UN R155
UN Regulation No. 155 makes cybersecurity a condition for vehicle type approval. Who it applies to, the CSMS and vehicle requirements, and how the EU enforces it.
Updated This page as Markdown
In short
UN Regulation No. 155 is the UNECE regulation on cyber security and cyber security management systems for road vehicles. It requires manufacturers to hold a certified CSMS and to show, per vehicle type, that risks have been identified, treated and tested. In the EU it is mandatory through Regulation (EU) 2019/2144 for new vehicle types since July 2022 and for all new vehicles since July 2024.
What is UN R155?
UN R155 is the regulation of the UNECE World Forum for Harmonization of Vehicle Regulations (WP.29) that makes cybersecurity a condition for vehicle type approval. It has two parts. The manufacturer needs a Certificate of Compliance for its Cybersecurity Management System (paragraph 7.2), which shows that the organisation has processes to manage cybersecurity over the vehicle lifecycle. And each vehicle type needs an approval (paragraph 7.3), which shows that the manufacturer has identified the risks for that type, implemented proportionate mitigations, tested them and set up detection and response for the field.
The regulation came into force in January 2021 under the UNECE 1958 Agreement. Contracting parties include the EU member states, the UK, Japan and South Korea. The USA, Canada and China are not contracting parties and have their own approaches.
Where is it defined?
The text is published by UNECE and, for the EU, in the Official Journal (OJ L 82 of 9 March 2021). Regulation (EU) 2019/2144, the General Safety Regulation, makes it mandatory for EU type approval. The important paragraphs: 7.2 for the CSMS requirements, 7.3 for the vehicle type, 7.4 for the reporting duties of the manufacturer towards the approval authority (at least once a year on monitoring results), and Annex 5 with Part A (a list of threats and vulnerabilities), Part B (mitigations inside the vehicle) and Part C (mitigations outside the vehicle, such as back-end servers). Annex 5 is the checklist authorities use to see whether the TARA has considered everything the regulation expects.
What it means in practice
For OEMs, R155 means that cybersecurity documentation is part of the homologation file and that a technical service will read it. For suppliers it means the OEM asks for evidence that it can hand on: a TARA that covers the Annex 5 threats relevant to the component, cybersecurity requirements and their verification, penetration test and fuzzing reports, and a commitment to field monitoring.
In the complete-vehicle penetration test we did for an OEM, the test plan was derived directly from the vehicle TARA and Annex 5: external interfaces (cellular, Wi-Fi, Bluetooth, charging), diagnostic access over OBD and DoIP, in-vehicle networks and gateway filtering, and the back end. That is what paragraph 7.3.6 means by “appropriate and sufficient testing”: you test the mitigations the TARA claims, with evidence per claim.
Common misunderstandings
UN R155 is not a product standard with a security level you can “pass”. It is a process and evidence regulation; the actual security measures are what the manufacturer’s own risk analysis says they should be. It does not certify suppliers and it does not certify ECUs, only the manufacturer’s CSMS and the vehicle type. And it does not end at start of production: the monitoring, detection and reporting duties of paragraphs 7.2.2.2 (g) and 7.4 run as long as the vehicle type is supported.
FAQ
Frequently asked questions
Which vehicles does UN R155 apply to?
Paragraph 1 covers vehicle categories M and N (passenger cars, buses, trucks), and O trailers if they have at least one electronic control unit; L6 and L7 light vehicles are included when equipped with automated driving functions of level 3 or above. In the EU, Regulation (EU) 2019/2144 made it binding for new types from 6 July 2022 and for all newly registered vehicles from 7 July 2024.
Does UN R155 apply to suppliers?
Legally it addresses the vehicle manufacturer, who applies for the approval. The manufacturer has to show that supplier-related risks are managed (paragraph 7.2.2.3), so ECU and software suppliers receive the requirements by contract: ISO/SAE 21434 processes, a TARA for their component, test evidence and support in the field phase.
What is the difference between UN R155 and UN R156?
R155 is about cybersecurity and the CSMS. R156 is the sister regulation on software updates and the software update management system (SUMS), including over-the-air updates and the RxSWIN identifier. Both were adopted together and both are required for EU type approval.
Sources
Related pages
- GlossaryCSMS (Cybersecurity Management System)A CSMS is the organisational process framework UN R155 requires from vehicle manufacturers. What it must cover, how it is audited, and what suppliers deliver to it.
- GlossaryISO/SAE 21434ISO/SAE 21434:2021 is the standard for cybersecurity engineering of road vehicles. Its clauses, how it relates to UN R155, and what it asks from OEMs and suppliers.
- GlossaryTARA (Threat Analysis and Risk Assessment)TARA is the risk analysis method of ISO/SAE 21434 for vehicles and ECUs. The seven steps, how impact and attack feasibility are rated, and what a usable TARA looks like.
- InsightsISO/SAE 21434 vs UN R155: How They Fit TogetherUN R155 is the law, ISO/SAE 21434 is the engineering standard. Learn how CSMS, TARA and testing connect, and what suppliers need to deliver to OEMs.
- For your industryCybersecurity for Automotive Suppliers: UN R155, ISO/SAE 21434 and the CRAWhat Tier-1 and Tier-2 suppliers must deliver for cybersecurity: UN R155 and R156 via the OEM, ISO/SAE 21434 work products, CRA for aftermarket parts and a first project.
- ServicesFind the vulnerabilities in your vehicle before attackers do.ECU and vehicle penetration testing, fuzzing, TARA and ISO/SAE 21434 consulting to meet UN R155/R156. Hands-on automotive security experts from Germany.
