Next Generation Standard in Cyber Security for Road Vehicles
ISO/SAE 21434 is an international standard developed for the automotive industry that aims to systematically manage cyber security risks throughout the entire vehicle lifecycle. This standard provides a basic framework for securing vehicle systems against digital threats in today’s rapidly evolving connected and autonomous vehicle technologies.
Purpose of ISO/SAE 21434 Standard
ISO/SAE 21434 aims to make vehicles resistant to cyber threats from the concept stage to production, maintenance and even decommissioning. It requires the security of hardware, software, communication interfaces and all external systems.
Benefits of ISO/SAE 21434
- Cyber Security Risk Management: Provides a systematic security approach with threat modelling, risk assessment and security controls.
- Supply Chain Assurance: Creates a common security language for OEM and supplier integration.
- Compliance and Regulatory Readiness: Provides the technical basis for regulatory requirements such as UNECE WP.29 R155.
- Customer Trust: Provides a high perception of safety for users of connected and autonomous vehicles.
- Competitive Advantage: Offers strategic differentiation for brands investing in automotive cyber security.
Who is it suitable for?
- Automotive OEMs (vehicle manufacturers)
- Tier-1/Tier-2 suppliers
- Automotive software and electronic system developers
- Embedded system providers
- Companies developing mobility and connected vehicle technology
Why CFE CERT?
- Technical expertise in cyber security and automotive systems
- Integrated audit approaches specific to the supply chain
- Solutions compliant with global regulations (UNECE R155, R156)
- Certification and audit experience in 25+ countries
Certification Process
As CFE CERT, we provide evaluation and certification services within the scope of ISO / SAE 21434 standard with expert auditors and sectoral experience:
- Readiness and System Assessment (Optional) – The maturity of existing safety processes is analysed.
- Certification Audit – Phase 1 – Scope, documentation and technical control plans are reviewed.
- Certification Audit – Phase 2 – Threat modelling, risk assessment and implementation controls are audited during the product development process.
- Certification – ISO/SAE 21434 certificate is issued for systems compliant with the standard.
- Surveillance Audits – Annual audits are conducted to ensure the sustainability of processes.
- Recertification – Every 3 years the system is re-evaluated for currency.