How much does UN R155 / AIS-189 cost, and how long does it take?
An honest answer to the two questions every programme asks first — with the variables that move them
The honest answer first
Every programme asks the same two questions before any other: how much, and how long. The honest answer is that both depend on variables specific to your organisation, and anyone offering a single fixed number without understanding those variables is guessing. This is not evasion — it is the only accurate answer, and understanding why is the first step to planning a programme that does not overrun.
UN R155 requires a Certificate of Compliance for the CSMS, valid three years, plus per-vehicle-type approval. India runs AIS-189, its CSMS standard aligned to UN R155, published by ARAI for the AISC under the CMVR-TSC — with enforcement now proposed in MoRTH draft G.S.R. 503(E) (17 June 2026), phased from October 2026, but not yet finalised in the gazette. The compliance substance is broadly the same in both regimes, and so are the variables that move cost and timeline.
The three variables that move everything
Three factors drive cost and timeline far more than any headline day-rate. Understanding where you sit on each is the actual estimate.
| Variable | Low effort | High effort |
|---|---|---|
| Starting maturity | Existing ISO/SAE 21434 processes, maintained TARAs, records already produced as a by-product of work | No CSMS, no TARA discipline, evidence reconstructed from memory |
| Scope | One vehicle type, few variants | Many types and variants, each needing its own TARA and RxSWIN |
| Supplier readiness | Tier-1s already producing cybersecurity evidence under interface agreements | Suppliers with no flow-down, becoming the critical path |
Starting maturity is the biggest driver
The single largest determinant is the maturity of your processes and evidence on day one. A manufacturer that already runs ISO/SAE 21434 engineering — with TARAs (clause 15) that are maintained rather than frozen, and records generated as a by-product of the work — is refining an existing system. A manufacturer starting from a blank CSMS is building the management system, the engineering discipline and the evidence habit at once. The gap between those two starting points is measured in months and in cost, and it dwarfs any difference in consultant rates.
Scope multiplies the type-specific work
The CSMS is assessed once, but per-vehicle-type approval means the type-specific work repeats. Each type needs its own TARA, its own cybersecurity case and its own RxSWIN — the Regulation X Software Identification Number that identifies the type's regulation-relevant software and changes when that software changes. A broad portfolio therefore multiplies the effort, even where the underlying processes are shared. Scoping tightly and sequencing types is one of the few levers that genuinely reduces effort without cutting corners.
Supplier readiness decides the critical path
The OEM carries the approval but depends on the supply chain for much of the evidence behind it. Where Tier-1 and Tier-2 suppliers already produce cybersecurity evidence under interface agreements, flow-down is a coordination exercise. Where they do not, supplier evidence becomes the critical path — the thing everyone waits on — because it depends on other organisations moving to your timeline. Starting flow-down early is the difference between a supplier trail that is ready and one that stalls the assessment. This is also one of the recurring reasons a first assessment fails, examined in the gaps that fail a first UN R155 CSMS assessment.
Why ranges of effort, not fixed prices
It would be easy to print a single figure, and it would be wrong. The responsible way to estimate is to describe ranges of effort against the three variables above, then locate your programme within them after a gap assessment. A gap assessment is itself the cheapest and most valuable early spend, because it converts "it depends" into a specific list of what you have, what you lack, and therefore what the programme actually costs for you.
The same logic applies to timeline. Supplier flow-down and post-production monitoring take the longest because they depend on other parties and on time-in-operation, so they should start first, not last. Compressing a timeline usually means compressing the parts that cannot be compressed — the record-building that a three-year certificate depends on — which is how programmes arrive at an assessment with a polished manual and no evidence. A sequenced route from scoping to an assessable state is set out in an AIS-189/190 readiness checklist.
The Indian picture specifically
For Indian OEMs there is an additional planning reality: the AIS-189 enforcement date is proposed in MoRTH draft G.S.R. 503(E) but not yet final. The draft phases the obligation from October 2026 to October 2029; because it is open for comment, this reference treats those dates as a planning baseline rather than a settled deadline. That draft status does not change the cost-and-timeline calculus — if anything it sharpens it. Because the readiness work takes the same months to do well regardless of the eventual date, waiting on certainty does not shorten the work; it only compresses the runway once the date arrives. Planning on capability rather than on a rumoured date is the sound posture, and it is developed further in AIS-189 explained.
The AutoSifu view
A credible estimate starts with a gap assessment, not a price list. AutoSifu works with CIRT as one route — compliance, solutioning and CoC/VTA support with the approval body in the room — so that cost and timeline are grounded in your actual starting maturity, scope and supplier readiness rather than a fabricated single number. The honest answer to "how much and how long" is a plan, and the plan is worth more than the number.
Questions
- How much does UN R155 type approval cost?
- There is no single honest figure, because the cost is driven by your starting maturity, the scope of the vehicle types involved, and how ready your suppliers are. A manufacturer with existing ISO/SAE 21434 processes and maintained TARAs spends far less than one starting from a blank CSMS. Anyone quoting a fixed price without understanding those variables is guessing — the useful question is what drives the cost, not what the number is.
- How long does CSMS certification take?
- The timeline depends primarily on the maturity of your processes and evidence at the start. Standing up a CSMS, running or refreshing TARAs, flowing requirements down to suppliers and accumulating records takes months, not weeks, and the supplier and monitoring elements take longest because they depend on other parties and on time-in-operation. A dry-run assessment before the real one is time well spent rather than time lost.
- What drives the cost and timeline?
- The biggest single driver is the starting maturity of your processes and evidence. Scope — how many vehicle types and variants — multiplies the type-specific work such as the TARA and RxSWIN. Supplier readiness determines whether flow-down evidence arrives on time or becomes the critical path. Together these three variables move cost and timeline far more than any headline rate.
