With the introduction of the GSR II requirements, CSMS compliance under UN Regulation No 155 has become an important consideration in second-stage type approval. What should second-stage manufacturers do to address R155 correctly?
What Is a Cybersecurity Management System (CSMS)?
UN Regulation No 155 defines the cybersecurity management requirements applicable to vehicle manufacturers within its scope. It provides a comprehensive regulatory framework for protecting vehicles against cyber threats and is one of the requirements introduced through the GSR II regulatory package.
Compliance requires vehicle manufacturers to demonstrate that the applicable cybersecurity requirements have been met before the relevant vehicle types are placed on the market. Under the transition timetable for the GSR II requirements, manufacturers must obtain the approvals applicable to their scope. In this context, UN Regulation No 155 is intended to ensure that cybersecurity is managed throughout the vehicle lifecycle, from design and production to operation and maintenance.
Manufacturers affected by these requirements can broadly be considered in two groups: manufacturers that already hold second-stage type approval and manufacturers preparing a new approval application. Existing second-stage approval holders need to assess and adapt their current production processes for compliance with UN Regulation No 155. Manufacturers seeking a new approval should establish a management system that incorporates the applicable R155 requirements into design, production and cybersecurity approval activities from the outset.
A CSMS brings together the policies, processes and technical measures needed to manage vehicle cybersecurity. Its purpose is to improve resilience against cyberattacks, identify potential threats and support an effective response. It also covers secure software updates and the protection of relevant vehicle data.
Effective implementation requires access to personnel with appropriate cybersecurity expertise, whether in-house or through specialist support. Manufacturers must also work with supply-chain partners and third-party providers so that cybersecurity responsibilities and evidence are managed consistently across the relevant parties.
Which Vehicles Are Subject to the Requirement?
For second-stage and bodywork approvals, applicability is assessed according to the work performed on the base vehicle. For requirements concerning cybersecurity and the protection of vehicles against cyber threats, the Regulation (EU) 2019/2144 sets the regulatory framework under which manufacturers of M1, M2, M3, N1, N2 and N3 vehicles, components and separate technical units may fall within the mandatory regulatory scope.
Although there is no mandatory requirement for O-category manufacturers, approval under the regulation may be pursued voluntarily where appropriate.
Cybersecurity Approval for Second-Stage Type Approval
Bodybuilders should first determine whether their particular conversion falls within scope. The key consideration is the effect of the bodywork or conversion on the base vehicle. A reliable assessment therefore requires the relevant technical documentation to be reviewed.
For example, an M3 manufacturer may need to identify the electrical and electronic products it installs, their interaction with the base vehicle and their own cybersecurity characteristics. This can require a detailed and time-intensive technical assessment.
The resulting cybersecurity relevance determines the scope and depth of the management-system work required from the manufacturer.
Bodybuilders should therefore understand the CSMS framework and confirm how their activities will be assessed, including whether a cybersecurity management system is required for the approval concerned.
Depending on the scope and readiness of the organisation, the approval process may take between three months and one year.
Our CSMS and Cybersecurity Services
We support organisations throughout the CSMS approval process. In line with second-stage bodywork type-approval requirements, we coordinate scope assessment, documentation and approval activities and can advise how the regulation may affect the continuity of your type approval.
Follow us on LinkedIn and Instagram for further updates.
Overview
UN Regulation No 155 establishes a framework for managing vehicle cybersecurity risks throughout the vehicle lifecycle. This article examines how CSMS requirements may affect multi-stage type approval and bodybuilders. The article also covers What Is a Cybersecurity Management System (CSMS)?, Which Vehicles Are Subject to the Requirement? and Cybersecurity Approval for Second-Stage Type Approval.
