Overview
ISO 24089:2023 - Road vehicles - Software update engineering defines requirements and recommendations for engineering processes that govern software updates for road vehicles. It applies across the supply chain - vehicle manufacturers, Tier‑1/ Tier‑2 suppliers, service providers and infrastructure operators - and covers organizational and project levels, vehicle and system functions, ECUs, infrastructure, software update packages and update campaigns. The standard establishes a common vocabulary and process framework to manage safety, cybersecurity and quality when software in vehicles is updated. It does not prescribe specific technologies or tools.
Key topics and technical requirements
ISO 24089 structures software update engineering into clear domains and work products. Important technical topics include:
- Organizational governance and continuous improvement
- Establishing policies, roles, auditing and information sharing for update engineering.
- Project-level management and tailoring
- Project planning, tailoring of processes, and rationale for decisions for each update project.
- Interoperability and integrity
- Ensuring updates are compatible with vehicle systems and ECUs; maintaining data integrity during assembly and deployment.
- Risk management
- Identifying and managing safety and cybersecurity risks related to update operations.
- Vehicle and infrastructure functions
- Defining and using vehicle and infrastructure capabilities to support update campaigns (e.g., communication, configuration reporting).
- Software update package assembly
- Identification of targets and contents, package assembly, verification, validation and release approval.
- Software update campaign lifecycle
- Preparation, execution (including OTA or workshop methods) and completion, with traceability and campaign communication.
- Configuration management and communication
- Maintaining individual vehicle configuration information and communicating campaign details to relevant parties.
These topics are reflected in the standard’s clauses on objectives, requirements/recommendations and work products for organizational, project, infrastructure, vehicle, package and campaign levels.
Practical applications - who uses this standard
ISO 24089 is intended for:
- OEMs and vehicle system integrators that plan and deliver software updates.
- Suppliers and ECU vendors that produce updatable software components.
- Service providers and infrastructure operators managing update delivery and campaign orchestration.
- Safety and cybersecurity teams ensuring updates don’t introduce hazards or vulnerabilities.
Benefits include improved update quality, consistent cross‑company communication, clearer roles and responsibilities, and stronger alignment of safety and cybersecurity in update operations.
Related standards
- ISO 26262 (Functional safety) - relevant for software safety aspects.
- ISO/SAE 21434 (Road vehicles - Cybersecurity engineering) - relevant for managing cybersecurity risks during updates.
Keywords: ISO 24089, software update engineering, road vehicles, OTA updates, vehicle cybersecurity, software update package, software update campaign, ECUs, vehicle systems.