Article details
- Category
- Regulation Update
- Published
- Reading time
- 7 min read
- Author
- AutoSec Academy · Compliance Practice
UNECE Regulation No. 155 concerns cybersecurity and the Cyber Security Management System. Regulation No. 156 concerns software updates and the Software Update Management System. Both attach to vehicle type approval in contracting parties to the 1958 Agreement, and both require the manufacturer to hold a valid management system certificate before a vehicle type can be approved.
What each regulation is asking
- R155 asks whether you can identify, assess and manage cyber risk across the vehicle lifecycle, including for vehicles already in service
- R156 asks whether you can deliver a software update without compromising safety, integrity or the validity of the type approval
The distinction matters because the evidence differs. R155 evidence is risk-analytical: threat models, assessments, monitoring and response. R156 evidence is configuration-analytical: which software is on which vehicle, what changed, whether the change affects approved parameters and whether the update can be rolled back.
Practical separation
Keep the processes distinct and the governance shared. One steering function, two evidence trails. The interfaces between them — a security patch is both a risk treatment and a software update — are where you should invest review effort.
Applicability dates and national implementation vary by market and by vehicle category. Confirm current status against the primary regulation text and your type-approval authority rather than relying on a secondary summary, including this one.