UN Regulation No. 155 — Uniform provisions concerning the approval of vehicles with regards to cyber security and cyber security management system

International

RAI-IO-UNECE-R155-2021

UN Regulation No. 155

Effective: January 22, 2021
In Force (Amended)(In Force (Amended))
RegulationRisk ManagementSafety, Testing, and Evaluation
Export PDF

UN Regulation No. 155 mandates vehicle manufacturers to implement robust Cybersecurity Management Systems (CSMS) to manage cyber risks across the entire vehicle lifecycle, ensuring safety and security for connected and automated vehicles globally.

Overview

UN Regulation No. 155 (UN R155) represents a landmark international regulatory framework designed to address the escalating cybersecurity threats facing modern vehicles. Developed under the auspices of the United Nations Economic Commission for Europe (UNECE) World Forum for Harmonization of Vehicle Regulations (WP.29), this regulation aims to establish a standardized approach to securing connected and automated vehicles throughout their entire lifecycle. It formally entered into force on January 22, 2021, marking a pivotal moment in automotive cybersecurity governance. The core objective of UN R155 is to mandate that vehicle manufacturers implement a robust Cybersecurity Management System (CSMS), ensuring that cybersecurity is systematically considered and managed from the earliest design stages through to production, and extending into the post-production operational phase, including maintenance and decommissioning. This holistic approach is crucial given the increasing complexity and connectivity of vehicles, which introduce numerous potential attack vectors.

The scope of UN R155 primarily covers passenger cars (category M), commercial vehicles (category N), and certain trailers (category O) equipped with at least one electronic control unit. It is a binding regulation for the 54 countries that are Parties to the 1958 Agreement, including the European Union, the United Kingdom, Japan, and South Korea, where compliance became mandatory for all new vehicle types from July 2022 and for all new vehicles produced from July 2024. The regulation is not a technical specification itself but rather a regulatory framework that mandates organizational capability. Manufacturers must demonstrate their ability to identify cybersecurity threats, assess risks, implement protective measures, detect attacks, and respond to incidents effectively. This proactive and continuous management of cybersecurity risks is fundamental to obtaining and maintaining vehicle type approval, thereby ensuring that vehicles sold in contracting markets meet stringent security standards.

Definitions

UN Regulation No. 155 introduces and relies upon several key definitions to establish its requirements and scope. A central concept is the "Cybersecurity Management System (CSMS)," defined as a systematic risk-based approach that outlines organizational processes, responsibilities, and governance structures. Its purpose is to manage risks associated with cyber threats to vehicles and protect them from cyberattacks across their entire lifecycle. This encompasses the cybersecurity culture, organizational structure, documentation of development processes, continuous monitoring of work, and the necessary infrastructure and competencies within a manufacturing entity. Another critical term is "Type Approval," which refers to the procedure by which a Contracting Party to the 1958 Agreement certifies that a vehicle type meets the technical requirements of this Regulation, a prerequisite for selling vehicles in adhering markets.

The regulation also implicitly or explicitly references other important terms. A "vehicle type" is a classification used for approval purposes, referring to a series of vehicles that do not differ in essential cybersecurity-relevant characteristics. "Cybersecurity attack" refers to any attempt to compromise the confidentiality, integrity, or availability of vehicle systems or data. Related to this are "threats" (potential causes of an unwanted incident) and "vulnerabilities" (weaknesses that could be exploited by a threat). While UN R155 focuses on the CSMS, it is intrinsically linked to "Software Update Management System (SUMS)" as defined in UN Regulation No. 156, which addresses the secure and safe management of software updates, including over-the-air (OTA) updates, often crucial for mitigating cybersecurity risks post-production. These definitions collectively form the linguistic and conceptual backbone for implementing and enforcing vehicle cybersecurity requirements.

Governance and Institutional Framework

The governance of UN Regulation No. 155 is rooted in the United Nations Economic Commission for Europe (UNECE) and its World Forum for Harmonization of Vehicle Regulations (WP.29). WP.29 serves as a global regulatory forum responsible for developing and harmonizing UN Regulations concerning vehicle safety and environmental performance, now extended to include cybersecurity. The regulation's authority stems from the 1958 Agreement, to which 54 countries are Contracting Parties, committing them to apply these harmonized technical regulations. Within this framework, national Approval Authorities play a crucial role. They are responsible for granting type approval with regard to cybersecurity, verifying that vehicle manufacturers satisfy the requirements of UN R155. This involves auditing the manufacturer's CSMS and assessing the cybersecurity of specific vehicle types.

Vehicle manufacturers (OEMs) bear the primary responsibility for establishing, implementing, and maintaining a compliant Cybersecurity Management System. This obligation extends across the entire vehicle lifecycle, from the initial design and development phases through production and into the post-production operation, including ongoing monitoring and incident response. Manufacturers must demonstrate to the Approval Authorities that their CSMS is robust and effectively manages cybersecurity risks, including those related to their supply chain. The framework also emphasizes continuous improvement, requiring manufacturers to stay abreast of new cyber threats and vulnerabilities and adapt their security measures accordingly. This collaborative structure, involving international bodies, national authorities, and industry players, ensures a globally harmonized and continuously evolving approach to vehicle cybersecurity.

Key Focus Areas

UN Regulation No. 155 outlines several key focus areas that manufacturers must address to ensure vehicle cybersecurity. At its core, the regulation mandates a systematic approach to risk management. This involves the identification and assessment of cybersecurity risks throughout the vehicle's lifecycle, from concept to decommissioning. Manufacturers are required to identify critical elements of the vehicle type and perform an exhaustive risk assessment, considering individual elements and their interactions. Following risk identification, appropriate and proportionate protective measures must be implemented to mitigate these risks. Annex 5 of the regulation provides a list of attack vectors and potential mitigations, guiding manufacturers in their risk treatment strategies. This 'security by design' principle ensures that cybersecurity considerations are embedded from the earliest stages of vehicle development, rather than being an afterthought.

Beyond initial design and risk mitigation, UN R155 places significant emphasis on ongoing monitoring, detection, and response capabilities. Manufacturers must implement measures to detect and prevent cyberattacks against vehicles, support continuous monitoring for threats and vulnerabilities, and provide data forensic capabilities to analyze attempted or successful attacks. This includes managing cybersecurity throughout the supply chain, ensuring that suppliers also adhere to appropriate security standards. Furthermore, the regulation works in conjunction with UN Regulation No. 156 to ensure the safe and secure updating of vehicle software, including over-the-air (OTA) updates, which are critical for addressing vulnerabilities discovered post-production. These interconnected focus areas collectively aim to create a resilient and adaptable cybersecurity posture for modern vehicles, capable of evolving with the threat landscape.

Implementation Framework

The implementation framework for UN Regulation No. 155 centers on the establishment and maintenance of a Cybersecurity Management System (CSMS) by vehicle manufacturers. This system is not merely a set of technical controls but a comprehensive organizational capability that encompasses policies, processes, roles, competencies, and governance structures to manage cybersecurity across all projects and suppliers. Manufacturers must demonstrate that their CSMS applies to the vehicle development, production, and post-production stages, ensuring that cybersecurity is adequately considered and implemented continuously. This involves documenting required development processes and procedures, monitoring adherence to these processes, and verifying that the work performed results in appropriately secure products. The CSMS must also include provisions for managing dependencies with contracted suppliers and service providers, ensuring cybersecurity throughout the entire value chain.

To support compliance with the goal-based requirements of UN R155, many manufacturers leverage the international standard ISO/SAE 21434, "Road vehicles — Cybersecurity engineering". While R155 sets the regulatory mandate, ISO/SAE 21434 provides the technical framework and detailed guidance for implementing cybersecurity engineering processes, work products, and risk management activities. This standard helps organizations manage cyber risks and develop more secure, regulation-ready vehicles by focusing on a vehicle's electrical and electronic systems and in-vehicle software. Manufacturers must obtain a CSMS certificate from an approval authority, which is valid for three years, and then secure vehicle-level type approval for each vehicle type. Without both certificates, vehicles cannot be registered or sold in contracting markets, underscoring the critical role of this implementation framework in market access.

Monitoring and Evaluation

Monitoring and evaluation are integral components of UN Regulation No. 155, designed to ensure the continuous effectiveness of a manufacturer's Cybersecurity Management System (CSMS) and the ongoing cybersecurity posture of vehicles throughout their operational lifetime. Manufacturers are required to implement measures for the vehicle type to detect and prevent cyber-attacks, support the monitoring capability with regards to detecting threats, vulnerabilities, and cyber-attacks, and provide data forensic capability for analysis. This includes continuously evaluating new vulnerability information and taking appropriate action. The CSMS must demonstrate continuous improvement through management review, ensuring that the system remains current and effective against evolving cyber threats. This proactive stance is essential in a rapidly changing threat landscape, where new vulnerabilities and attack methods emerge regularly.

The effectiveness of the CSMS and vehicle cybersecurity measures is subject to oversight by the Approval Authorities. Manufacturers must undergo periodic audits of their CSMS, and the Certificate of Compliance for the CSMS is typically valid for three years, requiring renewal. During this period, Approval Authorities may conduct surveillance audits at any time to verify ongoing compliance. For each vehicle type, manufacturers must perform appropriate and sufficient testing to verify the effectiveness of the security measures implemented prior to type approval. This dual approach of continuous internal monitoring by manufacturers and external auditing by regulatory bodies ensures accountability and drives sustained efforts in maintaining high cybersecurity standards for vehicles, from their initial approval through their entire service life.

Penalties, Liability, and Appeals

While UN Regulation No. 155 itself does not explicitly detail specific penalties or liability clauses, the consequences of non-compliance are severe and directly impact a manufacturer's ability to sell vehicles in contracting markets. The regulation mandates that a manufacturer must have a valid Certificate of Compliance for their Cybersecurity Management System (CSMS) and obtain vehicle-level type approval for each vehicle type before it can be registered or sold. Failure to meet these requirements means that type approval will not be granted or can be withdrawn, effectively preventing the sale of non-compliant vehicles. This regulatory gatekeeping mechanism serves as the primary enforcement tool, compelling manufacturers to adhere to the cybersecurity provisions.

Beyond market access restrictions, non-compliance with UN R155 can lead to significant legal liabilities, reputational damage, and financial implications for vehicle manufacturers. In the event of a cybersecurity incident involving a non-compliant vehicle, manufacturers could face lawsuits, regulatory fines imposed by national authorities (which implement the UN Regulation into their national law), and substantial costs associated with recalls, investigations, and remediation. The emphasis on a robust CSMS also implies a shift in responsibility, placing a greater burden on manufacturers to demonstrate due diligence in cybersecurity throughout the vehicle's lifecycle. While the regulation does not outline an appeals process, any disputes regarding type approval decisions would typically fall under the administrative law of the respective national Approval Authority, allowing manufacturers to challenge adverse decisions through established legal channels.

Relationship to Other Instruments

UN Regulation No. 155 does not exist in isolation but is part of a broader ecosystem of international regulations and standards aimed at enhancing vehicle safety and security. It is intrinsically linked with UN Regulation No. 156 (UN R156) on Software Update Management Systems (SUMS). UN R156 sets requirements for managing software updates securely throughout a vehicle's lifetime, including over-the-air (OTA) updates, which are often critical for mitigating cybersecurity risks identified post-production. The two regulations are complementary, with R155 focusing on the overall cybersecurity management system and R156 addressing the secure deployment of software changes, both being prerequisites for type approval in many jurisdictions. This integrated approach ensures both the initial security of the vehicle and its ability to adapt to new threats through secure updates.

Furthermore, UN R155 is strongly influenced by and often implemented in conjunction with the international standard ISO/SAE 21434, "Road vehicles — Cybersecurity engineering". While R155 provides the high-level regulatory framework and mandates organizational capabilities, ISO/SAE 21434 offers detailed technical guidance and processes for implementing cybersecurity engineering throughout the vehicle development lifecycle. Manufacturers often use ISO/SAE 21434 to demonstrate compliance with the technical aspects of R155's CSMS requirements. The regulation also coordinates with other standards such as ISO 26262 for functional safety, recognizing the interplay between safety and security in complex automotive systems. Beyond these, UN R155 serves as a benchmark for national and regional regulations, influencing or aligning with instruments like the EU Cyber Resilience Act and China's GB 44495 automotive cybersecurity standard, fostering a globally harmonized approach to vehicle cybersecurity.

International Alignment

UN Regulation No. 155 plays a pivotal role in fostering international alignment on vehicle cybersecurity. As the first binding international regulation specifically governing vehicle cybersecurity, it sets a global benchmark for the industry. Developed and adopted by the UNECE World Forum for Harmonization of Vehicle Regulations (WP.29), it is applicable in the 54 countries that are Parties to the 1958 Agreement, which includes major automotive markets such as the European Union, the United Kingdom, Japan, and South Korea. This widespread adoption ensures a common baseline for cybersecurity requirements across a significant portion of the global automotive market, facilitating trade and reducing regulatory fragmentation for manufacturers operating internationally.

The principles and requirements of UN R155, particularly around the Cybersecurity Management System (CSMS), have been widely embraced by both OEMs and suppliers globally. Consequently, the regulation is not only binding in its direct contracting parties but also serves as a foundational reference for countries and regions outside the UNECE area developing their own parallel regulations. For instance, China's GB 44495 automotive cybersecurity standard is influenced by R155, and other countries continue to adopt or align with its provisions, expanding the global regulatory landscape. This international alignment is crucial for addressing the transnational nature of cyber threats and for ensuring that vehicles, regardless of their origin or destination, meet a consistent level of cybersecurity, thereby enhancing trust and safety in the global connected car ecosystem.

Implementation Timeline

MilestoneDateNotes
Regulation Adopted by WP.292020-06Formal adoption by the World Forum for Harmonization of Vehicle Regulations.
Entry into Force2021-01-22Official entry into force for Contracting Parties to the 1958 Agreement.
Mandatory for New Vehicle Types (EU, Japan, South Korea, etc.)2022-07Compliance required for all new vehicle types submitted for type approval.
Mandatory for All New Vehicles Produced (EU, Japan, South Korea, etc.)2024-07Compliance required for all new vehicles produced and sold, including existing vehicle types.
Supplement 3 to Original Version Entry into Force2025-01-10Latest amendment to the regulation enters into force.
Proposed Expansion to all Category L vehicles (if accepted)2029-07Potential future expansion of scope to include motorcycles and other L category vehicles.

Compliance Checklist

CheckRequired Action
Establish CSMSImplement a comprehensive Cybersecurity Management System covering vehicle development, production, and post-production stages.
Risk Assessment & ManagementSystematically identify, assess, and treat cybersecurity risks for each vehicle type, considering all critical elements and their interactions.
Protective MeasuresImplement appropriate and sufficient security measures to mitigate identified risks, including those outlined in Annex 5 of the regulation.
Testing & VerificationPerform thorough testing to verify the effectiveness of implemented security measures prior to type approval.
Incident Detection & ResponseImplement capabilities to detect and prevent cyberattacks, monitor for threats, and provide forensic data for incident analysis.
Software Update ManagementEnsure secure and safe management of software updates, aligning with UN Regulation No. 156 requirements.
Supply Chain CybersecurityIdentify and manage supplier-related cybersecurity risks, ensuring adequate consideration of security throughout the supply chain.
Documentation & EvidenceMaintain objective records demonstrating that the CSMS and risk management processes are consistently applied to the vehicle type under approval.
Continuous ImprovementEstablish processes for continuous monitoring, evaluation of new vulnerabilities, and regular review and improvement of the CSMS.
Obtain CSMS CertificateSecure a valid Certificate of Compliance for the CSMS from an approval authority, renewable every three years.
Obtain Vehicle Type ApprovalObtain cybersecurity type approval for each distinct vehicle type from the relevant Approval Authority.

Sources and References

SourceType
UN Regulation No. 155 - Cyber security and cyber security management system | UNECEofficial
UN Regulation No. 155 - Uniform provisions concerning the approval of vehicles with regards to cyber security and cyber security management system [2025/5] | EUR-Lexlegal
ECE/TRANS/WP.29/2020/155 - Original text of UN Regulation No. 155official
ECE/TRANS/WP.29/2024/155 - Supplement 3 to the original version of UN Regulation No. 155official
Plain English

UN Regulation No. 155 is an international law that requires vehicle manufacturers to implement robust cybersecurity management systems for connected and automated vehicles sold in countries that have adopted it.

This regulation applies to manufacturers of passenger cars (category M), commercial vehicles (category N), and certain trailers (category O) equipped with at least one electronic control unit. It is binding in 54 countries that are parties to the 1958 Agreement, including major markets like the European Union, the United Kingdom, Japan, and South Korea.

Manufacturers must establish and maintain a comprehensive Cybersecurity Management System (CSMS) across the entire vehicle lifecycle – from initial design and development through production, and into post-sale operation and maintenance. Key obligations include: - Systematically identifying and assessing cybersecurity risks for each vehicle type. - Implementing appropriate protective measures to mitigate these risks. - Developing capabilities to detect and prevent cyberattacks, continuously monitor for threats, and provide data for forensic analysis. - Managing cybersecurity risks throughout their supply chain, ensuring suppliers also meet security standards.

The regulation officially entered into force on January 22, 2021. It became mandatory for all new vehicle types submitted for approval from July 2022 and will apply to all new vehicles produced and sold from July 2024 in adhering markets.

The primary enforcement mechanism is market access. Manufacturers cannot sell their vehicles in these countries without first obtaining a valid CSMS certificate, which is audited and renewed every three years, and then securing vehicle-level type approval for each distinct vehicle type. Failure to comply means type approval will not be granted or can be withdrawn, effectively blocking sales. Beyond this, non-compliance can lead to significant legal liabilities, national fines, recalls, and severe reputational damage.

A crucial practical pitfall is understanding that this regulation mandates an *organizational system* for cybersecurity, not just technical controls. Manufacturers must demonstrate continuous management, monitoring, and adaptation of their CSMS, extending these requirements to their entire supply chain. It also works closely with UN Regulation No. 156, which governs the secure management of software updates, including over-the-air updates, essential for post-production security.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 13 marked complete

Plain-English obligations under UN Regulation No. 155 — Uniform provisions concerning the approval of vehicles with regards to cyber security and cyber security management system. Not legal advice — verify against the official text before relying on it.

  1. #1CriticalBefore placing on market

    Applies to: Manufacturers of vehicles (categories M, N, O) with electronic control units.

    mandate that vehicle manufacturers implement a robust Cybersecurity Management System (CSMS)
  2. #2CriticalBefore placing on market

    Applies to: Manufacturers of vehicles (categories M, N, O) with electronic control units.

    identify and assess of cybersecurity risks throughout the vehicle's lifecycle
  3. #3CriticalBefore placing on market

    Applies to: Manufacturers of vehicles (categories M, N, O) with electronic control units.

    appropriate and proportionate protective measures must be implemented to mitigate these risks.
  4. #4CriticalBefore placing on market

    Applies to: Manufacturers of vehicles (categories M, N, O) with electronic control units.

    Manufacturers must implement measures to detect and prevent cyberattacks against vehicles
  5. #5CriticalBefore placing on market

    Applies to: Manufacturers of vehicles (categories M, N, O) with electronic control units.

    provide data forensic capabilities to analyze attempted or successful attacks.
  6. #6CriticalBefore placing on market

    Applies to: Manufacturers of vehicles (categories M, N, O) with electronic control units.

    ensure the safe and secure updating of vehicle software, including over-the-air (OTA) updates
  7. #7CriticalBefore type approval

    Applies to: Manufacturers of vehicles (categories M, N, O) with electronic control units.

    Manufacturers must perform appropriate and sufficient testing to verify the effectiveness of the security measures
  8. #8CriticalBefore placing on market

    Applies to: Manufacturers of vehicles (categories M, N, O) with electronic control units.

    Manufacturers must obtain a CSMS certificate from an approval authority
  9. #9CriticalBefore placing on market

    Applies to: Manufacturers of vehicles (categories M, N, O) with electronic control units.

    secure vehicle-level type approval for each vehicle type.
  10. #10CriticalEvery 3 years

    Applies to: Manufacturers of vehicles (categories M, N, O) with electronic control units.

    the Certificate of Compliance for the CSMS is typically valid for three years, requiring renewal.
  11. #11ImportantBefore placing on market

    Applies to: Manufacturers of vehicles (categories M, N, O) with electronic control units.

    managing cybersecurity throughout the supply chain, ensuring that suppliers also adhere to appropriate security standards.
  12. #12ImportantBefore placing on market

    Applies to: Manufacturers of vehicles (categories M, N, O) with electronic control units.

    documenting required development processes and procedures
  13. #13Important

    Applies to: Manufacturers of vehicles (categories M, N, O) with electronic control units.

    The CSMS must demonstrate continuous improvement through management review

© Regulations.AI — created on 20-May-2026 using Gemini 2.5 Flash