International (ISO/TC 22/SC 32 with SAE International)

ISO/SAE 21434

183 controls. 250 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

183 controls 250 frameworks share controls with it International (ISO/TC 22/SC 32 with SAE International) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
21434-10Product Development at System Level0
21434-10.4Hardware and Software Component Requirements0
21434-11Cybersecurity Validation0
21434-12Production3
21434-13Operations and Maintenance0
21434-14End of Cybersecurity Support and Decommissioning0
21434-15.3Asset Identification (TARA Step 1)0
21434-15.5Threat Scenario Identification (TARA Step 2)0
21434-15.6Impact Rating (TARA Step 3)0
21434-15.7Attack Path Analysis (TARA Step 4)0
21434-15.8Attack Feasibility and Risk Determination (TARA Step 5)0
21434-15.9Cybersecurity Assurance Level (CAL) and Risk Treatment0
21434-5Cybersecurity Governance0
21434-6Cybersecurity Culture and Competence0
21434-7Continuous Cybersecurity Activities0
21434-8Risk Assessment Methods4
21434-9.3Item Definition0
21434-9.4Cybersecurity Goals and Claims0
21434-Annex-EDistributed Cybersecurity Activities and Supplier Management0
ISO21434-01Information security policy framework0
ISO21434-02Management direction and commitment0
ISO21434-03Policy review and update procedures0
ISO21434-04Roles and responsibilities definition136
ISO21434-05Contact with authorities and special interest groups2
ISO21434-06Asset inventory and ownership0
ISO21434-07Acceptable use of assets24
ISO21434-08Information classification and labeling51
ISO21434-09Asset handling procedures24
ISO21434-10Media management and disposal0
ISO21434-11Access control policy and enforcement1
ISO21434-12User access management and provisioning110
ISO21434-13Authentication and password management69
ISO21434-14Privileged access management123
ISO21434-15Access review and recertification98
ISO21434-16Cryptographic policy and key management112
ISO21434-17Encryption of data at rest112
ISO21434-18Encryption of data in transit99
ISO21434-19Certificate management112
ISO21434-20Key lifecycle management0
ISO21434-21Operational procedures and responsibilities3
ISO21434-22Protection from malware32
ISO21434-23Backup and recovery procedures69
ISO21434-24Logging and monitoring51
ISO21434-25Technical vulnerability management56
ISO21434-26Audit considerations0
ISO21434-27Network security management58
ISO21434-28Network service security0
ISO21434-29Segregation in networks1
ISO21434-30Information transfer policies4
ISO21434-31Secure messaging0
ANNEXESAnnexes A to H0
CLAUSES-1-4Clauses 1 to 4: scope, normative references, terms, general considerations0
Clause 1010 Product development0
Clause 1111 Cybersecurity validation0
Clause 1212 Production0
Clause 1313 Operations and maintenance0
Clause 1414 End of cybersecurity support and decommissioning0
Clause 1515 Threat analysis and risk assessment methods0
Clause 55 Organizational cybersecurity management0
Clause 66 Project dependent cybersecurity management0
Clause 77 Distributed cybersecurity activities0
Clause 88 Continual cybersecurity activities0
Clause 99 Concept0
PM-06-08[PM-06-08] Omitting conformity for risk value 10
PM-06-13[PM-06-13] Tailoring permitted0
PM-06-29[PM-06-29] Assessment against the objectives0
PM-15-07[PM-15-07] Omitting further impact analysis0
RC-05-10[RC-05-10] Aligned management of shared information0
RC-05-13[RC-05-13] Production cybersecurity management system0
RC-05-15[RC-05-15] Reproducible remediation environment0
RC-05-16[RC-05-16] Work products managed under the management system0
RC-07-02[RC-07-02] Cybersecurity capability record0
RC-07-05[RC-07-05] Agreement before activities start0
RC-07-08[RC-07-08] Responsibility assignment matrix0
RC-10-06[RC-10-06] Established design and implementation principles0
RC-10-12[RC-10-12] Testing for remaining weaknesses0
RC-15-11[RC-15-11] Attack feasibility method0
RC-15-12[RC-15-12] Attack-potential-based approach0
RC-15-13[RC-15-13] CVSS-based approach0
RC-15-14[RC-15-14] Attack-vector-based approach0
RQ-05-01[RQ-05-01] Cybersecurity policy0
RQ-05-02[RQ-05-02] Organizational rules and processes0
RQ-05-03[RQ-05-03] Responsibilities and authority0
RQ-05-04[RQ-05-04] Resources0
RQ-05-05[RQ-05-05] Interaction with related disciplines0
RQ-05-06[RQ-05-06] Cybersecurity culture0
RQ-05-07[RQ-05-07] Competence and awareness0
RQ-05-08[RQ-05-08] Continuous improvement0
RQ-05-09[RQ-05-09] Information sharing circumstances0
RQ-05-11[RQ-05-11] Quality management system supporting cybersecurity engineering0
RQ-05-12[RQ-05-12] Configuration information available until end of support0
RQ-05-14[RQ-05-14] Tool management0
RQ-05-17[RQ-05-17] Organizational cybersecurity audit0
RQ-06-01[RQ-06-01] Assignment of project cybersecurity responsibilities0
RQ-06-02[RQ-06-02] Cybersecurity relevance and planning analysis0
RQ-06-03[RQ-06-03] Cybersecurity plan contents0
RQ-06-04[RQ-06-04] Responsibility for the plan and progress0
RQ-06-05[RQ-06-05] Plan referenced in the project plan0
RQ-06-06[RQ-06-06] Plan specifies the concept and development activities0
RQ-06-07[RQ-06-07] Plan updated on change or refinement0
RQ-06-09[RQ-06-09] Work products kept accurate to release0
RQ-06-10[RQ-06-10] Plans in distributed activities0
RQ-06-11[RQ-06-11] Plan under configuration and documentation management0
RQ-06-12[RQ-06-12] Work products under management0
RQ-06-14[RQ-06-14] Rationale for tailoring0
RQ-06-15[RQ-06-15] Reuse analysis triggers0
RQ-06-16[RQ-06-16] Reuse analysis content0
RQ-06-17[RQ-06-17] Reuse analysis for components0
RQ-06-18[RQ-06-18] Assumptions of out-of-context components0
RQ-06-19[RQ-06-19] Requirements based on the assumptions0
RQ-06-20[RQ-06-20] Validating the assumptions at integration0
RQ-06-21[RQ-06-21] Off-the-shelf component analysis0
RQ-06-22[RQ-06-22] Activities when documentation is insufficient0
RQ-06-23[RQ-06-23] Cybersecurity case0
RQ-06-24[RQ-06-24] Decision on cybersecurity assessment0
RQ-06-25[RQ-06-25] Independent review of the decision0
RQ-06-26[RQ-06-26] Assessment judges cybersecurity0
RQ-06-27[RQ-06-27] Independent assessor appointed0
RQ-06-28[RQ-06-28] Assessor access and cooperation0
RQ-06-30[RQ-06-30] Assessment scope0
RQ-06-31[RQ-06-31] Assessment recommendation0
RQ-06-32[RQ-06-32] Conditions of a conditional acceptance0
RQ-06-33[RQ-06-33] Work products available before release0
RQ-06-34[RQ-06-34] Release conditions0
RQ-07-01[RQ-07-01] Supplier capability evaluation0
RQ-07-03[RQ-07-03] Request for quotation content0
RQ-07-04[RQ-07-04] Cybersecurity interface agreement0
RQ-07-06[RQ-07-06] Agreed actions on vulnerabilities0
RQ-07-07[RQ-07-07] Notification of unclear or conflicting requirements0
RQ-08-01[RQ-08-01] Sources of cybersecurity information0
RQ-08-02[RQ-08-02] Triggers for triage0
RQ-08-03[RQ-08-03] Collection and triage into events0
RQ-08-04[RQ-08-04] Event assessment for weaknesses0
RQ-08-05[RQ-08-05] Vulnerability analysis0
RQ-08-06[RQ-08-06] Rationale when not a vulnerability0
RQ-08-07[RQ-08-07] Vulnerability management0
RQ-08-08[RQ-08-08] Incident response when required0
RQ-09-01[RQ-09-01] Item definition0
RQ-09-02[RQ-09-02] Operational environment description0
RQ-09-03[RQ-09-03] Risk analysis of the item0
RQ-09-04[RQ-09-04] Risk treatment decision per threat scenario0
RQ-09-05[RQ-09-05] Cybersecurity goals0
RQ-09-06[RQ-09-06] Cybersecurity claims0
RQ-09-07[RQ-09-07] Verification of goals and claims0
RQ-09-08[RQ-09-08] Description of cybersecurity controls0
RQ-09-09[RQ-09-09] Cybersecurity requirements and requirements on the operational environment0
RQ-09-10[RQ-09-10] Allocation of cybersecurity requirements0
RQ-09-11[RQ-09-11] Verification of the cybersecurity concept0
RQ-10-01[RQ-10-01] Cybersecurity specification0
RQ-10-02[RQ-10-02] Allocation to architectural components0
RQ-10-03[RQ-10-03] Post-development procedures0
RQ-10-04[RQ-10-04] Criteria for design, modelling and programming languages0
RQ-10-05[RQ-10-05] Guidelines covering the language's gaps0
RQ-10-07[RQ-10-07] Analysis of the architectural design for weaknesses0
RQ-10-08[RQ-10-08] Verification of the cybersecurity specification0
RQ-10-09[RQ-10-09] Integration and verification against the specification0
RQ-10-10[RQ-10-10] Specifying integration and verification0
RQ-10-11[RQ-10-11] Test coverage metrics0
RQ-10-13[RQ-10-13] Rationale when testing is not performed0
RQ-11-01[RQ-11-01] Validation of the item at vehicle level0
RQ-11-02[RQ-11-02] Rationale for the validation activities0
RQ-12-01[RQ-12-01] Production control plan0
RQ-12-02[RQ-12-02] Production control plan contents0
RQ-12-03[RQ-12-03] Implementing the production control plan0
RQ-13-01[RQ-13-01] Cybersecurity incident response plan0
RQ-13-02[RQ-13-02] Executing the incident response plan0
RQ-13-03[RQ-13-03] Updates developed under this document0
RQ-14-01[RQ-14-01] Communicating the end of cybersecurity support0
RQ-14-02[RQ-14-02] Post-development requirements for decommissioning0
RQ-15-01[RQ-15-01] Damage scenarios0
RQ-15-02[RQ-15-02] Assets with cybersecurity properties0
RQ-15-03[RQ-15-03] Threat scenarios0
RQ-15-04[RQ-15-04] Impact rating in four categories0
RQ-15-05[RQ-15-05] Impact rating levels0
RQ-15-06[RQ-15-06] Safety impact from ISO 262620
RQ-15-08[RQ-15-08] Attack path analysis0
RQ-15-09[RQ-15-09] Attack paths associated with threat scenarios0
RQ-15-10[RQ-15-10] Attack feasibility rating0
RQ-15-15[RQ-15-15] Risk value determination0
RQ-15-16[RQ-15-16] Risk value scale0
RQ-15-17[RQ-15-17] Risk treatment decision0
STANDARDISO/SAE 21434:2021: the standard and what is held0
STATUSEdition status: first edition in force, second edition development starting 20260

Tell me when ISO/SAE 21434 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What this page is

A control-level reference for ISO/SAE 21434, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition