Skip to main content

ISO/SAE 21434 (Road Vehicles — Cybersecurity Engineering)

ISO/SAE 21434 (“Road vehicles — Cybersecurity engineering”) is the central cybersecurity standard of the automotive industry. It describes an end-to-end cybersecurity engineering process across the entire vehicle lifecycle — from concept and development through production and operation to decommissioning. The standard was published in August 2021 jointly by ISO and SAE International.

Who does the standard apply to?

ISO/SAE 21434 applies to electrical and electronic (E/E) systems in road vehicles, their components and interfaces. It addresses OEMs as well as the entire supply chain: tier 1 and tier 2 suppliers must demonstrably deliver their contribution to vehicle cybersecurity. Important for understanding the standard: it does not prescribe specific technologies or protection measures, but processes and work products — what is appropriate follows from the risk analysis of the respective system.

The four core elements

Core elementContent
Cybersecurity Management System (CSMS)Organizational anchoring of cybersecurity across all projects: roles, processes, responsibilities
Risk-based approachEvery security measure is derived from a threat analysis and risk assessment (TARA)
Lifecycle coverageCybersecurity activities in every development phase, plus monitoring and incident response in the field
Distributed Cybersecurity ActivitiesClear distribution of responsibility between OEM and suppliers via the Cybersecurity Interface Agreement

TARA: the central method

The methodological core of the standard is the Threat Analysis and Risk Assessment (TARA). It identifies assets worth protecting, derives threat scenarios, rates damage potential (impact level) and attack probability (attack feasibility level), and prioritizes the security measures from this. The TARA starts as early as the concept phase and is maintained across the entire lifecycle: if a new CVE appears in an installed component, it must be assessed whether it changes an original risk decision — for example because an attack path suddenly becomes easier to carry out.

Relationship to UNECE R155

ISO/SAE 21434 is a standard, UNECE R155 is mandatory. The UN regulation requires a demonstrated Cyber Security Management System for type approval — ISO/SAE 21434 is the recognized technical framework with which manufacturers provide this evidence. In the EU, R155 has applied to all new vehicle types since July 2022 and to all newly produced and sold vehicles since July 2024. Without a robust CSMS and without a documented TARA there is no type approval — and thus no market access. This shifts cybersecurity from a technical recommendation to a commercial prerequisite.

ISO/SAE 21434 in practice

In projects, implementation rarely fails due to a lack of understanding of the standard, but due to the scale and maintenance of the evidence. Spreadsheet-based TARAs age quickly, quality varies depending on the author, and with every system change the assessment effectively starts from scratch. Especially tier 1 suppliers, who inherit the OEM’s requirements and must fulfil them for many product variants in parallel, need a consistent, reusable risk analysis — otherwise the compliance evidence becomes a separate feat of strength before every audit instead of a by-product of ongoing work.

Frequently asked questions

Is ISO/SAE 21434 legally mandatory?
The standard itself is not. However, under UNECE R155 a Cyber Security Management System is a prerequisite for type approval, and ISO/SAE 21434 is the recognized technical framework for providing this evidence. In practice, there is no way around the standard for OEMs and their suppliers.
What is the difference between ISO/SAE 21434 and ISO 26262?
ISO 26262 addresses functional safety, i.e. protecting people from malfunctions of the system. ISO/SAE 21434 addresses cybersecurity, i.e. protecting the system from attacks. Both work risk-based: HARA and TARA share the same system scope.
Does ISO/SAE 21434 also apply to suppliers?
Yes. Tier 1 and tier 2 suppliers inherit the cybersecurity requirements of the OEM and must demonstrably deliver their contribution to vehicle cybersecurity. The interface is governed by the Cybersecurity Interface Agreement, which records the responsibilities between OEM and supplier.

Related terms

Reviewed by Dirk Leopold, Executive Vice President Digital Engineering on July 20, 2026