ISO/SAE 21434 defines cybersecurity engineering across the vehicle lifecycle: organisational capability (the CSMS), item-level TARA, cybersecurity goals and claims, product development controls, validation, incident response and end-of-support decisions. Its enforcement mechanism is what makes it unusual — UNECE R155 requires OEMs to run an audited CSMS and demonstrate vehicle-type cybersecurity to a type-approval authority. No CSMS, no homologation, no market. R156 does the same for software update management.
The consequence is contractual gravity: OEMs discharge their obligations downward through cybersecurity interface agreements (CIAs), making 21434 conformance a de-facto condition of supply for Tier-1s, Tier-2s and increasingly chip vendors. Distributed TARA — whose analysis covers which attack surface, who owns which control — is where supply-chain relationships now succeed or sour.
For the certification world, automotive is a distinct continent: assessment is done by type-approval technical services and CSMS auditors rather than CC-style labs, and the CRA deliberately leaves type-approved vehicles to this regime. But the toolboxes interconnect — automotive secure elements carry CC/EUCC certificates, HSM firmware carries SESIP-style claims, and a chip vendor’s 21434 work package increasingly cites both.