ISO/SAE 21434
ISO/SAE 21434:2021 is the standard for cybersecurity engineering of road vehicles: processes, TARA, concept, development, validation. Structure and testing clauses.
Updated This page as Markdown
In short
ISO/SAE 21434:2021, "Road vehicles, Cybersecurity engineering", is the international standard that defines how cybersecurity is managed and engineered over the lifecycle of a vehicle E/E system: organisational and project management (clauses 5 to 7), continual activities such as monitoring and vulnerability analysis (clause 8), concept with TARA (clause 9 and 15), product development and verification (clause 10), validation (clause 11), production, operations and decommissioning (clauses 12 to 14). It is the usual way to implement the CSMS that UN R155 requires.
What is ISO/SAE 21434?
ISO/SAE 21434 is the standard that defines cybersecurity engineering for road vehicles. Published in August 2021 jointly by ISO and SAE International, it covers electrical and electronic systems of series-production vehicles, their components and interfaces, from the first concept to decommissioning. It replaces the older SAE J3061 guidance and is the technical backbone of UN Regulation No. 155, which requires a certified cybersecurity management system (CSMS) for vehicle type approval.
The standard sets out what has to be done and which work products have to exist. It does not prescribe specific technical controls, algorithms or test cases; those come from the risk assessment of the item in question.
Where is it defined?
The standard is structured in clauses. Clause 5 covers organisational cybersecurity management (policy, culture, competence, tooling), clause 6 project-dependent management (the cybersecurity plan, the cybersecurity case, the assessment in 6.4.9), clause 7 distributed activities between customer and supplier (the cybersecurity interface agreement). Clause 8 defines the continual activities: monitoring (8.3), event evaluation (8.4), vulnerability analysis (8.5) and vulnerability management (8.6). Clause 9 is the concept phase with the item definition, the cybersecurity goals and the cybersecurity concept; clause 10 the product development with specification, integration and verification (10.4.2); clause 11 the cybersecurity validation at vehicle level; clauses 12 to 14 production, operations and maintenance, and end of support. Clause 15 holds the TARA methods, and the informative Annex E describes the Cybersecurity Assurance Level (CAL). Requirements are tagged [RQ-xx-yy], recommendations [RC-xx-yy], permissions [PM-xx-yy], and the work products [WP-xx-yy].
What it means in practice
For a supplier, 21434 arrives as a customer requirement: a cybersecurity interface agreement that says which activities the supplier owns, a TARA or a slice of one, cybersecurity requirements for the component, and the duty to deliver verification and validation reports. For a test team, it arrives as a demand for evidence: clause 10.4.2 asks for verification that the implementation meets the cybersecurity specification, and [RC-10-12] recommends fuzz testing and vulnerability scanning so that unidentified weaknesses are minimised; clause 11 asks for validation of the goals, naming penetration testing in [RQ-11-01].
What turns a test into evidence is traceability. In audit support we did for a Tier-1, the assessor did not ask whether fuzzing had been done; the question was which requirement a given test verified, on which software version it ran, and where the finding went. Tests without that chain did not count.
How AutoST tests it
AutoST covers the testing side of clauses 10.4.2, 11 and 8.5 for the diagnostic and bus attack surface: UDS enumeration, SecurityAccess checks, UDS and CAN fuzzing with crash detection, DoIP, SOME/IP and Android IVI checks, repeatable on every build through the REST API and the Bamboo plugin. Every finding carries a severity and a fix, the Fix Plan links tasks to your requirement or ticket, scan history and risk acceptance persist across re-tests, and reports come as PDF and SARIF. The TARA, the cybersecurity case and the assessment are not tool output; Zyberum supports those as consulting.
Common misunderstandings
There is no such thing as an “ISO/SAE 21434 certified ECU”. The standard describes processes, and its assessment (6.4.9) judges a project’s cybersecurity case, while the regulatory certificate under UN R155 goes to the manufacturer’s CSMS. A tool, a component or a company can work in accordance with the standard, but the standard does not certify products.
FAQ
Frequently asked questions
Is ISO/SAE 21434 mandatory?
Not as a law. UN R155 is the binding regulation, and it requires a certified CSMS without naming a standard. ISO/SAE 21434 is the standard the industry and the approval authorities use to show that the CSMS and the engineering behind a vehicle type meet R155, so in practice OEMs require it from their suppliers.
Where does the standard ask for security testing?
Clause 10.4.2 (integration and verification) with [RQ-10-09] and the recommendation [RC-10-12] for fuzz testing and vulnerability scanning; clause 11 (cybersecurity validation) with [RQ-11-01], which names penetration testing; and clause 8.5 (vulnerability analysis) as a continual activity.
Can a tool make us ISO/SAE 21434 compliant?
No. The standard is about processes, work products and engineering judgement. A tool can produce the verification evidence those processes need, repeatably and traceably, which is what AutoST does; the TARA, the cybersecurity case and the assessment are people work.
Sources
Related pages
- GlossaryTARA (Threat Analysis and Risk Assessment)TARA is the threat analysis and risk assessment of ISO/SAE 21434 clause 15: assets, threat scenarios, impact, attack paths, feasibility, risk value and treatment.
- GlossaryCAL (Cybersecurity Assurance Level)The Cybersecurity Assurance Level (CAL 1 to 4) of ISO/SAE 21434 Annex E sets how rigorous verification and validation must be. How it is derived and used in testing.
- GlossaryCSMS (Cybersecurity Management System)A CSMS is the system of processes UN R155 requires from a vehicle manufacturer: risk management, testing, monitoring and response over the vehicle lifecycle.
- GlossaryUN R155 (UN Regulation No. 155, Cyber Security)UN R155 is the UNECE regulation that makes a certified CSMS and cyber security measures a condition for vehicle type approval. What it requires and what testers deliver.
- InsightsTraceability in an ISO 21434 audit: making fuzzing countSecurity testing is required by ISO/SAE 21434, but tests only pass an assessment when they are traceable. Here is what an assessor looks for and how to get there.
- PlatformEvidence for your 21434 work, on tap.How AutoST supports ISO/SAE 21434 and UN R155: fuzzing and vulnerability analysis for [RC-10-12], penetration-test evidence for [RQ-11-01], plus traceable reports.
