ISO 21434

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

ISO/SAE 21434 Cluster

Map of ISO/SAE 21434:2021 — Road vehicles cybersecurity engineering. Joint ISO + SAE standard. Pairs with UN R155 (vehicle CSMS regulation) and TISAX (supplier-side information security). Reference cluster for vehicle product cybersecurity work.

Anchors

Provenance

  • SAE J3061 (2016) — predecessor cybersecurity guidebook.
  • ISO/SAE 21434 — joint development. Published August 2021.

What ISO 21434 is

Vehicle cybersecurity engineering standard for the entire automotive product lifecycle. Establishes:

  • CSMS (Cybersecurity Management System) requirements at organizational level.
  • Cybersecurity engineering throughout vehicle lifecycle.
  • TARA (Threat Analysis and Risk Assessment) methodology.
  • Cybersecurity considerations for concept, development, production, operation, decommissioning phases.

Complementary to organization-side standards (TISAX, ISO 27001) and to vehicle-type-approval regulation (UN R155).

Scope

Applies to:

  • Road vehicle E/E systems (electrical / electronic).
  • Components and interfaces (with vehicle and external).
  • Product lifecycle: concept → development → production → operation → decommissioning.

OEMs and tier-N suppliers.

Key concepts

CSMS (Cybersecurity Management System)

Organizational management system for cybersecurity engineering. Includes:

  • Cybersecurity policies.
  • Roles and responsibilities.
  • Continuous cybersecurity activities.
  • Risk management.
  • Audit and assessment.

TARA (Threat Analysis and Risk Assessment)

Methodology for identifying threats, attack paths, impact, risk. Inputs to cybersecurity goals and requirements.

Cybersecurity engineering phases

  • Concept phase: TARA, cybersecurity goals.
  • Product development phase: requirements, design, integration, verification, validation.
  • Production phase: secure manufacturing.
  • Operation and maintenance phase: incident response, security updates.
  • Decommissioning phase: secure decommissioning.

Detail in ISO 21434 Lifecycle and TARA.

ISO 21434 vs UN R155 vs TISAX

  • ISO 21434: vehicle product cybersecurity engineering. Standard.
  • UN R155: vehicle type approval cybersecurity. Regulation. ISO 21434 is the implementation standard supporting R155 compliance.
  • TISAX: organization-side information security. Different scope.

All three commonly present for automotive supplier landscape.

Why this matters

  • Mandatory for vehicle manufacturers under UN R155.
  • Tier-1/2 suppliers contributing E/E systems must implement.
  • AI features in vehicles (ADAS, autonomous driving) within scope.
  • TISAX — supplier organization-side InfoSec.
  • UN R155 / R156 — vehicle type approval.
  • ASPICE — automotive software process.

See also

ISO 21434 Cluster (pillars MOC) · position · anchors · TISAX Cluster · UN R155 R156 Cluster