Don’t do SECURITY. Do business SECURELY.

Vehicle cyber security rules now apply to all new vehicles in the EU

UN Regulations 155 and 156 become mandatory for all new vehicles registered in the EU, extending beyond new vehicle types.

From today, all new vehicles registered in the European Union must comply with UN Regulation No. 155 (cyber security management systems) and Regulation No. 156 (software update management systems), under the EU General Safety Regulation.

Key points

  • The requirements have applied to new vehicle types since July 2022.
  • They now extend to all newly registered vehicles, including those based on older type approvals.
  • Manufacturers must hold a certified Cyber Security Management System and Software Update Management System.
  • Some manufacturers have withdrawn older models that could not be made compliant.
  • Suppliers are commonly required to follow ISO/SAE 21434 and hold TISAX labels.

UK automotive suppliers selling into EU vehicle programmes should expect continued scrutiny of product security processes, vulnerability handling and support for software updates throughout the vehicle lifecycle.

Source: UN Regulation No. 155 (UNECE)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights