SDV SectorNews and signals from the software-defined vehicle sector. Global coverage, daily.
SDV WikiUpdated August 1, 2026

UNECE R155

The UN regulation requiring vehicle manufacturers to run a certified cybersecurity management system as a condition of type approval.

UNECE Regulation No. 155 is the UN regulation on vehicle cybersecurity. It requires manufacturers to operate a certified Cyber Security Management System (CSMS) covering the full vehicle lifecycle — development, production and the years a vehicle is on the road — and to demonstrate, per vehicle type, that risks have been identified and treated. Without it, no type approval.

Adopted in 2020 under the UNECE WP.29 framework, R155 became binding in the EU for all new vehicle types in July 2022 and for all new registrations in July 2024. Japan and South Korea apply it too; the US does not (NHTSA works through guidance instead), which is why global platforms are engineered to the strictest common denominator.

R155 changed cybersecurity from a product feature into an approval condition with board-level consequences: manufacturers have dropped models from sale rather than retrofit compliance. ISO/SAE 21434 is the engineering standard commonly used to demonstrate CSMS conformance.

Related: ISO/SAE 21434 · Type approval / homologation · UNECE R156