ISO/SAE 21434 defines a cybersecurity engineering framework for automotive E/E systems, from concept through decommissioning.
It underpins compliance with UN Regulation No. 155 (CSMS) required for type approval of vehicles in UNECE contracting parties.
It defines a Cybersecurity Management System (CSMS), risk assessment methodology (TARA), and requirements for distributed development, production, operations, and incident response.
OEMs and suppliers involved in the development, production and operation of road-vehicle E/E systems.
Organisations pursuing UN R155 type approval for their vehicles or components.
Organisational cybersecurity management (CSMS): policies, rules, competence, tool management.
Project-dependent cybersecurity management, distributed activities and supplier management.
Concept phase, product development, cybersecurity validation.
Production, operations & maintenance, end of support and decommissioning.
Threat analysis and risk assessment (TARA) methods.
- 2016-01-01SAE J3061 predecessor
- 2020-02-01Draft International Standard
- 2021-08-31Published
- 2022-07-06UN R155 mandatory for new types
- 2024-07-01UN R155 mandatory for all vehicles
License · ISO/SAE 21434 is copyrighted and must be purchased from ISO or SAE. Nix2 does not redistribute clause text; only public metadata is shown here.