Skip to content
Zyberum Cyber Security Firm
Menu
AutomotiveISO 21434

ISO/SAE 21434 vs UN R155: How They Fit Together

UN R155 is the law, ISO/SAE 21434 is the engineering standard. Learn how CSMS, TARA and testing connect, and what suppliers need to deliver to OEMs.

Zyberum Security Team · Published · 7 min read

Anyone working on vehicle electronics hears two names constantly: UN Regulation No. 155 and ISO/SAE 21434. They are often used interchangeably, but they play very different roles.

In short: UN R155 is a regulation. It says vehicle manufacturers must manage cybersecurity to obtain type approval. ISO/SAE 21434 is a standard. It describes how to do cybersecurity engineering across the vehicle lifecycle.

UN R155 was adopted by UNECE World Forum WP.29 and applies in the EU, Japan, Korea and other contracting parties. In the EU it is mandatory for all new vehicle types since July 2022 and for all newly registered vehicles since July 2024.

It requires the vehicle manufacturer to:

  1. Operate a certified Cybersecurity Management System (CSMS) covering development, production and post-production.
  2. Identify and assess risks for each vehicle type, including risks from suppliers.
  3. Implement mitigations (Annex 5 lists threats and mitigations).
  4. Test the effectiveness of security measures before approval.
  5. Monitor, detect and respond to attacks on vehicles in the field.

Its sister regulation UN R156 covers the Software Update Management System (SUMS), including over-the-air updates.

ISO/SAE 21434: the engineering playbook

ISO/SAE 21434:2021 “Road vehicles: Cybersecurity engineering” defines processes and work products, for example:

  • Organisational cybersecurity management: policy, roles, competence, audits
  • Project-dependent management: cybersecurity plan and cybersecurity case
  • Concept phase: item definition, TARA, cybersecurity goals
  • Product development: requirements, architecture, integration and verification
  • Validation: including penetration testing of the item
  • Post-development: production, operations, vulnerability management, decommissioning

How they map to each other

UN R155 asks for… ISO/SAE 21434 provides…
A CSMS Clauses 5–8: organisational and project management, continuous activities
Risk assessment per vehicle type Clause 15: TARA methods
Supplier risk management Clause 7: distributed cybersecurity activities (CIA agreements)
Testing before approval Clauses 10–11: verification and validation, incl. penetration testing
Monitoring and response Clauses 8 and 13: monitoring, vulnerability analysis and management

What suppliers must deliver

Tier-1 and Tier-2 suppliers are not directly regulated by R155, but OEMs pass the obligations down via a Cybersecurity Interface Agreement (CIA). Typical deliverables:

  • TARA for the component and its interfaces
  • Cybersecurity requirements and their verification evidence
  • Penetration test and fuzzing reports with findings and remediation status
  • Vulnerability monitoring and incident response commitments for the component’s lifetime

Where testing fits

Testing is the step where many programmes struggle: it happens late, under time pressure, and is hard to repeat for every software release. Two practices help:

  1. Automate what repeats. Fuzzing and protocol security tests of UDS, DoIP, SOME/IP and CAN can run on every release. This is what our AutoST suite is built for.
  2. Go deep where it matters. Manual penetration testing of hardware, firmware and critical functions finds the issues automation cannot. See our automotive security services.

Need help with a TARA, a CSMS audit or a pentest before SOP? Talk to our automotive team.

FAQ

Frequently asked questions

Is ISO/SAE 21434 mandatory?

Not by itself. UN R155 is mandatory for type approval in the EU and other UNECE markets, and ISO/SAE 21434 is the most widely accepted way to demonstrate that its requirements are met. In practice, OEMs require it from their suppliers contractually.

What is a TARA?

A Threat Analysis and Risk Assessment is the core method of ISO/SAE 21434. It identifies assets, derives damage and threat scenarios, rates attack feasibility and determines risk values, which then drive cybersecurity goals and requirements.

Does UN R155 require penetration testing?

UN R155 requires manufacturers to test the effectiveness of implemented security measures before type approval. Penetration testing is the established way to do this, and ISO/SAE 21434 explicitly lists it as a validation method.

Call usBook a call

Pick a time that suits you

Open in a new tab