
- 01ISO/SAE 21434 has become the gating cybersecurity standard for road vehicles, working alongside UN Regulation No. 155. For manufacturers and tier-N suppliers, it imposes lifecycle obligations across design, production, and post-production.
- 02What 21434 requires: Cybersecurity Management System (CSMS) for process-level governance, Threat Analysis and Risk Assessment (TARA) per item and per change, distributed development with security obligations across the supply chain, production-phase controls (secure manufacturing, key injection), post-production vulnerability management, incident response, and decommissioning.
- 03Supplier obligations: suppliers cannot opt out by being upstream. The OEM's CSMS extends through Cybersecurity Interface Agreements that govern roles, responsibilities, and information flow. Build the CSMS to that standard early; retrofitting during a homologation cycle is painful.
- 04Where this connects: 21434 maps cleanly to IEC 62443 for OT-style controls and to ISO 27001 for organizational security management. Many automotive suppliers run all three concurrently with shared evidence — audit overhead in parallel is much lower than sequential.
ISO/SAE 21434 has become the gating cybersecurity standard for road vehicles, working alongside UN Regulation No. 155. For manufacturers and tier-N suppliers, it imposes lifecycle obligations across design, production, and post-production.
What 21434 requires
- 01Cybersecurity Management System (CSMS) — process-level governance
- 02Threat Analysis and Risk Assessment (TARA) — per item, per change
- 03Distributed development — security obligations across the supply chain
- 04Production-phase controls — secure manufacturing, key injection
- 05Post-production — vulnerability management, incident response, decommissioning
Supplier obligations
Suppliers cannot 'opt out' by being upstream. The OEM's CSMS extends to its supply chain, with documented agreements (Cybersecurity Interface Agreements) governing roles, responsibilities, and information flow. Build the CSMS to that standard early; retrofitting it during a homologation cycle is painful.
Where this connects to broader programs
21434 maps cleanly to IEC 62443 for OT-style controls and to ISO 27001 for organizational security management. Many automotive suppliers run all three concurrently with shared evidence; the audit overhead of doing them in parallel is much lower than doing them sequentially.


