top of page

ISO/SAE 21434 Reference Guide

Information Security Management Systems

What Is ISO 21434?

ISO/SAE 21434 is the international engineering standard for cybersecurity in road vehicles. Published jointly by ISO and SAE International in 2021, it defines how cybersecurity should be engineered into vehicle systems across their entire lifecycle, from concept and design through production, operation, and decommissioning.

Where UN R155 mandates that manufacturers must have a cybersecurity management system, ISO/SAE 21434 provides the detailed engineering framework for building one. It describes the methods, processes, and activities required to systematically identify cybersecurity threats, assess risks, design and implement security controls, verify their effectiveness, and maintain them throughout the product's operational life.

The standard applies to the full supply chain, including the telematics, software, and connected systems that fleet management depends on. It is not limited to the vehicle itself; any electronic component, software module, or connected system that could affect vehicle cybersecurity falls within its scope.

Who Is Affected by ISO/SAE 21434?

ISO/SAE 21434 applies to any organisation involved in the development, production, or maintenance of cybersecurity-relevant road vehicle systems. Its requirements extend across the supply chain through documented interface agreements.

ai generated a blue car is on the assemb

Vehicle Manufacturers

Manufacturers typically use ISO/SAE 21434 as the technical basis for meeting UN R155 requirements. The standard provides the methodology for threat analysis, risk assessment, and security engineering that R155 demands.
 

data security concept person protecting

Tier 1 and Tier 2 Suppliers

Directly affected. ISO/SAE 21434 defines how cybersecurity activities should be distributed across the supply chain, including requirements for interfaces between organisations, shared responsibility agreements, and supplier capability assessments.

macro shot of computer circuit board_edited.jpg

Connected Device Manufacturers

Fleet operators across ASEAN and the Middle East benefit from understanding ISO/SAE 21434 because it shapes the security engineering behind the connected fleet products they use. When a provider claims their product is secure, ISO/SAE 21434 provides the framework against which that claim can be evaluated.

The ISO/SAE 21434 Cybersecurity Lifecycle

ISO/SAE 21434 organises cybersecurity engineering into distinct lifecycle phases. Each phase has defined activities, work products, and decision points.

Phase 1

Concept and Design
The process begins with a cybersecurity item definition, followed by Threat Analysis and Risk Assessment (TARA). TARA identifies potential attack paths, evaluates their feasibility and impact, and determines the cybersecurity risk level. Based on TARA results, cybersecurity goals and requirements are defined alongside functional requirements. Security is designed in from the start, not added later.

Phase 2

Development and Validation
During development, cybersecurity requirements are implemented in hardware, software, and system design. Verification activities confirm that the implementation meets the security requirements defined in the concept phase. Vulnerability analysis and testing, including penetration testing, validate that the system can withstand the threats identified in TARA.

Phase 3

Production
Production processes must ensure that cybersecurity measures are not compromised during manufacturing. This includes secure key provisioning, firmware signing, configuration management, and protection against supply chain tampering.

Phase 4

Operation and Maintenance

Once the vehicle is in the field, ongoing cybersecurity monitoring is required. This includes tracking new vulnerabilities, monitoring for incidents, managing cybersecurity-relevant software updates (in coordination with UN R156), and maintaining the vehicle's cybersecurity posture throughout its operational life.

Phase 5

Decommissioning

When vehicles or systems reach end of life, secure disposal of data and credentials is required. Legacy systems that remain connected but are no longer maintained become unmonitored entry points. ISO/SAE 21434 requires planning for secure decommissioning as part of the lifecycle.

ISO/SAE 21434 Threat Analysis and Risk Assessment (TARA)

TARA is the central methodology in the ISO/SAE 21434 standard. It provides a structured approach to identifying what can go wrong, how likely it is, and how severe the consequences would be.

Asset identification: What needs protection? Data, functions, communication channels, hardware components.
 

Threat modelling: What attack paths exist? Who are the potential attackers? What are their capabilities and motivations?
 

Impact assessment: What happens if the attack succeeds? Safety, financial, operational, and privacy impacts are evaluated.
 

Attack feasibility: How difficult is the attack to execute? Considers required expertise, equipment, access, and time.
 

Risk determination: Combines impact and feasibility to assign a risk level. High-risk scenarios require treatment; lower risks may be accepted with justification.
 

Risk treatment: Design and implement controls to reduce, transfer, or accept each risk. Document the rationale and verify effectiveness.

How UN R155 Relates to Other Standards

UN R155 is the regulatory mandate; ISO/SAE 21434 is the engineering standard commonly used to demonstrate compliance. R155 says you must have a CSMS; 21434 tells you how to build one.
 

UN R156 covers software update management. ISO/SAE 21434 provides the threat analysis methodology used to identify the security requirements that R156's SUMS must address.
 

ISO 27001 addresses information security management at the organisational level. ISO/SAE 21434 is specifically focused on product-level cybersecurity engineering for road vehicles. Organisations may hold both, with ISO 27001 covering corporate information security and 21434 covering vehicle product security.
 

ISO 24089 provides the software update engineering framework aligned with R156. ISO/SAE 21434 provides the cybersecurity engineering framework aligned with R155. Together, they form the technical foundation for both regulations.

Key Terms

TTMI maintains continuous alignment with international cybersecurity standards, updating platform controls as regulations evolve. Our architecture aligns with international requirements for cybersecurity engineering, software integrity, and information security management.

Attack Feasibility: An assessment of how practical a specific attack is, considering the expertise required, equipment needed, access time, and attacker motivation. TARA evaluates feasibility alongside impact to determine risk priority.
 

Cybersecurity Case: The comprehensive documentation package demonstrating that a system meets its cybersecurity requirements. Includes TARA results, requirement specifications, design decisions, verification evidence, and residual risk acceptance.
 

Cybersecurity Interface Agreement: A documented agreement between organisations in the supply chain defining which cybersecurity activities each party is responsible for, how information is shared, and how compliance is verified across the boundary.
 

Cybersecurity Item: The component, system, or function being assessed for cybersecurity risk. Defining the cybersecurity item is the first step in the ISO/SAE 21434 lifecycle and determines the scope of everything that follows.
 

Decommissioning: The end-of-life phase covering secure disposal of data, credentials, cryptographic keys, and configuration stored on a connected system. Fleet operators replacing telematics devices or decommissioning vehicles should confirm that data remnants are securely removed.

Distributed Cybersecurity Activities: Cybersecurity responsibilities shared across organisations through documented interface agreements. When a telematics provider supplies components to an OEM, ISO/SAE 21434 defines how obligations are allocated and verified between them.
 

Post-Development: Activities required after development is complete, covering production security controls, ongoing vulnerability monitoring, incident response, secure updates, and decommissioning. The standard treats post-development as a continuous obligation, not a handoff.
 

Risk Treatment: The decision made after TARA about how to handle each identified cybersecurity risk. Options are to avoid the risk, reduce it through controls, transfer it contractually, or accept it with documented justification.
 

Verification and Validation: The testing and review activities that confirm cybersecurity requirements have been correctly implemented. Verification checks that the system was built right. Validation checks that the right system was built.
 

Vulnerability Management: The ongoing process of identifying, evaluating, and responding to newly discovered vulnerabilities in deployed systems. Distinct from development-phase security, this continues for the entire operational life of the product.

Frequently Asked Questions

We answer the questions that drive cybersecurity decisions.

multiple screens displaying ai neural network visualization_edited.jpg

How TTMI Helps

TTMI provides cybersecurity services grounded in the ISO/SAE 21434 lifecycle approach. For telematics providers, fleet platform vendors, and connected device manufacturers, TTMI can help build the cybersecurity engineering evidence that OEM customers and approval authorities expect.
 

TARA-Based Assessment: Conduct threat analysis and risk assessment aligned with the ISO/SAE 21434 methodology. Identify attack paths, evaluate feasibility and impact, and define cybersecurity requirements for your connected systems.
 

Vulnerability Testing: Penetration testing and vulnerability analysis of telematics platforms, fleet management systems, and connected device firmware. Validate that your security controls withstand the threats identified in your TARA.
 

Cybersecurity Case Development: Support the documentation package that demonstrates your product meets its cybersecurity requirements, from TARA results through control implementation to verification evidence.

Related Standards and Official Sources

ISO/SAE 21434 is one part of a wider regulatory and engineering framework for vehicle cybersecurity. The official documentation for each related standard is available from the links below.

Speak with our Cybersecurity Team

Whether you are beginning the certification pathway or looking to strengthen existing controls, we can help you understand where you stand and what comes next.

bottom of page