Automotive Software: Dual Regulation
Automotive software sits at the intersection of two regulatory frameworks: the Cyber Resilience Act (CRA) for products with digital elements, and UNECE R155/R156 for vehicle cybersecurity and software updates. While the CRA exempts products already covered by sector-specific EU regulations (like the Vehicle General Safety Regulation), the boundary is not always clear — especially for aftermarket devices, fleet management systems, and connected vehicle infrastructure.
What Falls Where
UNECE R155/R156 Scope (Vehicle Type Approval)
- R155: Cybersecurity Management System (CSMS) — required for vehicle type approval. Covers the vehicle as a whole.
- R156: Software Update Management System (SUMS) — secure OTA update capability for vehicles
- In scope: ECU firmware, vehicle OS, infotainment systems, ADAS software, telematics units — anything that's part of the type-approved vehicle
- Mandatory since July 2024: All new vehicles sold in the EU must have CSMS and SUMS certification
CRA Scope (Non-Vehicle Products)
- Aftermarket devices: OBD dongles, dash cameras, fleet trackers, aftermarket infotainment — not part of type approval
- EV charging infrastructure: OCPP-based chargers, charging management software, grid integration
- Fleet management platforms: SaaS platforms for fleet tracking, route optimisation, driver behaviour
- V2X infrastructure: Roadside units, traffic management systems communicating with vehicles
Key Requirements Comparison
| Requirement | UNECE R155 | CRA |
|---|---|---|
| Risk assessment | TARA (threat analysis) | Cybersecurity risk assessment |
| Vulnerability handling | CSMS process | CVD + ENISA reporting |
| Software updates | SUMS (R156) | Secure update mechanism |
| SBOM | Recommended (ISO/SAE 21434) | Mandatory |
| Conformity | Type approval authority | Self-assessment or notified body |
Kubernetes Recipes
Practical guide for container orchestration and deployment — hands-on patterns you can use today.
View on Amazon →Practical Implications
- Tier 1 suppliers: Software components supplied to OEMs must support the OEM's CSMS. The supplier doesn't need separate CRA compliance if the component is part of a type-approved vehicle — but needs ISO/SAE 21434 compliance.
- Aftermarket companies: Full CRA compliance required. This is new regulatory burden for many aftermarket device manufacturers.
- EV charging: CRA applies. Chargers are products with digital elements. SBOM, vulnerability handling, and secure updates all required by December 2027.
- Connected vehicle data: GDPR applies to all personal data from connected vehicles — driving behaviour, location, voice commands. Must be considered alongside cybersecurity requirements.
Related Solution
Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 2-3 weeks.
Explore AI Readiness for Regulated Enterprises →
Luca Berton