Article details
- Category
- Blog
- Published
- Reading time
- 9 min read
- Author
- AutoSec Academy · Practitioner Editorial Team
ISO/SAE 21434 is the international standard for road vehicle cybersecurity engineering. It is frequently reduced in conversation to its risk assessment method, but the method is one clause among many. What the standard actually defines is a set of lifecycle activities — and, crucially, the evidence that those activities produced a defensible result.
The lifecycle, not the document
The standard organises work across concept, product development, production, operations and maintenance, and decommissioning. Most organisations discover their gap is not in the concept phase, where enthusiasm is high, but in operations: monitoring for new vulnerabilities affecting a vehicle already in the field, and being able to act on them for the remainder of a fifteen-year service life.
What an assessor is actually looking for
- An item definition that establishes boundaries, interfaces and assumptions before any analysis begins
- Threat scenarios traceable to identified assets and damage scenarios
- Attack paths with a feasibility rating that a second engineer could reproduce
- Cybersecurity goals and requirements that flow into actual design artefacts
- Evidence that the above was reviewed, not merely produced
Supplier interfaces are where it breaks
The standard requires a Cybersecurity Interface Agreement between customer and supplier, allocating responsibility for each activity. In practice this is the clause most often signed and then ignored. When an OEM cannot evidence which party performed the TARA for a bought-in ECU, neither party can close the finding.
Treat the interface agreement as a working engineering document rather than a procurement artefact, and review it when the design changes. That single discipline resolves a disproportionate share of audit findings.