# UN R155 (UN Regulation No. 155, Cyber Security)

> UN Regulation No. 155 is the UNECE regulation on cyber security and cyber security management systems. A vehicle manufacturer needs a Certificate of Compliance for its CSMS and must show for each vehicle type that risks were assessed, mitigations were implemented and their effectiveness was tested before type approval. Annex 5 lists the threats and mitigations to consider. ECU security tests are part of the evidence; the regulation does not prescribe a specific test method or tool.

UN R155 is the UNECE regulation that makes a certified CSMS and cyber security measures a condition for vehicle type approval. What it requires and what testers deliver.

Source: https://auto-st.com/glossary/un-r155 · Updated: 2026-10-07

## What is UN R155?

UN R155 is a regulation under the UNECE 1958 Agreement (World Forum WP.29) that sets cyber security requirements for vehicle type approval. It has two parts: an organisational one, the Cyber Security Management System (CSMS) that the manufacturer must have certified, and a vehicle-type one, the proof that the CSMS was applied to the specific vehicle type.

## Where is it defined?

The regulation text itself is the source. Paragraph 7.2 lists what the CSMS must cover, from risk identification to monitoring and response. Paragraph 7.3 sets the requirements for the vehicle type: a risk assessment of the vehicle and its elements, proportionate mitigations, protection of dedicated environments, testing to verify the effectiveness of the security measures before approval, and the ability to detect and respond to attacks. Annex 5 lists threats in Part A and mitigations in Parts B and C; diagnostic access, software manipulation and external connectivity all appear there. In the EU the regulation has applied to new vehicle types since July 2022 and to all newly registered vehicles since July 2024. ISO/SAE 21434 is the standard most manufacturers use to implement the engineering side.

## What it means in practice

For a test team, R155 turns security testing from good practice into a type-approval obligation with an audit trail. The auditor and the approval authority want to see that each relevant threat from the risk assessment has a mitigation and that the mitigation was tested on the software version that goes into production. Evidence is sampled: a test report with dates, versions, findings and their resolution.

In R155 audit support at a Tier-1 the recurring gap was traceability, not testing. Tests had been run, but it was hard to show which test case covered which threat and which finding had been closed in which release.

## How AutoST tests it

AutoST does not certify anything and is not an R155 approval. It provides repeatable test evidence for ECU-level mitigations: diagnostic access control, SecurityAccess, robustness under fuzzing, DoIP, SOME/IP and IVI exposure. Each finding carries severity and remediation, Fix Plan tasks carry a reference to your requirement, and the results export to PDF and SARIF for the audit file.

## Common misunderstandings

R155 is not a technical standard with test cases; it states outcomes. A CSMS certificate is not a statement that a vehicle is secure. And R155 does not end at type approval: monitoring and response continue for the vehicles on the road.

## FAQ

**Does UN R155 apply to suppliers?**

Formally it applies to the vehicle manufacturer, who receives the CSMS certificate and the type approval. In practice the manufacturer has to manage supplier-related risks, so Tier-1 and Tier-2 suppliers receive the requirements through contracts and have to deliver risk analyses and test evidence for their components.

**Does UN R155 require penetration testing?**

It requires appropriate and sufficient testing to verify the effectiveness of the security measures before type approval, without naming a method. ISO/SAE 21434 fills that in: component testing with fuzzing and vulnerability scanning in Clause 10 and penetration testing as part of validation in Clause 11.

**Can a tool make a vehicle R155 compliant?**

No. Compliance is a matter of the manufacturer processes and the type approval by the authority. A test tool supplies evidence that the approval process can use, nothing more.

## Sources

- [UN Regulation No. 155, Cyber security and cyber security management system, paragraphs 7.2 and 7.3 and Annex 5](https://unece.org/transport/documents/2021/03/standards/un-regulation-no-155-cyber-security-and-cyber-security)
- [ISO/SAE 21434:2021 Road vehicles, Cybersecurity engineering](https://www.iso.org/standard/70918.html)

## Related

- [CSMS (Cybersecurity Management System)](https://auto-st.com/glossary/csms)
- [ISO/SAE 21434](https://auto-st.com/glossary/iso-sae-21434)
- [UN R156 (UN Regulation No. 156, Software Update)](https://auto-st.com/glossary/un-r156)
- [TARA (Threat Analysis and Risk Assessment)](https://auto-st.com/glossary/tara)
- [UN R155 audits: what testers need to deliver](https://auto-st.com/insights/un-r155-audit-what-testers-need)
- [Evidence for your 21434 work, on tap.](https://auto-st.com/iso-21434-testing)

---
AutoST by Zyberum. Canonical page: https://auto-st.com/glossary/un-r155
