Nix2
Back to Nix2
Standard·International (ISO/SAE)

ISO 21434

ISO/SAE 21434:2021 — Road vehicles — Cybersecurity engineering

Cybersecurity engineering requirements for the entire lifecycle of road-vehicle electrical and electronic (E/E) systems.

Official sources ↓
Published August 2021
Scroll
Overview

ISO/SAE 21434 defines a cybersecurity engineering framework for automotive E/E systems, from concept through decommissioning.

It underpins compliance with UN Regulation No. 155 (CSMS) required for type approval of vehicles in UNECE contracting parties.

It defines a Cybersecurity Management System (CSMS), risk assessment methodology (TARA), and requirements for distributed development, production, operations, and incident response.

Who it applies to
01

OEMs and suppliers involved in the development, production and operation of road-vehicle E/E systems.

02

Organisations pursuing UN R155 type approval for their vehicles or components.

Core obligations
Duty · 01

Organisational cybersecurity management (CSMS): policies, rules, competence, tool management.

Duty · 02

Project-dependent cybersecurity management, distributed activities and supplier management.

Duty · 03

Concept phase, product development, cybersecurity validation.

Duty · 04

Production, operations & maintenance, end of support and decommissioning.

Duty · 05

Threat analysis and risk assessment (TARA) methods.

Timeline
  1. 2016-01-01
    SAE J3061 predecessor
  2. 2020-02-01
    Draft International Standard
  3. 2021-08-31
    Published
  4. 2022-07-06
    UN R155 mandatory for new types
  5. 2024-07-01
    UN R155 mandatory for all vehicles
Official sources

License · ISO/SAE 21434 is copyrighted and must be purchased from ISO or SAE. Nix2 does not redistribute clause text; only public metadata is shown here.

Explore other frameworks