Skip to main content
← All posts·
Regulatory Compliance

CRA & UNECE R155: Automotive Software Cybersecurity Requirements

Cyber Resilience Act and UNECE R155 compliance for automotive software. Vehicle cybersecurity management systems, software update management, SBOM for vehicle ECUs, and interaction between CRA and type approval regulations.

Luca Berton10 min read

Automotive Software: Dual Regulation

Automotive software sits at the intersection of two regulatory frameworks: the Cyber Resilience Act (CRA) for products with digital elements, and UNECE R155/R156 for vehicle cybersecurity and software updates. While the CRA exempts products already covered by sector-specific EU regulations (like the Vehicle General Safety Regulation), the boundary is not always clear — especially for aftermarket devices, fleet management systems, and connected vehicle infrastructure.

What Falls Where

UNECE R155/R156 Scope (Vehicle Type Approval)

  • R155: Cybersecurity Management System (CSMS) — required for vehicle type approval. Covers the vehicle as a whole.
  • R156: Software Update Management System (SUMS) — secure OTA update capability for vehicles
  • In scope: ECU firmware, vehicle OS, infotainment systems, ADAS software, telematics units — anything that's part of the type-approved vehicle
  • Mandatory since July 2024: All new vehicles sold in the EU must have CSMS and SUMS certification

CRA Scope (Non-Vehicle Products)

  • Aftermarket devices: OBD dongles, dash cameras, fleet trackers, aftermarket infotainment — not part of type approval
  • EV charging infrastructure: OCPP-based chargers, charging management software, grid integration
  • Fleet management platforms: SaaS platforms for fleet tracking, route optimisation, driver behaviour
  • V2X infrastructure: Roadside units, traffic management systems communicating with vehicles

Key Requirements Comparison

RequirementUNECE R155CRA
Risk assessmentTARA (threat analysis)Cybersecurity risk assessment
Vulnerability handlingCSMS processCVD + ENISA reporting
Software updatesSUMS (R156)Secure update mechanism
SBOMRecommended (ISO/SAE 21434)Mandatory
ConformityType approval authoritySelf-assessment or notified body
📘 Book

Kubernetes Recipes

Practical guide for container orchestration and deployment — hands-on patterns you can use today.

View on Amazon

Practical Implications

  • Tier 1 suppliers: Software components supplied to OEMs must support the OEM's CSMS. The supplier doesn't need separate CRA compliance if the component is part of a type-approved vehicle — but needs ISO/SAE 21434 compliance.
  • Aftermarket companies: Full CRA compliance required. This is new regulatory burden for many aftermarket device manufacturers.
  • EV charging: CRA applies. Chargers are products with digital elements. SBOM, vulnerability handling, and secure updates all required by December 2027.
  • Connected vehicle data: GDPR applies to all personal data from connected vehicles — driving behaviour, location, voice commands. Must be considered alongside cybersecurity requirements.
CRA
automotive
UNECE R155
vehicle cybersecurity
software updates
SBOM
compliance

Related Solution

Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 2-3 weeks.

Explore AI Readiness for Regulated Enterprises →

Need help applying this in your organization?

Get a free 30-minute assessment with actionable recommendations — whether we work together or not.

Book Your Free AI Platform Assessment

18+ years experience · Ex-Red Hat & Dell · Speaker at KubeCon EU 2026

Luca Berton

Written by

Luca Berton

CEO at Open Empower. 18+ years building enterprise infrastructure at JPMorgan Chase, Red Hat & Dell. Author of 9 technical books. Speaker at Red Hat Summit and KubeCon EU 2026. Instructor on Coursera, Pluralsight & Udemy.

Get more insights like this

Practical AI infrastructure and platform engineering guides — delivered to your inbox.

Subscribe to Newsletter →