What is ISO/SAE 21434?

ISO/SAE 21434 is the international standard for cybersecurity engineering of road vehicles. It defines how automotive organizations should manage cybersecurity risk for electrical and electronic (E/E) systems across the entire product lifecycle — from concept and development, through production and operation, to maintenance and decommissioning.

It was developed jointly by ISO and SAE and published in 2021. The standard does not tell you which specific security controls to fit; instead it sets out a risk-based engineering process so that cybersecurity is designed in, argued for, and maintained throughout a product's life. At its heart is Threat Analysis and Risk Assessment (TARA) — identifying assets, threats and attack paths, assessing risk, and deciding how to treat it.

Just as important is its link to regulation. UN Regulation No. 155 (UNECE WP.29) requires vehicle manufacturers to have a certified Cybersecurity Management System (CSMS) for type approval in many markets, and ISO/SAE 21434 is the recognized engineering framework for demonstrating that capability. In practice, conformity is largely driven by OEM and regulatory requirements flowing down the supply chain, rather than being a voluntary badge.

Who needs ISO/SAE 21434?

ISO/SAE 21434 applies to organizations that design, build or supply the electronics and software that go into modern vehicles. It is essential for:

  • Vehicle manufacturers (OEMs) who need a Cybersecurity Management System, not least to meet UN R155 type-approval expectations.
  • Tier 1 and Tier 2 suppliers providing ECUs, connectivity modules, control units, sensors and embedded software.
  • Software and semiconductor companies whose components end up in E/E systems.
  • Engineering, integration and validation service providers working on automotive projects.
  • Suppliers of connected, autonomous and electric vehicle technology, where the attack surface — telematics, over-the-air updates, charging, ADAS — is largest.
  • Any organization whose automotive customers now write cybersecurity requirements into contracts and expect evidence of a capable process.

A simple rule of thumb: if your product carries software or communicates, and it ends up in a vehicle, your customers will expect you to work to ISO/SAE 21434 — and increasingly they will ask for proof.

What ISO/SAE 21434 requires

The standard asks you to make cybersecurity a managed engineering discipline with evidence at every stage. In practical terms it requires you to:

  • Establish cybersecurity governance and culture — assign responsibility, competence and awareness, and set up an organization-wide cybersecurity management approach.
  • Run Threat Analysis and Risk Assessment (TARA) — identify assets, threats and attack paths, assess impact and feasibility, and decide how each risk is treated.
  • Engineer cybersecurity across the concept and development phases, deriving cybersecurity goals and requirements and verifying that the design meets them.
  • Manage the supply chain — define cybersecurity responsibilities between customer and supplier, often through an interface agreement.
  • Maintain a cybersecurity case — the structured argument and evidence that a product is adequately protected.
  • Handle production, operations, monitoring and incident response — including continuous monitoring for new vulnerabilities and a way to respond after the vehicle is on the road.
  • Manage the full lifecycle through to end of support and decommissioning.

What sets ISO/SAE 21434 apart is that it is about demonstrable, risk-based engineering, not a checklist of features. You have to be able to show why your decisions were reasonable — through TARA, work products and the cybersecurity case — for the whole life of the product.

Why get ISO/SAE 21434 certified

The most immediate reason is market access. With UN R155 tying vehicle type approval to a certified Cybersecurity Management System, cybersecurity capability has become a condition of doing business in automotive. OEMs pass those expectations down to their suppliers, so demonstrating conformity to ISO/SAE 21434 is often what keeps you on the bid list and shortens the qualification questions in every tender.

Beyond access, it protects you from real risk. A cybersecurity failure in a connected vehicle can mean recalls, safety incidents, reputational damage and regulatory exposure. Building the discipline of TARA, secure development and post-production monitoring into how you work means problems are found and treated during design, when they are far cheaper to fix, rather than in the field.

Finally, it builds trust. A recognized cybersecurity engineering process — supported by an assessment or certificate from a competent body — gives your OEM customers confidence that your parts will not be the weak link in their vehicle. In a supply chain where one gap can compromise the whole system, that assurance is worth a great deal.

How QSE gets you certified

With more than 30 years of experience, 900+ clients certified and a 100% first-time pass rate, we make ISO/SAE 21434 achievable without drowning your engineering teams in process. Our 10-Step Approach keeps the project focused on the work products and evidence that actually matter.

We begin by understanding your products, your role in the supply chain and what your customers and UN R155 require of you. We help you set up cybersecurity governance and a Cybersecurity Management System, then build the practical machinery — TARA method, cybersecurity requirements, the cybersecurity case and monitoring — so it fits how your engineers already work. Because cybersecurity sits alongside functional safety and automotive quality, we help you integrate it with any ISO 26262 and IATF 16949 activity rather than bolting on a parallel system.

We keep the documentation lean — a single-level system, typically under 200 pages — train your people, run internal audits, and support you through the assessment or certification audit. A typical ISO/SAE 21434 project runs 4–10 months depending on product complexity, the number of programs in scope and your starting maturity. You finish with a working cybersecurity engineering capability, not just a document set.

Common pitfalls we help you avoid

  • Treating cybersecurity as a bolt-on. It has to live inside your engineering lifecycle. We integrate it with development, safety and quality rather than creating a parallel system.
  • TARA as a one-off form. Threat analysis is a living activity. We build a method your teams can repeat and update as designs and threats change.
  • Ignoring the supply-chain interface. Unclear responsibilities between customer and supplier cause gaps and finger-pointing. We help you define who owns what.
  • Forgetting life after launch. The standard covers production, monitoring and incident response. We make sure your post-production obligations are real, not theoretical.
  • A weak cybersecurity case. If you cannot argue and evidence why your product is adequately protected, an assessor will not be satisfied. We help you build that argument as you go.
  • Over-documenting. Heavy process slows engineers and adds no security. Our lean, single-level approach keeps it usable.
  • Confusing safety with security. ISO 26262 and ISO/SAE 21434 are related but distinct. We keep both clear and connected.