ISO/SAE 21434 (Road Vehicles — Cybersecurity Engineering)
ISO/SAE 21434 (“Road vehicles — Cybersecurity engineering”) is the central cybersecurity standard of the automotive industry. It describes an end-to-end cybersecurity engineering process across the entire vehicle lifecycle — from concept and development through production and operation to decommissioning. The standard was published in August 2021 jointly by ISO and SAE International.
Who does the standard apply to?
ISO/SAE 21434 applies to electrical and electronic (E/E) systems in road vehicles, their components and interfaces. It addresses OEMs as well as the entire supply chain: tier 1 and tier 2 suppliers must demonstrably deliver their contribution to vehicle cybersecurity. Important for understanding the standard: it does not prescribe specific technologies or protection measures, but processes and work products — what is appropriate follows from the risk analysis of the respective system.
The four core elements
| Core element | Content |
|---|---|
| Cybersecurity Management System (CSMS) | Organizational anchoring of cybersecurity across all projects: roles, processes, responsibilities |
| Risk-based approach | Every security measure is derived from a threat analysis and risk assessment (TARA) |
| Lifecycle coverage | Cybersecurity activities in every development phase, plus monitoring and incident response in the field |
| Distributed Cybersecurity Activities | Clear distribution of responsibility between OEM and suppliers via the Cybersecurity Interface Agreement |
TARA: the central method
The methodological core of the standard is the Threat Analysis and Risk Assessment (TARA). It identifies assets worth protecting, derives threat scenarios, rates damage potential (impact level) and attack probability (attack feasibility level), and prioritizes the security measures from this. The TARA starts as early as the concept phase and is maintained across the entire lifecycle: if a new CVE appears in an installed component, it must be assessed whether it changes an original risk decision — for example because an attack path suddenly becomes easier to carry out.
Relationship to UNECE R155
ISO/SAE 21434 is a standard, UNECE R155 is mandatory. The UN regulation requires a demonstrated Cyber Security Management System for type approval — ISO/SAE 21434 is the recognized technical framework with which manufacturers provide this evidence. In the EU, R155 has applied to all new vehicle types since July 2022 and to all newly produced and sold vehicles since July 2024. Without a robust CSMS and without a documented TARA there is no type approval — and thus no market access. This shifts cybersecurity from a technical recommendation to a commercial prerequisite.
ISO/SAE 21434 in practice
In projects, implementation rarely fails due to a lack of understanding of the standard, but due to the scale and maintenance of the evidence. Spreadsheet-based TARAs age quickly, quality varies depending on the author, and with every system change the assessment effectively starts from scratch. Especially tier 1 suppliers, who inherit the OEM’s requirements and must fulfil them for many product variants in parallel, need a consistent, reusable risk analysis — otherwise the compliance evidence becomes a separate feat of strength before every audit instead of a by-product of ongoing work.


