What is ISO/SAE 21434?
ISO/SAE 21434 describes the security engineering / cybersecurity perspective of electrical and electronic (E/E) systems within road vehicles in the automotive environment.
With the trend towards ever greater networking of vehicles and the focus on embedded platforms, attack scenarios are emerging that were previously more familiar from the classic IT environment. The planned standard is therefore aimed at securing the systematic development of safe vehicles and maintaining this security throughout the entire vehicle life Cycle.
With the trend of increasing technological complexity in connection, software content and mechatronic implementation, and networking, we are facing exponentially increasing risk from security and cybersecurity threat to cause unintended failures and/or malfunction, which is becoming a priority. Therefore, a document (ISO/SAE 21434:2021) was jointly prepared by Technical Committee ISO/TC 22, Road Vehicles, Subcommittee SC 32, Electrical and Electronic Components and General System Aspects, and SAE Vehicle Cybersecurity Systems Engineering Committee.
By ensuring appropriate consideration of cybersecurity, this document aims to enable the engineering of these complex systems in order to keep up with changing technology and attack methods. This document provides vocabulary, objectives, requirements and guidelines as a foundation for common understanding throughout the supply chain.
This enables organizations to:
Define cybersecurity policies and processes; Manage cybersecurity risk; and foster a cybersecurity culture.
ISO/SAE 21434:2021 can be used to implement a cybersecurity management system including cybersecurity risk management in accordance with ISO 31000. ISO/SAE 21434:2021 is intended to supersede SAE J3061 recommended practice.
The framework of ISO/SAE 21434:2021 is also intended to be used for integrating cybersecurity activities into a company-specific development framework such as APQP (Advanced Product Quality Planning) and Project Management.
Organizations involved in engineering design and development of automotive electrical and electronic systems and sub-systems
- Organizations who are developing secure components in automotive that will be based on the ISO/SAE 21434 standard
- Organizations that are involved in the cybersecurity of automotive electronic systems and the ISO/SAE 21434 standard
- Organizations who intended to be engaged in ISO/SAE 21434 compliance
- Vehicle manufacturers
- Suppliers of hard and software-based components and systems
- Suppliers of engineering services
- Software and ICT infrastructure providers
- Process of ISO/SAE 21434 certification starts with preparation of an Automotive Quality Management System (AQMS) suitable to the ISO/SAE 21434:2021 standard
- Once AQMS is ready a thorough Gap analysis using ISO/SAE 21434 Process audit checklists is to be conducted to identify any deficiencies in meeting the requirements of ISO/SAE 21434 certification
- ISO Consultants assist in developing a comprehensive, AQMS to meet all requirements of ISO/SAE 21434 and third party Certification Body stage 1 audit requirements. The stage 1 audit from Certification Bodies vary depending on the selected Certification Body which verifies the documented system meeting all ISO/SAE 21434 requirements
- An ISO consulting firm provides the techniques for implementation, and trains organization’s internal auditors to become competent to perform internal audits using ISO process audit checklists or provides ISO/SAE 21434 Internal Auditing Services to audit all processes, all ISO/SAE 21434 Standard requirements using ISO process audit checklists and examine effective implementation of the ISO Standard
- Developing a comprehensive system to meet all the ISO/SAE 21434 process audit requirements for effective implementation to achieve desired results, a competent ISO consulting company or a competent ISO consultant is essential
- AQMS as per ISO standard can assure automotive manufacturers that the facility has a robust system and can produce safe, quality products and services
- 3 process audits conducted and a substantially high score is mandatory requirement for Tier 1 and Tier 2 suppliers catering to the Automobile Industry. Therefore ISO/SAE 21434 certification seeking facilities must learn the process approach the right way
- ISO/SAE 21434 certification seeking Facilities need to initiate corrective actions and witness that continual improvement is realized through control of nonconforming products/services
- ISO/SAE 21434 certification seeking facilities need to implement the prepared AQMS for a minimum of 3 months and gather adequate data and record to show as evidence when seeking ISO/SAE 21434 certification
- Management of the ISO/SAE 21434 certification seeking facilities need to conduct one full scale review of the entire AQMS and ensure its adequacy for their organization. Management Team needs to identify Action items to make corrections to any ISO requirement not being fulfilled
- Once a AQMS is ready, ISO/SAE 21434 Internal audit is performed and one full set of Management review takes place, the facility needs to contact a certification Body for certification audit
- Certification Bodies conduct ISO/SAE 21434 Audit in 2 stages. During Stage 1, audit evaluates the documentation system and basic requirements of meeting ISO/SAE 21434 standard
- Certification Body returns for final audit where all ISO/SAE 21434 requirements are thoroughly audited to ensure that requirements are met and documentary evidence exists to demonstrate compliance
- Once certification Body is satisfied, recommendation is sent to accrediting agencies to issue ISO/SAE 21434 certification
- ISO/SAE 21434 certification provides international recognition and approval in the manufacturing and supply of parts for automobiles
- ISO/SAE 21434 process audit Creates a standardized sector rational to measure the effective capacity of industry players to produce high quality products that are secure for supply
- ISO/SAE 21434 process audit Promotes consistency in effective management in the Automobile sector to ensure quality production is maintained at all stages to the letter
- ISO/SAE 21434 process audit is informative in modern production practices that are cost effective and risk mitigated
- ISO/SAE 21434 process audit helps validate AQMS and give the ability to supply to automakers
- ISO/SAE 21434 Standard helps in process control in every process resulting in increased quality of your products
- ISO/SAE 21434 standard presents a simple and singular management strategy that covers a multi-dimensional organization to guarantee safe quality production and supply
- ISO/SAE 21434 certification is a great marketing tool for selling in the automotive industry
- QSE has over 30 Years of standing in the field of ISO Consulting, Auditing and Training for any ISO Standard as well as Automotive standard Sector Specific Standard, AISC standard or Food Safety Standard
- QSE has helped over 800 facilities to earn their ISO certifications, VDA 6.3 and other certifications. All QSE customers pass final audits with no or minimal nonconformities
- Over 98 % of QSE customers passed ISO certification audits with no nonconformities first time around
- Unlike our competitors, QSE ‘s ISO consultants provide a unique, comprehensive, evidence based simplified single level system which is easy to implement and provide evidence for implementation to earn ISO certification
- ISO Templates designed by QSE are tried and tested. They are perfect. Facilities using the documentation developed by QSE do not have to struggle for evidence
- Evidence is built in to the system. The facility needs to only follow the given ISO Standard formats, and tables to sail through a certification audit with a high score or with minimal nonconformities
- QSE engages all competent auditors to conduct internal audits or suppler audits
- President of QSE is a member of the technical committee involved in writing ISO 19011, the guidance standard for audits since its inception in 1985 to recent changes in 2018
- At the end of an Internal audit QSE submits a detailed report which assists the facilities in building corrective actions and prevent actions to avoid possible nonconformities and helps to undertake preventive actions to avoid occurrence of any nonconformity
- Several of our competitors engage in ISO process audits through ISO Audit Process checklists. QSE performs audits by ISO process audit checklist, and gathers evidence covering all requirements of ISO standards clause by clause
- QSE has system designed to fix process controls in the system which ensure high scores during ISO Audit
- QSE has designed unique comprehensive single level documentation which ensure effective implementation of ISO standard
- QSE helps create all required documented processes as per ISO Standard and other requirements covered in ISO which is mandatory
- QSE’s consultants provide ISO standard documentation that is unique, simple, lean and easy to implement and sustain certification
- QSE ensures to provide implementation assistance or complete understanding of the documentation and requirements of ISO process audit.
- QSE includes all 4 stages of quality control. Receiving, Setup, In-process and Final release and ensures that they are built in the system for effective control mechanism
- QSE’s Unique Management review format ensures that facilities implement methods to verify the adequacy of AQMS. This helps to eliminate all probable nonconformities on Management Review
- The review techniques of AQMS help make corrections in the system where required and ensures continual improvement
- QSE does not simply tell what needs to be done instead QSE holds the hand of the facility and show how to do it
- QSE’s 10 step disciplined path is insensitive to failure and facilities are guaranteed to obtain certification when all 10 steps are implemented.
- QSE provides post ISO certification process audit services, if required, and can take the disputes to highest levels.
QSE has helped many organizations to get certified to Automotive standards throughout our more than 30 years of service to our valued clients.
Reference to our customers can be given on request.
ISO/SAE 21434 examination must be taken at an agency accredited by ANAB. Application for examination is to be submitted, evidence of having undergone ISO/SAE 21434 training is essential, subsequently permissions given to take the ISO/SAE 21434 examination. On successful completion for the examination ISO/SAE 21434 Process Auditor certificate will be provided.
Official translated versions are available from ISO organization. Other standard sellers can provide English version of the standard
For first time practitioners of ISO/SAE 21434 the scoring pattern could be overwhelming but QSE can make it simple and bring it to easily understandable terms and ensure that system is followed to attain high scores.