What is UN R155?

UN Regulation No. 155 (UN R155) is a United Nations Economic Commission for Europe (UNECE) regulation that establishes mandatory cybersecurity requirements for vehicle type approval. It requires automotive manufacturers to implement a cybersecurity management system (CSMS) that manages cyber risks throughout the vehicle lifecycle.

Why does UN R155 matter?

Connected, software-defined vehicles have dramatically expanded the automotive attack surface. UN R155 provides a structured regulatory framework for managing cybersecurity risk and demonstrating due diligence across vehicle development, production, and post-production operations.

What does UN R155 require?

Manufacturers must demonstrate the ability to:

  • Operate a certified CSMS
  • Identify and assess cybersecurity risks
  • Implement appropriate security controls
  • Validate cybersecurity before production
  • Monitor vulnerabilities throughout the vehicle lifecycle
  • Respond to cybersecurity incidents

How UN R155 works

UN R155 focuses on cybersecurity processes, governance, and evidence rather than prescribing specific technologies. Organizations must demonstrate that cybersecurity is integrated into engineering, supported by documented processes, and continuously managed.

UN R155 and ISO/SAE 21434

UN R155 defines regulatory obligations, while ISO/SAE 21434 provides the engineering processes many organizations use to satisfy those obligations. Together they form the foundation of modern automotive cybersecurity.

UN R155 and semiconductor security

Because semiconductors underpin modern vehicle electronics, hardware-level cybersecurity verification has become increasingly important. Demonstrating that silicon security requirements have been implemented and verified supports broader compliance activities.

Arteris, Cycuity, and hardware security assurance

Through Cycuity technology, Arteris helps engineering teams improve hardware security assurance by increasing visibility into security requirements, verification coverage, and security evidence. This strengthens cybersecurity risk management while supporting compliance initiatives without replacing existing engineering workflows.

Benefits of UN R155

  • Improved cybersecurity governance
  • Reduced cybersecurity risk
  • Greater supply chain accountability
  • Better lifecycle vulnerability management
  • More complete compliance evidence
  • Support for secure software-defined vehicles

Common use cases

  • Automotive semiconductor development
  • Vehicle OEM cybersecurity programs
  • Tier 1 supplier development
  • ADAS and autonomous systems
  • Connected vehicle platforms
  • Automotive compliance programs

Frequently asked questions

What is UN R155?

A UNECE regulation establishing cybersecurity requirements for vehicle type approval.

Is UN R155 mandatory?

Yes, for new vehicle type approvals in many markets adopting UNECE regulations.

How is UN R155 different from ISO/SAE 21434?

UN R155 is a regulation; ISO/SAE 21434 is an engineering standard commonly used to achieve compliance.

Who is affected by UN R155?

Vehicle manufacturers are directly responsible, while suppliers contribute cybersecurity evidence and assurance.

How does hardware security assurance help?

Hardware security verification is a vital step in the hardware development process and is performed to identify and mitigate potentially exploitable hardware security weaknesses. The results of hardware security verification provide objective evidence that hardware security requirements have been verified and implemented as intended.