Skip to content

Independent standards discovery and compliance platform

How we work
European standard guide European standard guide

ISO/SAE 21434

ISO/SAE 21434

An automotive cybersecurity engineering contract should cover decisions and support across the product's life, not just a one-off test. ISO/SAE 21434 is the publication to examine for that engineering assignment. The buying brief should identify the vehicle system, supplier interfaces and responsibility for information after delivery.
Editorial guide Content updated 7 October 2026
On this page
  1. Choose the published ISO/SAE 21434:2021 edition
  2. The cybersecurity engineering scope
  3. Allocate cybersecurity responsibilities
  4. Questions for a component or service supplier
  5. Example: sourcing a connected control module
  6. Keep functional safety and legal conclusions explicit
  7. Frequently asked buying questions
  8. Related guidance
  9. Explore more standards buying guides

Choose the published ISO/SAE 21434:2021 edition

The cybersecurity engineering scope

The public scope addresses cybersecurity risk management for road-vehicle electrical/electronic systems, components and interfaces across development, production, operation, maintenance and decommissioning. It does not prescribe a particular security technology. The ISO publication record confirms the edition and revision status.

Describe the proposed system and the organisations involved. A security-tool subscription, penetration test and lifecycle engineering service are different purchases. State what decisions and evidence are expected so the supplier can quote the correct assignment.

Allocate cybersecurity responsibilities

Original automotive cybersecurity supplier map
Work boundaryQuestion to settle in the contract
System and interfacesWhich component, connections and product assumptions are included?
Engineering evidenceWhich records will be delivered and who reviews them?
Post-delivery informationWho receives, evaluates and communicates relevant vulnerability information?
Changes and supportWho reviews updates and supports the agreed product versions?

The map is a purchasing aid rather than a prescribed process checklist. The responsible engineering team must define the project activities and evidence. Ask it to explain which tasks are performed internally and which are assigned to suppliers.

Questions for a component or service supplier

  • Does the offer identify the exact product versions and interfaces covered?
  • Which customer information is needed before the supplier can complete its work?
  • How are assumptions and unresolved risks communicated to the vehicle team?
  • Which deliverables are engineering records, and which are individual test results?
  • What support, notification and review arrangements continue after delivery?

Make the supplier explain exclusions and dependencies. If a third party owns a software component or connection, identify who obtains the information needed for review. A fixed-price offer is easier to assess when those dependencies have named owners.

Example: sourcing a connected control module

A vehicle programme buys a control module with connected functions. One supplier offers an engineering evidence package; another quotes a security test against the current firmware. The buyer asks both to respond to the same system description and to state which lifecycle responsibilities their offers cover.

The resulting comparison shows which work is included and which remains with the vehicle team. The final contract names evidence handover, supported versions and contacts for relevant post-delivery information. The example does not choose a security design or declare the module secure.

Coordinate cybersecurity with other project assignments through shared system identities and interfaces. The ISO 26262-3 buying guide concerns a functional safety concept assignment. Define each team's work and review points without treating the two documents as substitutes.

If a contract requires a regulatory conclusion, describe that separate deliverable and obtain a current, project-specific assessment. The publication's identity or a completed test does not by itself answer the full vehicle approval question. This article focuses on defining a useful purchase.

Frequently asked buying questions

Does the standard require one specific security tool?

The public scope does not prescribe a particular technology. Ask the engineering team to justify proposed methods and tools for the actual assignment.

Is a penetration test the complete purchase?

It can be a defined service within a project. Compare its stated scope with the broader engineering and support responsibilities the buyer needs.

Has a new edition replaced 2021?

The checked records list the 2021 edition as published and its successor under development. Confirm status again when agreeing a later project basis.

Continue with automotive functional safety concept work and the electrotechnical overview.

Explore more standards buying guides

Browse standards by reference and subject to compare related document choices.

From reading to action

Need help interpreting, implementing or testing against this standard?

Describe the product, organisation, target market and decision you need to make. We will direct you to the most relevant guide or specialist route available on the platform.

Describe your project