Skip to content

ISO/SAE 21434 Certification

The ISO/SAE 21434 standard, often referred to as ISO 21434 or SAE 21434, addresses cyber security in the automotive industry by defining process-oriented security requirements for electrical and electronic systems, as well as software, IT services and vehicles, throughout the entire vehicle life cycle, in order to ensure protection against cyber attacks.

Request Offer
Ingenieure diskutieren um ein holografisches Modell eines Autos in einem High-Tech-Labor.
ISO/SAE 21434 test mark from TÜV NORD CERT GmbH

ISO/SAE 21434: Quality standard for cybersecurity in the automotive sector

Vehicles are becoming increasingly networked and therefore more susceptible to cyber attacks from outside. Cars are already equipped with wireless interfaces that offer potential attackers the opportunity to access the internal vehicle network. This could seriously jeopardise the safety of passengers and the public. Threats and vulnerabilities must be identified at an early stage and minimised through appropriate measures. Planned concepts for a wireless vehicle infrastructure pose further challenges for security managers.

This is why the UNECE has launched regulations for vehicle manufacturers and suppliers with the aim of increasing cyber security in the automotive sector. Cybersecurity in the automotive sector requires a security-related consideration of all cybersecurity aspects: Product, processes and IT systems and over the entire guaranteed service life of a vehicle.

For these reasons, ISO/SAE 21434 "Road Vehicles - Cyber Security Engineering" was introduced for cyber security in the automotive sector. The standard is process-orientated and aims to ensure the security of all electrical and, in particular, electronic systems throughout the entire life cycle of a vehicle.

Cyber security in the automotive sector and ISO/SAE 21434 therefore affect all market participants, from development, production and placing on the market through to the user.  Securing the entire supply chain plays a key role in this, enabling threats and vulnerabilities to be identified at an early stage throughout the product life cycle.

Target group for certification according to ISO/SAE 21434

  • Vehicle manufacturers
  • Suppliers of hardware and/or software-based components and/or systems
  • Engineering service providers
  • Software and ICT infrastructure service providers

For companies with complex production processes, a systematic risk assessment is a key component in identifying and addressing cyber risks at an early stage.
We at TÜV NORD CERT have extensive expertise and experience in the field of cyber security, which has enabled us to establish the world’s first accredited ISO/SAE 21434 audit programme for management systems.
We will be happy to support you in the ISO/SAE 21434 certification process. Do you have any questions about the structure and requirements of the standard? Then do not hesitate to contact us.

Advantages of a ISO/SAE 21434 certification

  • The test criteria are relevant for the automotive industry, the test and reporting procedures are standardised
  • Basis for proof of conformity with UN ECE 155/156
  • Transparency for the fulfilment of requirements towards customers and business partners through neutral verification by TÜV NORD CERT
  • Reduction of costs and risks through the identification and elimination of digital security gaps in advance
  • Minimisation of the risk of errors and reputational damage
  • Your customer focus, performance, quality and security are visible to outsiders
  • Transparent feedback from competent TÜV NORD security experts for the further development of your learning organisation
  • Accredited, certified proof of continuous improvement of your security standards against cybercrime

Audit process for ISO/SAE 21434 certification

1

01

Enquiry & quotation

2

02

Commissioning TÜV NORD

3

03

Audit stage 1: Determination of readiness for certification

4

04

Audit stage 2: Certification audit

5

05

Issue of certificate

ISO/SAE 21434 – Why does the automotive industry need a CSMS?

With increasing digitalisation and networking in the automotive sector, the risk of cyber attacks is rising. In our 5-page white paper you will learn in a compact way:

  • Background information on UNECE Regulation R 155
  • The obligation of automotive suppliers to provide evidence
  • The main requirements of ISO/SAE 21434
  • Advantages of certification
Customer information (PDF)

Successful thanks to certifications from TÜV NORD

Based on our international recognition as an IATF contract partner and our international network of experts, we are able to offer our services worldwide

TÜV NORD CERT is accredited in accordance with ISO/SAE 21434 for management system and product certifications, and we also have the necessary accreditation and recognition to carry out audits and certifications in accordance with the requirements of IATF 16949 and other management system standards. Both international audit teams and local auditors can be deployed for you.

Request an offer

FAQs about ISO/SAE 21434 certification

ISO/SAE 21434 “Road Vehicles – Cyber Security Engineering” is an international standard for cyber security in the automotive industry. The standard is often referred to as ISO 21434 or SAE 21434 and sets out requirements for securing electrical and electronic systems throughout the entire vehicle life cycle.

Automotive cyber security refers to the protection of vehicles, software, electronic control units and connected systems against cyber attacks. The ISO/SAE 21434 cyber security standard sets out requirements for processes and products within the automotive value chain.

ISO/SAE 21434 certification is important for all OEMs, system integrators and suppliers in the automotive industry.

The scope of ISO/SAE 21434 covers electrical and electronic systems, software, hardware and connected components of road vehicles throughout their entire life cycle.

Although TISAX® is also aimed at OEM suppliers, it does not involve product testing. Instead, the assessments focus on the security of an organization's information, including its interfaces and processes.
ISO/SAE 21434 goes one step further and ensures that products are created that are secure against cyber attacks.

ISO 21434 applies to vehicle manufacturers, suppliers, software providers and engineering service providers. The standard is suitable for connected components, systems, software and hardware across the entire automotive sector.

From 1 January 2022, UN ECE 155 will require mandatory proof of a cybersecurity management system for the automotive sector. Compliance with ISO 21434 is one way of providing this proof.

Do you have any further questions? Our team, led by Felix Rehbein and Toheeb Ajibola, is here to assist you, together with the auditors.

ISMS Sales & Projectmanagement, TÜV NORD CERT GmbH

Competent, international, TÜV NORD CERT

TÜV NORD CERT GmbH

TÜV NORD CERT is an internationally recognised and reliable partner for testing and certification services. Our experts and auditors possess in-depth knowledge and are all permanently employed by TÜV NORD. This ensures independence, impartiality and continuity in the support we provide to our clients. The benefit for you is clear: our auditors guide and support the development of your business and provide you with objective feedback.

This may also interest you