CAL (Cybersecurity Assurance Level)
The CAL (Cybersecurity Assurance Level) is the classification scheme of ISO/SAE 21434 with four levels from CAL 1 to CAL 4. It does not answer the question of which security measures an item needs — that is what the risk analysis does — but with what rigour the cybersecurity activities are carried out and demonstrated: the higher the CAL, the higher the requirements for depth of verification, methodology and independence, for example.
Determining the CAL
The CAL is determined in the concept phase, typically per cybersecurity goal. Two properties of the underlying threat scenario feed into it: the impact of the associated damage scenario and the attack vector, i.e. the access path through which the attack is possible. A high possible damage combined with an easily reachable vector — for example via the network instead of only with physical access — leads to a high CAL. Unlike the attack feasibility level, which can change with every new vulnerability, the CAL remains largely stable throughout development: the attack vector is a property of the architecture, not of the current threat landscape.
Classification: Informative, but Practically Relevant
The CAL scheme is part of the informative Annex E of the standard and is therefore formally a recommendation. It becomes practically relevant through the supply chain: OEMs increasingly specify the CAL in requirement specifications and cybersecurity interface agreements, and suppliers have to demonstrate the required process rigour. The CAL thus becomes the common language for how much assurance effort a development artefact justifies.
Parallel to the ASIL
The idea of a graded level clearly comes from the ASIL of ISO 26262. The difference lies in its character: the ASIL is normative and directly governs the technical and methodological requirements for the implementation; the CAL governs the rigour of the assurance, i.e. how thoroughly activities such as review, testing and analysis are to be carried out. How CAL, TARA and the other building blocks of the standard interact is shown on the cyber security spoke page.


