Skip to content

GUIDE · Product security

Automotive cybersecurity: standards, regulation and engineering practice

This is the entry point to the automotive cybersecurity cluster: which instrument applies to what, how the risk method works, what an audit asks for, and where programmes typically lose time.

LAST REVIEWED

Which instrument applies to what

Most confusion in automotive cybersecurity programmes comes from treating standards, type-approval regulation and product regulation as one requirement set. They are separate instruments with separate evidence expectations, and conformity to one does not discharge the others. A vehicle manufacturer typically needs UN R155 approval, uses ISO/SAE 21434 as the technical basis for it, and still has to determine whether accessories or aftermarket connected products fall under the Cyber Resilience Act.

InstrumentApplies toPrimary evidence
ISO/SAE 21434Road vehicle E/E systems, all lifecycle phasesTARA outputs traceable to cybersecurity goals, requirements and verification
UN Regulation No. 155Vehicle type approval in adopting marketsCertified cybersecurity management system, audited at organisational level
UN Regulation No. 156Software update processes for type-approved vehiclesSoftware update management system and update integrity records
Cyber Resilience Act (EU) 2024/2847Connected products with digital elements outside vehicle type approvalRisk assessment, SBOM, vulnerability handling, technical documentation
ISO 26262Functional safety of E/E systemsHazard analysis, ASIL allocation, safety case — coordinated with the TARA
The instruments that govern automotive cybersecurity and what each one asks for.

The risk method: threat analysis and risk assessment

The technical core of automotive cybersecurity is the TARA. It identifies assets and their cybersecurity properties, derives threat scenarios, analyses attack paths and rates their feasibility, rates impact across safety, financial, operational and privacy dimensions, and produces a risk value that drives treatment decisions and cybersecurity requirements. Done well, it is a living analysis maintained alongside the architecture. Done badly, it is a spreadsheet produced once at concept stage that no reviewer can reconstruct.

The organisational layer: cybersecurity management system

Engineering evidence alone does not satisfy an automotive cybersecurity audit. UN R155 requires a certified cybersecurity management system covering governance, competence, risk management, supplier control, incident response and post-production monitoring, and ISO/SAE 21434 places equivalent organisational requirements around the project-level work. Programmes that resource only the project work and treat the management system as documentation typically fail their first audit on organisational evidence, not on technical analysis.

Where safety and security have to meet

A security compromise can be the initiating cause of a safety-relevant malfunction — a manipulated message to a braking or steering function is the standard example. Neither a hazard analysis nor a TARA finds this class of risk on its own, because each starts from a different failure model. The practical fix is a shared asset and function model reviewed jointly by safety and security engineers, with an explicit reconciliation step between hazard and threat catalogues.

Where programmes lose time

  • Deciding instrument applicability late, after architecture decisions have already been made.
  • A TARA whose feasibility ratings have no documented method, so risk values cannot be defended under audit.
  • Cybersecurity requirements with no traceability to the threat scenario they mitigate.
  • Supplier assurance left undefined through Tier 2 and Tier 3, where cybersecurity engineering maturity varies widely.
  • Post-production monitoring run as general IT security rather than a defined process feeding the vehicle's cybersecurity case.

Frequently asked questions

What is automotive cybersecurity?

Automotive cybersecurity is the engineering and management of cybersecurity risk in road vehicle electrical and electronic systems, across concept, development, production, operation and decommissioning. It covers both technical analysis such as the TARA and organisational processes such as a cybersecurity management system.

Is ISO/SAE 21434 mandatory?

No. ISO/SAE 21434 is a voluntary standard. UN Regulation No. 155 is the mandatory instrument in adopting markets, and manufacturers commonly use ISO/SAE 21434 as the technical basis for demonstrating that their cybersecurity management system and engineering processes meet it.

Does the Cyber Resilience Act apply to vehicles?

Vehicles covered by EU type-approval cybersecurity requirements are excluded from the corresponding CRA obligations, but connected accessories, aftermarket devices and standalone software outside type approval can fall within CRA scope. Applicability has to be confirmed per product rather than assumed for the sector.

How do ISO 26262 and ISO/SAE 21434 work together?

ISO 26262 addresses hazards from malfunctioning behaviour; ISO/SAE 21434 addresses cybersecurity threats. They meet where a compromise could cause a safety hazard, which requires the hazard analysis and the TARA to inform each other through a shared asset and function model.

What does an automotive cybersecurity audit look at?

Auditors examine the cybersecurity management system at organisational level, TARA outputs traceable to cybersecurity goals and requirements, verification evidence matched to assurance level, supplier assurance arrangements, and evidence of ongoing monitoring and incident response for vehicles in the field.