UN R155IndustrialGlobalAutomotive

UN Regulation 155 - Cyber Security and Cyber Security Management System

UN regulation requiring cybersecurity management systems for vehicle manufacturers. Mandatory for type approval in UNECE countries including EU, UK, Japan, and Korea.

Get a Gap Assessment
The Mapping

What your auditor cites,
and what produces the evidence

The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.

UN R1557.2.2.2(g)Spotting the abnormal

Forensic Capability

Manufacturers MUST have capability to analyze attempted or successful cyber attacks with data collection.

Rules catch what you already thought of. Behavioural models baseline every user and application against their own history and their peer group, then score deviations in real time — so a service account reading tables it has never touched surfaces without anyone having written a rule for it first. That is what makes monitoring hold up as access patterns change, instead of decaying into a ruleset nobody maintains.

UN R1557.2.2.2(h)A record of access

Logging Requirements

REQUIRES audit logs for Over-the-Air (OTA) update databases and vehicle telemetry.

A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.

UN R1557.2.2.5Routing and evidencing the response

Incident Response

Organizations MUST detect and respond to cyber attacks with evidence preservation.

Findings route by severity to Slack, Teams, email, PagerDuty, or your SIEM, and escalate automatically when nobody acknowledges them and again when nobody resolves them. Every alert arrives with the query, the identity, and the data classification already attached, so the response starts with context rather than with an investigation. The acknowledge-to-resolve history is retained, which is what evidences that the procedure was followed. Your ticketing system stays where it is — what this produces is a finding worth opening a ticket for.

UN R155Annex 5 Part CRetention and availability

Data Retention

Forensic data MUST be retained for 10 years to support post-incident analysis.

Retention obligations are easy to state and expensive to meet, because the cost is in keeping the record queryable rather than merely stored. Audit events land in columnar storage on immutable object storage, so a multi-year window costs object-storage prices and is still searchable in seconds when an examiner asks for a sample. Each record carries a verification hash, so what you produce years later is demonstrably what was written at the time.

What UN R155 covers

This instrument defines no data category of its own. Governs the cyber security management SYSTEM and the vehicle type. Annex 5 lists threats and mitigations rather than data classes.

How UN R155 is enforced

Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by National type approval authorities across the contracting parties.

R155 turns cybersecurity into a market access condition rather than a compliance obligation. A manufacturer must hold a Cyber Security Management System certificate before a vehicle type can be approved, and since July 2024 the requirement extends to all new vehicles sold in the European Union, including types approved before 2022 that remain in production.

The consequence is binary and commercial. There is no partial-compliance position that still lets you sell.

Uncapped exposure that sits outside this instrument

These come from company law rather than from UN R155, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.

Duty of oversight

Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.

Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.

Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.

This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.

In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).

Enforcement data reviewed August 2026. Several figures are indexed annually and move.

Ships With It

Built for UN R155,
not configured for it afterwards

Policy Template

Automotive CSMS Monitoring

Track OTA updates, telematics, and vehicle diagnostic data

Report

UN R155 Compliance Report

10-year forensic retention for type approval

Classification

Automotive Data Patterns

Identify VIN, ECU data, and vehicle telemetry

Alert

Vehicle Cyber Attack Detection

Alert on attempted or successful vehicle cyber attacks

Walk into the UN R155 audit knowing the answer

228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.

Get a Gap Assessment