Automotive Security
DETAIL

UN Regulation No. 155 — Cybersecurity and Cybersecurity Management System

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

arrow_back
arrow_forward

Overview

UNECE WP.29 — Vehicle Cybersecurity Regulation (R155) is an international automotive cybersecurity regulation that requires vehicle manufacturers to implement and maintain robust cybersecurity management systems to ensure the security of vehicles throughout their lifecycle. Its primary goal is to mitigate cybersecurity risks that could impact road safety, vehicle operations, and data protection.

Published by the United Nations Economic Commission for Europe (UNECE), this regulation is mandatory for automotive manufacturers selling vehicles in markets governed by UNECE member states, including much of Europe and parts of Asia. R155 provides requirements related to risk management, secure software updates, and the protection of vehicle electronic systems from cyber threats, supporting organizations in establishing effective cybersecurity controls and compliance practices.

To comply with UNECE R155, organizations integrate cybersecurity risk assessments, develop and enforce technical security controls, and maintain ongoing incident response capabilities as part of their product development and management processes. The regulation also aligns with established information security frameworks, supporting automotive cybersecurity governance and audit readiness within broader compliance programs.

Why it Matters

UNECE WP.29 R155establishes comprehensive vehicle cybersecurity management, ensuringautomotive manufacturers safeguard vehicles and their data throughoutthe entire lifecycle.

Key benefits include:

  • Strengthen cybersecurity governance

Promote a structured,organization-wide approach to managing vehicle cybersecurity risksand enforcing security accountability across product teams.

  • Enhance regulatory alignment

Enable compliance with internationalrequirements, supporting lawful vehicle market access and aligningautomotive practices with global regulatory expectations.

  • Improve incident response readiness

Mandate development of processes fortimely detection of, and effective response to, cyber threatsaffecting vehicle safety or operational integrity.

  • Protect sensitive vehicle data

Support robust safeguards for in-cardata and critical vehicle functions, minimizing the risk ofunauthorized access or data breaches.

  • Increase audit and compliance readiness

Require systematic documentation andprocess validation, streamlining internal and external audits forregulatory and customer compliance.

How it Works

The UNECE WP.29R155 Vehicle Cybersecurity Regulation establishes a structured set ofregulatory requirements that span the vehicle lifecycle, focusing onrisk-based management and continuous improvement. The frameworkcovers governance, risk assessment, technical and organizationalsecurity controls, incident detection, and response, all mapped tokey lifecycle phases such as development, production,post-production, and end-of-life management. These requirements areformalized in terms of processes and controls that must beimplemented and demonstrated by automotive manufacturers and theirsupply chains.

In practice,organizations integrate UNECE WP.29 R155 by developing andmaintaining a Cybersecurity Management System (CSMS) that governssecurity policies, conducts periodic risk assessments, implementsappropriate security controls, and ensures ongoing monitoring andreporting. Compliance activities include mapping controls toorganizational processes, supporting regulatory audits, managingincident response procedures, and producing evidence of regulatoryadherence. Risk management and governance processes are continuouslyreviewed and updated to address emerging threats and vulnerabilitiesthroughout the vehicle’s lifecycle.

SmartSuiteenables operationalization of UNECE WP.29 R155 by providing controllibraries mapped to regulatory requirements, risk registers fortracking cyber risks, and centralized policy governance tools.Organizations leverage compliance tracking, evidence collectionmodules, audit readiness features, and reporting dashboards to managethe regulatory lifecycle and demonstrate continuous compliance withR155 mandates throughout their automotive security programs.

Key Elements

  • Cybersecurity Management System Structure

Establishes organizational processesand responsibilities for managing vehicle cybersecurity across thedevelopment lifecycle.

  • Risk Assessment and Treatment Process

Describes systematic approaches foridentifying, evaluating, and addressing cyber risks to vehiclesystems.

  • Cybersecurity Controls for Vehicle Systems

Specifies technical andorganizational measures to safeguard vehicle electronic systems fromcybersecurity threats.

  • Incident Response and Notification

Outlines procedures for detecting,reporting, and responding to cybersecurity incidents affectingvehicles.

  • Secure Software Update Processes

Defines requirements forauthentication, integrity, and delivery of software and firmwareupdates to vehicles.

  • Continuous Monitoring and Review

Provides mechanisms for ongoingassessment and improvement of cybersecurity measures throughout thevehicle’s operational life.

Framework Scope

UNECE WP.29 —Vehicle Cybersecurity Regulation (R155) is adopted by automotivemanufacturers producing vehicles for regulated markets, encompassingelectronic systems, software, and connectivity features withinvehicles. It typically governs environments during productdevelopment and vehicle lifecycle management, supporting ongoing riskmanagement, cybersecurity controls, and compliance oversight forregulatory and operational requirements.

Framework Objectives

UNECE WP.29 —Vehicle Cybersecurity Regulation (R155) sets requirements formanaging automotive cybersecurity risks and ensuring compliancethroughout the vehicle lifecycle.

Strengthen cybersecurity governance and oversight for connectedvehicle systems

Establish comprehensive risk management processes specific toautomotive security threats

Enhance data protection by safeguarding personal and operationalvehicle information

Support regulatory compliance with evolving vehicle cybersecurity andprivacy standards

Improve operational resilience against cyber threats affectingvehicle safety and performance

Demonstrate audit readiness through effective documentation ofsecurity controls and processes UNECE WP.29 R155 mandates vehiclecybersecurity requirements and is commonly implemented alongsideISO/SAE 21434 (cybersecurity engineering), ISO 26262 (functionalsafety), and UNECE R156 (software update management). Organizationsadopt R155 for regulatory type-approval, demonstrating compliance,strengthening security governance, and aligning engineering andupdate processes with certification requirements.

Framework in Context

UNECE WP.29 R155 mandates vehiclecybersecurity requirements and is commonly implemented alongsideISO/SAE 21434 (cybersecurity engineering), ISO 26262 (functionalsafety), and UNECE R156 (software update management). Organizationsadopt R155 for regulatory type-approval, demonstrating compliance,strengthening security governance, and aligning engineering andupdate processes with certification requirements.

Common Framework Mappings

Organizationscommonly map R155 to related automotive safety, privacy, andcybersecurity standards to ensure cohesive risk management,regulatory compliance, and secure vehicle software lifecyclepractices.

Mapped frameworks include:

EU General DataProtection Regulation (GDPR)

ISO 26262 —Road vehicles — Functional safety

ISO/IEC 27001 —Information security management

ISO/SAE 21434 —Road vehicles — Cybersecurity engineering

MITRE ATT&CK

UNECE WP.29 —Vehicle Software Update Regulation (R156)

At a Glance
UN Regulation No. 155 (R155) — Cybersecurity & CSMS
  • checklist
    Classification
    Category
    info
    Automotive Security
    Domain
    info
    Cybersecurity
    Framework Family
    info
    Other
  • info
    Regulatory Context
    Type
    info
    Regulation
    Legal Instrument
    info
    Regulation
    Sector
    info
    Transportation Sector
    Industry
    info
    Automotive
  • arrow_upload_ready
    Region / Publisher
    Region
    info
    Global
    Region Detail
    info
    United Nations Economic Commission for Europe (UNECE)
    Publisher
    info
    United Nations Economic Commission for Europe (UNECE)
  • published_with_changes
    Versioning
    Version
    info
    2020
    Effective Date
    info
    22 January 2021
    Issue Date
    info
    24 June 2020
  • graph_3
    Adoption
    Adoption Model
    info
    Regulatory Compliance
    Implementation Complexity
    info
    High
  • captive_portal
    Official Reference
License Information

License included / downloadable: Yes

UN Regulation No. 155 is published by the UNECE/WP.29 and is publicly available on the UNECE website. License included with platform

Official Resources
UNECE WP.29 — Vehicle Cybersecurity Regulation (R155)
Defines cybersecurity requirements for automotive manufacturers to ensure vehicle security throughout its lifecycle.
chevron_forward
UNECE R155 Implementation Guidance
Outlines guidance on implementing the UNECE R155 cybersecurity regulation for vehicle manufacturers.
chevron_forward
UNECE WP.29 Cybersecurity Management System (CSMS) Guide
Provides detailed instructions for establishing a Cybersecurity Management System under UNECE R155.
chevron_forward
UNECE R155 Regulatory Framework Overview
Describes the structure and objectives of the UNECE WP.29 Vehicle Cybersecurity Regulation.
chevron_forward
SMARTSUITE

How SmartSuite Supports UNECE WP.29 (R155)

Manage UNECE WP.29 (R155) requirements by structuring cybersecurity management systems (CSMS), tracking vehicle risks, and maintaining evidence supporting regulatory approval and lifecycle compliance.

Cybersecurity Management System (CSMS)

Organize policies, governance, and processes required for vehicle cybersecurity certification.

Vehicle Risk Assessment and TARA Tracking

Manage threat analysis and risk assessments across vehicle platforms and components.

Control Implementation and Traceability

Link cybersecurity controls to risks, systems, and lifecycle requirements.

Vehicle Vulnerability and Incident Management

Track vulnerability disclosures, incident investigations, and remediation activities affecting vehicle systems.

Supplier and Supply Chain Security Oversight

Manage supplier requirements, assurance evidence, and third-party cybersecurity risks.

Regulatory Compliance and Type Approval Reporting

Provide dashboards supporting CSMS compliance, audit readiness, and regulatory submissions.

Related frameworks

GDPR

GDPR is an EU regulation that protects individuals' personal data and strengthens organizations' accountability for privacy.

Learn More
arrow_forward
ISO 27001:2022

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

Learn More
arrow_forward
ISO/SAE 21434

ISO/SAE 21434 is a cybersecurity engineering standard that defines processes to manage cyber risks across vehicle lifecycles and supply chains.

Learn More
arrow_forward
MITRE ATT&CK

MITRE ATT&CK is a knowledge framework documenting adversary tactics and techniques to help organizations detect, analyze, and respond to attacks.

Learn More
arrow_forward
NIST CSF 2.0

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

Learn More
arrow_forward
ONBOARDING FAQS

Frequently Asked Questions For UNECE WP.29 — Vehicle Cybersecurity Regulation (R155)

What is UN Regulation No. 155 used for?

UN Regulation No. 155 establishes mandatory requirements for automotive cybersecurity management systems (CSMS) to ensure vehicles are protected against cyber threats throughout their lifecycle. Its primary goal is to address cybersecurity risks in the design, development, production, and post-production of vehicles.

Is compliance with UN Regulation No. 155 mandatory?

Yes, compliance with UN Regulation No. 155 is mandatory for vehicle manufacturers seeking type approval in many jurisdictions, including the European Union. Without demonstrating compliance, manufacturers cannot market new vehicle types in these regions.

What types of vehicles or components does UN Regulation No. 155 apply to?

UN Regulation No. 155 applies to passenger vehicles, light commercial vehicles, heavy-duty vehicles, and buses. It also covers electronic components and systems related to cybersecurity, throughout their supply chain.

What is a Cybersecurity Management System (CSMS) under UN Regulation No. 155?

A CSMS is a formal set of processes, policies, and procedures required by UN Regulation No. 155 to manage and mitigate cybersecurity risks throughout a vehicle's lifecycle. Key artifacts include documented risk assessments, incident response plans, and security testing evidence.

How should organizations implement UN Regulation No. 155 requirements?

Implementation involves developing and maintaining a CSMS, performing vehicle and component risk assessments, defining and applying cybersecurity controls, and preparing for incident detection and response. Organizations must also ensure traceability, accountability, and continuous improvement within their cybersecurity management processes.

How does UN Regulation No. 155 relate to other cybersecurity standards?

UN Regulation No. 155 complements existing cybersecurity standards such as ISO/SAE 21434 by embedding similar risk management principles and controls into regulatory requirements. While ISO/SAE 21434 provides technical guidance, UN R155 is legally enforced and necessary for type approval.

What ongoing compliance activities are needed for UN Regulation No. 155?

Organizations must regularly update their CSMS, conduct continuous risk monitoring, log and respond to incidents, and document all activities for audit and regulatory review. Periodic reviews and evidence-based reporting are required to demonstrate ongoing compliance for type-approved vehicles.

How would SmartSuite support UN Regulation No. 155?

SmartSuite enables organizations to manage UN Regulation No. 155 compliance by facilitating cybersecurity risk tracking, control implementation, and ongoing evidence collection. It provides tools for documentation, workflow management, audit readiness, and streamlined reporting, supporting continuous oversight and regulatory alignment.

What is UNECE WP.29 R155 used for?

UNECE WP.29 Regulation R155 is used to establish minimum cybersecurity requirements for vehicles, ensuring that manufacturers manage cyber risks throughout a vehicle’s lifecycle. It provides a regulatory basis for addressing threats to vehicle systems and road safety through structured cybersecurity controls and processes.

Operationalize UNECE R155 with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

Schedule a Demo
chevron_forward
Demo Library
chevron_forward