UNECE R155 (UN Regulation No. 155 — Cybersecurity)
UNECE R155 is UN Regulation No. 155 on the cybersecurity of road vehicles. It makes an audited Cyber Security Management System (CSMS) a prerequisite for type approval: without CSMS evidence, new vehicle types receive no approval in the EU — and thus no market access. The regulation was developed by the UNECE World Forum for Harmonization of Vehicle Regulations (WP.29).
What does R155 require?
The regulation assesses on two levels, which must be passed separately:
- CSMS at organizational level: The manufacturer must demonstrate that it systematically identifies, assesses and treats cybersecurity risks — across the entire lifecycle from development through production to the operational phase in the field, including monitoring and response to new threats.
- Type approval per vehicle type: For each vehicle type, the manufacturer must prove that the risks of this specific type have been analyzed and appropriate measures implemented. The primary technical evidence for this is the documented threat analysis and risk assessment (TARA).
Both together mean: a one-off certificate is not enough. R155 mandates the continuous maintenance of the risk analyses — a TARA that is written once and filed away is already outdated by the time of the first new attack.
The deadlines
| Date | Scope |
|---|---|
| Since July 2022 | Mandatory for all new vehicle types |
| Since July 2024 | Mandatory for all newly produced and sold vehicles, including existing types |
| From December 2027 | CSMS obligation also for motorcycles |
Where does the regulation apply?
R155 applies in the contracting states of the UNECE 1958 Agreement that apply the regulation — including the EU member states, the United Kingdom, Japan and South Korea. It does not apply in the USA, where separate regulatory frameworks are in place. For manufacturers with global sales, R155 is nevertheless the de facto benchmark, because European type approval cannot be obtained without it.
Relationship to ISO/SAE 21434
ISO/SAE 21434 is a standard, R155 is mandatory. The regulation itself describes what must be demonstrated — a working CSMS and managed risks per vehicle type. How this evidence is technically provided is described by the standard: ISO/SAE 21434 is the recognized engineering framework with which manufacturers fulfil the R155 requirements. Those who implement the standard properly have the essential building blocks for type approval in place.
UNECE R155 in practice
The most demanding part of R155 is not the first audit, but continuous operation: new vulnerabilities in installed components must be constantly assessed against the existing risk decisions — across many vehicle types and variants in parallel. This only works if the original decisions are documented and retrievable. This is exactly where spreadsheet-based approaches typically fail first: the question is rarely whether a threat exists, but whether a new CVE changes an attack path that was previously considered acceptable.


