Real-world car advice, without the sales pitch Start Here About Trust Newsletter
Vehicle Cybersecurity: The New Regulatory Baseline

Vehicle Cybersecurity: The New Regulatory Baseline

Connected, software-defined cars now face a real attack surface — and international regulation has moved from guidance to hard requirements for new vehicle type approval.

News & Trends Region: Global Updated July 2026 By the True Motion Auto editorial team
Quick answer

Since 2024, UNECE regulations R155 (cybersecurity management) and R156 (software update management) have been mandatory for all new vehicle type approvals across the roughly 60 countries that follow UN vehicle regulations, including the EU, UK, Japan, and South Korea — meaning automakers must run a certified cybersecurity management system across a vehicle's full lifecycle, not just at launch. The US has no direct federal equivalent, relying instead on industry standards like ISO/SAE 21434 and NHTSA guidance rather than a binding regulation, which means requirements can differ meaningfully depending on where a vehicle is type-approved and sold.

At a glance

Regulation/standardWhat it coversWhere it applies
UNECE R155Cybersecurity management system across the vehicle lifecycleMandatory for new type approvals in ~60 UN-regulation countries since 2024
UNECE R156Software update management, including OTA update processesSame coverage as R155, run alongside it
ISO/SAE 21434Technical engineering standard for automotive cybersecurity risk managementGlobal industry standard, referenced to demonstrate R155 compliance
US federal approachNo single binding vehicle-cybersecurity regulationNHTSA guidance and industry self-regulation via ISO/SAE 21434

Why cars needed cybersecurity regulation at all

A modern vehicle is a network of connected computers — dozens of control units, often an embedded cellular modem, Bluetooth, Wi-Fi, and increasingly cloud-connected services — which means it carries a genuine digital attack surface that a purely mechanical car never had. Security researchers have previously demonstrated remote exploits that could affect steering, braking, or other safety systems in controlled test conditions, which pushed regulators to treat vehicle cybersecurity as a safety issue rather than purely an IT concern.

What R155 and R156 actually require

R155 requires automakers to operate a certified Cybersecurity Management System covering the entire vehicle lifecycle — design, production, and post-sale — including risk assessment, incident monitoring, and a process for responding to newly discovered vulnerabilities even after the vehicle has shipped. R156 covers the software update process itself, requiring a Software Update Management System that ensures updates (especially OTA updates) are delivered securely, don't compromise safety-critical functions, and are properly documented and auditable. Together, they mean an automaker can't simply build in cybersecurity once at launch and walk away — ongoing monitoring and response capability is now a condition of type approval in markets that follow these regulations.

Where this applies, and where it doesn't

Because R155/R156 are UNECE regulations, they bind the roughly 60 countries that are contracting parties to the relevant UN vehicle-regulation agreement, including the EU, UK, Japan, South Korea, and others — a vehicle can't get new type approval in these markets without meeting them. The US is not a party to this specific UN framework and has no equivalent binding federal cybersecurity regulation for vehicles; automakers selling in both markets typically apply the same engineering standard (ISO/SAE 21434) globally for consistency, even though it's only a strict legal requirement in the UNECE markets.

MarketLegal cybersecurity requirement
EU, UK, Japan, South Korea (UNECE markets)R155/R156 mandatory for new type approval since 2024
United StatesNo single binding federal regulation; relies on standards and guidance
Watch out

A vehicle sold in both a UNECE market and the US isn't necessarily held to different real-world security engineering. Most global automakers apply the same ISO/SAE 21434-based process everywhere, even though it's legally mandatory in only some markets.

Where this is headed

Expect continued expansion of formal cybersecurity requirements as vehicles become more software-defined and OTA-dependent, growing pressure for a US federal equivalent as connected and automated vehicle features scale, and continued reliance on ISO/SAE 21434 as the practical global engineering baseline regardless of which specific regulation a given market enforces.

Frequently asked questions

What are UNECE R155 and R156?
R155 requires automakers to run a certified cybersecurity management system across a vehicle's lifecycle; R156 requires a certified process for managing software updates, including OTA updates. Both have been mandatory for new type approvals in UN-regulation markets since 2024.
Does the US require the same vehicle cybersecurity regulation?
No — the US has no single binding federal vehicle-cybersecurity regulation equivalent to R155/R156, relying instead on NHTSA guidance and industry standards like ISO/SAE 21434.
What is ISO/SAE 21434?
It's the global technical engineering standard for automotive cybersecurity risk management, widely used by automakers worldwide to demonstrate compliance with regulations like R155.
Can a car be hacked remotely?
Security researchers have previously demonstrated remote vulnerabilities in controlled test conditions, which is part of why regulators now require ongoing cybersecurity monitoring and response processes, not just launch-time security.
Does vehicle cybersecurity regulation cover OTA updates specifically?
Yes — UNECE R156 specifically covers software update management, requiring that OTA and other update processes are secure, documented, and don't compromise safety-critical systems.

Sources & further reading

Figures, prices and policy details were current at the last-updated date above. Automotive pricing, incentives and regulations change frequently — verify time-sensitive details with the linked primary sources. Read our editorial policy and fact-checking standards.