Skip to main content
Automotive & Industrial Cybersecurity

ISO/SAE 21434 and IEC 62443 in Practice

Cybersecurity is no longer optional for connected products: it is a market access requirement. In the automotive sector, UNECE regulation R155 makes a Cybersecurity Management System (CSMS) a condition for type approval. In the industrial environment, IEC 62443 sets the benchmark for plants, controls and critical infrastructure. Both worlds share the same logic: systematically assess threats, demonstrate security across the entire lifecycle and document it in an audit-ready way. Anyone building products with software and interfaces cannot avoid one or both standards.

Two standards, one discipline

Automotive and Industrial Cybersecurity

ISO/SAE 21434

Automotive Cybersecurity Engineering across the entire vehicle lifecycle: from concept and development through to decommissioning.

IEC 62443

Industrial & OT security for industrial controls, automation systems, energy supply and critical infrastructure.
ISO/SAE 21434

What is ISO/SAE 21434?

ISO/SAE 21434 «Road vehicles — Cybersecurity engineering» (published in August 2021) describes a continuous cybersecurity engineering process across the entire vehicle lifecycle: from concept and development through production and operation to decommissioning.

Who does the standard apply to?

It applies to electrical and electronic systems in road vehicles, their components and interfaces. It is binding for OEMs as well as the entire supply chain: Tier-1 and Tier-2 suppliers must demonstrably fulfil their contribution to vehicle cybersecurity.

The four core elements

  • Cybersecurity Management System (CSMS): organisational anchoring across all projects.
  • Risk-based approach: every measure is derived from a Threat Analysis and Risk Assessment (TARA).
  • Lifecycle coverage: cybersecurity activities in every development phase, plus monitoring and incident response in the field.
  • Distributed Cybersecurity Activities: clear distribution of responsibility between OEM and suppliers via the Cybersecurity Interface Agreement.

What does ISO 21434 mean for Tier-1 suppliers?

The Tier-1 inherits the OEM’s requirements and must fulfil them demonstrably, often for many variants in parallel. This is exactly where a consistent, reusable TARA becomes either a bottleneck or a competitive advantage.

TARA

TARA: the central method of ISO 21434

The Threat Analysis and Risk Assessment (TARA) is the heart of ISO 21434. It identifies assets worth protecting, derives threat scenarios, assesses damage potential and attack probability, and prioritises the security measures from these.

In practice, TARA rarely fails at the concept level: it fails at scope and maintenance. Spreadsheet-based TARAs age quickly, quality varies depending on who carries them out, and every change effectively restarts the assessment from scratch.

itemis SECURE makes the TARA model-based: threats, attack paths and measures are anchored to a consistent model. AI Assistants propose threats and attack trees, and changes propagate through the model instead of being manually tracked. According to itemis, agentic automation reduces TARA effort by up to 80 %, with full human-in-the-loop control.

The same TARA methodology also underpins the Cyber Resilience Act: details in the spoke Cyber Resilience Act.

UNECE R155

ISO 21434 and UNECE R155: the regulatory lever

ISO 21434 is a standard; R155 is mandatory. UN Regulation No. 155 requires a demonstrated Cybersecurity Management System for type approval. ISO 21434 is the technical framework manufacturers use to provide this proof.

The deadlines

  • Since July 2022: mandatory for all new vehicle types.
  • Since July 2024: mandatory for all newly produced and sold vehicles, including existing types.
  • From December 2027: CSMS obligation also for motorcycles.

Without a robust CSMS and without documented TARA, there is no type approval, and therefore no market access. This shifts cybersecurity from a technical recommendation to a commercial prerequisite.

IEC 62443

IEC 62443: industrial and OT security

Where ISO 21434 addresses the vehicle, IEC 62443 covers operational technology: industrial controls, automation systems, energy supply and critical infrastructure. The standard series addresses all roles, from component manufacturer through system integrator to the asset owner who operates the plant.

Zones and conduits

The fundamental principle is segmentation. Assets with similar protection needs are grouped into zones; communication between zones runs via controlled conduits. This creates a defensible architecture instead of a flat network, often oriented around the Purdue model of manufacturing levels.

Security Level SL1 to SL4

  • SL1: protection against accidental or unintentional misuse.
  • SL2: protection against intentional attacks with simple means.
  • SL3: protection against organised attackers with moderate resources.
  • SL4: protection against state-level attackers with high effort.

Important: the security level is not a single value but a vector across seven foundational requirements. Each zone and each conduit receives its own protection level, derived from the risk, not imposed uniformly.

The relevant standard parts

  • 62443-2-1: CSMS requirements for the asset owner.
  • 62443-3-3: system security requirements and security level.
  • 62443-4-1: secure product development lifecycle.
  • 62443-4-2: technical requirements for individual components.
Standards compared

ISO 21434 or IEC 62443: which standard applies when?

The short answer: ISO 21434 for road vehicles and their components, IEC 62443 for industrial automation and OT. The longer answer is more interesting, because many manufacturers need both today.

A supplier building control units for vehicles and for industrial plants faces both standards simultaneously. The good news: the methodological basis is related. Both work risk-based, both require security across the lifecycle, both rely on structured threat analysis.

And both feed into the Cyber Resilience Act, which sits above both as a horizontal EU regulation. Whoever sets up their TARA methodology cleanly once serves ISO 21434, IEC 62443 and CRA from one model, instead of maintaining three separate compliance worlds. For products that simultaneously require ISO 26262 and IEC 61508, HARA and TARA share the same system boundary: safety protects the environment from the system, security protects the system from the environment.

itemis SECURE

Implementation with itemis SECURE: Agentic Cybersecurity

itemis SECURE is the model-based platform for both standards. Instead of fragmented spreadsheets, a living security model is created: TARA, risk assessment, measure tracking and reporting in one tool, with AI support for threat intelligence and attack trees, and with documentation that passes an audit.

The lever is reuse and maintenance. A TARA modelled once can be scaled across variants, new vulnerabilities flow into the model, and the compliance evidence is a by-product of the work, not a separate effort before the audit.

Agentic on a deterministic model

The AI support is not a bolted-on add-on. The agentic capabilities sit on a deterministic model layer, so the AI does not work in a vacuum but uses the complete TARA context. Via the Cybersecurity Lifecycle Integration, the system connects requirements, architecture components and software vulnerabilities with end-to-end traceability directly in the security model. The heavy lifting runs automated, the expert retains control, and every conclusion is grounded in real engineering data.

What the AI concretely handles

  • Conversational TARA: create, edit and refine risk analyses via a natural language interface.
  • Embedded TARA expert: an integrated assistant contributes domain knowledge and proactively suggests complex threat scenarios.
  • Full context awareness: the engine knows requirements, SysML models and previous TARAs. All suggestions are anchored to the concrete architecture.
  • Deterministic governance: every AI suggestion is checked against a model-based rule set and adheres to rule sets and industry standards.
  • Human-in-the-loop: all suggestions are versioned and show where and when the AI made a proposal, verifiable, adjustable, rejectable.

Typical use cases

  • TARA review and completeness check: comparison of the model against known threat patterns uncovers blind spots, missing assets and implausible attack paths.
  • Agentic triage and vulnerability sync: assisted triage of SBOM vulnerabilities with automatically proposed TARA updates and extended attack trees based on new CVEs.
  • Automatic item definition: accelerated generation from existing artefacts such as requirements, specifications and architecture diagrams.
  • Interview mode: the agent asks targeted questions about the system and populates the model automatically, instead of sending the user through menus.

Architecture and business value

PillarFunctionBenefit
Lifecycle ManagementEnd-to-end security traceability across development and product lifecycleEliminates virtually all manual documentation work for audits
Model-Based GovernanceIndustry-specific rule sets, plausibility and consistency checksAI suggestions comply with guidelines and regulatory requirements
Agentic AutomationContext-aware, automated generation of TARA elements with human-in-the-loopUp to 80 % less TARA time
Live Vulnerability SyncContinuous triage of SBOM components and CVEsLiving documents for ISO/SAE 21434, IEC 62443 and CRA

According to itemis, agentic automation reduces TARA effort by up to 80 %, with full human-in-the-loop control. This way even small teams maintain a living security posture and serve ISO/SAE 21434, IEC 62443 and CRA from one model.

itemis SECURE is used by cybersecurity teams in automotive and industry, including ZF, AVL and Sygic.

Frequently asked questions

FAQ on ISO 21434 and IEC 62443

Is ISO/SAE 21434 mandatory?
The standard itself is not legally mandatory. However, via UNECE R155, a Cybersecurity Management System is a prerequisite for type approval. ISO 21434 is the recognised technical framework for this proof. In practice, there is no way around it for OEMs and their suppliers.
What is the difference between ISO 21434 and IEC 62443?
ISO 21434 addresses cybersecurity engineering for road vehicles; IEC 62443 governs the security of industrial automation systems and OT. Both work risk-based and lifecycle-oriented. Manufacturers active in both domains can use the same TARA methodology for both sets of evidence.
What is a TARA?
The Threat Analysis and Risk Assessment identifies assets worth protecting, derives threat scenarios, assesses damage potential and attack probability, and prioritises security measures from these. It is the central method of ISO 21434 and the basis of every cybersecurity proof.
Which security levels does IEC 62443 define?
Four levels: SL1 (protection against unintentional misuse) to SL4 (protection against state-funded attackers). The security level is a vector across seven foundational requirements and is derived per zone and conduit from the risk.
Does ISO 21434 also help with the Cyber Resilience Act?
Yes. Like ISO 21434 and IEC 62443, the CRA requires a risk-based threat analysis and lifecycle security. A cleanly set-up, model-based TARA serves all three regulatory frameworks from one model.
Our Experts
Dirk Leopold

Executive Vice President Digital Engineering · itemis AG

Dirk Leopold bridges complex engineering requirements and cybersecurity standards in the automotive and IoT domains. As a driving force behind itemis SECURE, he has deep expertise in Threat Analysis and Risk Assessment (TARA) and “Security by Design” methodologies. As a speaker, he focuses on how standards like ISO/SAE 21434 and the Cyber Resilience Act (CRA) impact the future of connected products. He is co-founder and president of CRAIG, an online community supporting the introduction of the CRA across Europe.
Jens Bühl

Product Owner · itemis AG

Jens Bühl is Product Owner at itemis and has specialised in cyber security engineering and model-based threat and risk analyses since 2019. He is actively involved in the standardisation of the openXSAM exchange format within the Automotive Security Research Group (ASRG). His focus is on the automation of security processes and the protection of complex cyber-physical systems in accordance with ISO/SAE 21434 and IEC 62443.
Dr. Stephan Eberle is CTO/CIO of itemis AG, driving the company’s transformation into a product-driven, AI-enabled organisation. With more than 25 years of experience at the intersection of software innovation and engineering, he focuses on auditable, deterministic AI for regulated industries such as automotive, healthcare, and defence. He led itemis to ISO 27001 and TISAX certification in 2025, and to ISO 9001 certification in 2026. Stephan holds a PhD in Engineering from the University of Stuttgart.
Get started

Book an itemis SECURE demo

Schedule a call with Dirk Leopold and Jens Bühl.

Expertise

Insights on Automotive & Industrial Cybersecurity

Security by Design in the Automotive Development Process
Blog Cyber security

Security by Design in the Automotive Development Process

In the automotive domain, security is becoming more and more important – especially for the new generations of connected, (semi-)autonomous vehicles. Learn how to develop a secure system design and which additional security challenges may arise.

Read Article
Dirk Leopold Dirk Leopold 9 min read
Cohesion Without Disruption – Whitepaper
Whitepapers Functional safety

Cohesion Without Disruption

How leading OEMs and Tier-1 suppliers unite Functional Safety and Cyber Security enterprise-wide — without disrupting proven engineering environments.

Download Whitepaper