, and Clause 10 asks for verification of the cybersecurity specifications during development, with penetration testing named as one method. The standard does not prescribe depth or duration; the TARA and the cybersecurity plan should.
Sources
Related pages
- GlossaryUN R155UN Regulation No. 155 makes cybersecurity a condition for vehicle type approval. Who it applies to, the CSMS and vehicle requirements, and how the EU enforces it.
- GlossaryTARA (Threat Analysis and Risk Assessment)TARA is the risk analysis method of ISO/SAE 21434 for vehicles and ECUs. The seven steps, how impact and attack feasibility are rated, and what a usable TARA looks like.
- GlossaryCSMS (Cybersecurity Management System)A CSMS is the organisational process framework UN R155 requires from vehicle manufacturers. What it must cover, how it is audited, and what suppliers deliver to it.
- ComparisonsISO/SAE 21434 vs IEC 62443: Vehicle or Plant, and What If Your Product Is Both?ISO/SAE 21434 covers cybersecurity engineering for vehicles and ECUs, IEC 62443 covers industrial automation. Differences, overlaps and products that sit in between.
- InsightsISO/SAE 21434 vs UN R155: How They Fit TogetherUN R155 is the law, ISO/SAE 21434 is the engineering standard. Learn how CSMS, TARA and testing connect, and what suppliers need to deliver to OEMs.
- ServicesISO/SAE 21434 that survives the audit and the attacker.ISO/SAE 21434 consulting by certified experts: gap analysis, CSMS implementation, TARA, verification and audit preparation for UN R155. With real testing.
