ISO 21434
Automotive Cybersecurity Engineering
ISO 21434:2021 at a glance
- Current edition
- ISO/SAE 21434:2021 - Road vehicles — Cybersecurity engineering
- Published
- 2021
- Status
- Published
- Type of standard
- Requirements
- Certifiable
- Yes — organizations can be certified by an accredited body
- Official ISO page
- View ISO 21434:2021 on iso.org
- Last verified
Overview
Joint ISO/SAE standard specifying cybersecurity engineering requirements for road vehicle electrical and electronic systems across the whole vehicle lifecycle
ISO/SAE 21434:2021 specifies engineering requirements for cybersecurity risk management of road vehicle electrical and electronic (E/E) systems, covering concept, product development, production, operation, maintenance and decommissioning. It was published in August 2021 as a joint deliverable of ISO/TC 22/SC 32 and SAE International — the first international standard for automotive cybersecurity engineering — and remains the current edition; work on a second edition is under way but not published.
The standard defines a common vocabulary and a framework, not a set of technical countermeasures. It explicitly does not prescribe specific technologies, remediation methods or cryptographic solutions, and it does not address functional safety (ISO 26262) or the cybersecurity of non-E/E items, although it requires interfaces with safety and other disciplines to be defined.
Requirements are organised across organizational and project levels. Organizational cybersecurity management covers cybersecurity policy, rules and processes, a cybersecurity culture, competence management, information sharing, tool management, and an organizational cybersecurity audit. Project-dependent cybersecurity management covers cybersecurity planning, the cybersecurity case, cybersecurity assessment and release for post-development.
Distributed cybersecurity activities address the supply chain: responsibilities between customer and supplier are allocated in a Cybersecurity Interface Agreement (CIA), supported by supplier capability evaluation and requests for quotation that state cybersecurity responsibilities. Continual cybersecurity activities require cybersecurity monitoring, cybersecurity event assessment, vulnerability analysis and vulnerability management throughout the item's life — obligations that continue long after start of production.
The engineering lifecycle clauses cover the concept phase (item definition, cybersecurity goals and cybersecurity claims), product development (requirements, architectural design, integration and verification, with refinement down to component level), cybersecurity validation, production, operations and maintenance (including cybersecurity incident response and update handling), and end of cybersecurity support and decommissioning.
Risk assessment is defined in detail as Threat Analysis and Risk Assessment (TARA), comprising asset identification, threat scenario identification, impact rating, attack path analysis, attack feasibility rating, risk value determination and risk treatment decision. The optional concept of Cybersecurity Assurance Levels (CAL) is provided in an annex as a way of scaling rigour of activity to risk.
The commercial driver behind adoption is regulatory. UN Regulation No. 155 requires vehicle manufacturers to hold an approved Cyber Security Management System (CSMS), and UN Regulation No. 156 requires a Software Update Management System; in the EU these have applied to new vehicle types since July 2022 and to all newly registered vehicles since July 2024. ISO/SAE 21434 is the recognised engineering basis for demonstrating the technical processes that a CSMS approval requires, and OEMs push equivalent expectations down to their suppliers through contracts.
Third-party assessment and certification against ISO/SAE 21434 is offered by automotive certification bodies, typically covering an organization's cybersecurity processes and often combined with UN R155 CSMS readiness assessment. It should be understood as a process/engineering assessment rather than an ISO management system certification of the ISO 9001 type. Suppliers commonly run ISO/SAE 21434 alongside IATF 16949, ISO 26262 and ISO/IEC 27001.
Purpose
To define a common framework and set of engineering requirements for managing cybersecurity risk in road vehicle E/E systems throughout the lifecycle, and to provide the technical basis for demonstrating a cyber security management system under UN Regulation No. 155.
Key Benefits
- The recognised engineering basis for demonstrating processes required by UN R155 CSMS approval
- Provides a common cybersecurity vocabulary shared by OEMs and suppliers worldwide
- Defines a structured TARA method so risk assessments are comparable across projects and companies
- Covers the full lifecycle, including monitoring, incident response and end of cybersecurity support
- Clarifies supply chain responsibilities through the Cybersecurity Interface Agreement
- Requires organizational competence, culture and audit, not just project-level activity
- Supports production of a cybersecurity case that documents argument and evidence for release
- Aligns with ISO 26262 functional safety practice, easing integrated safety and security engineering
- Reduces rework by defining cybersecurity requirements at concept stage rather than retrofitting controls
- Increasingly a contractual expectation for suppliers of connected and software-defined vehicle components
Key Requirements
- Establish organizational cybersecurity policy, rules and processes, and foster a cybersecurity culture
- Manage competence, awareness and continuous improvement of cybersecurity capability
- Manage tools and information sharing that can affect cybersecurity
- Perform an organizational cybersecurity audit of the implemented processes
- Produce a cybersecurity plan for each project, assign responsibilities and manage tailoring of activities
- Maintain a cybersecurity case and perform cybersecurity assessment prior to release for post-development
- Define distributed cybersecurity activities and record them in a Cybersecurity Interface Agreement with suppliers
- Evaluate supplier cybersecurity capability and state cybersecurity requirements in requests for quotation
- Operate continual cybersecurity monitoring, event assessment, vulnerability analysis and vulnerability management
- Define the item, its boundary and its operational environment in the concept phase
- Perform Threat Analysis and Risk Assessment: asset identification, threat scenarios, impact rating, attack path analysis, attack feasibility rating, risk determination and treatment decisions
- Derive cybersecurity goals, cybersecurity claims and cybersecurity requirements, and refine them through architecture, design, integration and verification
- Perform cybersecurity validation at vehicle level and control cybersecurity in production
- Define and operate incident response and update processes during operations and maintenance, and manage end of cybersecurity support and decommissioning
Who Needs This Standard?
Vehicle manufacturers and their tier 1 and tier 2 suppliers of E/E components, ECUs, embedded software, telematics and connectivity systems; engineering service providers and semiconductor vendors serving automotive; and organizations preparing for or maintaining UN R155 type approval.
Where to get ISO 21434
The full text of ISO 21434 is copyrighted and is sold by ISO and its national member bodies — buy the official edition on iso.org, or order the same document from your national standards body, often at a member price. Sites offering a free PDF of the complete standard are not authorised to distribute it, and the files circulating there are frequently superseded editions, partial scans or altered copies, with no way to tell which. What is legitimately free is the standard's page on iso.org: the abstract, the current edition and status, the table of contents, and a preview of the opening sections. This page summarises the scope and requirements of ISO 21434 in our own words; it does not reproduce the standard's text and is not a substitute for the published document.
Get our free implementation resources
Send me the implementation checklist for ISO 21434, plus an alert when this standard is revised, withdrawn or replaced. Free, no account needed.
We'll only email you about this standard. Unsubscribe anytime.
Need help getting certified?
Certificates for ISO 21434 are issued by accredited certification bodies, not by ISO itself. Tell us what stage you are at and we will put you in touch with people who work with this standard — implementation support, audit or training. Free and no obligation.
Get help with ISO 21434 certification
In a hurry? You can also compare provider quotes on CertBetter (affiliate link — we earn a commission, and it stays free for you).