UN R155 R156

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

UN R155 / R156 Cluster

UN Regulations 155 and 156. CSMS (Cybersecurity Management System) under R155 and SUMS (Software Update Management System) under R156. Mandatory for vehicle type approval in UNECE contracting parties since 2022. ISO 21434 supports R155 implementation; ISO 24089 supports R156.

Anchors

Provenance

  • UNECE WP.29 — Working Party 29, World Forum for Harmonization of Vehicle Regulations.
  • R155 (Cybersecurity) — adopted 2020; entered into force July 2022 for new vehicle types in some contracting parties.
  • R156 (Software Update Management) — adopted 2020; similar timeline.
  • Mandatory in EU for new vehicle types from 2022, all new vehicles from July 2024.
  • Also adopted by UK, Japan, South Korea, others.

What R155 / R156 establish

R155 — Cybersecurity

Type-approval requirement: vehicle manufacturer must have:

  • CSMS — Cybersecurity Management System covering organizational practices.
  • Cybersecurity engineering for vehicle types.
  • Risk-based approach including threat assessment, risk treatment.
  • Vulnerability management during vehicle service life.
  • Incident response for cybersecurity incidents.
  • Supplier cybersecurity management.

R156 — Software Update Management

Type-approval requirement: vehicle manufacturer must have:

  • SUMS — Software Update Management System.
  • Documented software update processes including authorization, integrity, dependency analysis.
  • Wireless update specifics where applicable (OTA).
  • Vehicle owner information about updates.
  • Update verification and rollback.

How R155 / R156 relate to ISO 21434 / ISO 24089

  • R155 = regulation (mandatory for type approval).
  • ISO 21434 = standard (implementation guidance supporting R155 compliance).
  • R156 = regulation.
  • ISO 24089 = standard supporting R156.

ISO 21434 + ISO 24089 are typical implementation paths for R155 + R156 compliance.

Type approval process

  1. Manufacturer develops CSMS / SUMS.
  2. Type-approval authority assesses CSMS / SUMS at organizational level.
  3. Manufacturer applies for vehicle type approval; demonstrates CSMS / SUMS coverage for the type.
  4. Approval granted; vehicle can be marketed in the contracting party.

Scope

Categories M (passenger), N (commercial), O (trailers) — specific subcategories per R155/R156 scope. Some categories phased in over time.

Mutual recognition

UNECE contracting parties recognize each other's type approvals (1958 Agreement). R155 / R156 compliance for EU type approval typically accepted in other contracting parties.

Why this matters for SRE and AI-agent work

  • Limited direct applicability outside automotive.
  • For automotive client engagements: R155 / R156 vocabulary load-bearing.
  • AI features in vehicles (ADAS, autonomous driving) within R155 cybersecurity scope.
  • OTA update systems within R156 scope.
  • ISO 21434 — implementation standard for R155.
  • TISAX — supplier organization-side InfoSec.
  • ASPICE — automotive software process.

See also

UN R155 R156 Cluster (pillars MOC) · position · anchors · ISO 21434 Cluster