General Information

Abstract

Status
Not Published
Current Stage
6000 - International Standard under publication
Start Date
01-Sep-2026
Completion Date
26-Sep-2026

Buy Documents

Draft

ISO/SAE DPAS 8475 - Road vehicles — Cybersecurity Assurance Levels (CAL) and Targeted Attack Feasibility (TAF)

Release Date:22-Jun-2026
English language (23 pages)
sale 15% off
sale 15% off
Draft

REDLINE ISO/SAE DPAS 8475 - Road vehicles — Cybersecurity Assurance Levels (CAL) and Targeted Attack Feasibility (TAF)

Release Date:22-Jun-2026
English language (23 pages)
sale 15% off
sale 15% off

Overview

ISO/SAE PAS 8475: Road Vehicles - Cybersecurity Assurance Levels (CAL) and Targeted Attack Feasibility (TAF) is a standard jointly developed by ISO and SAE to support cybersecurity engineering in the automotive sector. Building on the foundation established by ISO/SAE 21434:2021, this standard introduces, details, and formalizes two key approaches for structured cyber risk management: Cybersecurity Assurance Levels (CAL) and Targeted Attack Feasibility (TAF). These frameworks aim to enhance clarity, rigour, and consistency in the management of cybersecurity activities throughout the lifecycle of road vehicles and their components.

By leveraging CAL and TAF, organizations can better communicate cybersecurity expectations, scale the depth and breadth of their efforts, and address the evolving landscape of automotive cyber threats.

Key Topics

1. Cybersecurity Assurance Levels (CAL)

  • Definition: CAL specifies the rigour (i.e., depth and breadth) of cybersecurity activities during development.
  • Purpose: Facilitates communication of required cybersecurity assurance between stakeholders, including OEMs and suppliers.
  • Determination: CAL is determined through a risk-based approach, considering factors such as impact ratings and attack vectors.
  • Levels: Typically encompasses three levels (CAL1, CAL2, CAL3), ranging from basic to advanced assurance.

2. Targeted Attack Feasibility (TAF)

  • Concept: TAF assesses the feasibility of attacks on an item or component, after cybersecurity controls have been applied.
  • Application: Used to specify targeted resistance to attacks, providing flexibility in defining necessary controls and measures.
  • Integration: Complements CAL by quantifying the expected threat landscape post-mitigation.

3. Assignment and Management

  • Cybersecurity Goals: CAL is assigned as an attribute to cybersecurity goals, and inherited by related requirements.
  • Change Management: Adjustments to CAL are formally managed in accordance with established processes, maintaining alignment with ISO/SAE 21434.

4. Scaling of Rigour

  • Depth and Breadth: The standard provides examples of how to scale cybersecurity activities for each CAL, allowing customization based on the determined risk and context.
  • Examples: These include various levels and types of analysis, verification, review, and testing.

Applications

1. Automotive Design and Development

  • Application of CAL allows automotive manufacturers, suppliers, and integrators to align on the necessary rigour for cybersecurity tasks in concept and product development phases.
  • Facilitates out-of-context development, enabling independent modules or components to meet defined cybersecurity standards.

2. Tier 1 and Tier 2 Supplier Communication

  • Clear definitions of CAL and TAF support effective communication between OEMs and their supply chain, particularly in distributed development environments.
  • Streamlines contracts and agreements regarding cybersecurity obligations and deliverables.

3. Lifecycle Cybersecurity Management

  • Provides a framework for managing cybersecurity changes as products are updated or as threats evolve.
  • Enables traceable, documented assurance levels across the vehicle ecosystem.

4. Risk-Based Approach Implementation

  • Standardizes how organizations assess attack feasibility and scale their security measures, improving overall resilience to cyber threats in connected vehicles.

Related Standards

  • ISO/SAE 21434:2021 - Road vehicles - Cybersecurity engineering (core standard referenced in ISO/SAE PAS 8475 for terminology, process, and work products)
  • ISO/SAE DTR 8477 and SAE J3322 (mentioned for further guidance on assurance activities, verification, and validation)
  • ISO 26262-2:2018 - Functional safety, referenced for definitions around independence in assessment
  • ISO/IEC 27001 - Information security management (general context for cybersecurity processes)

Keywords: ISO/SAE PAS 8475, CAL, TAF, automotive cybersecurity, cybersecurity assurance levels, targeted attack feasibility, ISO/SAE 21434, automotive security standard, cybersecurity engineering, road vehicles, automotive risk management, vehicle cybersecurity compliance.

Buy Documents

Draft

ISO/SAE DPAS 8475 - Road vehicles — Cybersecurity Assurance Levels (CAL) and Targeted Attack Feasibility (TAF)

Release Date:22-Jun-2026
English language (23 pages)
sale 15% off
sale 15% off
Draft

REDLINE ISO/SAE DPAS 8475 - Road vehicles — Cybersecurity Assurance Levels (CAL) and Targeted Attack Feasibility (TAF)

Release Date:22-Jun-2026
English language (23 pages)
sale 15% off
sale 15% off

Get Certified

Connect with accredited certification bodies for this standard

BSI Group

BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

UKAS United Kingdom Verified

TÜV Rheinland

TÜV Rheinland is a leading international provider of technical services.

DAKKS Germany Verified

TÜV SÜD

TÜV SÜD is a trusted partner of choice for safety, security and sustainability solutions.

DAKKS Germany Verified

Sponsored listings

Frequently Asked Questions

ISO/SAE PAS 8475 is a draft published by the International Organization for Standardization (ISO). Its full title is "Road vehicles — Cybersecurity Assurance Levels (CAL) and Targeted Attack Feasibility (TAF)". This standard covers: Road vehicles — Cybersecurity Assurance Levels (CAL) and Targeted Attack Feasibility (TAF)

Road vehicles — Cybersecurity Assurance Levels (CAL) and Targeted Attack Feasibility (TAF)

ISO/SAE PAS 8475 is classified under the following ICS (International Classification for Standards) categories: 35.030 - IT Security; 43.020 - Road vehicles in general; 43.040.10 - Electrical and electronic equipment. The ICS classification helps identify the subject area and facilitates finding related standards.

ISO/SAE PAS 8475 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.

Standards Content (Sample)


FINAL DRAFT
Publicly
Available
Specification
ISO/DPAS 8475
ISO/TC 22/SC 32
Road vehicles — Cybersecurity
Secretariat: JISC
Assurance Levels (CAL) and
Voting begins on:
Targeted Attack Feasibility (TAF)
2026-07-06
Véhicules routiers - Niveaux d'assurance (CAL) et faisabilité des
Voting terminates on:
attaques ciblées (TAF) en matière de cybersécurité
2026-08-31
RECIPIENTS OF THIS DRAFT ARE INVITED TO SUBMIT,
WITH THEIR COMMENTS, NOTIFICATION OF ANY
RELEVANT PATENT RIGHTS OF WHICH THEY ARE AWARE
AND TO PROVIDE SUPPOR TING DOCUMENTATION.
IN ADDITION TO THEIR EVALUATION AS
BEING ACCEPTABLE FOR INDUSTRIAL, TECHNO­
LOGICAL, COMMERCIAL AND USER PURPOSES, DRAFT
INTERNATIONAL STANDARDS MAY ON OCCASION HAVE
TO BE CONSIDERED IN THE LIGHT OF THEIR POTENTIAL
TO BECOME STAN DARDS TO WHICH REFERENCE MAY BE
MADE IN NATIONAL REGULATIONS.
Reference number
ISO/DPAS 8475:2026(en) © ISO 2026

FINAL DRAFT
ISO/DPAS 8475:2026(en)
Publicly
Available
Specification
ISO/DPAS 8475
ISO/TC 22/SC 32
Road vehicles — Cybersecurity
Secretariat: JISC
Assurance Levels (CAL) and
Voting begins on:
Targeted Attack Feasibility (TAF)
Véhicules routiers - Niveaux d'assurance (CAL) et faisabilité des
Voting terminates on:
attaques ciblées (TAF) en matière de cybersécurité
RECIPIENTS OF THIS DRAFT ARE INVITED TO SUBMIT,
© ISO/SAE International 2026
WITH THEIR COMMENTS, NOTIFICATION OF ANY
RELEVANT PATENT RIGHTS OF WHICH THEY ARE AWARE
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may be
AND TO PROVIDE SUPPOR TING DOCUMENTATION.
reproduced, or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
IN ADDITION TO THEIR EVALUATION AS
the internet or an intranet, without prior written permission. Permission can be requested from either ISO or SAE International at
BEING ACCEPTABLE FOR INDUSTRIAL, TECHNO­
the respective address below or ISO’s member body in the country of the requester.
LOGICAL, COMMERCIAL AND USER PURPOSES, DRAFT
INTERNATIONAL STANDARDS MAY ON OCCASION HAVE
ISO copyright office SAE International
TO BE CONSIDERED IN THE LIGHT OF THEIR POTENTIAL
CP 401 • Ch. de Blandonnet 8 400 Commonwealth Dr.
TO BECOME STAN DARDS TO WHICH REFERENCE MAY BE
CH-1214 Vernier, Geneva Warrendale, PA, USA 15096
MADE IN NATIONAL REGULATIONS.
Phone: +41 22 749 01 11 Phone: 877-606-7323 (inside USA and Canada)
Phone: +1 724-776-4970 (outside USA)
Fax: 724-776-0790
Email: copyright@iso.org Email: CustomerService@sae.org
Website: www.iso.org Website: www.sae.org
Published in Switzerland by ISO, published in the USA by SAE International
Reference number
ISO/DPAS 8475:2026(en) © ISO 2026

ii
ISO/DPAS 8475:2026(en)
Contents Page
Foreword .iv
Introduction .v
1 Scope . 1
2 Normative references . 1
3 Terms, definitions and abbreviated terms . 1
3.1 Terms and definitions .1
3.2 Abbreviated terms .2
4 General . 2
5 CAL determination and assignment . 3
5.1 Objectives .3
5.2 Recommendations and permissions .3
5.2.1 CAL Determination .3
5.2.2 CAL Assignment .4
6 CAL usage and examples . 4
6.1 Objective.4
6.2 Recommendations and permissions .5
6.2.1 CAL usage .5
Annex A (informative) Assignment of CAL to cybersecurity requirements . 6
Annex B (informative) Examples of scaling rigour . 10
Annex C (informative) The targeted attack feasibility (TAF) concept .16
Annex D (informative) Example application of TAF with multiple cybersecurity controls .20
Bibliography .23

iii
ISO/DPAS 8475:2026(en)
Foreword
ISO (the International Organization for Standardization) is a worldwide federation of national standards
bodies (ISO member bodies). The work of preparing International Standards is normally carried out through
ISO technical committees. Each member body interested in a subject for which a technical committee
has been established has the right to be represented on that committee. International organizations,
governmental and non-governmental, in liaison with ISO, also take part in the work. ISO collaborates closely
with the International Electrotechnical Commission (IEC) on all matters of electrotechnical standardization.
SAE International is a global association of more than 128,000 engineers and related technical experts in
the aerospace, automotive and commercial-vehicle industries. Standards from SAE International are used to
advance mobility engineering throughout the world. The SAE Technical Standards Development Program is
among the organization's primary provisions to those mobility industries it serves aerospace, automotive,
and commercial vehicle. These works are authorized, revised, and maintained by the volunteer efforts of
more than 9,000 engineers, and other qualified professionals from around the world. SAE subject matter
experts act as individuals in the standards process, not as representatives of their organizations. Thus, SAE
standards represent optimal technical content developed in a transparent, open, and collaborative process.
The procedures used to develop this document and those intended for its further maintenance are
described in the ISO/IEC Directives, Part 1 and the SAE Executive Standards Committee Policy. In
particular, the different approval criteria needed for the different types of ISO documents should be noted.
This document was drafted in accordance with the editorial rules of the ISO/IEC Directives, Part 2 (see
www.iso.org/directives).
ISO and SAE draw attention to the possibility that the implementation of this document may involve the
use of (a) patent(s). ISO and SAE take no position concerning the evidence, validity or applicability of any
claimed patent rights in respect thereof. As of the date of publication of this document, ISO and SAE had not
received notice of (a) patent(s) which may be required to implement this document. However, implementers
are cautioned that this may not represent the latest information, which may be obtained from the patent
database available at www.iso.org/patents. ISO and SAE shall not be held responsible for identifying any or
all such patent rights.
SAE Executive Standards Committee Rules provide that: “This document is published to advance the state
of technical and engineering sciences. The use of this document is entirely voluntary, and its applicability
and suitability for any particular use, including any patent infringement arising therefrom, is the sole
responsibility of the user.”
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT), see www.iso.org/iso/foreword.html.
This document was jointly prepared by Technical Committee ISO/TC 22, Road vehicles, Subcommittee SC
32, Electrical and electronic components and general system aspects, and SAE Committee SAE TEVEES18A,
Vehicle Cybersecurity Systems Engineering Committee.
Any feedback or questions on this document should be directed to the user’s national standards body. A
complete listing of these bodies can be found at www.iso.org/members.html.

iv
ISO/DPAS 8475:2026(en)
Introduction
This document elaborates the cybersecurity assurance level (CAL) classification scheme introduced in
ISO/SAE 21434 and introduces the targeted attack feasibility (TAF) concept.
The CAL classification scheme, as described in ISO/SAE 21434:2021, Annex E, is a measure of how rigorously
the cybersecurity activities for the concept and development phases of an item or component are executed.
The use of CAL provides a scheme to scale the rigour of the cybersecurity development activities. This can
be communicated between customers and suppliers in a distributed development to highlight differences in
the security assurance to be expected from items or components. It does not provide an absolute measure. It
is not comparable between different customers or different suppliers.
CAL can also be used for out-of-context development according to ISO/SAE 21434:2021, 6.4.5 with
appropriate communication between customer and supplier.
The TAF concept introduced in Annexes C and D describes the expected level of attack feasibility once
cybersecurity controls are applied for a given item or component. The TAF concept gives flexibility to the
organization that develops an item or component to specify and implement cybersecurity controls.
While ISO/SAE 21434 does not require use of either CAL or TAF, they can be used to streamline discussion
and improve consistency between customers and suppliers.
Results from the requirements and recommendations in this document are incorporated into existing work
products defined in ISO/SAE 21434.

v
FINAL DRAFT Publicly Available Specification ISO/DPAS 8475:2026(en)
Road vehicles — Cybersecurity Assurance Levels (CAL) and
Targeted Attack Feasibility (TAF)
1 Scope
This document elaborates on the cybersecurity assurance level (CAL) classification scheme and introduces
the targeted attack feasibility (TAF) concept, within the context of cybersecurity engineering for road
vehicles as specified in ISO/SAE 21434.
This document describes the concepts of CAL and TAF. It provides requirements and recommendations to
determine and use CAL as applied to cybersecurity engineering of an item or component.
2 Normative references
The following document is referred to in the text in such a way that some or all of its content constitutes
requirements of this document. For dated references, only the edition cited applies. For undated references,
the latest edition of the referenced document (including any amendments) applies.
ISO/SAE 21434:2021, Road vehicles — Cybersecurity engineering
3 Terms, definitions and abbreviated terms
3.1 Terms and definitions
For the purposes of this document, the terms and definitions given in ISO/SAE 21434:2021 and the following
apply.
ISO and IEC maintain terminological databases for use in standardization at the following addresses:
— IEC Electropedia: available at http:// www .electropedia .org/
— ISO Online browsing platform: available at http:// www .iso .org/ obp
3.1.1
cybersecurity assurance level
CAL
rigour (3.1.3) during the concept and product development phases for an item or component
Note 1 to entry: CAL does not address the selection of cybersecurity controls.
3.1.2
targeted attack feasibility
TAF
required attack feasibility rating for an item or component after cybersecurity controls are applied
3.1.3
rigour
depth (3.1.4) and breadth (3.1.5) in performing cybersecurity activities that support justifiable confidence in
the achieved results
3.1.4
depth
detail at which cybersecurity activities are performed

ISO/DPAS 8475:2026(en)
3.1.5
breadth
range of cybersecurity activities performed
3.1.6
static factor
risk-related factor that is expected not to change during the development of an item or component
3.2 Abbreviated terms
CAN controller area network
ECU electronic control unit
4 General
This document describes the cybersecurity assurance level (CAL) classification scheme. CAL is used in the
concept and product development phases to specify and communicate a set of cybersecurity activities, in
terms of rigour, to provide justifiable confidence that the cybersecurity engineering of an item or component
is appropriate.
CAL is an attribute of a cybersecurity goal. CAL provides a common language for communicating the
required rigour of cybersecurity activities between organizations.
The determination, assignment and use of CAL is illustrated in Figure 1. A CAL is determined, using a
combination of static factors (see 5.2.1). The CAL is then assigned as an attribute of a cybersecurity goal
and inherited by the cybersecurity requirements specified from that cybersecurity goal (5.2.2). Finally, the
cybersecurity activities related to the cybersecurity requirements are performed at the rigour set by the
CAL (6.2 and Annex B).
Figure 1 — Determination, assignment and use of CAL
A CAL is determined during the concept phase. CAL remains fixed throughout concept and development
phases to provide a consistent level of assurance, unless the basis for determining CAL changes (e.g. a change

ISO/DPAS 8475:2026(en)
of functionality introducing a new damage scenario or an update to an item or component). Any changes in
CAL during the product development phase are handled through change management in accordance with
ISO/SAE 21434:2021, 5.4.4, [RQ-05-11].
EXAMPLE Due to an update to an item or component.
If ISO/SAE 21434:2021, 6.4.2, [PM-06-08] is applied, CAL is not applicable.
CAL is not the same as tailoring defined in ISO/SAE 21434:2021, 6.4.3. If tailoring is used, the tailored
activities are performed at the associated CAL.
5 CAL determination and assignment
5.1 Objectives
The objectives of this clause are to:
a) determine a CAL;
b) assign a CAL as an attribute of a cybersecurity goal.
5.2 Recommendations and permissions
5.2.1 CAL Determination
5.2.1.1 The determined CAL should be taken into account in applying ISO/SAE 21434:2021, 6.4.2, [RQ-06-
06].
NOTE Organizations can adjust their policies, rules and processes if they decide to use CAL.
5.2.1.2 A CAL should be CAL1, CAL2 or CAL3.
NOTE 1 CAL1 is basic rigour, CAL2 is intermediate rigour and CAL3 is advanced rigour. See tables in Annex B for
examples of scaling.
NOTE 2 In the further development of the CAL in this document, the number of levels was reduced to three from the
four levels in ISO/SAE 21434:2021, Annex E.
NOTE 3 Factors of rigour are depth and breadth.
NOTE 4 ISO/SAE 21434 requires independence for cybersecurity assessment (see Table B.6).
5.2.1.3 A CAL should be determined based on the combination of the impact rating and the attack vector
of a threat scenario.
NOTE 1 Impact rating is determined according to ISO/SAE 21434:2021, 15.5.2, [RQ-15-05].
NOTE 2 Attack vector is used because it is a static factor.
NOTE 3 For a detailed explanation of the attack vector-based approach, see ISO/SAE 21434:2021, Table G.9.
NOTE 4 Impact categories can be considered when determining a CAL.
NOTE 5 Organizations determine the CAL mapping to impact rating and attack vector based upon their internal
process.
NOTE 6 See Annex A for examples.
5.2.1.4 The determination of CAL from 5.2.1.2 may be changed based on consideration of other static
factors, with a rationale.
ISO/DPAS 8475:2026(en)
EXAMPLE Static Factor: Architectural decisions, such as a single ECU on a CAN network segment protected by a
gateway.
Rationale: The ECU is protected by a gateway on the CAN network segment. In that case, the original attack
vector evaluated as “network” is equivalent to “local”, and this changes the CAL.
5.2.1.5 Once a CAL has been determined and assigned, it is intended to remain stable but may be changed.
NOTE Any change is handled through change management according to ISO/SAE 21434:2021, 5.4.4, [RQ-05-11].
EXAMPLE 1 During an update to an item or component.
EXAMPLE 2 Changes to a threat scenario.
5.2.2 CAL Assignment
5.2.2.1 The determined CAL should be assigned as an attribute of the corresponding cybersecurity goals
resulting from the associated threat scenario, according to ISO/SAE 21434:2021, 9.4.2, [RQ-09-05].
5.2.2.2 A cybersecurity requirement derived from a cybersecurity goal or higher-level cybersecurity
requirement should inherit the CAL assigned to the cybersecurity goal or higher-level cybersecurity
requirement.
5.2.2.3 If a cybersecurity requirement is associated with multiple cybersecurity goals or higher-level
cybersecurity requirements, it should inherit the highest CAL of those cybersecurity goals or higher-level
cybersecurity requirements.
NOTE 1 Refer to Annex A for examples of assignments of CAL to cybersecurity requirements.
NOTE 2 The cybersecurity requirements with their associated CALs are documented in the cybersecurity concept
and cybersecurity specification, in according to ISO/SAE 21434:2021, 9.5.3, [WP-09-06], and 10.5, [WP-10-01].
5.2.2.4 A cybersecurity activity for an item or component should be performed at the highest CAL associated
with the cybersecurity requirements allocated to the item or component.
NOTE 1 Cybersecurity requirements are allocated to an item or component according to ISO/SAE 21434:2021,
9.5.2, [RQ-09-10].
NOTE 2 See Annex B for usage of CAL in cybersecurity activities.
5.2.2.5 If cybersecurity activities are associated with a subset of allocated cybersecurity requirements,
then those activities may be performed at the highest CAL associated with that subset.
5.2.2.6 If a first component cannot be adversely affected by a second component, then the cybersecurity
activities for the second component may be performed at a lower CAL than the cybersecurity activities for
the first component, with a rationale.
NOTE See example in Figure A.3.
EXAMPLE Development of a hypervisor and a guest.
6 CAL usage and examples
6.1 Objective
The objective of this clause is to use a CAL to determine rigour for performing cybersecurity activities.

ISO/DPAS 8475:2026(en)
6.2 Recommendations and permissions
6.2.1 CAL usage
6.2.1.1 The CAL determined according to 5.2 should be used to scale the rigour of the cybersecurity activities
performed to fulfil the corresponding requirements of ISO/SAE 21434.NOTE 1 See tables in Annex B for examples
of scaling rigour.
NOTE 1 The selected rigour can be included in an appropriate ISO/SAE 21434 work product, e.g. cybersecurity
plan, cybersecurity interface agreement, verification specification.
NOTE 2 The evidence for achieving the assurance associated to the assigned CAL is documented in the appropriate
work products according to ISO/SAE 21434.

ISO/DPAS 8475:2026(en)
Annex A
(informative)
Assignment of CAL to cybersecurity requirements
A.1 General
This annex describes CAL determination, the assignment of CAL, the allocation of cybersecurity
requirements to an item and components and the refinement of cybersecurity requirements.
A.2 Example of CAL determination
Tables A.1 and A.2 give examples of CAL determination using impact rating and attack vector. The first
example shows the application of ISO/SAE 21434:2021, 6.4.2, [PM-06-08] to threat scenarios with negligible
impact ratings with a risk value of 1.
Table A.1 — Example of determining CAL
Attack vector
Physical Local Adjacent Network
Impact Severe CAL2 CAL2 CAL2 CAL3
rating
Major CAL1 CAL2 CAL2 CAL2
Moderate CAL1 CAL1 CAL2 CAL2
Negligible See ISO/ SAE 21434:2021, 6.4.2, [PM-06-08]
Table A.2 — Example of determining CAL
Attack vector
Physical Local Adjacent Network
Impact Severe CAL1 CAL2 CAL3 CAL3
rating
Major CAL1 CAL2 CAL2 CAL3
Moderate CAL1 CAL2 CAL2 CAL2
Negligible CAL1 CAL1 CAL1 CAL1
Examples of physical attack vector can include:
— desoldering a system-on-chip from a printed circuit board;
— connecting to a non-exposed JTAG port;
— making physical modifications to the vehicle.
A.3 Assignment of CAL to cybersecurity requirements
Cybersecurity goals are specified according to ISO/SAE 21434:2021, 9.4.2, [RQ-09-05] and CALs are assigned
to corresponding cybersecurity goals as their attributes according to 5.2.2.1.
The cybersecurity requirements are defined for the cybersecurity goals according to ISO/SAE 21434:2021,
9.5.2, [RQ-09-09] and cybersecurity requirements are assigned the same CAL associated with the
cybersecurity goal from which the cybersecurity requirement is defined. If a cybersecurity requirement
is derived from multiple cybersecurity goals, the cybersecurity requirement is assigned the highest CAL

ISO/DPAS 8475:2026(en)
of the related cybersecurity goals (see 5.2.2.3). An example of the assignment of CALs to cybersecurity
requirements is shown in Figure A.1.
Figure A.1 — Example of assignment of CALs to the cybersecurity requirements from the
cybersecurity goals
A.4 Allocation of cybersecurity requirements to items or components with CAL
This section illustrates how to allocate cybersecurity requirements and their assigned CAL to an item and
components.
Cybersecurity requirements are allocated to the item and one or more components according to
ISO/SAE 21434:2021, 9.5.2, [RQ-09-10]. Cybersecurity requirements are subsequently allocated to
components of the architectural design in accordance with ISO/SAE 21434:2021, 10.4.1, [RQ-10-02].
Figure A.2 shows an example where there is no isolation in the cybersecurity concept and cybersecurity
specification. Component B is isolated from component A if component B cannot be adversely affected
by component A. Under 5.2.2.4, the cybersecurity activities performed during the development of the
components are done at the highest CAL of the allocated cybersecurity requirements. Even if the highest
CAL for each component is different, the lack of isolation from other components with other requirements
means that all components inherit the highest CAL of all requirements assigned to the item, which is CAL3.
Figure A.3 is an example where isolation is considered in the cybersecurity concept and cybersecurity
specification. When different cybersecurity requirements have different CALs assigned, the isolation
enables the cybersecurity activities for a component to be performed at the highest CAL of all inherited
cybersecurity requirements without being affected by cybersecurity requirements allocated to other
components.
An application of the example in Figure A.3 can be if component 2 represented an ECU, component 5
represented a hypervisor and component 6 represented a guest. Since the guest cannot adversely affect
the operation of the hypervisor, the cybersecurity activities on the guest are performed at CAL1, while the
cybersecurity activities of the hypervisor performed at CAL2.

ISO/DPAS 8475:2026(en)
Key
RQ cybersecurity requirement
Figure A.2 — Example of allocation of cybersecurity requirements including CAL without isolation

ISO/DPAS 8475:2026(en)
Key
RQ cybersecurity requirement
isolated
Figure A.3 — Example of allocation of cybersecurity requirements including CAL with isolation
between components
A.5 Example refinement of cybersecurity requirements
This subclause describes the concept of refining cybersecurity requirements. When a cybersecurity
requirement is refined into multiple cybersecurity requirements, each refined cybersecurity requirement
can be assigned a different CAL (see 5.2.2.5 and 5.2.2.6). Figure A.4 illustrates an example where RQ A is
refined into RQ B and C. RQ B is assigned CAL X, while RQ C is assigned CAL Y which is less than CAL X. These
cybersecurity requirements are allocated to different components.
Figure A.4 — Example refinement of a cybersecurity requirement

ISO/DPAS 8475:2026(en)
Annex B
(informative)
Examples of scaling rigour
This annex present examples of scaling the rigour by depth and breadth for CAL1, CAL2 and CAL3 related
to the requirements and recommendations in ISO/SAE 21434. These examples follow the recommendations
in 6.2.1. These are examples and are not an exhaustive list. Other ways of scaling rigour based on depth and
breadth can be considered.
Tabl
...


ISO/SAE DPAS 8475
ISO/TC 22/SC 32
Secretariat: JISC
Road vehicles — Cybersecurity Assurance Levels (CAL) and Targeted
Attack Feasibility (TAF)
Véhicules routiers - Niveaux d'assurance (CAL) et faisabilité des attaques ciblées (TAF) en matière de
cybersécurité
FDIS stage
ISO/SAE DPAS 8475 (:(en)
© ISO/SAE 2026
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication
may be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying,
or posting on the internet or an intranet, without prior written permission. Permission can be requested from either ISO
at the address below or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: + 41 22 749 01 11
E-mail: copyright@iso.org
Website: www.iso.org
Published in Switzerland
© ISO/SAE 2026 – All rights reserved
ii
ISO/SAE DPAS 8475:(en)
Contents
Foreword . iv
Introduction . v
1 Scope . 1
2 Normative references . 1
3 Terms, definitions and abbreviated terms . 1
3.1 Terms and definitions . 1
3.2 Abbreviated terms . 2
4 General . 2
5 CAL determination and assignment . 4
5.1 Objectives . 4
5.2 Recommendations and permissions . 4
6 CAL usage and examples . 5
6.1 Objective . 5
6.2 Recommendations and permissions . 6
Annex A (informative) Assignment of CAL to cybersecurity requirements . 7
Annex B (informative) Examples of scaling rigour . 14
Annex C (informative) The targeted attack feasibility (TAF) concept . 21
Annex D (informative) Example application of TAF with multiple cybersecurity controls . 25
Bibliography . 29

© ISO/SAE 2026 – All rights reserved
iii
ISO/SAE DPAS 8475 (:(en)
Foreword
ISO (the International Organization for Standardization) is a worldwide federation of national standards
bodies (ISO member bodies). The work of preparing International Standards is normally carried out through
ISO technical committees. Each member body interested in a subject for which a technical committee has been
established has the right to be represented on that committee. International organizations, governmental and
non-governmental, in liaison with ISO, also take part in the work. ISO collaborates closely with the
International Electrotechnical Commission (IEC) on all matters of electrotechnical standardization.
SAE International is a global association of more than 128,000 engineers and related technical experts in the
aerospace, automotive and commercial-vehicle industries. Standards from SAE International are used to
advance mobility engineering throughout the world. The SAE Technical Standards Development Program is
among the organization's primary provisions to those mobility industries it serves aerospace, automotive, and
commercial vehicle. These works are authorized, revised, and maintained by the volunteer efforts of more
than 9,000 engineers, and other qualified professionals from around the world. SAE subject matter experts act
as individuals in the standards process, not as representatives of their organizations. Thus, SAE standards
represent optimal technical content developed in a transparent, open, and collaborative process.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1.Part 1 and the SAE Executive Standards Committee Policy. In particular, the
different approval criteria needed for the different types of ISO documents should be noted. This document
was drafted in accordance with the editorial rules of the ISO/IEC DirectivesIEC Directives, Part 2Part 2 (see
www.iso.org/directives).
Attention is drawnISO and SAE draw attention to the possibility that some of the elementsimplementation of
this document may beinvolve the subjectuse of (a) patent(s). ISO and SAE take no position concerning the
evidence, validity or applicability of any claimed patent rights in respect thereof. As of the date of publication
of this document, ISO and SAE had not received notice of (a) patent(s) which may be required to implement
this document. However, implementers are cautioned that this may not represent the latest information,
which may be obtained from the patent database available at www.iso.org/patents rights. ISO. ISO and SAE
shall not be held responsible for identifying any or all such patent rights. Details of any patent rights identified
during the development of the document will be in the Introduction and/or on the ISO list of patent
declarations received (see ).
SAE Executive Standards Committee Rules provide that: “This document is published to advance the state of
technical and engineering sciences. The use of this document is entirely voluntary, and its applicability and
suitability for any particular use, including any patent infringement arising therefrom, is the sole
responsibility of the user.”
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation onof the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT)), see the following URL:
www.iso.org/iso/foreword.html.
This document was jointly prepared by Technical Committee ISO/TC 22, Road vehicles, Subcommittee SC 32,
Electrical and electronic components and general system aspects, and SAE Committee SAE TEVEES18A, Vehicle
Cybersecurity Systems Engineering Committee.
Any feedback or questions on this document should be directed to the user’s national standards body. A
complete listing of these bodies can be found at www.iso.org/members.html.
© ISO/SAE 2026 – All rights reserved
iv
ISO/SAE DPAS 8475:(en)
Introduction
This document elaborates the cybersecurity assurance level (CAL) classification scheme introduced in
ISO/SAE 21434:2021 and introduces the targeted attack feasibility (TAF) concept.
The CAL classification scheme, as described in ISO/SAE 21434:2021, Annex E, is a measure of how rigorously
the cybersecurity activities for the concept and development phases of an item or component are executed.
The use of CAL provides a scheme to scale the rigorrigour of the cybersecurity development activities. This
can be communicated between customers and suppliers in a distributed development to highlight differences
in the security assurance to be expected from items or components. It does not provide an absolute measure.
It is not comparable between different customers or different suppliers.
CAL can also be used for out-of-context development in accordance withaccording to ISO/SAE 21434:2021,
6.4.5 with appropriate communication between customer and supplier.
The TAF concept introduced in Annexes CAnnexes C and DD describes the expected level of attack feasibility
once cybersecurity controls are applied for a given item or component. The TAF concept gives flexibility to the
organization that develops an item or component to specify and implement cybersecurity controls.
While ISO/SAE 21434:2021 does not require use of either CAL or TAF, they can be used to streamline
discussion and improve consistency between customers and suppliers.
Results from the requirements and recommendations in this document are incorporated into existing work
products defined in ISO/SAE 21434:2021.
© ISO/SAE 2026 – All rights reserved
v
ISO/SAE DPAS 8475:(en)
Road vehicles — Cybersecurity Assurance Levels (CAL) and Targeted
Attack Feasibility (TAF)
1 Scope
This document elaborates on the cybersecurity assurance level (CAL) classification scheme and introduces the
targeted attack feasibility (TAF) concept, both within the context of cybersecurity engineering for road
vehicles as specified in ISO/SAE 21434.
This document describes the concepts of CAL and TAF. It provides requirements and recommendations to
determine and use CAL as applied to cybersecurity engineering of an item or component.
2 Normative references
The following document is referred to in the text in such a way that some or all of its content constitutes
requirements of this document. For dated references, only the edition cited applies. For undated references,
the latest edition of the referenced document (including any amendments) applies.
ISO/SAE 21434:2021, Road vehicles — Cybersecurity engineering
3 Terms, definitions and abbreviated terms
3.1 Terms and definitions
For the purposes of this document, the terms and definitions given in ISO/SAE 21434:2021 and the following
apply.
ISO and IEC maintain terminological databases for use in standardization at the following addresses:
— IEC Electropedia: available at http://www.electropedia.org/
— ISO Online browsing platform: available at http://www.iso.org/obp
3.1.1 3.1.1
cybersecurity assurance level
CAL
rigour (3.1.3rigor (3.3)) during the concept and product development phases for an item or component
Note 1 to entry: CAL does not address the selection of cybersecurity controls.
3.1.2 3.1.2
targeted attack feasibility
TAF
required attack feasibility rating for an item or component after cybersecurity controls are applied
3.1.3
rigor
3.1.3
rigour
depth (3.1.4) and breadth (3.1.5) in performing cybersecurity activities that support justifiable confidence in
the achieved results
© ISO/SAE 2026 – All rights reserved
ISO/SAE DPAS 8475:(en)
3.1.33.1.4 3.1.4
depth
detail at which cybersecurity activities are performed
3.1.43.1.5 3.1.5
breadth
range of cybersecurity activities performed
3.1.53.1.6 3.1.6
static factor
risk-related factor that is expected not to change during the development of an item or component
3.2 Abbreviated terms
CAN controller area network
ECU electronic control unit
CAN controller area network
ECU electronic control unit
4 General
This document describes the cybersecurity assurance level (CAL) classification scheme. CAL is used in the
concept and product development phases to specify and communicate a set of cybersecurity activities, in
terms of rigorrigour, to provide justifiable confidence that the cybersecurity engineering of an item or
component is appropriate.
CAL is an attribute of a cybersecurity goal. CAL provides a common language for communicating the required
rigorrigour of cybersecurity activities between organizations.
The determination, assignment and use of CAL is illustrated in Figure 1Figure 1. A CAL is determined, using a
combination of static factors (see 5.2.15.2.1).). The CAL is then assigned as an attribute of a cybersecurity goal
and inherited by the cybersecurity requirements specified from that cybersecurity goal (5.2.2(5.2.2).). Finally,
the cybersecurity activities related to the cybersecurity requirements are performed at the rigorrigour set by
the CAL (6.2(6.2 and Annex BAnnex B).).
© ISO/SAE 2026 – All rights reserved
ISO/SAE DPAS 8475:(en)
Figure 1 — Determination, assignment and use of CAL
A CAL is determined during the concept phase. CAL remains fixed throughout concept and development
phases to provide a consistent level of assurance, unless the basis for determining CAL changes (e.g. a change
of functionality introducing a new damage scenario or an update to an item or component). Any changes in
CAL during the product development phase are handled through change management in accordance with
ISO/SAE 21434:2021, 5.4.4, [RQ-05-11].
© ISO/SAE 2026 – All rights reserved
ISO/SAE DPAS 8475:(en)
EXAMPLE Due to an update to an item or component.
If ISO/SAE 21434:2021, 6.4.2, [PM-06-08] is applied, CAL is not applicable.
CAL is not the same as tailoring defined in ISO/SAE 21434:2021, 6.4.3. If tailoring is used, the tailored activities
are performed at the associated CAL.
5 CAL determination and assignment
5.1 Objectives
The objectives of this clause are to:
a) determine a CAL; and
b) assign a CAL as an attribute of a cybersecurity goal.
5.2 Recommendations and permissions
5.2.1 CAL Determination
5.2.1.1 The determined CAL should be taken into account in applying ISO/SAE 21434:2021, 6.4.2, [RQ-06-
06].
NOTE Organizations can adjust their policies, rules and processes if they decide to use CAL.
5.2.1.2 A CAL should be CAL1, CAL2 or CAL3.
NOTE 1 CAL1 is basic rigorrigour, CAL2 is intermediate rigorrigour and CAL3 is advanced rigorrigour. See tables in
Annex BAnnex B for examples of scaling.
NOTE 2 In the further development of the CAL in this document, the number of levels was reduced to three from the
four levels in ISO/SAE 21434:2021, Annex E.
NOTE 3 Factors of rigorrigour are depth and breadth.
NOTE 4 ISO/SAE 21434:2021 requires independence for cybersecurity assessment (see Table B.6Table B.6).).
5.2.1.3 A CAL should be determined based on the combination of the impact rating and the attack vector of
a threat scenario.
NOTE 1 Impact rating is determined in accordance withaccording to ISO/SAE 21434:2021, 15.5.2, [RQ-15-05].
NOTE 2 Attack vector is used because it is a static factor.
NOTE 3 For a detailed explanation of the attack vector-based approach, see ISO/SAE 21434:2021, Table G.9.
NOTE 4 Impact categories can be considered when determining a CAL.
NOTE 5 Organizations determine the CAL mapping to impact rating and attack vector based upon their internal
process.
NOTE 6 See Annex AAnnex A for examples.
5.2.1.4 The determination of CAL from 5.2.1.2 may be changed based on consideration of other static
factors, with a rationale.
© ISO/SAE 2026 – All rights reserved
ISO/SAE DPAS 8475:(en)
EXAMPLE Static Factor: Architectural decisions, such as a single ECU on a CAN network segment protected by a
gateway.
Rationale: The ECU is protected by a gateway on the CAN network segment. In that case, the original attack
vector evaluated as “Network"network” is equivalent to “Local“,local”, and this changes the CAL.
5.2.1.5 Once a CAL has been determined and assigned, it is intended to remain stable but may be changed.
NOTE Any change is handled through change management in accordance withaccording to ISO/SAE 21434:2021,
5.4.4, [RQ-05-11].
EXAMPLE 1 During an update to an item or component.
EXAMPLE 2 Changes to a threat scenario.
5.2.2 CAL Assignment
5.2.2.1 The determined CAL should be assigned as an attribute of the corresponding cybersecurity goals
resulting from the associated threat scenario, in accordance withaccording to ISO/SAE 21434:2021, 9.4.2,
[RQ-09-05].
5.2.2.2 A cybersecurity requirement derived from a cybersecurity goal or higher-level cybersecurity
requirement should inherit the CAL assigned to the cybersecurity goal or higher-level cybersecurity
requirement.
5.2.2.3 If a cybersecurity requirement is associated with multiple cybersecurity goals or higher-level
cybersecurity requirements, it should inherit the highest CAL of those cybersecurity goals or higher-level
cybersecurity requirements.
NOTE 1 Refer to Annex AAnnex A for examples of assignments of CAL to cybersecurity requirements.
NOTE 2 The cybersecurity requirements with their associated CALs are documented in the cybersecurity concept and
cybersecurity specification, in accordance withaccording to ISO/SAE 21434:2021, 9.5.3, [WP-09-06]], and 10.5, [WP-10-
01].
5.2.2.4 A cybersecurity activity for an item or component should be performed at the highest CAL
associated with the cybersecurity requirements allocated to the item or component.
NOTE 1 Cybersecurity requirements are allocated to an item or component in accordance withaccording to ISO/SAE
21434:2021, 9.5.2, [RQ-09-10].
NOTE 2 See Annex BAnnex B for usage of CAL in cybersecurity activities.
5.2.2.4 If cybersecurity activities are associated with a subset of allocated cybersecurity requirements, then
those activities may be performed at the highest CAL associated with that subset.
5.2.2.5 If a first component cannot be adversely affected by a second component, then the cybersecurity
activities for the second component may be performed at a lower CAL than the cybersecurity activities for the
first component, with a rationale.
NOTE See example in Figure A.3Figure A.3.
EXAMPLE Development of a hypervisor and a guest.
6 CAL usage and examples
6.1 Objective
The objective of this clause is to use a CAL to determine rigorrigour for performing cybersecurity activities.
© ISO/SAE 2026 – All rights reserved
ISO/SAE DPAS 8475:(en)
6.2 Recommendations and permissions
6.2.1 CAL usage
6.2.1.1 The CAL determined in accordance with according to 5.2 should be used to scale the rigorrigour of the
cybersecurity activities performed to fulfil the corresponding requirements of ISO/SAE 21434.NOTE 1
See tables in Annex B:2021 for examples of scaling rigour.
NOTE 1  See tables in for examples of scaling rigor.
NOTE 2 The selected rigorrigour can be included in an appropriate ISO/SAE 21434:2021 work product, e.g.
cybersecurity plan, cybersecurity interface agreement, verification specification.
NOTE 3 2 The evidence for achieving the assurance associated to the assigned CAL is documented in the appropriate
work products in accordance withaccording to ISO/SAE 21434:2021.
© ISO/SAE 2026 – All rights reserved
ISO/SAE DPAS 8475:(en)
Annex A
(informative)
Assignment of CAL to cybersecurity requirements
A.1 General
This annex describes CAL determination, the assignment of CAL, the allocation of cybersecurity requirements
to an item and components, and the refinement of cybersecurity requirements.
A.2 Example of CAL determination
Tables A.1Tables A.1 and A.2A.2 give examples of CAL determination using impact rating and attack vector.
The first example shows the application of ISO/SAE 21434:2021, 6.4.2, [PM-06-08] to threat scenarios with
negligible impact ratings with a risk value of 1.
Table A.1 — Example of determining CAL
Attack vector
Physical Local Adjacent Network
Impact Severe CAL2 CAL2 CAL2 CAL3
rating
Major CAL1 CAL2 CAL2 CAL2
Moderate CAL1 CAL1 CAL2 CAL2
Negligible See ISO/ SAE 21434:2021, 6.4.2, [PM-06-08]
Table A.2 — Example of determining CAL
Attack vector
Physical Local Adjacent Network
Impact Severe CAL1 CAL2 CAL3 CAL3
rating
Major CAL1 CAL2 CAL2 CAL3
Moderate CAL1 CAL2 CAL2 CAL2
Negligible CAL1 CAL1 CAL1 CAL1
Examples of physical attack vector can include:
— desoldering a system-on-chip from a printed circuit board;
— connecting to a non-exposed JTAG port; and
— making physical modifications to the vehicle.
A.3 Assignment of CAL to cybersecurity requirements
Cybersecurity goals are specified according to ISO/SAE 21434:2021, 9.4.2, [RQ-09-05] and CALs are assigned
to corresponding cybersecurity goals as their attributes in accordance withaccording to 5.2.2.1.
© ISO/SAE 2026 – All rights reserved
ISO/SAE DPAS 8475:(en)
The cybersecurity requirements are defined for the cybersecurity goals according to ISO/SAE 21434:2021,
9.5.2, [RQ-09-09] and cybersecurity requirements are assigned the same CAL associated with the
cybersecurity goal from which the cybersecurity requirement is defined. If a cybersecurity requirement is
derived from multiple cybersecurity goals, the cybersecurity requirement is assigned the highest CAL of the
related cybersecurity goals (see 5.2.2.3). An example of the assignment of CALs to cybersecurity requirements
is shown in Figure A.1Figure A.1. .

Figure A.1 — Example of assignment of CALs to the cybersecurity requirements from the
cybersecurity goals
A.4 Allocation of cybersecurity requirements to items or components with CAL
This section illustrates how to allocate cybersecurity requirements and their assigned CAL to an item and
components.
Cybersecurity requirements are allocated to the item and one or more components according to
ISO/SAE 21434:2021, 9.5.2, [RQ-09-10]. Cybersecurity requirements are subsequently allocated to
components of the architectural design in accordance with ISO/SAE 21434:2021, 10.4.1, [RQ-10-02].
Figure A.2Figure A.2 shows an example where there is no isolation in the cybersecurity concept and
cybersecurity specification. Component B is isolated from Componentcomponent A if Componentcomponent
B cannot be adversely affected by Componentcomponent A. Under ,5.2.2.4, the cybersecurity activities
performed during the development of the components are done at the highest CAL of the allocated
cybersecurity requirements. Even if the highest CAL for each component is different, the lack of isolation from
other components with other requirements means that all components inherit the highest CAL of all
requirements assigned to the item, which is CAL3.
Figure A.3Figure A.3 is an example where isolation is considered in the cybersecurity concept and
cybersecurity specification. When different cybersecurity requirements have different CALs assigned, the
isolation enables the cybersecurity activities for a component to be performed at the highest CAL of all
inherited cybersecurity requirements without being affected by cybersecurity requirements allocated to other
components.
© ISO/SAE 2026 – All rights reserved
ISO/SAE DPAS 8475:(en)
An application of the example in Figure A.3Figure A.3 can be if Componentcomponent 2 represented an ECU,
Componentcomponent 5 represented a hypervisor, and Componentcomponent 6 represented a guest. Since
the guest cannot adversely affect the operation of the hypervisor, the cybersecurity activities on the guest are
performed at CAL1, while the cybersecurity activities of the hypervisor performed at CAL2.
© ISO/SAE 2026 – All rights reserved
ISO/SAE DPAS 8475:(en)
© ISO/SAE 2026 – All rights reserved
ISO/SAE DPAS 8475:(en)
Key
RQ cybersecurity requirement
Figure A.2 — Example of allocation of cybersecurity requirements including CAL without isolation
© ISO/SAE 2026 – All rights reserved
ISO/SAE DPAS 8475:(en)
© ISO/SAE 2026 – All rights reserved
ISO/SAE DPAS 8475:(en)
Key
RQ cybersecurity requirement
isolated
Figure A.3 — Example of allocation of cybersecurity requirements including CAL with isolation
between components
A.5 Example refinement of cybersecurity requirements
This sub-clausesubclause describes the concept of refining cybersecurity requirements. When a cybersecurity
requirement is refined into multiple cybersecurity requirements, each refined cybersecurity requirement can
be assigned a different CAL (see 5.2.2.5 and 5.2.2.6). Figure A.4Figure A.4 illustrates an example where RQ A
is refined into RQ B and C. RQ B is assigned CAL X, while RQ C is assigned CAL Y which is less than CAL X. These
cybersecurity requirements are allocated to different components.

Figure A.4 — Example refinement of a cybersecurity requirement
© ISO/SAE 2026 – All rights reserved
ISO/SAE DPAS 8475:(en)
Annex B
(informative)
Examples of scaling rigorrigour
This annex present examples of scaling the rigorrigour by depth and breadth for CAL1, CAL2 and CAL3 related
to the requirements and recommendations in ISO/SAE 21434:2021. These examples follow the
requirementsrecommendations in 6.2.16.2.1. These are examples and are not an exhaustive list. Other ways
of scaling rigorrigour based on depth and breadth can be considered.
Tables B.1 to B.6Each table lists list a requirement or recommendation in ISO/SAE 21434:2021 and then
examples of depth and breadth. The tables are followed by examples of what and how cybersecurity activities
under that requirement or recommendation could be conducted for each CAL.
Table B.1Table lists examples of breadth and depth for ISO/SAE 21434:2021, 10.4.1, [RQ-10-07].
Table B.1 — Examples of breadth and depth for ISO/SAE 21434:2021, [RQ-10-07]
ISO/SAE Examples of breadth Examples of depth
21434:2021 requirement/ or
recommendation
— Analysis of architectural design focusing on
[RQ-10-–07] Analyse the architecture
external interfaces of the component
design to identify
The architectural design defined in
weaknesses in the
[RQ-10-–01] shall be analysed to
— Analysis of architectural design considers
component considering
identify weaknesses.
the interfaces and interactions between
walk-through review,
components including sub-components
inspection or similar
methods.
— Details about architectural design
NOTE 1 Analysis of vulnerabilities is covered in ISO/SAE 21434:2021 8.5.
Examples of each CAL for ISO/SAE 21434:2021, [RQ-10-07]:], include:
CAL1: Walk-through review of the architectural design focusing on external interfaces to identify weaknesses
in the component.
CAL2: Inspection review of the architectural design focusing on external interfaces to identify weaknesses in
the component.
CAL3: Inspection review of the architectural design focusing on external interfaces and interfaces and
interactions between sub-components to identify weaknesses in the component.
Table B.2Table lists examples of breadth and depth for ISO/SAE 21434:2021, [RQ-10-08].
Table B.2 — Examples of breadth and depth for ISO/SAE 21434:2021, [RQ-10-08]
ISO/SAE Examples of breadth Examples of depth
21434:2021 requirement/ or
recommendation
— Level of detail in verification approach
[RQ-10-–08] Verification Enforcement of
correctness /, consistency
© ISO/SAE 2026 – All rights reserved
...