ISO 21434 position

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

ISO/SAE 21434 Position

What it does well

  • Vehicle-product cybersecurity previously gap; ISO 21434 fills it.
  • TARA methodology structured threat-analysis approach.
  • Lifecycle integration from concept through decommissioning.
  • UN R155 implementation path — recognized as primary supporting standard.
  • OEM + supplier alignment via lifecycle phases.

What it does poorly

  • Heavy implementation effort. Comprehensive lifecycle requirements.
  • TARA depth varies in practice.
  • AI / ML feature treatment limited in 2021 publication; updates likely.
  • Software-defined vehicle dynamics outpacing standard cycle.
  • Connected services boundary with vehicle product unclear in places.

Evidence

  • Widely adopted across automotive industry.
  • UN R155 + ISO 21434 combined implementation standard practice.
  • ASPICE + ISO 21434 + TISAX combined for many suppliers.

Personal calibration

  • For automotive client work: ISO 21434 vocabulary load-bearing alongside TISAX.
  • For AI features in vehicles: ISO 21434 + AI Act + UN R155 co-apply.

See also