Back to Field Notes
International Standards/Field Note

Automotive Cybersecurity — ISO/SAE 21434 in the Real World

21434 is now the gating standard for road vehicles. The lifecycle obligations extend across the supplier base.

Author

Hiroshi Tanaka

OT Security Lead

Published

April 22, 2026

Read

9 min

Share
AI-generated illustration of a power plant facility
AI-generated illustration of a power plant facility
Key Takeaways
  • 01ISO/SAE 21434 has become the gating cybersecurity standard for road vehicles, working alongside UN Regulation No. 155. For manufacturers and tier-N suppliers, it imposes lifecycle obligations across design, production, and post-production.
  • 02What 21434 requires: Cybersecurity Management System (CSMS) for process-level governance, Threat Analysis and Risk Assessment (TARA) per item and per change, distributed development with security obligations across the supply chain, production-phase controls (secure manufacturing, key injection), post-production vulnerability management, incident response, and decommissioning.
  • 03Supplier obligations: suppliers cannot opt out by being upstream. The OEM's CSMS extends through Cybersecurity Interface Agreements that govern roles, responsibilities, and information flow. Build the CSMS to that standard early; retrofitting during a homologation cycle is painful.
  • 04Where this connects: 21434 maps cleanly to IEC 62443 for OT-style controls and to ISO 27001 for organizational security management. Many automotive suppliers run all three concurrently with shared evidence — audit overhead in parallel is much lower than sequential.

ISO/SAE 21434 has become the gating cybersecurity standard for road vehicles, working alongside UN Regulation No. 155. For manufacturers and tier-N suppliers, it imposes lifecycle obligations across design, production, and post-production.

What 21434 requires

  • 01Cybersecurity Management System (CSMS) — process-level governance
  • 02Threat Analysis and Risk Assessment (TARA) — per item, per change
  • 03Distributed development — security obligations across the supply chain
  • 04Production-phase controls — secure manufacturing, key injection
  • 05Post-production — vulnerability management, incident response, decommissioning

Supplier obligations

Suppliers cannot 'opt out' by being upstream. The OEM's CSMS extends to its supply chain, with documented agreements (Cybersecurity Interface Agreements) governing roles, responsibilities, and information flow. Build the CSMS to that standard early; retrofitting it during a homologation cycle is painful.

Where this connects to broader programs

21434 maps cleanly to IEC 62443 for OT-style controls and to ISO 27001 for organizational security management. Many automotive suppliers run all three concurrently with shared evidence; the audit overhead of doing them in parallel is much lower than doing them sequentially.

#ISO 21434#Automotive#OT

/WRITTEN_BY

Hiroshi Tanaka

OT Security Lead · Alexa Cybersecurity