Technical Insight

GAR INSIGHT
Connected, Updated, Regulated: The Evolution of UN R155 & R156

The modern vehicle is no longer defined only by its mechanical systems. Connectivity, software, electronic control units, cloud services, mobile applications and over-the-air updates increasingly determine how a vehicle operates throughout its life.

This transformation has created a new homologation challenge. A vehicle may be technically compliant when it leaves the production line, yet its cybersecurity exposure can change as new vulnerabilities emerge, connected services evolve and software is updated.

UN Regulations No. 155 and No. 156 respond to this fundamental shift. Together, they introduce regulatory frameworks for vehicle cybersecurity, cybersecurity management and software-update governance — extending conformity from the physical vehicle into the manufacturer’s organizational processes and the vehicle’s continuing digital lifecycle.

The homologation question has changed. Regulators no longer need to know only whether the vehicle is compliant today. They increasingly need assurance that cybersecurity risks and software changes can continue to be controlled after the vehicle enters service.
01
THE DIGITAL VEHICLE

Homologation Is No Longer Only About Hardware

Traditional vehicle approval developed around relatively stable physical systems: brakes, steering, lighting, structures, emissions and occupant protection.

Modern vehicles introduce a very different engineering environment. Software increasingly controls safety-critical functions while vehicles communicate continuously with external systems.

TRADITIONAL VEHICLE Relatively Stable Configuration

Vehicle characteristics remain largely fixed after production, with regulatory assessment concentrated around design approval and conformity of production.

CONNECTED VEHICLE Continuously Changing Digital Environment

Software, connectivity, backend services and emerging cyber threats can alter the vehicle’s operational environment throughout its service life.

The vehicle now has a digital attack surface. Every communication interface, software component, connected service and external dependency can potentially influence vehicle cybersecurity.
Back to Article Guide
02
UN REGULATION NO. 155

Cybersecurity Becomes Part of Vehicle Type Approval

UN Regulation No. 155 establishes uniform provisions concerning the approval of vehicles with regard to cybersecurity and the Cyber Security Management System — CSMS.

The regulation creates two closely connected layers of assurance.

ORGANIZATIONAL LEVEL Cyber Security Management System

The manufacturer must demonstrate processes for identifying, assessing, treating and monitoring cybersecurity risks throughout relevant phases of the vehicle lifecycle.

VEHICLE LEVEL Cybersecurity Type Approval

The manufacturer must demonstrate that cybersecurity risks relevant to the vehicle type have been identified and appropriately addressed.

R155 does not simply ask whether a vehicle can resist one penetration test. It asks whether the manufacturer has a systematic capability to manage cybersecurity risks across vehicle development, production and post-production activities.
Back to Article Guide
03
CSMS

Cybersecurity Must Be Managed as a Lifecycle Process

The Cyber Security Management System changes the compliance model because approval depends partly on organizational capability rather than only on the characteristics of one vehicle.

Risk Identification

Processes must identify relevant cybersecurity threats, vulnerabilities and potential attack paths.

Risk Assessment

Identified risks need to be evaluated according to their potential consequences and likelihood.

Risk Treatment

Appropriate design, technical and organizational measures are implemented to reduce cybersecurity risk.

Verification

Cybersecurity measures need supporting evidence demonstrating that they perform as intended.

Monitoring

New threats and vulnerabilities must continue to be considered after vehicles enter service.

Response

Manufacturers require processes for responding when relevant cybersecurity issues are identified.

The important regulatory change is continuity.

Cybersecurity management cannot finish when type approval is granted because the threat environment itself continues to change.

Back to Article Guide
04
THREATS & VULNERABILITIES

The Vehicle Attack Surface Extends Far Beyond the Vehicle

Connected vehicles interact with multiple internal and external systems. Cybersecurity assessment therefore needs to consider the complete ecosystem rather than only individual electronic components.

Vehicle Networks

Internal communication networks and electronic control units can become potential attack paths.

Wireless Interfaces

Cellular, Wi-Fi, Bluetooth and other communication interfaces increase external connectivity.

Diagnostic Interfaces

Service and diagnostic access can introduce cybersecurity risks if inadequately controlled.

Backend Infrastructure

Manufacturer servers and connected services can influence vehicle functions and data.

Mobile Applications

Vehicle-control and user applications can become part of the wider cybersecurity boundary.

Software Supply Chain

Third-party software, libraries, components and suppliers can introduce vulnerabilities outside the OEM’s direct development environment.

A vehicle can be attacked without physically touching it. This fundamentally changes the meaning of vehicle safety and expands homologation into systems that may exist far beyond the physical boundary of the vehicle.
Back to Article Guide
05
UN REGULATION NO. 156

Software Updates Become Part of Regulatory Control

UN Regulation No. 156 establishes uniform provisions concerning software updates and the Software Update Management System — SUMS.

Its importance extends far beyond over-the-air updating. The regulation creates a structured framework for controlling software changes that can affect approved vehicle characteristics.

ORGANIZATIONAL LEVEL Software Update Management System

The manufacturer establishes processes for identifying, assessing, controlling, documenting and deploying vehicle software updates.

VEHICLE LEVEL Software Update Compliance

The vehicle and its update processes must satisfy applicable requirements relating to software identification, integrity and safe update execution.

UN R156 is not simply an “OTA regulation.”

Its wider purpose is to ensure that software updates are systematically controlled and that approval-relevant vehicle characteristics remain traceable as software changes.

Back to Article Guide
06
SUMS

Software Change Requires Governance

The Software Update Management System provides the organizational framework through which manufacturers control software updates affecting vehicles.

Software Identification

Relevant software versions and configurations need to remain identifiable and traceable.

Update Assessment

Manufacturers need processes for determining how an update affects approved vehicle characteristics.

Approval Impact

Changes must be assessed to determine whether additional testing, approval extension or other regulatory action is necessary.

Update Integrity

Software-update packages and deployment processes require protection against unauthorized manipulation.

Safe Installation

The vehicle must appropriately manage the installation process and relevant conditions for update execution.

Documentation

Software changes and their relationship with the approved vehicle configuration require controlled records.

Software governance becomes part of homologation governance. Once software can change an approval-relevant vehicle function, software configuration becomes part of the vehicle’s regulatory identity.
Back to Article Guide
07
SOFTWARE IDENTIFICATION

RxSWIN Connects Software to Type Approval

One of the important concepts introduced through the UN R156 framework is the Regulation Software Identification Number — RxSWIN.

Where applicable, RxSWIN provides a regulatory mechanism for linking software relevant to a particular UN Regulation with the vehicle’s approved configuration.

PHYSICAL IDENTIFICATION Vehicle Type & Components

Traditional homologation identifies physical configurations, systems and components associated with an approval.

DIGITAL IDENTIFICATION Approval-Relevant Software

RxSWIN enables the applicable software configuration to become identifiable within the regulatory framework.

Why is this important?

Two physically identical vehicles can behave differently because they contain different software. Regulatory traceability therefore increasingly needs to identify not only the hardware but also the software governing approved functions.

Back to Article Guide
08
OVER-THE-AIR UPDATES

The Vehicle Can Change After It Leaves the Factory

Over-the-air updating allows manufacturers to modify vehicle software remotely without requiring every vehicle to visit a workshop.

The benefits are substantial. Manufacturers can correct faults, improve functionality, address cybersecurity vulnerabilities and deploy new capabilities across vehicle fleets.

But the same capability creates an unprecedented homologation question: what happens when an already-approved vehicle changes after it has entered service?

Before Update

Determine the existing vehicle configuration and applicable regulatory approvals.

Impact Assessment

Evaluate whether the proposed update changes approval-relevant characteristics.

Validation

Verify that the modified software behaves as intended and continues to satisfy applicable requirements.

Deployment

Deliver the update through controlled and protected mechanisms.

Installation

Ensure the vehicle can safely complete or appropriately manage the update process.

Post-Update Traceability

Maintain evidence of the resulting software and regulatory configuration.

The production line is no longer the final point at which the vehicle is configured. OTA capability effectively extends part of the manufacturer’s configuration-management environment into the vehicle’s service life.
Back to Article Guide
09
R155 + R156

Cybersecurity and Software Updates Cannot Be Managed Separately

UN R155 and UN R156 address different regulatory objectives, but operationally they are closely connected.

UN R155 Manage Cybersecurity Risk

Identify threats and vulnerabilities, implement appropriate mitigation and continue monitoring cybersecurity throughout the relevant vehicle lifecycle.

UN R156 Manage Software Change

Control, assess, document and deploy software updates while maintaining the vehicle’s applicable regulatory conformity.

The connection becomes especially clear when a cybersecurity vulnerability is discovered after vehicles have entered service.

01 Vulnerability Identified
02 Cyber Risk Assessed
03 Software Fix Developed
04 Approval Impact Evaluated
05 Update Validated
06 Update Deployed
R155 identifies the need to manage the cyber risk. R156 helps govern the software change used to address it. Together they form an important regulatory foundation for maintaining digitally evolving vehicles after type approval.
Back to Article Guide
10
SUPPLY-CHAIN CONTROL

The OEM Cannot Secure the Vehicle Alone

Modern vehicle software and electronic architectures depend on extensive supplier ecosystems. OEMs may integrate hardware, embedded software, operating systems, connectivity modules, cloud infrastructure and third-party services originating from many organizations.

Supplier Requirements

Cybersecurity and software-management expectations need to be incorporated into supplier relationships.

Evidence Exchange

OEMs need appropriate technical evidence from suppliers to support vehicle-level cybersecurity assessment.

Change Notification

Supplier software and component changes need controlled communication where they can affect vehicle conformity.

Vulnerability Response

Newly identified vulnerabilities may require coordinated investigation and mitigation across multiple organizations.

Cybersecurity responsibility cannot simply be outsourced.

The vehicle manufacturer remains dependent on evidence and cooperation from its supply chain while maintaining responsibility for demonstrating conformity of the vehicle type.

Back to Article Guide
11
REGULATORY EVOLUTION

UN R155 and R156 Are Continuing to Evolve

Cybersecurity and software regulation cannot remain static because the technologies and risks they govern are themselves changing.

UNECE’s Working Party on Automated/Autonomous and Connected Vehicles — GRVA — and its specialist cybersecurity and software-update activities continue to develop the regulatory framework.

R156 — 01 Series

UN R156 has progressed to a new 01 series of amendments, reflecting continued development of the software-update regulatory framework.

Interpretation Guidance

The R156 interpretation document continues to be developed to support consistent application of software-update and SUMS requirements.

R155 Development

Further proposals concerning UN R155 and its cybersecurity-management framework remain under active UNECE consideration.

Cross-Regulation Integration

Cybersecurity and software-update provisions increasingly interact with other regulations governing electronically controlled vehicle functions.

The direction is toward deeper integration. Cybersecurity and software-update governance are progressively becoming horizontal requirements that interact with braking, steering, ADAS, automated driving and other software-controlled vehicle systems.
Back to Article Guide
12
MANUFACTURER READINESS

Building Continuous Digital Conformity

R155 and R156 require manufacturers to think beyond individual approval tests and establish repeatable systems capable of supporting compliance throughout the vehicle lifecycle.

01 — Establish CSMS

Build cybersecurity governance covering development, production, monitoring, incident response and relevant supply-chain activities.

02 — Establish SUMS

Implement controlled processes for software identification, update assessment, validation, deployment and regulatory traceability.

03 — Map Vehicle Architecture

Understand electronic systems, interfaces, data flows, software dependencies and potential attack surfaces.

04 — Integrate Suppliers

Establish evidence, communication and change-control mechanisms across the software and component supply chain.

05 — Link Software to Approval

Maintain traceability between software configurations and the regulations affected by those configurations.

06 — Monitor the Fleet

Maintain the ability to identify emerging cybersecurity issues and respond appropriately after vehicles enter service.

The objective is not simply to obtain a CSMS or SUMS certificate.

The real objective is to create an operating system of governance capable of supporting secure, controlled and demonstrably compliant vehicles as software and cyber risks evolve.

Back to Article Guide

From Type Approval to Continuous Digital Conformity

UN R155 and UN R156 represent more than two additional requirements in the vehicle homologation portfolio.

They reflect a structural change in the relationship between vehicle engineering and regulatory conformity.

Cybersecurity threats can emerge after production. Software can change vehicle behaviour after approval. Vulnerabilities can originate within the vehicle, the supply chain or connected infrastructure. Regulatory evidence therefore has to extend beyond the traditional moment of type approval.

TRADITIONAL HOMOLOGATION Design → Test → Approve → Produce

Compliance is concentrated around a relatively stable vehicle configuration.

DIGITAL HOMOLOGATION Design → Assess → Approve → Monitor → Update → Reassess

Cybersecurity and software governance extend conformity into the operational life of the vehicle.

The regulatory perimeter of the vehicle is expanding. Software, cybersecurity processes, supplier relationships, backend systems and post-production updates increasingly become part of the evidence needed to maintain confidence in vehicle conformity.
The connected vehicle does not stop evolving when it leaves the factory. Its conformity framework cannot stop there either.
Regulatory context: Cybersecurity and software-update requirements depend on vehicle category, target market, applicable UN Regulation series and the regulations affected by individual software configurations or updates. UN Regulations No. 155 and No. 156 and their interpretation documents continue to evolve through UNECE WP.29 and GRVA activities. Manufacturers should therefore confirm the currently applicable regulatory text, series of amendments, implementation provisions and approval requirements for the specific vehicle programme before commencing certification or homologation activities.
GLOBAL ALLIANCE REGISTER

How Global Alliance Register Can Support You

Global Alliance Register supports manufacturers, suppliers and responsible economic operators with independent technical-assurance services relevant to un r155 & r156 within the automotive context. Based on the article's emphasis on technical assurance, verification and risk management, GAR can coordinate competent specialists, laboratories, inspectors, auditors and accredited conformity-assessment resources as appropriate to the actual technical need. Within the context of this article, Global Alliance Register can support you in the following areas:

01

Identify the changes affecting un r155 & r156, perform a structured impact assessment and develop a transition plan covering responsibilities, timing, documentation and implementation evidence.

02

Define the technical, regulatory, quality and risk objectives for un r155 & r156 and determine which combination of testing, inspection, certification, audit or advisory services is appropriate.

03

Coordinate competent laboratories, inspectors, auditors, certification bodies and specialist technical resources for un r155 & r156 according to scope, geography and the required level of independence.

04

Integrate test results, inspection reports, audit evidence and certification outcomes relating to un r155 & r156 into a coherent assurance process with clear responsibilities and traceability.

05

Review test records, inspection evidence, calculations, reports and other technical documentation relating to un r155 & r156 for completeness, consistency and traceability.

Scroll to Top