What Are the ISO/SAE 21434 and UN R155 Automotive Cybersecurity Standards?
UN R155 mandates a cybersecurity management system for vehicle type approval, and ISO/SAE 21434 is its technical guide defining the TARA methodology. What these mean for a manufacturer and how they are applied.
Quick answer: ISO/SAE 21434 and UN Regulation No. 155 (UN R155) are two complementary documents that define how cybersecurity must be managed across a vehicle's entire life, from design to end of life. UN R155 legally requires manufacturers in the European Union and many other countries to operate a Cybersecurity Management System (CSMS) before a new vehicle type can be approved for sale; ISO/SAE 21434 describes in technical detail how that system should be built, including a threat analysis and risk assessment method called TARA. In short, R155 is the law and ISO/SAE 21434 is the technical guide to complying with it; a manufacturer cannot bring a modern vehicle type to market without applying both together.
A penetration test report or a list of vulnerabilities is only the visible part of automotive cybersecurity. The real shift is that regulators now tell manufacturers not just make your vehicle secure but prove how you manage security. The two documents that make this possible are UN R155 and ISO/SAE 21434.
UN R155: the legal requirement
UN R155 was published by the WP.29 working group of the United Nations Economic Commission for Europe (UNECE) and has been mandatory for all new vehicle types in the European Union since 2024; similar regulations are in force in Japan, South Korea and other countries. The regulation requires a manufacturer to prove two things before a vehicle type can be approved: first, that it operates a Cybersecurity Management System (CSMS) at the organizational level; second, that risks have been identified and mitigated for that specific vehicle type.
| Concept | Meaning |
|---|---|
| CSMS | Cybersecurity Management System, the organization's process level management system |
| Type approval | A vehicle type that does not comply with R155 cannot be sold in the European market |
| Lifetime scope | Approval is not a one time event, post production monitoring is also mandatory |
ISO/SAE 21434: the technical guide
ISO/SAE 21434 Road vehicles Cybersecurity engineering translates what R155 requires into technical engineering language. The standard treats security not as a single checkpoint but as a life cycle spanning from the vehicle's concept design through post production monitoring.
At the heart of the standard is the TARA (Threat Analysis and Risk Assessment) methodology. TARA consists of seven steps: asset identification, deriving threat scenarios, assessing impact, modeling attack paths, assessing attack feasibility, calculating risk level, and finally deciding on risk treatment. This process resembles a threat modeling exercise but is specifically adapted to the automotive context.
Other related standards
Around ISO/SAE 21434 there are other standards that complete the picture: ISO 24089 defines how software update management (SUMS) is handled over the vehicle's life and pairs with UN R156; TISAX is a German automotive industry framework that assesses the information security maturity of supply chain companies; Automotive SPICE for Cybersecurity measures how mature the software development process is from a cybersecurity perspective. Together these standards, similar to ISO 27001 information security certification, make an organization's processes externally auditable.
What changes for a manufacturer
The technical counterpart of this framework is, for example, a concrete security assessment of a vehicle's CAN bus and UDS diagnostic surface; the attack path and impact fields of a TARA report are filled precisely by findings coming from this kind of technical testing.
Before these standards, a manufacturer could treat cybersecurity as an optional quality step. Now, every manufacturer seeking type approval and every supplier feeding parts to it directly or indirectly must document that its processes comply with this framework. This requires both a top level CSMS audit and a separate TARA report for each vehicle type; both must be regularly updated and reassessed as new threats emerge.
The KAOS and DSET approach
DSET provides technical support to organizations during ISO/SAE 21434 and UN R155 compliance, producing concrete, runnable evidence especially at the asset identification and attack path modeling stages required by the TARA methodology. Our local AI engine KAOS links technical findings in a vehicle system, such as an unprotected UDS service, directly to a CVSS based impact assessment, turning the technical input of a TARA report into evidence based work instead of a paperwork exercise.
Frequently asked questions
Is UN R155 only valid in Europe? Mandatory enforcement currently applies in the European Union and countries party to the UNECE 1958 agreement, but countries such as Japan and South Korea have adapted similar regulations into their own legislation. China and India are also developing their own automotive cybersecurity regulations; the global trend is toward such requirements becoming widespread.
Does complying with ISO/SAE 21434 mean the vehicle cannot be hacked? No. The standard does not guarantee zero risk; instead it requires that risk be systematically identified, assessed and reduced to an acceptable level. Even a manufacturer fully compliant with the standard can have a new vulnerability discovered; what matters is how that vulnerability is managed.
Who should prepare the TARA report? TARA is an interdisciplinary effort requiring both vehicle engineering knowledge and cybersecurity expertise. Typically the manufacturer's own engineering team prepares the report together with an outside cybersecurity consultancy; having technical findings come from an independent party increases the report's credibility.
Sources
- UNECE UN Regulation No. 155 Cyber security and cyber security management system: https://unece.org
- ISO/SAE 21434:2021 Road vehicles Cybersecurity engineering: https://www.iso.org
- DSET Cybersecurity and Compliance Consulting Services: https://dset.com.tr/hizmetler
To get technical support for your organization's ISO/SAE 21434 and UN R155 compliance, contact DSET. We provide automotive cybersecurity compliance consulting from our Ankara Hacettepe Teknokent laboratory.
Kimliğinizi doğrulayın
Yetkilendirilmiş erişim alanı. Tüm giriş denemeleri kayıt altına alınır.