Tensor Earns ISO/SAE 21434 Cybersecurity Certification

Tensor Auto's Cybersecurity Management System earned ISO/SAE 21434 certification from Applus+ IDIADA with zero non-conformities, a process step the company says supports UN R155 type approval in global markets.

Tensor Auto has earned ISO/SAE 21434 certification for its Cybersecurity Management System (CSMS), and auditor Applus+ IDIADA recorded zero findings or non-conformities. Tensor is the San Jose, California-based developer of the Tensor Robocar, an SAE Level 4 vehicle designed for private ownership and robotaxi deployment. The company announced the certification this week and says it establishes the process foundation for UN R155 type approval. According to Tensor, UN Regulation No. 155 governs cybersecurity type approval of vehicles in more than 60 countries, including the European Union, the United Kingdom, Japan, and South Korea.

Highlights

  • Zero non-conformities were recorded in the independent Applus+ IDIADA audit of Tensor’s CSMS.
  • Seven core engineering processes were audited, from threat analysis to end-of-line production verification.
  • More than 60 countries apply UN R155 cybersecurity type approval, according to the company.
  • Four offices support Tensor’s global plans: San Jose, Barcelona, Singapore, and Dubai.

What Does ISO/SAE 21434 Certification Cover?

ISO/SAE 21434 sets engineering requirements for managing cybersecurity risk across the full lifecycle of connected vehicles. That lifecycle runs from initial concept and hardware-software design through production, post-production operation, and decommissioning.

Tensor says certification with zero non-conformities confirms that its CSMS aligns with the cybersecurity management requirements underlying UN R155.

Edge-First Architecture Under Review

The Tensor Robocar handles environmental perception, trajectory planning, and biometric authentication on the vehicle, using its onboard supercomputing stack. The Applus+ IDIADA audit covered the cybersecurity process governing this edge-first architecture. The company reports that the architecture is designed to operate without persistent cloud connectivity.

“In the era of Physical AI, cybersecurity isn’t just about protecting software—it’s about safeguarding personal agency. While legacy automakers build connected vehicles that continuously stream data back to corporate clouds, the Tensor Robocar is engineered to answer solely to its owner. Completing the ISO/SAE 21434 audit with zero findings shows that our security-by-design processes are built to the standard the world’s regulators expect – and that decentralized, onboard AI supercomputing can be developed with cybersecurity engineered in from the ground up,” said Dr. Jay Xiao, founder and CEO of Tensor.

Which Engineering Processes Were Audited?

  • Lifecycle-wide security engineering: Every cybersecurity work product is uniquely identified, version-controlled, and traceable from top-level vehicle goals down to component requirements and verification tests.
  • Threat Analysis and Risk Assessment (TARA): TARAs are run at vehicle and ECU level, with traceability between assets, threat scenarios, attack paths, risks, and controls, using ISO/SAE 21434 methods.
  • Vehicle Security Operations Center (VSOC): The center provides intrusion detection, tiered incident escalation, and defined response timelines for deployed vehicles.
  • Secure over-the-air (OTA) updates: Tensor’s proprietary OTA platform manages, deploys, and monitors firmware packages under cryptographic control.
  • Defensive validation: This covers penetration testing, fuzz testing, communication security testing, and static and dynamic code analysis, all linked to requirements derived from the TARA.
  • Supply chain governance: Cybersecurity-relevant suppliers are evaluated on governance, secure development practices, vulnerability management, incident support, evidence delivery, and change control.
  • Production and end-of-line verification: Cybersecurity requirements extend into vehicle flashing, provisioning, configuration, functional validation, and end-of-line testing before commercial release.

Alejandro Manilla of Applus+ IDIADA said the assessment was an independent evaluation of Tensor’s processes against ISO/SAE 21434. He said Tensor demonstrated compliance with the standard’s applicable requirements and that Applus+ IDIADA expects to continue working with the company.

UN R155 Type Approval and Platform Licensing

Tensor says the certification lays the groundwork for vehicle homologation and UN R155 type approval in Europe, the United Kingdom, South Korea, and Japan.

The certification also supports the company’s licensing business. Tensor offers a full-stack AI driving technology platform to automakers and Tier-1 suppliers under an Autonomous Driving as a Service (ADaaS) model. According to the company, the certification strengthens the cybersecurity foundation for that platform, covering the processes behind its vehicle architecture, software, onboard computing, secure OTA updates, and vehicle security operations.

Tensor was founded in Silicon Valley in 2016. The company’s Level 4 personal Robocar features a foldable steering wheel, retractable pedals, and a sliding display. Tensor has offices in San Jose, Barcelona, Singapore, and Dubai.

How this story was produced: drafted with AI assistance from company announcements and public sources, then reviewed, edited and approved by publisher Brian Hagman. Our editorial standards →
Self Drive News
Self Drive News Staff

Self Drive News is the trade publication of record for vehicle autonomy. Published by Hagman Media and edited by founder Brian Hagman, it covers autonomous vehicles, robotaxis, ADAS, self-driving software and hardware, and L4 commercial deployments for an audience of AV engineers, software safety professionals, and mobility investors.