What is ISO/SAE 21434?
ISO/SAE 21434:2021, developed jointly by ISO and SAE International, is the road vehicle cybersecurity engineering standard. It defines process requirements for managing cybersecurity risk of a vehicle's electrical and electronic (E/E) systems — from the organizational level (policy, culture, audit) through development projects to continual activities: vulnerability monitoring, incident response and software updates, until end of support.
The heart of the standard is the TARA (Threat Analysis and Risk Assessment, Clause 15) — a modular threat analysis methodology: asset identification, threat scenarios, impact ratings across safety-financial-operational-privacy categories, attack paths, attack feasibility and risk treatment decisions. TARA results translate into cybersecurity goals and a cybersecurity concept, and the whole argument is tied together by the cybersecurity case — structured evidence that product risks are not unreasonable.
Who does it apply to?
The standard applies to the entire automotive chain: vehicle manufacturers (OEMs), Tier 1 and Tier 2 suppliers of E/E components (ECUs, telematics units, harnesses with electronics, sensors), vehicle software vendors and R&D engineering centres. The formal driver is UN R155: since July 2024 every new vehicle registered in the EU requires type approval with a certified manufacturer CSMS (Cybersecurity Management System), and OEMs cascade the requirements to suppliers in nominations and contracts.
In practice, an E/E component supplier receives in the contract: a requirement of ISO/SAE 21434 process conformance, a CIAD (Cybersecurity Interface Agreement for Development) splitting responsibilities, and the duty to deliver evidence (TARA, cybersecurity case, verification reports) for the customer's CSMS assessment. For Polish automotive companies — software centres and electronics manufacturers — these requirements are today a standard element of OEM nominations.
Structure of the standard
The requirements are organized in Clauses 5-15, each with objectives, requirements ([RQ]), recommendations ([RC]) and work products ([WP]):
- Clause 5 — organizational management: policy, culture, information sharing, management systems, tools, information security, audit
- Clause 6 — project management: cybersecurity plan, tailoring, reuse, out-of-context and off-the-shelf components, cybersecurity case, assessment, release
- Clause 7 — distributed activities: supplier capability, requests for quotation, CIAD agreements
- Clause 8 — continual activities: monitoring, event triage, vulnerability analysis and management
- Clauses 9-11 — concept (item definition, TARA, goals, concept), product development, vehicle-level validation
- Clauses 12-14 — production, operations and maintenance (incidents, OTA updates), end of support and decommissioning
- Clause 15 — TARA methods: assets, threat scenarios, S-F-O-P impacts, attack paths, feasibility, risk value, treatment
ISO/SAE 21434 versus TISAX and UN R155/R156
ISO/SAE 21434 and TISAX are complementary, not interchangeable: TISAX (VDA-ISA) assesses the information security of the supplier's ORGANIZATION — protection of OEM data, prototypes and offices — while ISO/SAE 21434 covers PRODUCT cybersecurity: the vehicle and its E/E components across the lifecycle. An automotive supplier typically needs both: a TISAX label as a contractual condition for information exchange, and ISO/SAE 21434 processes for component engineering.
UN R155 requires the manufacturer to hold a certified CSMS — ISO/SAE 21434 is the recognized implementation path. For software updates (including OTA), UN R156 applies in parallel, requiring a SUMS (Software Update Management System), detailed by ISO 24089. Conformity evaluations and process certifications are offered by bodies such as TÜV NORD, TÜV Rheinland, TÜV SÜD, DEKRA and SGS.
