UNECE R155 is the United Nations Economic Commission for Europe (UNECE) regulation that establishes cybersecurity requirements for road vehicles. Its main objective is to ensure that manufacturers identify, assess, and mitigate cybersecurity risks throughout the entire vehicle lifecycle, from design and development to end-of-life. To achieve this, the regulation requires manufacturers to implement a Cyber Security Management System (CSMS) as a prerequisite for the type approval of new vehicle models.
As vehicles become increasingly connected through wireless communications, over-the-air software updates, and integration with smart infrastructure, the potential attack surface continues to grow. UNECE R155 requires manufacturers to address threats such as unauthorized access to vehicle systems, software manipulation, and attacks targeting internal and external communications. It also promotes continuous vulnerability monitoring and effective incident response processes.
UNECE R155 marks a significant shift in the automotive industry by making cybersecurity a regulatory obligation rather than a voluntary best practice. Its implementation encourages secure development practices, risk management, and lifecycle cybersecurity governance, ultimately strengthening the resilience of connected vehicles and increasing trust among manufacturers, suppliers, regulators, and end users.