Skip to main content

CAL (Cybersecurity Assurance Level)

The CAL (Cybersecurity Assurance Level) is the classification scheme of ISO/SAE 21434 with four levels from CAL 1 to CAL 4. It does not answer the question of which security measures an item needs — that is what the risk analysis does — but with what rigour the cybersecurity activities are carried out and demonstrated: the higher the CAL, the higher the requirements for depth of verification, methodology and independence, for example.

Determining the CAL

The CAL is determined in the concept phase, typically per cybersecurity goal. Two properties of the underlying threat scenario feed into it: the impact of the associated damage scenario and the attack vector, i.e. the access path through which the attack is possible. A high possible damage combined with an easily reachable vector — for example via the network instead of only with physical access — leads to a high CAL. Unlike the attack feasibility level, which can change with every new vulnerability, the CAL remains largely stable throughout development: the attack vector is a property of the architecture, not of the current threat landscape.

Classification: Informative, but Practically Relevant

The CAL scheme is part of the informative Annex E of the standard and is therefore formally a recommendation. It becomes practically relevant through the supply chain: OEMs increasingly specify the CAL in requirement specifications and cybersecurity interface agreements, and suppliers have to demonstrate the required process rigour. The CAL thus becomes the common language for how much assurance effort a development artefact justifies.

Parallel to the ASIL

The idea of a graded level clearly comes from the ASIL of ISO 26262. The difference lies in its character: the ASIL is normative and directly governs the technical and methodological requirements for the implementation; the CAL governs the rigour of the assurance, i.e. how thoroughly activities such as review, testing and analysis are to be carried out. How CAL, TARA and the other building blocks of the standard interact is shown on the cyber security spoke page.

Related terms

Frequently asked questions

Is the CAL mandatory?
No. The CAL scheme is part of the informative Annex E of ISO/SAE 21434 and is therefore a recommendation, not a normative must. In practice it becomes relevant nonetheless, because OEMs increasingly specify the CAL in requirement specifications and cybersecurity interface agreements, and suppliers have to demonstrate the required process rigour.
How is a CAL determined?
In the concept phase, from two properties of the threat scenario: the impact of the associated damage scenario and the attack vector, i.e. the access path of the attack. The more severe the possible damage and the more easily reachable the vector — for example via the network instead of only physically — the higher the CAL.
What is the difference between CAL and ASIL?
Both grade requirements for development, but differently: the ASIL of ISO 26262 is normative and directly governs the requirements for the implementation. The CAL is informative and governs the rigour of the assurance activities, such as depth of testing and independence of the reviewers. The ASIL is also derived from the risk of a malfunction, the CAL from damage severity and attack vector.
Reviewed by Jens Bühl, Product Owner on August 21, 2026