GUIDE · Product security
Automotive cybersecurity: standards, regulation and engineering practice
This is the entry point to the automotive cybersecurity cluster: which instrument applies to what, how the risk method works, what an audit asks for, and where programmes typically lose time.
LAST REVIEWED
Which instrument applies to what
Most confusion in automotive cybersecurity programmes comes from treating standards, type-approval regulation and product regulation as one requirement set. They are separate instruments with separate evidence expectations, and conformity to one does not discharge the others. A vehicle manufacturer typically needs UN R155 approval, uses ISO/SAE 21434 as the technical basis for it, and still has to determine whether accessories or aftermarket connected products fall under the Cyber Resilience Act.
| Instrument | Applies to | Primary evidence |
|---|---|---|
| ISO/SAE 21434 | Road vehicle E/E systems, all lifecycle phases | TARA outputs traceable to cybersecurity goals, requirements and verification |
| UN Regulation No. 155 | Vehicle type approval in adopting markets | Certified cybersecurity management system, audited at organisational level |
| UN Regulation No. 156 | Software update processes for type-approved vehicles | Software update management system and update integrity records |
| Cyber Resilience Act (EU) 2024/2847 | Connected products with digital elements outside vehicle type approval | Risk assessment, SBOM, vulnerability handling, technical documentation |
| ISO 26262 | Functional safety of E/E systems | Hazard analysis, ASIL allocation, safety case — coordinated with the TARA |
The risk method: threat analysis and risk assessment
The technical core of automotive cybersecurity is the TARA. It identifies assets and their cybersecurity properties, derives threat scenarios, analyses attack paths and rates their feasibility, rates impact across safety, financial, operational and privacy dimensions, and produces a risk value that drives treatment decisions and cybersecurity requirements. Done well, it is a living analysis maintained alongside the architecture. Done badly, it is a spreadsheet produced once at concept stage that no reviewer can reconstruct.
The organisational layer: cybersecurity management system
Engineering evidence alone does not satisfy an automotive cybersecurity audit. UN R155 requires a certified cybersecurity management system covering governance, competence, risk management, supplier control, incident response and post-production monitoring, and ISO/SAE 21434 places equivalent organisational requirements around the project-level work. Programmes that resource only the project work and treat the management system as documentation typically fail their first audit on organisational evidence, not on technical analysis.
Where safety and security have to meet
A security compromise can be the initiating cause of a safety-relevant malfunction — a manipulated message to a braking or steering function is the standard example. Neither a hazard analysis nor a TARA finds this class of risk on its own, because each starts from a different failure model. The practical fix is a shared asset and function model reviewed jointly by safety and security engineers, with an explicit reconciliation step between hazard and threat catalogues.
Where programmes lose time
- Deciding instrument applicability late, after architecture decisions have already been made.
- A TARA whose feasibility ratings have no documented method, so risk values cannot be defended under audit.
- Cybersecurity requirements with no traceability to the threat scenario they mitigate.
- Supplier assurance left undefined through Tier 2 and Tier 3, where cybersecurity engineering maturity varies widely.
- Post-production monitoring run as general IT security rather than a defined process feeding the vehicle's cybersecurity case.
Frequently asked questions
What is automotive cybersecurity?
Automotive cybersecurity is the engineering and management of cybersecurity risk in road vehicle electrical and electronic systems, across concept, development, production, operation and decommissioning. It covers both technical analysis such as the TARA and organisational processes such as a cybersecurity management system.
Is ISO/SAE 21434 mandatory?
No. ISO/SAE 21434 is a voluntary standard. UN Regulation No. 155 is the mandatory instrument in adopting markets, and manufacturers commonly use ISO/SAE 21434 as the technical basis for demonstrating that their cybersecurity management system and engineering processes meet it.
Does the Cyber Resilience Act apply to vehicles?
Vehicles covered by EU type-approval cybersecurity requirements are excluded from the corresponding CRA obligations, but connected accessories, aftermarket devices and standalone software outside type approval can fall within CRA scope. Applicability has to be confirmed per product rather than assumed for the sector.
How do ISO 26262 and ISO/SAE 21434 work together?
ISO 26262 addresses hazards from malfunctioning behaviour; ISO/SAE 21434 addresses cybersecurity threats. They meet where a compromise could cause a safety hazard, which requires the hazard analysis and the TARA to inform each other through a shared asset and function model.
What does an automotive cybersecurity audit look at?
Auditors examine the cybersecurity management system at organisational level, TARA outputs traceable to cybersecurity goals and requirements, verification evidence matched to assurance level, supplier assurance arrangements, and evidence of ongoing monitoring and incident response for vehicles in the field.