Cars are becoming increasingly software-defined, connected and reliant on cloud services, APIs and over-the-air (OTA) updates. With that transformation comes a rapidly expanding cybersecurity challenge, and a highly significant regulatory response.
At the centre of automotive cybersecurity regulation are UN Regulation No. 155 (UNECE R155) and UN Regulation No. 156 (UNECE R156). R155 establishes requirements for vehicle cybersecurity and a manufacturer’s Cyber Security Management System (CSMS), while R156 focuses on secure vehicle software updates and requires manufacturers to operate a Software Update Management System (SUMS).
The European Union’s General Safety Regulation made cybersecurity requirements applicable to new vehicle types from July 2022 and to all new vehicles covered by the regulation from 7 July 2024. Great Britain has now followed. Legislation bringing UN R155 and R156 into the GB type-approval system entered into force in November 2025, with the first mandatory deadline applying to new types of complete and base vehicles from 1 June 2026.
At the same time, cyber threats facing manufacturers continue to grow. Upstream Security’s 2026 Global Automotive and Smart Mobility Cybersecurity Report analysed 494 publicly reported automotive and smart-mobility cybersecurity incidents during 2025. Of those incidents, 44% involved ransom, while 67% originated from telematics and cloud environments.
Understanding R155 and R156 is therefore becoming essential not only for compliance teams, but for software developers, vehicle architects, cybersecurity engineers, homologation teams and suppliers throughout the automotive ecosystem.
What is UNECE R155?
UNECE R155 is an international vehicle type-approval regulation covering cybersecurity and Cyber Security Management Systems. Its objective is to ensure that manufacturers identify, assess, mitigate and continually monitor cybersecurity risks throughout the lifecycle of a vehicle.
The regulation requires manufacturers to establish a Cyber Security Management System (CSMS) demonstrating that cybersecurity is systematically managed rather than addressed only when individual vulnerabilities appear.
Under R155, the manufacturer’s cybersecurity processes must cover the:
- Development phase
- Production phase
- Post-production phase
The regulation requires processes for identifying cyber threats, assessing and treating risks, verifying cybersecurity controls, testing vehicle cybersecurity, monitoring emerging vulnerabilities and responding when new threats are discovered. Manufacturers must also manage cybersecurity dependencies involving suppliers and service providers.
What does UNECE R155 require from OEMs?
R155 moves automotive cybersecurity away from a vehicle-by-vehicle approach and towards continuous lifecycle management.Manufacturers need to demonstrate processes capable of:
- Identifying cybersecurity threats: This includes potential attacks against vehicle networks, ECUs, communication interfaces, backend infrastructure and other connected systems.
- Assessing cybersecurity risk: Threats must be assessed and categorised so appropriate mitigation measures can be applied.
- Testing cybersecurity measures: Manufacturers must verify that implemented cybersecurity controls actually work.
- Monitoring vehicles after production: Cybersecurity does not end when a vehicle leaves the factory. Manufacturers must continue monitoring emerging vulnerabilities and threats affecting vehicles already in operation.
- Responding to attacks and vulnerabilities: Processes must exist for detecting, analysing and responding to attempted or successful cyberattacks.
- Managing supply-chain cybersecurity: OEMs must also manage cybersecurity dependencies involving suppliers, service providers and other organisations contributing to the vehicle.
Automotive IQ has previously examined the impact of UNECE R155 on OEMs in our article with Darren Shelcusky, Senior Consultant for Vehicle and Mobility Cybersecurity at Ford Motor Company.
What Is a Cyber Security Management System (CSMS)?
A Cyber Security Management System, or CSMS, is the organisational framework used by an automotive manufacturer to manage vehicle cybersecurity risks throughout the vehicle lifecycle. It is one of the central requirements of UNECE R155.
Rather than prescribing one cybersecurity technology, R155 requires manufacturers to prove that they have repeatable, auditable processes governing cybersecurity.
This can include processes covering:
- Threat analysis and risk assessment
- Cybersecurity governance and responsibilities
- Security-by-design development
- Verification and validation
- Vulnerability monitoring
- Incident detection and response
- Supplier cybersecurity
- Post-production monitoring
- Cybersecurity documentation and evidence
- An approval authority assesses the manufacturer’s CSMS before issuing a Certificate of Compliance for CSMS.
Importantly, that certificate does not last indefinitely. Under R155, a CSMS Certificate of Compliance has a maximum validity of three years, although authorities can verify continued compliance during that period.
UNECE R156 Explained: What OEMs Need to Know About Software Updates
If R155 focuses on cybersecurity risk, UNECE R156 focuses specifically on software updates.
UN Regulation No. 156 establishes requirements covering vehicle software updates and the manufacturer’s Software Update Management System (SUMS).
The regulation is especially important as manufacturers increasingly use OTA updates to fix vulnerabilities, improve functionality, alter existing vehicle features or introduce completely new capabilities after production.
UNECE identifies several major responsibilities under R156. Manufacturers must be able to record hardware and software versions, identify software relevant to vehicle type approval, verify software integrity, understand dependencies between systems and determine whether an update affects safety or legally approved vehicle characteristics.
For OTA updates specifically, manufacturers must also consider issues such as:
- Authenticity and integrity of the update
- Whether the vehicle has sufficient power to complete installation
- Safe execution of the update
- Recovery or safe-state procedures if an update fails
- Informing the vehicle user about updates
- Confirming successful or unsuccessful installation
- The result is that software deployment becomes part of the vehicle’s regulated engineering lifecycle.
What Is a Software Update Management System (SUMS)?
A Software Update Management System is the organisational framework manufacturers use to control, document and safely execute vehicle software updates.
Under R156, manufacturers need processes capable of determining exactly which software is installed on a vehicle and whether a proposed update is appropriate for that particular vehicle configuration.
This becomes increasingly important as software-defined vehicles move towards centralised computing, more complex E/E architectures and frequent OTA releases. The SUMS itself is subject to assessment, and its Certificate of Compliance is also generally valid for a maximum of three years.
As vehicles become more software-centric, these processes increasingly connect cybersecurity, functional safety, software development and homologation teams.
For more on the wider move towards software-centric vehicle architectures, take a look at some of our latest SDV content here.
UNECE R155 vs ISO 21434: What’s the Difference?
One of the most common sources of confusion is the relationship between UNECE R155 and ISO/SAE 21434.
The simplest distinction is:
UNECE R155 is a regulation. ISO/SAE 21434 is an engineering standard.
R155 defines regulatory requirements manufacturers must satisfy when seeking relevant vehicle type approval. ISO/SAE 21434 provides a detailed engineering framework that organisations can use to manage cybersecurity risk throughout the automotive product lifecycle.
ISO describes ISO/SAE 21434:2021 as applying to cybersecurity risk management throughout the lifecycle of vehicle electrical and electronic systems, from concept and development through production, operation, maintenance and decommissioning.
CSMS vs SUMS: Cybersecurity and Software Update Management Explained
Although CSMS and SUMS are closely related, they address different parts of the vehicle lifecycle.
| CSMS | SUMS | |
|---|---|---|
| Full name | Cyber Security Management System | Software Update Management System |
| Main regulation | UNECE R155 | UNECE R156 |
| Main purpose | Manage vehicle cybersecurity risk | Manage vehicle software updates |
| Primary focus | Threats, vulnerabilities and cybersecurity controls | Software versions, deployment, integrity and update safety |
| Lifecycle role | Development through post-production | Development and post-production software management |
| Related standard | ISO/SAE 21434 | ISO 24089 |
| Certification | Required as part of applicable R155 approval | Required as part of applicable R156 approval |
Imagine an OEM discovers a cybersecurity vulnerability in a vehicle already on the road. The CSMS helps the manufacturer identify, evaluate and respond to that vulnerability.
If the chosen mitigation requires a software patch, the SUMS governs how that update is developed, validated, targeted, documented and securely delivered to the affected vehicles.
This connection becomes especially important as OTA updates become a routine part of automotive product development.
UNECE R155 and R156 Deadlines: What Changes in 2027?
For manufacturers operating in the EU, R155 and R156 are already established parts of vehicle regulation. Under the EU General Safety Regulation, cybersecurity requirements applied to new vehicle types from July 2022 and to all relevant new vehicles from 7 July 2024.
The significant development in 2026 is Great Britain. The Road Vehicles (Type-Approval) (Amendment) (No. 3) Regulations 2025 brought R155 and R156 into the GB type-approval framework.
The phased deadlines include:
- 1 June 2026: New types of complete and base vehicles within the specified categories must meet the new requirements.
- 1 June 2027: Registration restrictions begin for non-compliant new complete vehicles and completed vehicles incorporating a non-compliant base vehicle.
- 1 June 2028: R155 requirements extend to newly registered completed vehicles within the relevant categories.
- 7 July 2029: Later requirements apply to special-purpose vehicles and certain R156 applications.
For global vehicle manufacturers, harmonisation can reduce the need for completely separate vehicle architectures across markets. However, OEMs still need to understand the precise type-approval and implementation requirements that apply in each jurisdiction.
Why R155 and R156 Matter More for Software-Defined Vehicles
The shift towards the software-defined vehicle (SDV) significantly increases the importance of both regulations.
Future vehicles are expected to rely increasingly on centralised compute platforms, cloud connectivity, service-oriented architectures, APIs, downloadable functions and continuous software releases. That dramatically changes the potential attack surface.
Upstream’s analysis of publicly disclosed automotive cybersecurity events in 2025 found that 61% had the potential to affect thousands or millions of mobility assets, while telematics and cloud systems were associated with 67% of incidents in its dataset.
The challenge is therefore moving beyond protecting individual ECUs.
Manufacturers increasingly need to secure an ecosystem that can include:
- Vehicle hardware
- Operating systems
- Middleware
- Applications
- Cloud platforms
- APIs
- Companion smartphone apps
- Charging infrastructure
- OTA servers
- Development infrastructure
- Third-party software
- AI-powered vehicle functions
R155 provides the lifecycle cybersecurity framework, while R156 helps ensure manufacturers have controlled processes for modifying vehicle software once those vehicles are in customer hands.
R155 and R156 Are Still Evolving
Compliance should not be treated as a finished project. UNECE’s Working Party on Automated/Autonomous and Connected Vehicles (GRVA) continues to work on amendments and interpretation documents covering R155 and R156. Proposals relating to both regulations remained under active consideration during 2026.
At the same time, software-update standards continue to evolve. ISO 24089 has already received an amendment, while additional work is underway around areas such as vehicle configuration information for software update engineering.
OEMs and suppliers therefore need processes capable of adapting as regulations, vehicle architectures and cybersecurity threats evolve.
Frequently Asked Questions About UNECE R155 and R156
What is UNECE R155?
UNECE R155, formally UN Regulation No. 155, is an international automotive cybersecurity regulation. It requires manufacturers seeking applicable vehicle type approval to manage cybersecurity risks and operate a Cyber Security Management System.
What is UNECE R156?
UNECE R156, formally UN Regulation No. 156, establishes requirements for vehicle software updates and Software Update Management Systems. It covers areas including software identification, update integrity, compatibility, documentation and safe OTA deployment.
What is the difference between R155 and R156?
R155 focuses on cybersecurity risk management, while R156 focuses on software update management. R155 requires a CSMS; R156 requires a SUMS.
Is UNECE R155 the same as ISO 21434?
No. UNECE R155 is a regulatory type-approval framework, while ISO/SAE 21434 is an automotive cybersecurity engineering standard. ISO 21434 can help organisations establish processes that support R155 compliance.
Is UNECE R156 the same as ISO 24089?
No. R156 establishes regulatory requirements for software updates, while ISO 24089 provides requirements and recommendations for automotive software update engineering.
What is a CSMS?
A Cyber Security Management System is the organisational framework an OEM uses to identify, assess, mitigate and monitor cybersecurity risks throughout the vehicle lifecycle.
What is a SUMS?
A Software Update Management System is the organisational framework used to manage vehicle software versions and ensure software updates are documented, compatible, secure and safely deployed.
Does R155 apply after a vehicle has been sold?
Yes. One of the important features of R155 is its lifecycle approach. Manufacturers need processes for monitoring cyber threats and vulnerabilities affecting vehicles during the post-production phase, rather than treating cybersecurity as something completed at launch.
For more detailed analysis on UNECE R155 and the Cyber Resilience Act, view our latest article here.
Image Attribution
Image #1
– Automotve IQ R155