UNECE R155 / CSMS

Prepare for automotive cybersecurity requirements.

As vehicle technology advances, cybersecurity is no longer solely an IT concern; it has become an integral part of type approval. UNECE R155 and Cyber Security Management System (CSMS) requirements are intended to ensure that manufacturers can manage cyber risks throughout the vehicle lifecycle. Anemon Engineering helps manufacturers turn these requirements into a clear and manageable programme.

Vehicle-cybersecurity assessment environment for UNECE R155 and CSMS

A new-generation approach to vehicle cybersecurity.

Modern vehicles are no longer purely mechanical systems. Software updates, connected services, remote-access functions and data communications enable advanced capabilities, but also introduce new security risks.

UNECE R155 is a UN regulation designed to ensure that manufacturers manage these risks systematically. It requires both a cybersecurity management system at manufacturer level and evidence that vehicle types have been developed with cyber risks under control.

The objective is not merely to prevent a predefined set of attacks, but to manage cybersecurity risk throughout the vehicle lifecycle.

Connected vehicles create new security requirements.

01

Connected Vehicles

As vehicles exchange data with external systems, security assessment extends beyond hardware to system architecture, data flows and operating scenarios.

02

Over-the-Air Updates

Remote software updates accelerate the product lifecycle while making change management, version control and secure deployment more critical.

03

Data Communications

As communication within and beyond the vehicle increases, integrity, authorisation, traceability and confidentiality become part of type-approval preparation.

04

Remote Access

Service, fleet-management and connected-service functions may create remote access points that require risk-based assessment.

05

Vehicle Software

Software relationships between control units, driver-assistance systems and electronic modules are central to the cybersecurity approach.

A broad range of vehicle projects may fall within scope.

The applicable scope varies from one project to another. Each project must be assessed on its own merits.

Vehicle Manufacturers

UNECE R155 applicability should be assessed for projects involving a new type approval, a type extension or a change of target market.

Bodybuilders

Changes made to a base vehicle may affect electronic systems, connected functions or type-approval responsibilities.

Multi-Stage Type-Approval Projects

Where more than one manufacturer shares responsibility, cybersecurity effects and obligations must be allocated correctly.

Electric Vehicle Manufacturers

Electric powertrains, battery management, charging infrastructure and software functions broaden the cybersecurity assessment.

Electronic-System Manufacturers

Component manufacturers and system suppliers may form part of the process through supplier management, technical evidence and change tracking.

Connected-Vehicle Projects

Connected functions, data platforms and remote-access scenarios require particular attention in UNECE R155 and CSMS preparation.

What does a Cyber Security Management System mean in practice?

A CSMS is not a document produced and placed in an archive. It is an organisation-wide management framework. Identifying risks, managing incidents, monitoring supplier effects and controlling changes are all part of that framework.

Risk Management

Regular assessment of threats, vulnerabilities and potential consequences at both product and process level.

Threat Monitoring

Monitoring new threats and industry developments throughout the vehicle lifecycle.

Incident Management

Defining responsibilities, escalation paths and actions for cybersecurity incidents.

Supplier Management

Keeping the cybersecurity effects of component and software suppliers under control.

Change Management

Reassessing cybersecurity effects when software, hardware or vehicle functions change.

Continual Improvement

Keeping the CSMS current through audits, feedback and emerging-risk information.

Two complementary approaches.

The two frameworks are often considered together, but they are not the same.

TopicUNECE R155ISO/SAE 21434
PurposeDefines the regulatory approach to a manufacturer’s CSMS and vehicle cybersecurity for type approval.Provides an engineering framework for automotive cybersecurity processes.
ScopeRelates to the manufacturer’s management system, the vehicle type and the evidence submitted to the approval authority.Focuses on product development, risk analysis, verification and lifecycle engineering activities.
Primary FocusRegulatory compliance, the CSMS, vehicle approval and manufacturer responsibility.Engineering methods, threat analysis, technical controls and process maturity.
LifecycleExpects a management approach covering vehicle development, production, operation, service and changes.Describes cybersecurity engineering activities from concept through decommissioning.
Practical UseThe primary regulatory framework for type approval and compliance preparation.An engineering reference used to support UNECE R155 and CSMS implementation.

Cybersecurity is not solely a technical issue.

Unauthorised Access

Uncontrolled access to vehicle systems or service interfaces can have serious consequences for functional safety and data integrity.

Data Manipulation

Altered vehicle data can undermine confidence in diagnostics, fleet management, driver-assistance systems and compliance evidence.

Loss of Function

Electronic systems failing to operate as intended can affect vehicle availability, customer experience and perceptions of safety.

Operational Risks

Cybersecurity incidents can directly affect production, service, warranty and field-action processes.

Regulatory-Compliance Risks

Incomplete CSMS preparation or insufficient evidence can lead to delays and revisions during type approval.

Reputational Risks

Cybersecurity vulnerabilities can have long-term consequences not only technically, but also for brand trust and customer relationships.

Making the process more manageable.

01

Current-State Assessment

The vehicle type, electronic architecture, supplier structure, target market and current documentation maturity are assessed together.

02

Requirements Assessment

Applicable requirements are determined according to UNECE R155, GSR II and the specific scope of the project.

03

CSMS Roadmap

A practical, phased and auditable Cyber Security Management System roadmap is developed according to the organisation’s current maturity.

04

Documentation Framework

A structured framework is prepared for policies, procedures, records, risk assessments, change management and supplier evidence.

05

Technical Preparation

Vehicle cybersecurity, system functions and technical-file requirements are addressed from an engineering perspective.

06

Type-Approval Support

Support is provided throughout application preparation, evidence development, technical explanations and process coordination.

Structuring the process step by step.

01Current-State Assessment
02Risk Assessment
03Process Design
04Documentation
05Verification and Readiness
06Type-Approval Process
Vehicle electronic architecture, supplier boundaries and CSMS lifecycle risk assessment under UN R155

Do not leave cybersecurity until the final stage.

UNECE R155 and CSMS preparation is not a standalone documentation exercise to be added after product development. When vehicle architecture, supplier relationships, software changes and technical evidence are planned early, the process becomes more robust.

  • More predictable project planning
  • Fewer revisions
  • Stronger documentation
  • More efficient audit processes
  • Less uncertainty

Frequent issues encountered by manufacturers.

Starting Too Late

If cybersecurity effects are considered only at the end of development, architectural changes, repeat testing and documentation revisions may increase.

Insufficient Documentation

Even where processes operate in practice, an unclear evidence structure creates additional questions during type approval and audits.

Overlooking Supplier Processes

When changes from component and software suppliers are not monitored, the CSMS chain becomes weaker.

Treating Risk Management Superficially

Generic risk lists may fail to identify the project-specific threats and controls that actually matter.

Neglecting Change Management

Field updates, software revisions and new functions must be reassessed for their cybersecurity effects.

Complementary requirements.

GSR II UNECE R155 CSMS Vehicle Approval

GSR II introduces new vehicle-safety systems and performance requirements, while UNECE R155 and the CSMS focus on managing automotive cybersecurity risk. These areas often need to be considered together during type approval, with proper attention to vehicle category, target market, electronic-system scope and manufacturer responsibilities.

What manufacturers need to know about UNECE R155.

The requirements do not apply to every manufacturer in exactly the same way. Vehicle type, system architecture and target market must be assessed together.

UNECE R155 is a UN regulation aimed at the systematic management of automotive cybersecurity risk throughout the vehicle lifecycle. Manufacturers are expected to demonstrate not only individual technical controls, but also an organisational system for managing those risks.

CSMS stands for Cyber Security Management System. It encompasses risk management, incident management, supplier management, change management and continual improvement.

Scope depends on vehicle category, target market, electronic systems, connected functions and the type-approval strategy. Each project therefore requires an individual assessment.

ISO/SAE 21434 and UNECE R155 are not the same. ISO/SAE 21434 is an important reference for automotive cybersecurity engineering and can be used in practice to support R155 and CSMS preparation.

GSR II expands the vehicle-safety framework, while UNECE R155 and the CSMS address management of cybersecurity risk. These subjects should not be treated in isolation during vehicle approval.

Yes. In some bodybuilder and multi-stage approval projects, electronic systems, connected functions or changes to the base vehicle may have implications under UNECE R155.

Anemon Engineering provides current-state assessment, requirements analysis, CSMS roadmaps, documentation frameworks, technical preparation and type-approval support.

Let us assess your cybersecurity requirements.

Together, we can evaluate how UNECE R155 and CSMS affect your project and define an appropriate roadmap.