ISO/SAE 21434
The engineering standard for automotive cybersecurity — risk-based processes across the vehicle lifecycle, and the usual path to R155 conformance.
ISO/SAE 21434 “Road vehicles — Cybersecurity engineering” is the international standard defining how cybersecurity is engineered into vehicles. Published in 2021 and developed jointly by ISO and SAE International, it specifies risk-based processes across the full lifecycle: concept, development, production, operation, maintenance and decommissioning, with threat analysis and risk assessment (TARA) at its core.
The standard deliberately prescribes processes, not technologies. It defines what organizations must do — manage cybersecurity risk, validate mitigations, monitor for new vulnerabilities, handle incidents — while leaving specific technical measures to the engineering teams. It also structures supplier relationships, defining how cybersecurity responsibilities are distributed along the supply chain.
What the standard requires
The requirements operate at two levels. At the organizational level, a company must establish a cybersecurity governance framework: policies and rules, competent people, a security-aware engineering culture, and audits that confirm the framework is actually applied. At the project level, every development item gets planned cybersecurity activities with defined responsibilities, and the evidence they produce is collected into a cybersecurity case — the structured argument that the item’s residual risk is acceptable.
Around the engineering phases sit the continual activities, which are what make the standard a lifecycle framework rather than a development checklist: monitoring external and internal sources for new threats and vulnerabilities, evaluating whether they affect products already in the field, and responding through the incident and update processes. A vehicle can be in service for two decades; the standard’s premise is that its cybersecurity work does not end at start of production.
TARA: how risk is assessed
Threat analysis and risk assessment is the standard’s analytical engine. The method starts by identifying the item’s assets — data, functions, interfaces — and asking what damage would follow if their security properties were violated, rated across safety, financial, operational and privacy dimensions. Threat scenarios describe how an attacker could cause that damage; attack-path analysis breaks them into concrete steps and rates their feasibility. Impact and feasibility together yield a risk value, and for each risk the organization decides on treatment: reduce it with a mitigation, avoid it by changing the design, share it contractually, or accept it with justification. The output drives everything downstream — cybersecurity goals, requirements, verification, and the cybersecurity case. Done honestly, a TARA is a living document, revisited when the design changes or when monitoring surfaces a new attack technique.
From standard to regulation: R155 and the CSMS
The standard’s practical weight comes from regulation. UNECE R155, formally UN Regulation No. 155, requires vehicle manufacturers to operate a certified Cyber Security Management System (CSMS) as a condition of type approval in the markets that apply UNECE regulations — in the European Union it has applied to new vehicle types since mid-2022 and to all newly produced vehicles since mid-2024. The regulation states what the CSMS must achieve; ISO/SAE 21434 is the accepted route to demonstrating it, and auditors assess manufacturers’ processes largely through its lens. The companion regulation UNECE R156 does the same for software update management, which ties the cybersecurity framework directly to OTA update capability. The pairing of a process standard with a type-approval regulation is what turned automotive cybersecurity from good practice into a market-access requirement.
The supply chain dimension
Vehicles are built by supply chains, and the standard is explicit that cybersecurity engineering is distributed along them. Customer and supplier agree on who performs which cybersecurity activities for a given component, exchange the evidence, and align their vulnerability-monitoring and incident processes — because a weakness discovered in a supplier’s software stack becomes the manufacturer’s CSMS problem within days. In practice this has made ISO/SAE 21434 capability a procurement criterion: manufacturers cascade the requirements into contracts, and for suppliers, certification against the standard has become a de facto ticket to play in new vehicle programs. The standard reaches deep into companies that never see a type-approval authority themselves, including providers of diagnostic and UDS-based tooling whose products touch security-sensitive vehicle interfaces.
Current state as of 2026 and what to watch
Five years after publication, ISO/SAE 21434 is the settled baseline of automotive cybersecurity engineering: certification schemes are established, audits are routine in development programs, and the vocabulary of TARA has become the industry’s shared language for security risk. The pressure points now lie around its edges. Regulatory scope is widening — China has introduced mandatory national requirements for vehicle cybersecurity built on similar concepts, and markets outside the UNECE framework are converging on comparable expectations. Operational demands are growing too: software bills of materials, coordinated vulnerability disclosure and continuous monitoring are moving from good practice toward expectation, testing how well paper processes translate into working security operations for fleets in the field. What to watch is the maturing of that operational layer — whether the industry’s monitoring and response capability keeps pace with vehicles that are updated, connected and attacked for twenty years — and how a future revision of the standard absorbs the lessons of its first regulatory cycle.
Related: Type approval / homologation · UDS / vehicle diagnostics · UNECE R155 · UNECE R156