Official publication of ISO/SAE 21434:2021. All info here (Update: August 2021)

ISO/SAE 21434:2021 is now officially published.

ISO/SAE 21434 is considered a milestone for the automotive industry regarding cybersecurity. As of today, ISO/SAE 21434 has the new status “International Standard published”. What does this mean for the industry? We provide an overview in the following article and in a upcoming info webcast for which you can register free of charge.

First of all, the most important questions regarding the publication that has now taken place at a glance.

ISO/SAE 21434:2021: What you need to know now

However, regardless of that, let’s get started:

What is ISO/SAE 21434 in short?

ISO/SAE 21434 is to be considered as state of the art and thus as a binding reference point for cybersecurity in the automotive industry across large parts of the world. For the first time, the standard sets up a defined expectation respectively defined minimum cybersecurity requirements. Furthermore the standard defines a unified terminology that is valid along the entire supply chain and is intended to create an industry-specific consensus regarding cybersecurity in the automotive industry.

Why is ISO/SAE 21434 important?

Modern cars are becoming a very tempting target for cyberattacks and also multiply cyber risks due to the increasing amount of interfaces as a result of the progressing digitization.

From ever new steps forward and backwards on mega Trends in automotive cyber security, such as autonomous driving, over to the advancement of e-mobility and all the sophisticated data-based and always-online systems running onboard.

As the digitalization accelerates, cybersecurity is becoming an essential part in the automotive industry, an absolutely serious quality dimension for automobiles, if not the most important issue across the value chain. For an increasing number of positions in the diverse automotive industry, cybersecurity is becoming an absolutely unavoidable part of doing business. There is a real world need to think about cybersecurity today and to act accordingly. Compared to other industries, which have already built up real cybersecurity and IT security bastions, cybersecurity is being established in the automotive industry. This is where standards and regulations for harmonization come into play.

What is impacted by the ISO/SAE 21434?

The ISO/SAE 21434 will be valid for road vehicle type E/E systems, including their components, software and interfaces up to any external network or device.

All phases of the vehicle lifecycle, including design, engineering, production, operation, maintenance and decommissioning, are relevant for the compliance with ISO/SAE 21434.

How will ISO/SAE 21434 affect the ecosystem around road vehicles?

No matter if you are car manufacturer or Tier-n supplier – your organization will be affected by ISO/SAE 21434 on all levels:

Organizational level: Starting at C-level management, general awareness about cybersecurity must be given in all relevant departments. Decision-makers need to have an overview about: Why does cybersecurity matter? What kind of certification is necessary? How can cybersecurity awareness be spread onto other levels of the organization? What about documentation to have a proof of compliance when it comes to legal issues?

Project level: from the initial kick-off to the final completion of projects, cybersecurity in project management must be considered at every single step to guarantee that the entire product in itself is cybersecure.

Engineering level: steering wheels, headlights, sensors, radar and LiDAR systems, lane keeping systems, software – every single connected component of the vehicle must be cybersecure.

Is the ISO/SAE 21434 released?

The ISO/SAE 21434:2021 Road Vehicles – Cybersecurity Engineering has been officially released in its latest version on August 31, 2021. Thus, the release of the ISO/SAE 21434 standard replaces the previous draft versions (the DIS version from February 2020 as well as the latest FDIS version from May 2021).

Where can ISO/SAE 21434:2021 be officially purchased?

The document of the standard can be purchased in PDF format or hard copy on the official website of the International Standard Organization and (soon) probably also through the DIN at Beuth Verlag. In addition, the official Table of Contents and the general overview of the standard can be viewed via the ISO Online Browsing Platform.

What are the differences between the now released ISO/SAE 21434:2021 and the previous draft versions?

Since the start of the standard, the entire automotive industry has been keeping an eagle eye on what ISO/SAE 21434 requires of the stakeholders in the automotive value chain. Accordingly, even apparently minor adjustments and changes in the structure or wording of the standard can have far-reaching effects on practice.

From the draft versions to the officially published version, the structure of the document, i.e. the entire structure of ISO/SAE 21434, has changed from the DIS version once again. However, this change in the structure is not accompanied by serious changes in the content of the standard.

What is the structure of ISO/SAE 21434:2021?

The first thing to do is to think in the same way as ISO/SAE communicates: The structure of ISO/SAE 21434 does not represent an “execution sequence” of the individual topics.

For the official structure of ISO/SAE 21434:2021, we have created a custom graphical visualization that illustrates the structure not in sequence, but along the development product lifecycle:


The structure of ISO/SAE 21434:2021 in the order given in the now released document:

Clause 4 (General considerations) is informational and includes the context and perspective of the approach to road vehicle cybersecurity engineering.

  • Clause 6 (Project dependent cybersecurity management) includes the cybersecurity management and cybersecurity activities at the project level
  • Clause 7 (Distributed cybersecurity activities) includes requirements for assigning responsibilities for cybersecurity activities between customer and supplier, in other words distributed development
  • Clause 8 (Continual cybersecurity activities) includes activities that provide information for ongoing risk assessments and defines vulnerability management of E/E systems until end of cybersecurity support.
  • Clause 9 (Concept) includes activities that determine cybersecurity risks, cybersecurity goals and cybersecurity requirements for an item. You can also watch our Cybersecurity Concept video course.
  • Clause 10 (Product development) includes activities that define the cybersecurity specifications, and implement and verify cybersecurity requirements
  • Clause 11 (Cybersecurity validation) includes the cybersecurity validation of an item at the vehicle level
  • Clause 12 (Production) includes the cybersecurity-related aspects of manufacturing and assembly of an item or component
  • Clause 13 (Operations and maintenance) includes activities related to cybersecurity incident response and updates to an item or component
  • Clause 14 (End of cybersecurity support and decommissioning) includes cybersecurity considerations for end of support and decommissioning of an item or component

Clauses 5 to 15 are followed by the annexes, which summarize the cybersecurity activities and work products, among other things.

Does the ISO/SAE 21434 provide guidance?

Important to know: The standard is purposely kept in an abstract way.

It only describes the intention of a process and intentionally leaves the actual design of the process in the hands of the user. At the same time, to cope with the fast pace of cybersecurity development, the standard does not provide specific cybersecurity technologies or solutions, recovery solutions or clearly specified technical requirements.

How is the ISO/SAE 21434 related to the UN Regulation No. 155?

In the context of the ISO/SAE 21434 standard, the question of the relation to UN Regulation No. 155 (which was developed by UNECE WP.29) always comes up. It is advised to comply with at least 100 requirements of ISO/SAE 21434 to comply to UN R155, which will become mandatory for the approval of all new vehicle types by July 2022. Since insufficient compliance with UN Regulation No. 155 leads to a sales ban in 64 UNECE member countries, the relationship with ISO/SAE 21434 arises. For a more detailed explanation, we recommend a look at our blog UN R155.

Will there be relevant audits for ISO/SAE 21434?

In order to fill up the space ISO/SAE 21434 leaves for the scope definition and process of audits and assessments, the ISO Working Group 11 (or short WG11) wants to bring guidelines into life to ensure a consistent scope and provide a roadmap for such audits. This is where ISO PAS 5112 Road vehicles – Guidelines for auditing cybersecurity engineering comes into play, which you can learn more about in our blog article.

ISO/SAE 21434 DIS, FDIS and the latest publication: What are the differences?

Although the ISO/SAE 21434 was only officially published a few hours ago, the previous versions have already been made publicly available in recent months.

First as a committee draft, then as a draft international standard (DIS for short) and finally with the newer final draft international standard (FDIS for short), which had only received little publicity.

Accordingly, automotive cybersecurity education providers and automotive cybersecurity practitioners have relied on the draft versions of ISO/SAE 21434 in recent months and years to understand the requirements and work products.

Thus, starting from the first public available version (DIS) the ISO/SAE 21434 was considered as state-of-the-art reference document for automotive cybersecurity.

With the release of the official version, these draft versions will be more or less obsolete for upcoming development projects; it can be assumed that from now on, only the reference to ISO/SAE 21434:2021 will be on the agenda in automotive projects.

Your customer demands in a Statement of Work the application of ISO/SAE 21434 in the now published official version?

We believe that it is essential to compare the different versions of ISO/SAE 21434 in order to be able to adapt the requirements to your projects and product development if necessary.  This requires a dedicated synchronization, the simple comparison of the last three versions side by side is not sufficient.

For this purpose, we have been working intensively over the last few months on a ISO/SAE 21434 synchronization tool that allows you to compare the different versions of the standard in a way that is as straightforward and user-friendly as possible.

Additional Information materials next to the document of the standard

The ISO/SAE 21434 Road Vehicles – Cybersecurity Engineering is the main reference for automotive cybersecurity. Even though the ISO/SAE 21434 is only now officially published, further information is already available at the start.

