SOURCE-LINKED REGULATION GUIDE

UN R155 — Vehicle cybersecurity

Assess vehicle-type requirements alongside the cybersecurity management system.

Explore the scope

What does it cover?

UN R155 addresses vehicle cybersecurity through both the vehicle type and the manufacturer’s cybersecurity management system (CSMS). Identifying and managing risks, obtaining necessary supply-chain information and documenting measures applied to the vehicle type are part of the assessment. The application documents, CSMS compliance certificate and vehicle-type review are linked within the regulation.

Who is it for?

Vehicle-manufacturer cybersecurity, electrical/electronic architecture and type-approval teams, and those managing supplier risks.

Which subjects are addressed?

  • Cybersecurity management system (CSMS)
  • Vehicle-type risk assessment
  • Supply-chain risk management
  • Approval application and documentation of security measures

Common question

Are CSMS and vehicle-type assessment the same thing?

No. The regulation treats the CSMS compliance certificate and vehicle-type approval review as separate but connected matters. The application requires the CSMS certificate; vehicle-type risks, tests and measures are also assessed.

Source documents and references

Explore RegsUP features

Work with this regulation in RegsUP.

Read the text with its edition and sources. Assess available comparisons, relevant dates and question-and-answer features against your work needs.

Discuss access options

Related regulations