# TARA Risk Calculator per ISO/SAE 21434

> This calculator walks through the risk determination of ISO/SAE 21434 clause 15 for one threat scenario: you rate the damage in the safety, financial, operational and privacy categories, rate the attack feasibility with the attack potential method (elapsed time, expertise, knowledge of the item, window of opportunity, equipment, Annex G), and get the risk value from 1 to 5 per the matrix in Annex H, with a hint on the treatment decision. It runs in the browser; nothing is sent anywhere.

Rate a threat scenario the way ISO/SAE 21434 does: impact in four categories, attack feasibility from attack potential, and the risk value 1 to 5 with a treatment hint.

Source: https://auto-st.com/tools/tara-risk-calculator · Updated: 2026-10-07

<TaraCalculator
  client:load
  t={{
    impact: 'Impact rating',
    impactHint: 'Rate the damage scenario in each category. The highest category becomes the overall impact.',
    categories: {
      safety: { name: 'Safety', hint: 'Injuries, from none to life-threatening (ISO 26262 severity)' },
      financial: { name: 'Financial', hint: 'Damage to the road user, from negligible to substantial' },
      operational: { name: 'Operational', hint: 'Loss of vehicle function or performance' },
      privacy: { name: 'Privacy', hint: 'Exposure of personal data, from none to highly sensitive' },
    },
    levels: { negligible: 'Negligible', moderate: 'Moderate', major: 'Major', severe: 'Severe' },
    feasibility: 'Attack feasibility (attack potential)',
    feasibilityHint: 'Rate the easiest known attack path. Points follow ISO/SAE 21434 Annex G.',
    factors: {
      time: { name: 'Elapsed time', options: ['≤ 1 day', '≤ 1 week', '≤ 1 month', '≤ 6 months', '> 6 months'] },
      expertise: { name: 'Specialist expertise', options: ['Layman', 'Proficient', 'Expert', 'Multiple experts'] },
      knowledge: { name: 'Knowledge of the item', options: ['Public', 'Restricted', 'Confidential', 'Strictly confidential'] },
      window: { name: 'Window of opportunity', options: ['Unlimited', 'Easy', 'Moderate', 'Difficult'] },
      equipment: { name: 'Equipment', options: ['Standard', 'Specialised', 'Bespoke', 'Multiple bespoke'] },
    },
    result: 'Risk determination',
    overallImpact: 'Overall impact',
    attackPotential: 'Attack potential (sum)',
    feasibilityRating: 'Attack feasibility',
    feasibilityLevels: { high: 'High', medium: 'Medium', low: 'Low', veryLow: 'Very low' },
    riskValue: 'Risk value (1 to 5)',
    treatment: {
      1: 'Typically retained with a documented rationale. Record it in the TARA and revisit it when the attack feasibility changes.',
      2: 'Usually acceptable or reduced with a low-effort control, depending on your acceptance criteria. Document the decision.',
      3: 'Needs a treatment decision: reduce with a cybersecurity goal and control, share (for example with a supplier), or retain with justification by the risk owner.',
      4: 'Normally reduced: derive a cybersecurity goal, specify controls, verify them. Retaining a 4 needs management sign-off.',
      5: 'Reduce or avoid. A cybersecurity goal and verified controls are expected; this scenario drives the cybersecurity concept.',
    },
    reset: 'Reset',
  }}
/>

## How it works

The calculator follows ISO/SAE 21434 clause 15 step by step. The impact rating (15.5) rates one damage scenario in the four categories the standard names, using the four levels severe, major, moderate and negligible; the tool takes the highest as the overall impact. The attack feasibility rating (15.7) uses the attack potential approach of Annex G: five factors with the point values the standard takes from ISO/IEC 18045 are added up, and the sum maps to high (0 to 13), medium (14 to 19), low (20 to 24) or very low (25 and above). The risk value (15.8) then comes from the matrix in Annex H, Table H.8, which combines overall impact and feasibility into a value from 1 to 5.

## How to read the result

The risk value is an input to the treatment decision (15.9), not a verdict. What matters in an audit is that the inputs are traceable: which damage scenario, which attack path, why each factor was rated as it was. Rate the easiest attack path you know, not the average one, and revisit the rating when a test changes the facts. A SecurityAccess bypass found on the bench, for example, moves "knowledge of the item" from confidential to public and "equipment" from specialised to standard, which can turn a medium feasibility into a high one and a risk of 3 into a 5.

## Limits

The tool rates one scenario with the standard's default method and the conservative aggregation. It does not cover asset identification, threat scenario identification or attack path analysis (15.3 to 15.6), and it cannot know your organisation's acceptance criteria. OEM-specific methods differ in weights and thresholds; follow your customer's TARA template where one exists. AutoST feeds the attack feasibility side of this with test results: a confirmed finding is evidence for the rating.

## FAQ

**Is the attack potential method mandatory?**

No. ISO/SAE 21434 requires an attack feasibility rating but lets you choose the method: attack potential, CVSS-based, or attack vector based. Attack potential is the most common in TARAs we see because it maps to ISO/IEC 18045 and gives a traceable sum. The thresholds (high up to 13, medium 14 to 19, low 20 to 24, very low from 25) are the ones in Annex G.

**How do the four impact categories combine?**

The standard rates each category separately and leaves the aggregation to the organisation. The usual and conservative choice, which this tool uses, is to take the highest category as the overall impact. Some OEMs weight the categories or require safety to dominate; adapt to your customer’s method.

**What does the risk value decide?**

The treatment: avoid, reduce, share or retain the risk (clause 15.9). Values of 4 and 5 are normally reduced with cybersecurity goals and controls; 1 is typically retained with a rationale; 2 and 3 depend on your organisation’s acceptance criteria, which must be documented in the cybersecurity plan.

## Sources

- [ISO/SAE 21434:2021 Road vehicles, Cybersecurity engineering, clause 15 and Annexes F to H](https://www.iso.org/standard/70918.html)
- [ISO/IEC 18045:2022 Methodology for IT security evaluation (attack potential)](https://www.iso.org/standard/72889.html)

## Related

- [TARA (Threat Analysis and Risk Assessment)](https://auto-st.com/glossary/tara)
- [ISO/SAE 21434](https://auto-st.com/glossary/iso-sae-21434)
- [CAL (Cybersecurity Assurance Level)](https://auto-st.com/glossary/cal)
- [UN R155 (UN Regulation No. 155, Cyber Security)](https://auto-st.com/glossary/un-r155)
- [Evidence for your 21434 work, on tap.](https://auto-st.com/iso-21434-testing)
- [A number you can defend, evidence you can file.](https://auto-st.com/risk-scoring-reports)

---
AutoST by Zyberum. Canonical page: https://auto-st.com/tools/tara-risk-calculator
