Skip to content
Zyberum Cyber Security Firm
Menu

ISO/SAE 21434 & TARA

ISO/SAE 21434 that survives the audit and the attacker.

A cybersecurity management system on paper does not stop anyone. We build your CSMS and your TARA from the attacker’s side: with people who pentest ECUs every week and hold the SAE and TÜV SÜD Automotive Cybersecurity Certification.

  • SAE / TÜV SÜD certified, Level 1 & 2
  • TARA from real attack experience
  • UN R155 and R156

In short

ISO/SAE 21434 is the international standard for cybersecurity engineering of road vehicles. It requires a Cybersecurity Management System (CSMS), a Threat Analysis and Risk Assessment (TARA) for each item, cybersecurity requirements, verification and validation, and monitoring after production. It is the common way to meet UN Regulation No. 155 for type approval. Zyberum offers gap analyses, CSMS implementation, TARA, test planning and audit preparation, combined with hands-on ECU penetration testing.

What we do

From gap analysis to audit

Gap analysis

Your processes against the clauses of ISO/SAE 21434, with a prioritised roadmap and realistic timelines.

CSMS implementation

Policies, roles, competence management and continuous improvement that fit how your teams actually work.

TARA

Assets, damage and threat scenarios, attack feasibility, risk values and treatment decisions, based on how ECUs are really attacked.

V-model integration

Cybersecurity activities placed into your existing development lifecycle, from concept to production.

Verification & validation

Test strategy, test cases derived from the TARA, penetration testing and fuzzing as validation evidence.

Audit preparation

Cybersecurity case, assessment report and traceability from requirement to evidence, reviewed before the auditor does.

Approach

How a project runs

  1. 01

    Current state

    We assess your processes, tools and documents against the standard and establish the baseline.

  2. 02

    Process design

    Compliant processes tailored to your organisation, with templates that connect to your PLM and ALM tools.

  3. 03

    Pilot with coaching

    A real TARA and cybersecurity case on one of your projects, so your team learns by doing.

  4. 04

    Audit support

    We review all work products, prepare your team and support you during the audit.

The difference

A TARA written by people who attack ECUs

Attack feasibility ratings are only as good as the experience behind them. We rate them from practice: we know how long it takes to get firmware out of an ECU, and which diagnostic services fall first.

The same team can then test what the TARA predicts, by hand or automated with AutoST, and feed the results back as verification evidence. That closes the loop the standard asks for.

FAQ

ISO/SAE 21434 FAQ

What is a TARA?

A Threat Analysis and Risk Assessment is the core method of ISO/SAE 21434. It identifies assets, derives damage and threat scenarios, rates attack feasibility and impact, and determines risk values that drive cybersecurity goals and requirements.

Do suppliers need ISO/SAE 21434?

UN R155 obliges the vehicle manufacturer, who passes the requirements to suppliers by contract through a Cybersecurity Interface Agreement. In practice, Tier-1 and Tier-2 suppliers must provide a TARA, requirements and test evidence for their component.

How long does it take to implement a CSMS?

For a supplier starting from an existing quality or safety process, typically six to twelve months to audit readiness, with the first pilot project in parallel.

Is there a course for our team?

Yes, a one-day ISO/SAE 21434 compliance course with a hands-on TARA exercise, in-house or remote.

Get started

One hour on your ISO/SAE 21434 roadmap, free

We look at where you stand, what your customer or the type approval demands, and what to do first.

  • Your gaps against the standard, in plain language
  • What your OEM will ask for next
  • A realistic plan and effort estimate
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usFree ISO 21434 consultation

Pick a time that suits you

Open in a new tab