UN R155 (UN Regulation No. 155, Cyber Security)
UN R155 is the UNECE regulation that makes a certified CSMS and cyber security measures a condition for vehicle type approval. What it requires and what testers deliver.
Updated This page as Markdown
In short
UN Regulation No. 155 is the UNECE regulation on cyber security and cyber security management systems. A vehicle manufacturer needs a Certificate of Compliance for its CSMS and must show for each vehicle type that risks were assessed, mitigations were implemented and their effectiveness was tested before type approval. Annex 5 lists the threats and mitigations to consider. ECU security tests are part of the evidence; the regulation does not prescribe a specific test method or tool.
What is UN R155?
UN R155 is a regulation under the UNECE 1958 Agreement (World Forum WP.29) that sets cyber security requirements for vehicle type approval. It has two parts: an organisational one, the Cyber Security Management System (CSMS) that the manufacturer must have certified, and a vehicle-type one, the proof that the CSMS was applied to the specific vehicle type.
Where is it defined?
The regulation text itself is the source. Paragraph 7.2 lists what the CSMS must cover, from risk identification to monitoring and response. Paragraph 7.3 sets the requirements for the vehicle type: a risk assessment of the vehicle and its elements, proportionate mitigations, protection of dedicated environments, testing to verify the effectiveness of the security measures before approval, and the ability to detect and respond to attacks. Annex 5 lists threats in Part A and mitigations in Parts B and C; diagnostic access, software manipulation and external connectivity all appear there. In the EU the regulation has applied to new vehicle types since July 2022 and to all newly registered vehicles since July 2024. ISO/SAE 21434 is the standard most manufacturers use to implement the engineering side.
What it means in practice
For a test team, R155 turns security testing from good practice into a type-approval obligation with an audit trail. The auditor and the approval authority want to see that each relevant threat from the risk assessment has a mitigation and that the mitigation was tested on the software version that goes into production. Evidence is sampled: a test report with dates, versions, findings and their resolution.
In R155 audit support at a Tier-1 the recurring gap was traceability, not testing. Tests had been run, but it was hard to show which test case covered which threat and which finding had been closed in which release.
How AutoST tests it
AutoST does not certify anything and is not an R155 approval. It provides repeatable test evidence for ECU-level mitigations: diagnostic access control, SecurityAccess, robustness under fuzzing, DoIP, SOME/IP and IVI exposure. Each finding carries severity and remediation, Fix Plan tasks carry a reference to your requirement, and the results export to PDF and SARIF for the audit file.
Common misunderstandings
R155 is not a technical standard with test cases; it states outcomes. A CSMS certificate is not a statement that a vehicle is secure. And R155 does not end at type approval: monitoring and response continue for the vehicles on the road.
FAQ
Frequently asked questions
Does UN R155 apply to suppliers?
Formally it applies to the vehicle manufacturer, who receives the CSMS certificate and the type approval. In practice the manufacturer has to manage supplier-related risks, so Tier-1 and Tier-2 suppliers receive the requirements through contracts and have to deliver risk analyses and test evidence for their components.
Does UN R155 require penetration testing?
It requires appropriate and sufficient testing to verify the effectiveness of the security measures before type approval, without naming a method. ISO/SAE 21434 fills that in: component testing with fuzzing and vulnerability scanning in Clause 10 and penetration testing as part of validation in Clause 11.
Can a tool make a vehicle R155 compliant?
No. Compliance is a matter of the manufacturer processes and the type approval by the authority. A test tool supplies evidence that the approval process can use, nothing more.
Sources
Related pages
- GlossaryCSMS (Cybersecurity Management System)A CSMS is the system of processes UN R155 requires from a vehicle manufacturer: risk management, testing, monitoring and response over the vehicle lifecycle.
- GlossaryISO/SAE 21434ISO/SAE 21434:2021 is the standard for cybersecurity engineering of road vehicles: processes, TARA, concept, development, validation. Structure and testing clauses.
- GlossaryUN R156 (UN Regulation No. 156, Software Update)UN R156 is the UNECE regulation on software updates and the Software Update Management System. What it requires of OTA updates and how it connects to ECU testing.
- GlossaryTARA (Threat Analysis and Risk Assessment)TARA is the threat analysis and risk assessment of ISO/SAE 21434 clause 15: assets, threat scenarios, impact, attack paths, feasibility, risk value and treatment.
- InsightsUN R155 audits: what testers need to deliverWhat a UN R155 assessment expects from the test side: traceable test cases, versioned evidence, coverage, clean results, residual risk and supplier deliverables.
- PlatformEvidence for your 21434 work, on tap.How AutoST supports ISO/SAE 21434 and UN R155: fuzzing and vulnerability analysis for [RC-10-12], penetration-test evidence for [RQ-11-01], plus traceable reports.
