Keyfactor Tech Days 2027 – Be Part of The Trust Security Conference in San Diego Register now!

ISO/SAE 21434:

Cryptography and PKI for Automotive Cybersecurity Engineering

Updated: August 24, 2026
Region International (jointly published by ISO and SAE; underpins the UNECE UN R155 regulation applied in the EU, UK, Japan, South Korea, and other UNECE member states) 
Applicability OEMs (Vehicle Manufacturers): responsible for the organizational Cybersecurity Management System (CSMS) required for UN R155 type approval Tier 1 and Tier 2 Suppliers: ECU and component manufacturers required to provide cybersecurity engineering evidence and meet OEM interface agreements Aftermarket and Telematics Providers: organizations delivering over-the-air software updates and connected services to vehicles already in the field 
Relevant sections Clause 15: Threat Analysis and Risk Assessment (TARA) Clauses 9 and 10: Cybersecurity requirements and architecture in the concept and product development phases UNECE UN R155: Cybersecurity Management System regulation that ISO/SAE 21434 provides engineering evidence to support 

Overview

ISO/SAE 21434:2021, “Road vehicles — Cybersecurity engineering,” defines engineering requirements for cybersecurity risk management across the full vehicle lifecycle, from concept and product development through production, operation, maintenance, and decommissioning. It is the recognized engineering framework supporting UNECE UN R155, which is a legal precondition for vehicle type approval across UNECE contracting markets. 

In practical terms, Clause 15’s Threat Analysis and Risk Assessment (TARA) is the standard’s core methodology: asset identification, threat scenario identification, impact rating, attack path analysis, and risk determination, applied to every cybersecurity-relevant item, including ECUs, in-vehicle buses, and external interfaces such as V2X, Bluetooth, and OBD ports. 

Why It Matters 

Non-compliance with UN R155, which ISO/SAE 21434 provides the engineering evidence to satisfy, can mean a vehicle is refused type approval or barred from sale in UNECE member markets, making this a market-access issue as immediate as the EU Cyber Resilience Act covered earlier in this guide. 

OEMs increasingly cascade ISO/SAE 21434 requirements contractually to Tier 1 and Tier 2 suppliers, so a supplier unable to produce cybersecurity work-product evidence risks losing the supply contract itself, not just failing an audit; and because vehicles typically remain in service for 15 years or more, the cryptographic and key-management choices made at production must remain sound for the vehicle’s entire operational life. 

How This Maps to Cryptography 

ISO/SAE 21434 addresses cryptography across the concept, development, and production phases of the vehicle lifecycle. The key control areas with direct cryptographic implications are: 

SectionFunction What it says Products
Clauses 9–10 — Cybersecurity requirements and architecture; supports AUTOSAR SecOC Secure Onboard Communication Certificate and message-authentication-code based authentication of in-vehicle bus traffic (CAN, Ethernet) between ECUs EJBCA 
Clause 10 — Product development, cybersecurity specification ECU and Device Identity Provisioning Unique cryptographic identity provisioned per ECU at the point of manufacture for authenticated communication and diagnostics EJBCA 
Clause 10 — Post-development and OTA update handling Secure Software and Firmware Update Cryptographically signed firmware and over-the-air update packages, verified before installation on any ECU SignServer / Signum 
Clause 15 — TARA risk treatment; continual cybersecurity activities Cryptographic Key Management Across the Vehicle Lifecycle Lifecycle management of ECU keys and certificates from production through 15-plus years of field service, including revocation and re-keying Command 
Clause 9 — Concept phase threat scenarios for external interfaces V2X and External Interface Authentication PKI-backed certificates authenticating vehicle-to-everything (V2X) messages and other external interfaces EJBCA 
Clause 5 — Distributed cybersecurity activities; supplier interface agreements Cryptographic Component Inventory Inventory of cryptographic libraries and algorithms across ECUs and supplier components, supporting TARA and OEM audits AgileSec 

Audit Readiness 

ISO/SAE 21434 conformance is assessed through CSMS audits and product-level cybersecurity assessments, focused on documented engineering evidence rather than a policy statement alone. Key areas that OEM and third-party assessors probe: 

  • TARA Coverage: Has a Threat Analysis and Risk Assessment been performed and documented for every cybersecurity-relevant item, including ECUs, buses, and external interfaces? 
  • ECU Identity Provisioning Evidence: Is a unique cryptographic identity provisioned to each ECU at the point of manufacture, rather than a shared key across a platform or fleet? 
  • Signed Update Pipeline: Can the organization demonstrate that firmware and over-the-air updates are cryptographically signed and verified before installation? 
  • Key Lifecycle Across the Vehicle’s Service Life: Are procedures documented for key rotation, re-keying, and revocation across a vehicle service life of 15 years or more? 
  • Supplier Cybersecurity Interface Agreements: Do supplier agreements specify cryptographic requirements and cybersecurity work-product evidence for supplied components? 
  • CSMS Alignment with UN R155: Is the organizational Cybersecurity Management System aligned with UN R155 and supported by documented ISO/SAE 21434 engineering evidence?