Skip to content
AutoST by Zyberum GmbH
Menu
Free toolISO/SAE 21434

TARA Risk Calculator per ISO/SAE 21434

Rate a threat scenario the way ISO/SAE 21434 does: impact in four categories, attack feasibility from attack potential, and the risk value 1 to 5 with a treatment hint.

Updated This page as Markdown

In short

This calculator walks through the risk determination of ISO/SAE 21434 clause 15 for one threat scenario: you rate the damage in the safety, financial, operational and privacy categories, rate the attack feasibility with the attack potential method (elapsed time, expertise, knowledge of the item, window of opportunity, equipment, Annex G), and get the risk value from 1 to 5 per the matrix in Annex H, with a hint on the treatment decision. It runs in the browser; nothing is sent anywhere.

Impact rating

Rate the damage scenario in each category. The highest category becomes the overall impact.

SafetyInjuries, from none to life-threatening (ISO 26262 severity)
FinancialDamage to the road user, from negligible to substantial
OperationalLoss of vehicle function or performance
PrivacyExposure of personal data, from none to highly sensitive
Attack feasibility (attack potential)

Rate the easiest known attack path. Points follow ISO/SAE 21434 Annex G.

Elapsed time
Specialist expertise
Knowledge of the item
Window of opportunity
Equipment

How it works

The calculator follows ISO/SAE 21434 clause 15 step by step. The impact rating (15.5) rates one damage scenario in the four categories the standard names, using the four levels severe, major, moderate and negligible; the tool takes the highest as the overall impact. The attack feasibility rating (15.7) uses the attack potential approach of Annex G: five factors with the point values the standard takes from ISO/IEC 18045 are added up, and the sum maps to high (0 to 13), medium (14 to 19), low (20 to 24) or very low (25 and above). The risk value (15.8) then comes from the matrix in Annex H, Table H.8, which combines overall impact and feasibility into a value from 1 to 5.

How to read the result

The risk value is an input to the treatment decision (15.9), not a verdict. What matters in an audit is that the inputs are traceable: which damage scenario, which attack path, why each factor was rated as it was. Rate the easiest attack path you know, not the average one, and revisit the rating when a test changes the facts. A SecurityAccess bypass found on the bench, for example, moves “knowledge of the item” from confidential to public and “equipment” from specialised to standard, which can turn a medium feasibility into a high one and a risk of 3 into a 5.

Limits

The tool rates one scenario with the standard’s default method and the conservative aggregation. It does not cover asset identification, threat scenario identification or attack path analysis (15.3 to 15.6), and it cannot know your organisation’s acceptance criteria. OEM-specific methods differ in weights and thresholds; follow your customer’s TARA template where one exists. AutoST feeds the attack feasibility side of this with test results: a confirmed finding is evidence for the rating.

FAQ

Frequently asked questions

Is the attack potential method mandatory?

No. ISO/SAE 21434 requires an attack feasibility rating but lets you choose the method: attack potential, CVSS-based, or attack vector based. Attack potential is the most common in TARAs we see because it maps to ISO/IEC 18045 and gives a traceable sum. The thresholds (high up to 13, medium 14 to 19, low 20 to 24, very low from 25) are the ones in Annex G.

How do the four impact categories combine?

The standard rates each category separately and leaves the aggregation to the organisation. The usual and conservative choice, which this tool uses, is to take the highest category as the overall impact. Some OEMs weight the categories or require safety to dominate; adapt to your customer’s method.

What does the risk value decide?

The treatment: avoid, reduce, share or retain the risk (clause 15.9). Values of 4 and 5 are normally reduced with cybersecurity goals and controls; 1 is typically retained with a rationale; 2 and 3 depend on your organisation’s acceptance criteria, which must be documented in the cybersecurity plan.

Sources

Related pages

See it on your ECU

Useful? The full suite does this against your ECU, automatically.

In a one-hour demo we run AutoST against a demo ECU or, if you have one on the bench, against yours.

  • Enumeration, SecurityAccess, fuzzing, DoIP live
  • Your questions answered by an engineer
  • Free and without obligation
Tom Zaubermann

Your demo is withTom ZaubermannFounder of Zyberum, ex-lead of the VW InCar Security Testing Lab

Already trusted by Tier 1, Tier 2 suppliers and OEMs. References on request.

Call us: +49 176 439 17074automotive@zyberum.com

Or send us a message

We reply within one business day.

Call usSee the full test suite

Pick a time that suits you

Open in a new tab