Skip to main content
← Glossary

Glossary · UNECE / Type Approval

UNECE R155

Also known as: UN R155, UNECE Regulation No. 155

UN Regulation No. 155 makes a certified Cybersecurity Management System and vehicle-type cybersecurity evidence a precondition for vehicle type approval.

UN Regulation No. 155 (Cybersecurity and Cyber Security Management System) is the UNECE regulation that makes cybersecurity a condition of vehicle type approval, adopted under the 1958 Agreement and applied by the EU, the United Kingdom, Japan, and South Korea among other contracting parties. It works at two levels. At the organisational level, the vehicle manufacturer must hold a CSMS Certificate of Compliance: an approval authority or its technical service assesses that the manufacturer manages cybersecurity risk across development, production, and post-production, and the certificate remains valid for up to three years before reassessment. At the vehicle level, each type is approved on its own evidence — the manufacturer demonstrates that risks for the type were identified and treated, that the threats and mitigations catalogued in Annex 5 were considered against the architecture, that testing verified the implemented controls, and that attacks on vehicles in the field can be detected and responded to. In the European Union, Regulation (EU) 2019/2144 made UN R155 mandatory for new vehicle types from 6 July 2022 and for all new vehicles from 7 July 2024, and Delegated Regulation (EU) 2025/1455 extends cybersecurity requirements to L-category vehicles — new types from 11 December 2027, existing types from 11 June 2029. R155 states what must be achieved but not how; ISO/SAE 21434 is the engineering standard assessors expect manufacturers to use to achieve it, from CSMS processes down to the TARA and the cybersecurity evidence for each item. India's AIS 189 is the domestic derivation of the same regulation.

Why it matters

R155 moved cybersecurity from an engineering preference to a market-access requirement — without a valid CSMS certificate and per-type evidence, a vehicle type cannot be approved for sale in adopting markets. The obligation formally sits with the vehicle manufacturer, but most of the evidence originates with suppliers, so OEMs cascade R155-driven requirements into contracts through Cybersecurity Interface Agreements. Programmes that map their ISO/SAE 21434 Work Products to R155's evidence expectations early avoid reconstructing documentation inside the approval window.

Need help applying UNECE R155 on a programme? Use the contact form or request a KAVACH demo.