HomeServices › Automotive Cybersecurity

Automotive Cybersecurity Legal Counsel

ISO/SAE 21434:2021 Road Vehicles Cybersecurity Engineering establishes a cybersecurity management system (CSMS) obligation that affects the entire automotive supply chain. UNECE Regulation No. 155 (R155) makes CSMS certification a mandatory type approval gate in markets including the European Union, Japan, South Korea, and Australia. For U.S. companies selling into those markets or supplying OEMs that do, R155 creates binding legal obligations regardless of whether the U.S. has implemented equivalent domestic regulation.

At the same time, the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA, Pub. L. 117-58) is advancing toward final rulemaking, and the SEC cybersecurity disclosure rules (17 C.F.R. Parts 229 and 249) already impose material incident reporting obligations on public companies. The automotive cybersecurity legal landscape is not a future concern — it is a present one.

ISO/SAE 21434 Compliance Counsel

TARA documentation, CSMS obligations, and supply chain cybersecurity contracts →

UNECE R155 Type Approval Counsel

Legal support for cybersecurity type approval in regulated markets →

guibert.law Insight

The TARA (Threat Analysis and Risk Assessment) required by ISO/SAE 21434 is the cybersecurity analogue to the HARA (Hazard Analysis and Risk Assessment) required by ISO 26262. Like the HARA, the TARA is both an engineering tool and a litigation artifact. A TARA that identifies a threat but documents no adequate countermeasure is a roadmap for plaintiff counsel in a post-incident proceeding.

Frequently Asked Questions

Does ISO/SAE 21434 apply to U.S. companies?
ISO/SAE 21434 directly applies to any company in the automotive supply chain that sells to OEMs supplying markets where UNECE R155 type approval is required — including the EU, Japan, South Korea, and Australia. For U.S. domestic supply chains only, 21434 is currently a best practice, but contractual obligations from OEMs increasingly mandate compliance regardless of regulatory geography.
What is a Cybersecurity Management System under R155?
A CSMS is an organizational framework for managing cybersecurity risks across the vehicle lifecycle, from design through post-production. R155 requires OEMs to hold a type-approval-authority-issued CSMS certificate as a precondition to vehicle type approval in covered markets. Tier 1 and Tier 2 suppliers must demonstrate equivalent processes to their OEM customers.

Related Articles


Attorney advertising. The information on this page is provided for general informational purposes and does not constitute legal advice. Prior results do not guarantee a similar outcome. © 2026 guibert.law

Ready to discuss your situation?

Schedule a consultation with Nicolas Guibert de Bruet, Attorney at Law and Technology Consultant.

Schedule a consultation →