Talk to us: +49 30 86329721

ISO/SAE 21434 · Process certification

ISO/SAE 21434. Cybersecurity across the vehicle lifecycle

ISO/SAE 21434 defines requirements for the cybersecurity engineering of electrical and electronic systems in road vehicles across the entire lifecycle.

Overview

What is it about?

ISO/SAE 21434 “Road vehicles. Cybersecurity engineering” is the leading standard for securing connected vehicles against cyberattacks. It defines requirements for the processes, activities and responsibilities through which cybersecurity is managed across the design, development, production, operation, maintenance and decommissioning of E/E systems.

At the core of the standard is a risk-based approach: through a Threat Analysis and Risk Assessment (TARA), threats are identified, evaluated and translated into cybersecurity goals. The standard also addresses the overarching Cybersecurity Management System (CSMS), cooperation within the distributed supply chain, and continuous post-launch activity such as monitoring and responding to newly emerging vulnerabilities. It thereby forms the technical basis for demonstrating conformity with the regulatory requirements of UNECE Regulation R155.

Purpose & benefit

Certification demonstrates that standard-conform cybersecurity engineering is established in the automotive context. It supports evidence of conformity with UNECE R155, which is binding for the type approval of new vehicles.

What's included

  • Cybersecurity Management System (CSMS) with organisation, roles and cybersecurity culture
  • Threat Analysis and Risk Assessment (TARA) for the risk-based derivation of cybersecurity goals
  • Concept and product development at system, hardware and software level
  • Distributed cybersecurity activities and delineation of responsibilities in the supply chain
  • Production, operation, maintenance and secure decommissioning
  • Vulnerability and incident management across the entire field lifecycle

For whom

Is this right for you?

The standard is aimed at vehicle manufacturers (OEMs) and at suppliers of control units, components and software along the automotive supply chain. It is relevant for all organisations involved in developing safety- and security-relevant E/E systems for connected vehicles.

Your benefits

What it does for you

  • Structured evidence of standard-conform cybersecurity engineering
  • Basis for meeting UNECE R155 and the associated type approval
  • Clear, verifiable delineation of responsibilities across the distributed supply chain
  • Reduction of cyber risks across the entire vehicle lifecycle

Our role

How we work

  • 1Planning and conducting certification audits to assess the conformity of your management system with the requirements of the standard
  • 2Independent decision on certification based on the audit results
  • 3Issuing and maintaining certificates
  • 4Conducting surveillance and recertification audits in accordance with the applicable rules and defined time intervals

Impartiality

Consulting or support services for the introduction, implementation or improvement of management systems are not part of our activity as a certification body.

FAQ

Frequently asked questions

How do ISO/SAE 21434 and UNECE R155 relate to each other?

UNECE R155 is a binding regulatory requirement for type approval that mandates a Cybersecurity Management System. ISO/SAE 21434 provides the recognised technical and procedural basis for implementing and demonstrating these requirements in a structured way.

What is a TARA?

The Threat Analysis and Risk Assessment is the method anchored in the standard for identifying cybersecurity threats, evaluating their risk, and deriving cybersecurity goals and requirements from them. It is a central element of the risk-based approach.

Does ISO/SAE 21434 differ from functional safety?

Yes. ISO 26262 addresses functional safety against malfunctions, whereas ISO/SAE 21434 addresses protection against targeted cyberattacks. The two disciplines complement each other and are coordinated within the development process.

Your request

What would ISO/SAE 21434 cost for you?

Simply request a non-binding quote, quickly and directly.

Your request refers to: ISO/SAE 21434, ISO/SAE 21434. Cybersecurity across the vehicle lifecycle

Sending becomes possible once the privacy consent has been confirmed.

  • Without obligation
  • DAkkS-accredited for management systems

Or call us directly: +49 30 86329721

Get in touch with us

Provide your contact details, and we'll get in touch with you shortly.

Sending becomes possible once the privacy consent has been confirmed.

Call us · +49 30 86329721