Connected Vehicles
As vehicles exchange data with external systems, security assessment extends beyond hardware to system architecture, data flows and operating scenarios.
As vehicle technology advances, cybersecurity is no longer solely an IT concern; it has become an integral part of type approval. UNECE R155 and Cyber Security Management System (CSMS) requirements are intended to ensure that manufacturers can manage cyber risks throughout the vehicle lifecycle. Anemon Engineering helps manufacturers turn these requirements into a clear and manageable programme.
Modern vehicles are no longer purely mechanical systems. Software updates, connected services, remote-access functions and data communications enable advanced capabilities, but also introduce new security risks.
UNECE R155 is a UN regulation designed to ensure that manufacturers manage these risks systematically. It requires both a cybersecurity management system at manufacturer level and evidence that vehicle types have been developed with cyber risks under control.
The objective is not merely to prevent a predefined set of attacks, but to manage cybersecurity risk throughout the vehicle lifecycle.
As vehicles exchange data with external systems, security assessment extends beyond hardware to system architecture, data flows and operating scenarios.
Remote software updates accelerate the product lifecycle while making change management, version control and secure deployment more critical.
As communication within and beyond the vehicle increases, integrity, authorisation, traceability and confidentiality become part of type-approval preparation.
Service, fleet-management and connected-service functions may create remote access points that require risk-based assessment.
Software relationships between control units, driver-assistance systems and electronic modules are central to the cybersecurity approach.
The applicable scope varies from one project to another. Each project must be assessed on its own merits.
UNECE R155 applicability should be assessed for projects involving a new type approval, a type extension or a change of target market.
Changes made to a base vehicle may affect electronic systems, connected functions or type-approval responsibilities.
Where more than one manufacturer shares responsibility, cybersecurity effects and obligations must be allocated correctly.
Electric powertrains, battery management, charging infrastructure and software functions broaden the cybersecurity assessment.
Component manufacturers and system suppliers may form part of the process through supplier management, technical evidence and change tracking.
Connected functions, data platforms and remote-access scenarios require particular attention in UNECE R155 and CSMS preparation.
A CSMS is not a document produced and placed in an archive. It is an organisation-wide management framework. Identifying risks, managing incidents, monitoring supplier effects and controlling changes are all part of that framework.
The two frameworks are often considered together, but they are not the same.
| Topic | UNECE R155 | ISO/SAE 21434 |
|---|---|---|
| Purpose | Defines the regulatory approach to a manufacturer’s CSMS and vehicle cybersecurity for type approval. | Provides an engineering framework for automotive cybersecurity processes. |
| Scope | Relates to the manufacturer’s management system, the vehicle type and the evidence submitted to the approval authority. | Focuses on product development, risk analysis, verification and lifecycle engineering activities. |
| Primary Focus | Regulatory compliance, the CSMS, vehicle approval and manufacturer responsibility. | Engineering methods, threat analysis, technical controls and process maturity. |
| Lifecycle | Expects a management approach covering vehicle development, production, operation, service and changes. | Describes cybersecurity engineering activities from concept through decommissioning. |
| Practical Use | The primary regulatory framework for type approval and compliance preparation. | An engineering reference used to support UNECE R155 and CSMS implementation. |
Uncontrolled access to vehicle systems or service interfaces can have serious consequences for functional safety and data integrity.
Altered vehicle data can undermine confidence in diagnostics, fleet management, driver-assistance systems and compliance evidence.
Electronic systems failing to operate as intended can affect vehicle availability, customer experience and perceptions of safety.
Cybersecurity incidents can directly affect production, service, warranty and field-action processes.
Incomplete CSMS preparation or insufficient evidence can lead to delays and revisions during type approval.
Cybersecurity vulnerabilities can have long-term consequences not only technically, but also for brand trust and customer relationships.
The vehicle type, electronic architecture, supplier structure, target market and current documentation maturity are assessed together.
Applicable requirements are determined according to UNECE R155, GSR II and the specific scope of the project.
A practical, phased and auditable Cyber Security Management System roadmap is developed according to the organisation’s current maturity.
A structured framework is prepared for policies, procedures, records, risk assessments, change management and supplier evidence.
Vehicle cybersecurity, system functions and technical-file requirements are addressed from an engineering perspective.
Support is provided throughout application preparation, evidence development, technical explanations and process coordination.

UNECE R155 and CSMS preparation is not a standalone documentation exercise to be added after product development. When vehicle architecture, supplier relationships, software changes and technical evidence are planned early, the process becomes more robust.
If cybersecurity effects are considered only at the end of development, architectural changes, repeat testing and documentation revisions may increase.
Even where processes operate in practice, an unclear evidence structure creates additional questions during type approval and audits.
When changes from component and software suppliers are not monitored, the CSMS chain becomes weaker.
Generic risk lists may fail to identify the project-specific threats and controls that actually matter.
Field updates, software revisions and new functions must be reassessed for their cybersecurity effects.
GSR II introduces new vehicle-safety systems and performance requirements, while UNECE R155 and the CSMS focus on managing automotive cybersecurity risk. These areas often need to be considered together during type approval, with proper attention to vehicle category, target market, electronic-system scope and manufacturer responsibilities.
The requirements do not apply to every manufacturer in exactly the same way. Vehicle type, system architecture and target market must be assessed together.
UNECE R155 is a UN regulation aimed at the systematic management of automotive cybersecurity risk throughout the vehicle lifecycle. Manufacturers are expected to demonstrate not only individual technical controls, but also an organisational system for managing those risks.
CSMS stands for Cyber Security Management System. It encompasses risk management, incident management, supplier management, change management and continual improvement.
Scope depends on vehicle category, target market, electronic systems, connected functions and the type-approval strategy. Each project therefore requires an individual assessment.
ISO/SAE 21434 and UNECE R155 are not the same. ISO/SAE 21434 is an important reference for automotive cybersecurity engineering and can be used in practice to support R155 and CSMS preparation.
GSR II expands the vehicle-safety framework, while UNECE R155 and the CSMS address management of cybersecurity risk. These subjects should not be treated in isolation during vehicle approval.
Yes. In some bodybuilder and multi-stage approval projects, electronic systems, connected functions or changes to the base vehicle may have implications under UNECE R155.
Anemon Engineering provides current-state assessment, requirements analysis, CSMS roadmaps, documentation frameworks, technical preparation and type-approval support.
Together, we can evaluate how UNECE R155 and CSMS affect your project and define an appropriate roadmap.