Glossary · UNECE / Type Approval
UNECE R155
Also known as: UN R155, UNECE Regulation No. 155
UN Regulation No. 155 makes a certified Cybersecurity Management System and vehicle-type cybersecurity evidence a precondition for vehicle type approval.
Glossary · UNECE / Type Approval
Also known as: UN R155, UNECE Regulation No. 155
UN Regulation No. 155 makes a certified Cybersecurity Management System and vehicle-type cybersecurity evidence a precondition for vehicle type approval.
UN Regulation No. 155 (Cybersecurity and Cyber Security Management System) is the UNECE regulation that makes cybersecurity a condition of vehicle type approval, adopted under the 1958 Agreement and applied by the EU, the United Kingdom, Japan, and South Korea among other contracting parties. It works at two levels. At the organisational level, the vehicle manufacturer must hold a CSMS Certificate of Compliance: an approval authority or its technical service assesses that the manufacturer manages cybersecurity risk across development, production, and post-production, and the certificate remains valid for up to three years before reassessment. At the vehicle level, each type is approved on its own evidence — the manufacturer demonstrates that risks for the type were identified and treated, that the threats and mitigations catalogued in Annex 5 were considered against the architecture, that testing verified the implemented controls, and that attacks on vehicles in the field can be detected and responded to. In the European Union, Regulation (EU) 2019/2144 made UN R155 mandatory for new vehicle types from 6 July 2022 and for all new vehicles from 7 July 2024, and Delegated Regulation (EU) 2025/1455 extends cybersecurity requirements to L-category vehicles — new types from 11 December 2027, existing types from 11 June 2029. R155 states what must be achieved but not how; ISO/SAE 21434 is the engineering standard assessors expect manufacturers to use to achieve it, from CSMS processes down to the TARA and the cybersecurity evidence for each item. India's AIS 189 is the domestic derivation of the same regulation.
Why it matters
R155 moved cybersecurity from an engineering preference to a market-access requirement — without a valid CSMS certificate and per-type evidence, a vehicle type cannot be approved for sale in adopting markets. The obligation formally sits with the vehicle manufacturer, but most of the evidence originates with suppliers, so OEMs cascade R155-driven requirements into contracts through Cybersecurity Interface Agreements. Programmes that map their ISO/SAE 21434 Work Products to R155's evidence expectations early avoid reconstructing documentation inside the approval window.
Related terms
A Cybersecurity Management System (CSMS) is the organisation-wide set of processes that governs vehicle cybersecurity risk across the full lifecycle.
A Software Update Management System (SUMS) is the certified process framework for planning, protecting, delivering, and recording vehicle software updates.
UN Regulation No. 156 makes a certified Software Update Management System (SUMS) a precondition for approving vehicles whose software can be updated.
Regulator confirmation that a vehicle type meets specified technical requirements before market entry.
International standard for road-vehicle cybersecurity engineering across the lifecycle.
Need help applying UNECE R155 on a programme? Use the contact form or request a KAVACH demo.