Complete Vehicle-Wide Visibility
RunSafe Security’s Approach to R155/ISO21434
As vehicles become increasingly software-defined and interconnected, cybersecurity now plays a direct role in vehicle safety and operational integrity. New global standards and regulatory requirements reflect this shift, recognizing that vulnerabilities in connected ECUs, over-the-air update systems, and supplier-provided components can introduce real-world safety risk. The compliance landscape is evolving from process documentation to demonstrable, lifecycle cybersecurity assurance.
New Expectations: ISO 21434
Automotive manufacturers and suppliers face increasing regulatory scrutiny under ISO/SAE 21434 and UNECE R155. An SBOM alone is not enough. To ensure vehicle safety and regulatory approval, OEMs are expected to demonstrate:
- A complete, validated SBOM
- A clear understanding of vulnerabilities
- A risk-based remediation strategy
- Vehicle lifecycle monitoring and response processes
“From our perspective, adding RunSafe means we have more opportunity to shrink the attack surface and reduce overall risks for our customers since security is now already built into our product.”
How RunSafe Supports Automotive Compliance
RunSafe strengthens the technical evidence required to support ISO/SAE 21434 engineering activities and UNECE R155 CSMS regulatory obligations — without compromising functional safety under ISO 26262 (including ASIL A-D)
Software Transparency & SBOM Accuracy
Complete, validated SBOM ready to meet ISO 21434 standards as key aspect for software component management.
- Automated build-time SBOM generation for embedded systems
- Accurate ECU software inventory
- CycloneDX-compliant and aligned to NTIA minimum elements
Exploitability-Based Risk Clarity
Risk prioritization grounded in clear, outlined vulnerability posture.
- Maps CVE to SBOM components in real time
- Assesses and prioritize vulnerability by exploitability — not just presence
- Determines urgency (patch, mitigate, monitor, accept risk)
- Supports VEX documentation
Measurable Risk Reduction
Demonstrable reduction of exploitable software risk
- Makes classes of memory-based vulnerabilities non-exploitable
- Reduces risk when patches are unavailable
- No source code rewrites required
Lifecycle Monitoring Support
Sustained compliance confidence across the vehicle lifecycle.
- Continuous monitoring for new CVEs
- SBOM diff comparisons between builds
- Integration with GitHub, GitLab, Bitbucket
A Stroger Cybersecurity Position
RunSafe provides technical evidence and reporting that supports these elements.
| Component | Supported by RunSafe |
|---|---|
| Item Definition | ✓ |
| TARA (Threat Analysis & Risk Assessment) | ✓ |
| Cybersecurity Concept | ✓ |
| Cybersecurity Requirements & Architecture | ✓ |
| Verification & Validation Evidence | ✓ |
| Residual Risk & Cybersecurity Case | ✓ |
| SBOM & Vulnerability Status | ✓ |
| Post-Development Monitoring & Response Plan | ✓ |
Why RunSafe?
RunSafe helps automotive manufacturers and suppliers turn SBOMs into defensible cybersecurity evidence. By identifying vulnerabilities, prioritizing exploitability, and reducing real-world risk, we enable measurable compliance support for ISO 21434 and R155 — strengthening certification readiness and lifecycle assurance across the vehicle ecosystem.
Latest Resources
Why Critical Infrastructure Needs Operational Software Assurance
The world has changed, and software security has to change with it. Artificial intelligence is changing the risk profile of software by accelerating vulnerability discovery and exploit development. Geopolitical tensions are rising, putting more critical systems into...
Following Water System Cyberattacks, What Should “Secure” Actually Mean?
In late July, a coordinated cyberattack hit the operational technology (OT) at more than 30 community water systems in Minnesota, the first state to confirm what has since grown into a much larger campaign. Cyberattacks on water and wastewater systems have now been...
Preparing for the CRA: SBOM Adoption for Embedded Software Teams
On July 27, 2026, the European Commission published its most substantial guidance yet on applying the EU Cyber Resilience Act (CRA). The guidance helps manufacturers, developers, and businesses of all sizes by working through questions that have caused the most...



