Gap analysis
Your processes against the clauses of ISO/SAE 21434, with a prioritised roadmap and realistic timelines.
ISO/SAE 21434 & TARA
A cybersecurity management system on paper does not stop anyone. We build your CSMS and your TARA from the attacker’s side: with people who pentest ECUs every week and hold the SAE and TÜV SÜD Automotive Cybersecurity Certification.
In short
ISO/SAE 21434 is the international standard for cybersecurity engineering of road vehicles. It requires a Cybersecurity Management System (CSMS), a Threat Analysis and Risk Assessment (TARA) for each item, cybersecurity requirements, verification and validation, and monitoring after production. It is the common way to meet UN Regulation No. 155 for type approval. Zyberum offers gap analyses, CSMS implementation, TARA, test planning and audit preparation, combined with hands-on ECU penetration testing.
What we do
Your processes against the clauses of ISO/SAE 21434, with a prioritised roadmap and realistic timelines.
Policies, roles, competence management and continuous improvement that fit how your teams actually work.
Assets, damage and threat scenarios, attack feasibility, risk values and treatment decisions, based on how ECUs are really attacked.
Cybersecurity activities placed into your existing development lifecycle, from concept to production.
Test strategy, test cases derived from the TARA, penetration testing and fuzzing as validation evidence.
Cybersecurity case, assessment report and traceability from requirement to evidence, reviewed before the auditor does.
Approach
We assess your processes, tools and documents against the standard and establish the baseline.
Compliant processes tailored to your organisation, with templates that connect to your PLM and ALM tools.
A real TARA and cybersecurity case on one of your projects, so your team learns by doing.
We review all work products, prepare your team and support you during the audit.
The difference
Attack feasibility ratings are only as good as the experience behind them. We rate them from practice: we know how long it takes to get firmware out of an ECU, and which diagnostic services fall first.
The same team can then test what the TARA predicts, by hand or automated with AutoST, and feed the results back as verification evidence. That closes the loop the standard asks for.
FAQ
A Threat Analysis and Risk Assessment is the core method of ISO/SAE 21434. It identifies assets, derives damage and threat scenarios, rates attack feasibility and impact, and determines risk values that drive cybersecurity goals and requirements.
UN R155 obliges the vehicle manufacturer, who passes the requirements to suppliers by contract through a Cybersecurity Interface Agreement. In practice, Tier-1 and Tier-2 suppliers must provide a TARA, requirements and test evidence for their component.
For a supplier starting from an existing quality or safety process, typically six to twelve months to audit readiness, with the first pilot project in parallel.
Yes, a one-day ISO/SAE 21434 compliance course with a hands-on TARA exercise, in-house or remote.
Get started
We look at where you stand, what your customer or the type approval demands, and what to do first.

Your call is withTom ZaubermannFounder & CEO, Zyberum
We reply within one business day.
Your privacy
We use cookies and similar technologies to measure our website and the success of our ads. You decide which ones we may use. You can change your choice at any time via "Cookie settings" in the footer. Privacy policy