Skip to main content

UNECE R155 (UN Regulation No. 155 — Cybersecurity)

UNECE R155 is UN Regulation No. 155 on the cybersecurity of road vehicles. It makes an audited Cyber Security Management System (CSMS) a prerequisite for type approval: without CSMS evidence, new vehicle types receive no approval in the EU — and thus no market access. The regulation was developed by the UNECE World Forum for Harmonization of Vehicle Regulations (WP.29).

What does R155 require?

The regulation assesses on two levels, which must be passed separately:

  1. CSMS at organizational level: The manufacturer must demonstrate that it systematically identifies, assesses and treats cybersecurity risks — across the entire lifecycle from development through production to the operational phase in the field, including monitoring and response to new threats.
  2. Type approval per vehicle type: For each vehicle type, the manufacturer must prove that the risks of this specific type have been analyzed and appropriate measures implemented. The primary technical evidence for this is the documented threat analysis and risk assessment (TARA).

Both together mean: a one-off certificate is not enough. R155 mandates the continuous maintenance of the risk analyses — a TARA that is written once and filed away is already outdated by the time of the first new attack.

The deadlines

DateScope
Since July 2022Mandatory for all new vehicle types
Since July 2024Mandatory for all newly produced and sold vehicles, including existing types
From December 2027CSMS obligation also for motorcycles

Where does the regulation apply?

R155 applies in the contracting states of the UNECE 1958 Agreement that apply the regulation — including the EU member states, the United Kingdom, Japan and South Korea. It does not apply in the USA, where separate regulatory frameworks are in place. For manufacturers with global sales, R155 is nevertheless the de facto benchmark, because European type approval cannot be obtained without it.

Relationship to ISO/SAE 21434

ISO/SAE 21434 is a standard, R155 is mandatory. The regulation itself describes what must be demonstrated — a working CSMS and managed risks per vehicle type. How this evidence is technically provided is described by the standard: ISO/SAE 21434 is the recognized engineering framework with which manufacturers fulfil the R155 requirements. Those who implement the standard properly have the essential building blocks for type approval in place.

UNECE R155 in practice

The most demanding part of R155 is not the first audit, but continuous operation: new vulnerabilities in installed components must be constantly assessed against the existing risk decisions — across many vehicle types and variants in parallel. This only works if the original decisions are documented and retrievable. This is exactly where spreadsheet-based approaches typically fail first: the question is rarely whether a threat exists, but whether a new CVE changes an attack path that was previously considered acceptable.

Frequently asked questions

What happens without a CSMS?
Without an audited Cyber Security Management System there is no type approval under R155 — and without type approval no market access in the applying states, including the entire EU. Cybersecurity is thus no longer a technical recommendation, but a commercial prerequisite.
Does UNECE R155 also apply to suppliers?
The regulation formally addresses the vehicle manufacturer applying for type approval. However, the OEM must demonstrate that cybersecurity risks are managed across the entire supply chain — and therefore passes the requirements on contractually to tier 1 and tier 2 suppliers, typically via the Cybersecurity Interface Agreement.
Is ISO/SAE 21434 conformity sufficient for R155 type approval?
ISO/SAE 21434 is the recognized technical framework for meeting the R155 requirements — but it does not replace the assessment. The approval authority evaluates the manufacturer’s CSMS and the evidence for the specific vehicle type, first and foremost the documented TARA.

Related terms

Reviewed by Dirk Leopold, Executive Vice President Digital Engineering on July 20, 2026