UN Regulation No. 155 — Cybersecurity and Cybersecurity Management System

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
UNECE WP.29 — Vehicle Cybersecurity Regulation (R155) is an international automotive cybersecurity regulation that requires vehicle manufacturers to implement and maintain robust cybersecurity management systems to ensure the security of vehicles throughout their lifecycle. Its primary goal is to mitigate cybersecurity risks that could impact road safety, vehicle operations, and data protection.
Published by the United Nations Economic Commission for Europe (UNECE), this regulation is mandatory for automotive manufacturers selling vehicles in markets governed by UNECE member states, including much of Europe and parts of Asia. R155 provides requirements related to risk management, secure software updates, and the protection of vehicle electronic systems from cyber threats, supporting organizations in establishing effective cybersecurity controls and compliance practices.
To comply with UNECE R155, organizations integrate cybersecurity risk assessments, develop and enforce technical security controls, and maintain ongoing incident response capabilities as part of their product development and management processes. The regulation also aligns with established information security frameworks, supporting automotive cybersecurity governance and audit readiness within broader compliance programs.
Why it Matters
UNECE WP.29 R155establishes comprehensive vehicle cybersecurity management, ensuringautomotive manufacturers safeguard vehicles and their data throughoutthe entire lifecycle.
Key benefits include:
- Strengthen cybersecurity governance
Promote a structured,organization-wide approach to managing vehicle cybersecurity risksand enforcing security accountability across product teams.
- Enhance regulatory alignment
Enable compliance with internationalrequirements, supporting lawful vehicle market access and aligningautomotive practices with global regulatory expectations.
- Improve incident response readiness
Mandate development of processes fortimely detection of, and effective response to, cyber threatsaffecting vehicle safety or operational integrity.
- Protect sensitive vehicle data
Support robust safeguards for in-cardata and critical vehicle functions, minimizing the risk ofunauthorized access or data breaches.
- Increase audit and compliance readiness
Require systematic documentation andprocess validation, streamlining internal and external audits forregulatory and customer compliance.
How it Works
The UNECE WP.29R155 Vehicle Cybersecurity Regulation establishes a structured set ofregulatory requirements that span the vehicle lifecycle, focusing onrisk-based management and continuous improvement. The frameworkcovers governance, risk assessment, technical and organizationalsecurity controls, incident detection, and response, all mapped tokey lifecycle phases such as development, production,post-production, and end-of-life management. These requirements areformalized in terms of processes and controls that must beimplemented and demonstrated by automotive manufacturers and theirsupply chains.
In practice,organizations integrate UNECE WP.29 R155 by developing andmaintaining a Cybersecurity Management System (CSMS) that governssecurity policies, conducts periodic risk assessments, implementsappropriate security controls, and ensures ongoing monitoring andreporting. Compliance activities include mapping controls toorganizational processes, supporting regulatory audits, managingincident response procedures, and producing evidence of regulatoryadherence. Risk management and governance processes are continuouslyreviewed and updated to address emerging threats and vulnerabilitiesthroughout the vehicle’s lifecycle.
SmartSuiteenables operationalization of UNECE WP.29 R155 by providing controllibraries mapped to regulatory requirements, risk registers fortracking cyber risks, and centralized policy governance tools.Organizations leverage compliance tracking, evidence collectionmodules, audit readiness features, and reporting dashboards to managethe regulatory lifecycle and demonstrate continuous compliance withR155 mandates throughout their automotive security programs.
Key Elements
- Cybersecurity Management System Structure
Establishes organizational processesand responsibilities for managing vehicle cybersecurity across thedevelopment lifecycle.
- Risk Assessment and Treatment Process
Describes systematic approaches foridentifying, evaluating, and addressing cyber risks to vehiclesystems.
- Cybersecurity Controls for Vehicle Systems
Specifies technical andorganizational measures to safeguard vehicle electronic systems fromcybersecurity threats.
- Incident Response and Notification
Outlines procedures for detecting,reporting, and responding to cybersecurity incidents affectingvehicles.
- Secure Software Update Processes
Defines requirements forauthentication, integrity, and delivery of software and firmwareupdates to vehicles.
- Continuous Monitoring and Review
Provides mechanisms for ongoingassessment and improvement of cybersecurity measures throughout thevehicle’s operational life.
Framework Scope
UNECE WP.29 —Vehicle Cybersecurity Regulation (R155) is adopted by automotivemanufacturers producing vehicles for regulated markets, encompassingelectronic systems, software, and connectivity features withinvehicles. It typically governs environments during productdevelopment and vehicle lifecycle management, supporting ongoing riskmanagement, cybersecurity controls, and compliance oversight forregulatory and operational requirements.
Framework Objectives
UNECE WP.29 —Vehicle Cybersecurity Regulation (R155) sets requirements formanaging automotive cybersecurity risks and ensuring compliancethroughout the vehicle lifecycle.
Strengthen cybersecurity governance and oversight for connectedvehicle systems
Establish comprehensive risk management processes specific toautomotive security threats
Enhance data protection by safeguarding personal and operationalvehicle information
Support regulatory compliance with evolving vehicle cybersecurity andprivacy standards
Improve operational resilience against cyber threats affectingvehicle safety and performance
Demonstrate audit readiness through effective documentation ofsecurity controls and processes UNECE WP.29 R155 mandates vehiclecybersecurity requirements and is commonly implemented alongsideISO/SAE 21434 (cybersecurity engineering), ISO 26262 (functionalsafety), and UNECE R156 (software update management). Organizationsadopt R155 for regulatory type-approval, demonstrating compliance,strengthening security governance, and aligning engineering andupdate processes with certification requirements.
Framework in Context
UNECE WP.29 R155 mandates vehiclecybersecurity requirements and is commonly implemented alongsideISO/SAE 21434 (cybersecurity engineering), ISO 26262 (functionalsafety), and UNECE R156 (software update management). Organizationsadopt R155 for regulatory type-approval, demonstrating compliance,strengthening security governance, and aligning engineering andupdate processes with certification requirements.
Common Framework Mappings
Organizationscommonly map R155 to related automotive safety, privacy, andcybersecurity standards to ensure cohesive risk management,regulatory compliance, and secure vehicle software lifecyclepractices.
Mapped frameworks include:
EU General DataProtection Regulation (GDPR)
ISO 26262 —Road vehicles — Functional safety
ISO/IEC 27001 —Information security management
ISO/SAE 21434 —Road vehicles — Cybersecurity engineering
MITRE ATT&CK
UNECE WP.29 —Vehicle Software Update Regulation (R156)
- ClassificationCategoryAutomotive SecurityDomainCybersecurityFramework FamilyOther
- Regulatory ContextTypeRegulationLegal InstrumentRegulationSectorTransportation SectorIndustryAutomotive
- Region / PublisherRegionGlobalRegion DetailUnited Nations Economic Commission for Europe (UNECE)PublisherUnited Nations Economic Commission for Europe (UNECE)
- VersioningVersion2020Effective Date22 January 2021Issue Date24 June 2020
- AdoptionAdoption ModelRegulatory ComplianceImplementation ComplexityHigh
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
UN Regulation No. 155 is published by the UNECE/WP.29 and is publicly available on the UNECE website. License included with platform
How SmartSuite Supports UNECE WP.29 (R155)
Manage UNECE WP.29 (R155) requirements by structuring cybersecurity management systems (CSMS), tracking vehicle risks, and maintaining evidence supporting regulatory approval and lifecycle compliance.
Cybersecurity Management System (CSMS)
Organize policies, governance, and processes required for vehicle cybersecurity certification.
Vehicle Risk Assessment and TARA Tracking
Manage threat analysis and risk assessments across vehicle platforms and components.
Control Implementation and Traceability
Link cybersecurity controls to risks, systems, and lifecycle requirements.
Vehicle Vulnerability and Incident Management
Track vulnerability disclosures, incident investigations, and remediation activities affecting vehicle systems.
Supplier and Supply Chain Security Oversight
Manage supplier requirements, assurance evidence, and third-party cybersecurity risks.
Regulatory Compliance and Type Approval Reporting
Provide dashboards supporting CSMS compliance, audit readiness, and regulatory submissions.
Related frameworks

GDPR is an EU regulation that protects individuals' personal data and strengthens organizations' accountability for privacy.

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

ISO/SAE 21434 is a cybersecurity engineering standard that defines processes to manage cyber risks across vehicle lifecycles and supply chains.
Frequently Asked Questions For UNECE WP.29 — Vehicle Cybersecurity Regulation (R155)
UN Regulation No. 155 establishes mandatory requirements for automotive cybersecurity management systems (CSMS) to ensure vehicles are protected against cyber threats throughout their lifecycle. Its primary goal is to address cybersecurity risks in the design, development, production, and post-production of vehicles.
Yes, compliance with UN Regulation No. 155 is mandatory for vehicle manufacturers seeking type approval in many jurisdictions, including the European Union. Without demonstrating compliance, manufacturers cannot market new vehicle types in these regions.
UN Regulation No. 155 applies to passenger vehicles, light commercial vehicles, heavy-duty vehicles, and buses. It also covers electronic components and systems related to cybersecurity, throughout their supply chain.
A CSMS is a formal set of processes, policies, and procedures required by UN Regulation No. 155 to manage and mitigate cybersecurity risks throughout a vehicle's lifecycle. Key artifacts include documented risk assessments, incident response plans, and security testing evidence.
Implementation involves developing and maintaining a CSMS, performing vehicle and component risk assessments, defining and applying cybersecurity controls, and preparing for incident detection and response. Organizations must also ensure traceability, accountability, and continuous improvement within their cybersecurity management processes.
UN Regulation No. 155 complements existing cybersecurity standards such as ISO/SAE 21434 by embedding similar risk management principles and controls into regulatory requirements. While ISO/SAE 21434 provides technical guidance, UN R155 is legally enforced and necessary for type approval.
Organizations must regularly update their CSMS, conduct continuous risk monitoring, log and respond to incidents, and document all activities for audit and regulatory review. Periodic reviews and evidence-based reporting are required to demonstrate ongoing compliance for type-approved vehicles.
SmartSuite enables organizations to manage UN Regulation No. 155 compliance by facilitating cybersecurity risk tracking, control implementation, and ongoing evidence collection. It provides tools for documentation, workflow management, audit readiness, and streamlined reporting, supporting continuous oversight and regulatory alignment.
UNECE WP.29 Regulation R155 is used to establish minimum cybersecurity requirements for vehicles, ensuring that manufacturers manage cyber risks throughout a vehicle’s lifecycle. It provides a regulatory basis for addressing threats to vehicle systems and road safety through structured cybersecurity controls and processes.
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

