SOURCE-LINKED REGULATION GUIDE
UN R155 — Vehicle cybersecurity
Assess vehicle-type requirements alongside the cybersecurity management system.
Explore the scopeWhat does it cover?
UN R155 addresses vehicle cybersecurity through both the vehicle type and the manufacturer’s cybersecurity management system (CSMS). Identifying and managing risks, obtaining necessary supply-chain information and documenting measures applied to the vehicle type are part of the assessment. The application documents, CSMS compliance certificate and vehicle-type review are linked within the regulation.
Who is it for?
Vehicle-manufacturer cybersecurity, electrical/electronic architecture and type-approval teams, and those managing supplier risks.
Which subjects are addressed?
- Cybersecurity management system (CSMS)
- Vehicle-type risk assessment
- Supply-chain risk management
- Approval application and documentation of security measures
Common question
Are CSMS and vehicle-type assessment the same thing?
No. The regulation treats the CSMS compliance certificate and vehicle-type approval review as separate but connected matters. The application requires the CSMS certificate; vehicle-type risks, tests and measures are also assessed.
Source documents and references
Work with this regulation in RegsUP.
Read the text with its edition and sources. Assess available comparisons, relevant dates and question-and-answer features against your work needs.
Discuss access optionsRelated regulations
UN R156 — Software updates and management systems
Consider software updates alongside vehicle type, version identity and management processes.
UN R157 — Automated lane keeping systems
Review the ALKS function together with transfer of control to the driver.
UN R171 — Driver control assistance systems
Distinguish DCAS from other steering-assistance functions.