The Legal Problem
ISO/SAE 21434:2021 Road Vehicles Cybersecurity Engineering imposes a Cybersecurity Management System (CSMS) obligation on OEMs and a cascading set of cybersecurity requirements on the supply chain. The Threat Analysis and Risk Assessment (TARA) required by Clause 15 of ISO/SAE 21434 is the cybersecurity analogue to the HARA in ISO 26262: it is both the core engineering risk identification tool and a primary discovery target in any post-incident proceeding.
For Tier 1 and Tier 2 suppliers, the practical legal challenge is contract law: OEMs are increasingly inserting ISO/SAE 21434 compliance obligations into development agreements, often with warranties, audit rights, and indemnification provisions that have significant financial exposure if not carefully negotiated.
What guibert.law Delivers
- TARA documentation review for legal defensibility and discovery preparation
- CSMS gap analysis and legal exposure mapping
- OEM-supplier cybersecurity contract review and negotiation (warranty, indemnification, audit rights, liability caps)
- Supply chain cybersecurity obligation flow-down analysis
- ISO/SAE 21434 and UNECE R155 interaction mapping for type approval preparation
guibert.law Insight
The TARA identifies threats, assesses attack feasibility, and documents countermeasures. A TARA that identifies a high-feasibility threat path but documents an inadequate countermeasure (because the countermeasure was too costly to implement) is a litigation roadmap. Legal review of TARA methodology and documentation is not an audit of the engineering decisions; it is a review of the legal consequences of those decisions.
← Back to Automotive Cybersecurity
Related Articles
Attorney advertising. The information on this page is provided for general informational purposes and does not constitute legal advice. Prior results do not guarantee a similar outcome. © 2026 guibert.law

