| Clause | Title | Key Content |
|---|---|---|
| 5 | Overall Cybersecurity Management | CSMS, policy, competence, culture, management review |
| 6 | Project-Dependent Cybersecurity Management | Cybersecurity Plan, tailoring, seooC |
| 7 | Distributed Development | Cybersecurity Interface Agreement (CIA), supplier management |
| 8 | Continual Cybersecurity Activities | Monitoring, vulnerability management, incident response lifecycle |
| 9 | Concept Phase | Item definition, cybersecurity goals, cybersecurity concept |
| 10 | Product Development | Cybersecurity requirements, design, implementation, testing |
| 11 | Cybersecurity Validation | Validation of cybersecurity goals at system level |
| 12 | Production | Cybersecurity controls during manufacturing |
| 13 | Operations and Maintenance | Incident response, vulnerability disclosure, field monitoring |
| 14 | End of Life | Secure decommission, data deletion, certificate revocation |
| 15 | TARA Methods | Threat Analysis and Risk Assessment methodology (normative Annex B) |
💡 [RQ] vs [NI] Tags
ISO/SAE 21434 distinguishes normative requirements tagged [RQ] from informative notes tagged [NI]. Every [RQ] must be implemented and evidenced; [NI] items are guidance. A Technical Service assessment for UNECE R155 will walk every [RQ] in the applicable clauses and ask for evidence. Missing evidence for any [RQ] is a Major non-conformity blocking certification.