UN R155 explained: the CSMS in plain terms

The UN cyber security regulation, what a CSMS is, and what an approval authority checks

6 Aug 20264 min readAutoSifu

What UN R155 actually is

UN R155 is the United Nations cyber security regulation for road vehicles, adopted by the UNECE World Forum for Harmonization of Vehicle Regulations (WP.29) and given legal force through the 1958 Agreement. It does two things at once. It obliges a vehicle manufacturer to run a certified management system for cyber security, and it obliges each vehicle type to carry its own approval demonstrating that its cyber risks have been identified and treated.

That two-part structure is the single most important thing to understand about R155. You do not "pass R155" with a test on a bench. You demonstrate, first, that your organisation has a working process for managing cyber risk, and second, that you actually applied that process to the specific type you are trying to sell.

The two approvals

The first approval is the Certificate of Compliance for the CSMS. It is issued to the manufacturer, not to a vehicle, and it is valid for three years. It says the approval authority has examined your processes and is satisfied they can manage cyber security across development, production and the post-production phase.

The second is the vehicle type approval itself. It is granted per type and depends on the CSMS certificate already being in place. Here the authority checks that the risk assessment, the mitigations and the supporting evidence exist for that particular type — that the general capability certified in the CSMS was genuinely exercised on this product.

Element CSMS Certificate of Compliance Vehicle type approval
Granted to The manufacturer / organisation A specific vehicle type
What it proves You have processes to manage cyber risk You applied them to this type
Validity Three years Tied to the type
Precondition — A valid CSMS certificate
Evidence Process descriptions plus records TARA, mitigations, RxSWIN, test results

An organisation that treats these as one exercise usually discovers, late, that a beautifully written process manual is not the same as evidence that the process ran on the programme in front of the assessor.

What a CSMS has to cover

The CSMS is the heart of the regulation. It is a management system in the ISO sense — defined processes, owners, records and continual improvement — applied to cyber security. A compliant CSMS demonstrates that the manufacturer can identify and manage risks, verify that mitigations work, keep managing risk after the vehicle is in the field, detect attacks and respond to them, and impose the same discipline on its suppliers.

Crucially, R155 spans the whole lifecycle, including post-production monitoring. Approval is not the finish line. The regulation expects you to keep watching the fleet, feed what you learn back into risk management, and update software where needed. We treat that lifecycle span in more detail in what is a CSMS.

Where the threat model comes from

R155 does not leave "cyber risk" undefined. Its Annex 5 supplies a structured catalogue of threats and vulnerabilities across seven high-level categories — back-end servers; communication channels; update procedures; unintended human actions; external connectivity and connections; vehicle data and code; and potential vulnerabilities left un-hardened — with corresponding mitigations. In practice a manufacturer maps its threat analysis and risk assessment against Annex 5 to show nothing has been missed. The full breakdown sits in UN R155 Annex 5 decoded.

Annex 5 is the "what to worry about". The engineering method for working through it comes from ISO/SAE 21434:2021, the road-vehicle cyber security engineering standard the regulation leans on. R155 is the law; 21434 supplies the process substance that produces the evidence the assessor reads.

What the approval authority checks

An assessor is looking for two things that are easy to state and hard to fake. Does a defined process exist? And is there a record that it actually ran on a real programme?

That distinction is where most first assessments struggle. A risk assessment that was written once and never maintained, a supplier requirement that was sent but never verified, a monitoring capability that exists on a slide but produces no records — each is a process without evidence. The dossier that satisfies an assessor is examined in the UN R155 audit.

Timing and geography

The dates already bit in the EU: new types from 6 July 2022, all new vehicles from 7 July 2024, driven by the General Safety Regulation (EU) 2019/2144. Because R155 travels through the 1958 Agreement, an approval issued by one Contracting Party is recognised by the others that have adopted the regulation — which is what makes it valuable to an exporter.

India is not part of that mutual-recognition regime. It has published its own aligned standard, AIS-189, for assessment inside India, and its enforcement is proposed in MoRTH draft G.S.R. 503(E) (phased from October 2026) but not yet finalised. An Indian OEM exporting to UNECE markets therefore carries both files: the UN approval for the export market and the Indian regime at home.

The AutoSifu view

Most teams meet R155 as two disconnected problems — engineers building the CSMS on one side, an approval body on the other, and a consultancy in the middle translating. AutoSifu runs it as one route: we build the CSMS and its evidence, do the secure-architecture and solutioning work, and support the CoC and vehicle type approval, with our strategic partner CIRT — a named test agency in the room from the start. That way the process you write and the evidence the assessor opens are the same object, not two documents that meet for the first time on assessment day.

Questions

What is UN R155?
UN R155 is the UNECE cyber security regulation adopted under the 1958 Agreement through WP.29. It requires a vehicle manufacturer to operate a certified Cyber Security Management System (CSMS) and to obtain a per-vehicle-type approval that shows the specific type has been engineered and risk-assessed against cyber threats. It applies wherever a Contracting Party has brought it into force, and in the EU it is mandatory for all new vehicles from 7 July 2024.
What is a CSMS under UN R155?
A CSMS is the set of processes an organisation runs to manage cyber security risk across the vehicle lifecycle — governance, risk management, supplier flow-down, monitoring and incident response. R155 requires the manufacturer to hold a Certificate of Compliance for the CSMS, valid for three years, before any vehicle type is approved. It is assessed as a live management system, not judged as a document.
When did UN R155 come into force?
In the EU, UN R155 has applied to new vehicle types since 6 July 2022 and to all new vehicles produced from 7 July 2024, via the General Safety Regulation (EU) 2019/2144. Other Contracting Parties, including Japan and Korea, enforce it on their own schedules. India runs its own aligned standard, AIS-189, whose enforcement is proposed in MoRTH draft G.S.R. 503(E) (phased from October 2026) but not yet finalised.

09 — Start here

Bring us the file you are least sure about.

Most conversations start with a gap assessment, or a type approval submission that is closer than it feels. Either is a good place to begin.

Direct

Jaipur · registered office

Plot No. 8, ABS Plaza, Chanakya PuriJagatpura, Jaipur – 302017, RajasthanAUTOSIFU Pvt Ltd · India

Required