Skip to content
AutoST by Zyberum GmbH
Menu
GlossaryISO 21434

ISO/SAE 21434

ISO/SAE 21434:2021 is the standard for cybersecurity engineering of road vehicles: processes, TARA, concept, development, validation. Structure and testing clauses.

Updated This page as Markdown

In short

ISO/SAE 21434:2021, "Road vehicles, Cybersecurity engineering", is the international standard that defines how cybersecurity is managed and engineered over the lifecycle of a vehicle E/E system: organisational and project management (clauses 5 to 7), continual activities such as monitoring and vulnerability analysis (clause 8), concept with TARA (clause 9 and 15), product development and verification (clause 10), validation (clause 11), production, operations and decommissioning (clauses 12 to 14). It is the usual way to implement the CSMS that UN R155 requires.

What is ISO/SAE 21434?

ISO/SAE 21434 is the standard that defines cybersecurity engineering for road vehicles. Published in August 2021 jointly by ISO and SAE International, it covers electrical and electronic systems of series-production vehicles, their components and interfaces, from the first concept to decommissioning. It replaces the older SAE J3061 guidance and is the technical backbone of UN Regulation No. 155, which requires a certified cybersecurity management system (CSMS) for vehicle type approval.

The standard sets out what has to be done and which work products have to exist. It does not prescribe specific technical controls, algorithms or test cases; those come from the risk assessment of the item in question.

Where is it defined?

The standard is structured in clauses. Clause 5 covers organisational cybersecurity management (policy, culture, competence, tooling), clause 6 project-dependent management (the cybersecurity plan, the cybersecurity case, the assessment in 6.4.9), clause 7 distributed activities between customer and supplier (the cybersecurity interface agreement). Clause 8 defines the continual activities: monitoring (8.3), event evaluation (8.4), vulnerability analysis (8.5) and vulnerability management (8.6). Clause 9 is the concept phase with the item definition, the cybersecurity goals and the cybersecurity concept; clause 10 the product development with specification, integration and verification (10.4.2); clause 11 the cybersecurity validation at vehicle level; clauses 12 to 14 production, operations and maintenance, and end of support. Clause 15 holds the TARA methods, and the informative Annex E describes the Cybersecurity Assurance Level (CAL). Requirements are tagged [RQ-xx-yy], recommendations [RC-xx-yy], permissions [PM-xx-yy], and the work products [WP-xx-yy].

What it means in practice

For a supplier, 21434 arrives as a customer requirement: a cybersecurity interface agreement that says which activities the supplier owns, a TARA or a slice of one, cybersecurity requirements for the component, and the duty to deliver verification and validation reports. For a test team, it arrives as a demand for evidence: clause 10.4.2 asks for verification that the implementation meets the cybersecurity specification, and [RC-10-12] recommends fuzz testing and vulnerability scanning so that unidentified weaknesses are minimised; clause 11 asks for validation of the goals, naming penetration testing in [RQ-11-01].

What turns a test into evidence is traceability. In audit support we did for a Tier-1, the assessor did not ask whether fuzzing had been done; the question was which requirement a given test verified, on which software version it ran, and where the finding went. Tests without that chain did not count.

How AutoST tests it

AutoST covers the testing side of clauses 10.4.2, 11 and 8.5 for the diagnostic and bus attack surface: UDS enumeration, SecurityAccess checks, UDS and CAN fuzzing with crash detection, DoIP, SOME/IP and Android IVI checks, repeatable on every build through the REST API and the Bamboo plugin. Every finding carries a severity and a fix, the Fix Plan links tasks to your requirement or ticket, scan history and risk acceptance persist across re-tests, and reports come as PDF and SARIF. The TARA, the cybersecurity case and the assessment are not tool output; Zyberum supports those as consulting.

Common misunderstandings

There is no such thing as an “ISO/SAE 21434 certified ECU”. The standard describes processes, and its assessment (6.4.9) judges a project’s cybersecurity case, while the regulatory certificate under UN R155 goes to the manufacturer’s CSMS. A tool, a component or a company can work in accordance with the standard, but the standard does not certify products.

FAQ

Frequently asked questions

Is ISO/SAE 21434 mandatory?

Not as a law. UN R155 is the binding regulation, and it requires a certified CSMS without naming a standard. ISO/SAE 21434 is the standard the industry and the approval authorities use to show that the CSMS and the engineering behind a vehicle type meet R155, so in practice OEMs require it from their suppliers.

Where does the standard ask for security testing?

Clause 10.4.2 (integration and verification) with [RQ-10-09] and the recommendation [RC-10-12] for fuzz testing and vulnerability scanning; clause 11 (cybersecurity validation) with [RQ-11-01], which names penetration testing; and clause 8.5 (vulnerability analysis) as a continual activity.

Can a tool make us ISO/SAE 21434 compliant?

No. The standard is about processes, work products and engineering judgement. A tool can produce the verification evidence those processes need, repeatably and traceably, which is what AutoST does; the TARA, the cybersecurity case and the assessment are people work.

Sources

Related pages

See it on your ECU

A term that matters for your ECU?

In 15 minutes we tell you how AutoST tests it, what a finding looks like and what it means for your ISO/SAE 21434 evidence.

  • Direct answer from an ECU security engineer
  • Which test covers the term
  • Free and without obligation
Tom Zaubermann

Your demo is withTom ZaubermannFounder of Zyberum, ex-lead of the VW InCar Security Testing Lab

Already trusted by Tier 1, Tier 2 suppliers and OEMs. References on request.

Call us: +49 176 439 17074automotive@zyberum.com

Or send us a message

We reply within one business day.

Call usAsk the AutoST team

Pick a time that suits you

Open in a new tab