Security standard

ISO 21434

ISO/SAE 21434 is the road vehicle cybersecurity engineering standard — covering the full lifecycle of electrical and electronic (E/E) systems, from concept and TARA through development and production to OTA updates and decommissioning. It underpins the CSMS required for vehicle type approval under UN R155.

Start assessmentRead about the standard
0
controls in Guardiso
0
free-test questions
PL · EN
two languages

What is ISO/SAE 21434?

ISO/SAE 21434:2021, developed jointly by ISO and SAE International, is the road vehicle cybersecurity engineering standard. It defines process requirements for managing cybersecurity risk of a vehicle's electrical and electronic (E/E) systems — from the organizational level (policy, culture, audit) through development projects to continual activities: vulnerability monitoring, incident response and software updates, until end of support.

The heart of the standard is the TARA (Threat Analysis and Risk Assessment, Clause 15) — a modular threat analysis methodology: asset identification, threat scenarios, impact ratings across safety-financial-operational-privacy categories, attack paths, attack feasibility and risk treatment decisions. TARA results translate into cybersecurity goals and a cybersecurity concept, and the whole argument is tied together by the cybersecurity case — structured evidence that product risks are not unreasonable.

Who does it apply to?

The standard applies to the entire automotive chain: vehicle manufacturers (OEMs), Tier 1 and Tier 2 suppliers of E/E components (ECUs, telematics units, harnesses with electronics, sensors), vehicle software vendors and R&D engineering centres. The formal driver is UN R155: since July 2024 every new vehicle registered in the EU requires type approval with a certified manufacturer CSMS (Cybersecurity Management System), and OEMs cascade the requirements to suppliers in nominations and contracts.

In practice, an E/E component supplier receives in the contract: a requirement of ISO/SAE 21434 process conformance, a CIAD (Cybersecurity Interface Agreement for Development) splitting responsibilities, and the duty to deliver evidence (TARA, cybersecurity case, verification reports) for the customer's CSMS assessment. For Polish automotive companies — software centres and electronics manufacturers — these requirements are today a standard element of OEM nominations.

Structure of the standard

The requirements are organized in Clauses 5-15, each with objectives, requirements ([RQ]), recommendations ([RC]) and work products ([WP]):

  • Clause 5 — organizational management: policy, culture, information sharing, management systems, tools, information security, audit
  • Clause 6 — project management: cybersecurity plan, tailoring, reuse, out-of-context and off-the-shelf components, cybersecurity case, assessment, release
  • Clause 7 — distributed activities: supplier capability, requests for quotation, CIAD agreements
  • Clause 8 — continual activities: monitoring, event triage, vulnerability analysis and management
  • Clauses 9-11 — concept (item definition, TARA, goals, concept), product development, vehicle-level validation
  • Clauses 12-14 — production, operations and maintenance (incidents, OTA updates), end of support and decommissioning
  • Clause 15 — TARA methods: assets, threat scenarios, S-F-O-P impacts, attack paths, feasibility, risk value, treatment

ISO/SAE 21434 versus TISAX and UN R155/R156

ISO/SAE 21434 and TISAX are complementary, not interchangeable: TISAX (VDA-ISA) assesses the information security of the supplier's ORGANIZATION — protection of OEM data, prototypes and offices — while ISO/SAE 21434 covers PRODUCT cybersecurity: the vehicle and its E/E components across the lifecycle. An automotive supplier typically needs both: a TISAX label as a contractual condition for information exchange, and ISO/SAE 21434 processes for component engineering.

UN R155 requires the manufacturer to hold a certified CSMS — ISO/SAE 21434 is the recognized implementation path. For software updates (including OTA), UN R156 applies in parallel, requiring a SUMS (Software Update Management System), detailed by ISO 24089. Conformity evaluations and process certifications are offered by bodies such as TÜV NORD, TÜV Rheinland, TÜV SÜD, DEKRA and SGS.

Official sources

Other standards to assess

ISO 27001GlobalGDPREUNIS 2 (Polish KSC act)EU · PLSOC 2GlobalDORAEUTISAXAutomotiveISO 9001GlobalISO 42001 (AI)GlobalKRIPLPCI DSSGlobalNIST CSFUSANIST 800-53USAHIPAAUSACMMC 2.0USACyber EssentialsUKSOX ITGCUSABIO2NLEU AI ActEUISO 27701GlobalISO 22301GlobalISO 14001GlobalISO 45001GlobalISO 13485MedicalIEC 62304MedicalMDREU · MedicalISO 14971MedicalDCB0129UKMiCAEUIEC 62443Global
Browse all 30 standards