ISO/SAE 21434
Road vehicles - Cybersecurity engineering
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (19)
Component Development
| Code | Title |
|---|---|
| 21434-10.4 | Hardware and Software Component Requirements |
Concept Phase
| Code | Title |
|---|---|
| 21434-9.3 | Item Definition |
| 21434-9.4 | Cybersecurity Goals and Claims |
Development
| Code | Title |
|---|---|
| 21434-10 | Product Development at System Level |
ISO/SAE 21434: Access Control
Logical and physical access controls (ISO/SAE 21434)
| Code | Title |
|---|---|
| ISO21434-11 | Access control policy and enforcement |
| ISO21434-12 | User access management and provisioning |
| ISO21434-13 | Authentication and password management |
| ISO21434-14 | Privileged access management |
| ISO21434-15 | Access review and recertification |
ISO/SAE 21434: Asset Management
Information asset management (ISO/SAE 21434)
| Code | Title |
|---|---|
| ISO21434-06 | Asset inventory and ownership |
| ISO21434-07 | Acceptable use of assets |
| ISO21434-08 | Information classification and labeling |
| ISO21434-09 | Asset handling procedures |
| ISO21434-10 | Media management and disposal |
ISO/SAE 21434: Communications Security
Network and communications security (ISO/SAE 21434)
| Code | Title |
|---|---|
| ISO21434-27 | Network security management |
| ISO21434-28 | Network service security |
| ISO21434-29 | Segregation in networks |
| ISO21434-30 | Information transfer policies |
| ISO21434-31 | Secure messaging |
ISO/SAE 21434: Cryptography
Cryptographic controls (ISO/SAE 21434)
| Code | Title |
|---|---|
| ISO21434-16 | Cryptographic policy and key management |
| ISO21434-17 | Encryption of data at rest |
| ISO21434-18 | Encryption of data in transit |
| ISO21434-19 | Certificate management |
| ISO21434-20 | Key lifecycle management |
ISO/SAE 21434: Information Security Policies
Organizational information security policies (ISO/SAE 21434)
| Code | Title |
|---|---|
| ISO21434-01 | Information security policy framework |
| ISO21434-02 | Management direction and commitment |
| ISO21434-03 | Policy review and update procedures |
| ISO21434-04 | Roles and responsibilities definition |
| ISO21434-05 | Contact with authorities and special interest groups |
ISO/SAE 21434: Operations Security
Secure operations and monitoring (ISO/SAE 21434)
| Code | Title |
|---|---|
| ISO21434-21 | Operational procedures and responsibilities |
| ISO21434-22 | Protection from malware |
| ISO21434-23 | Backup and recovery procedures |
| ISO21434-24 | Logging and monitoring |
| ISO21434-25 | Technical vulnerability management |
| ISO21434-26 | Audit considerations |
Lifecycle
| Code | Title |
|---|---|
| 21434-14 | End of Cybersecurity Support and Decommissioning |
Operations
| Code | Title |
|---|---|
| 21434-13 | Operations and Maintenance |
| 21434-7 | Continuous Cybersecurity Activities |
Organisational
| Code | Title |
|---|---|
| 21434-5 | Cybersecurity Governance |
People
| Code | Title |
|---|---|
| 21434-6 | Cybersecurity Culture and Competence |
Production
| Code | Title |
|---|---|
| 21434-12 | Production |
Risk
| Code | Title |
|---|---|
| 21434-8 | Risk Assessment Methods |
Risk Treatment
| Code | Title |
|---|---|
| 21434-15.9 | Cybersecurity Assurance Level (CAL) and Risk Treatment |
Supply Chain
| Code | Title |
|---|---|
| 21434-Annex-E | Distributed Cybersecurity Activities and Supplier Management |
TARA
| Code | Title |
|---|---|
| 21434-15.3 | Asset Identification (TARA Step 1) |
| 21434-15.5 | Threat Scenario Identification (TARA Step 2) |
| 21434-15.6 | Impact Rating (TARA Step 3) |
| 21434-15.7 | Attack Path Analysis (TARA Step 4) |
| 21434-15.8 | Attack Feasibility and Risk Determination (TARA Step 5) |
Validation
| Code | Title |
|---|---|
| 21434-11 | Cybersecurity Validation |
Your Compliance Coverage
If you comply with ISO/SAE 21434, you already cover:
MITRE D3FEND
34%
17 controls mapped
Compare →3GPP Security
34%
17 controls mapped
Compare →OWASP ASVS
34%
17 controls mapped
Compare →+ 607 more: Proposal for a Regulation on Cyber Resilience Act (CRA) (34%), BSIMM (34%)
See all 610 mapped frameworks ↓Maps to 610 other frameworks
Frequently Asked Questions
What is ISO/SAE 21434?
ISO/SAE 21434 is a compliance framework from International with 19 domains and 50 controls. Road vehicles - Cybersecurity engineering It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does ISO/SAE 21434 have?
ISO/SAE 21434 has 50 controls organised across 19 domains. The largest domains are ISO/SAE 21434: Operations Security (6 controls), ISO/SAE 21434: Access Control (5 controls), ISO/SAE 21434: Asset Management (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does ISO/SAE 21434 map to?
ISO/SAE 21434 maps to 610 other compliance frameworks. The top mapping partners are MITRE D3FEND (34% coverage), 3GPP Security (34% coverage), OWASP ASVS (34% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with ISO/SAE 21434 compliance?
Start your ISO/SAE 21434 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/SAE 21434 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 50 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required