COMPARISON · Standards
UN R155 vs ISO/SAE 21434
One is law in the markets that adopt it; the other is engineering method. Programmes that treat them as interchangeable usually discover the gap at the audit.
LAST REVIEWED
The essential difference
UN Regulation No. 155 obliges vehicle manufacturers in adopting markets to demonstrate, to an approval authority, that they operate a cybersecurity management system and that the vehicle type has been risk-assessed and protected accordingly. ISO/SAE 21434 tells engineering organisations how to do cybersecurity engineering: how to structure the lifecycle, how to run a threat analysis and risk assessment, and what to trace to what. The regulation defines an obligation and an approval route; the standard defines a method.
| Dimension | UN Regulation No. 155 | ISO/SAE 21434 |
|---|---|---|
| Legal status | Binding in adopting markets | Voluntary standard |
| Applies to | Vehicle type approval | Road vehicle E/E systems and the organisations engineering them |
| Central requirement | A certified cybersecurity management system | Cybersecurity engineering lifecycle with TARA |
| Assessed by | Approval authority or technical service | Internal or independent assessment; no approval issued |
| Outcome | Certificate of compliance, then type approval | Demonstrable process conformity and engineering evidence |
| Coverage of updates | Complemented by UN R156 for software updates | Addresses change and post-production lifecycle phases |
How they are used together
In practice a manufacturer builds its cybersecurity management system and project processes on ISO/SAE 21434, then presents that system and its operating evidence for UN R155 assessment. This works because the standard's organisational and lifecycle requirements map closely onto what the regulation asks an authority to confirm. It stops working when the standard is applied only at project level: the regulation is satisfied by organisational evidence, and project artefacts alone do not supply it.
Common misreadings
- Assuming ISO/SAE 21434 conformity is itself UN R155 compliance — it is not; only an approval authority grants that.
- Assuming UN R155 prescribes the TARA method — it requires risk management, and the standard supplies the method most manufacturers use.
- Overlooking UN Regulation No. 156, which covers software update management and is a separate approval.
- Treating suppliers as out of scope; assurance has to be flowed down through cybersecurity interface agreements.
Frequently asked questions
Is ISO/SAE 21434 compliance enough for UN R155?
No. ISO/SAE 21434 is a voluntary standard and conformity to it does not grant type approval. It is widely used as the technical basis for demonstrating a compliant cybersecurity management system, but the approval decision rests with an approval authority or its technical service.
Who does UN R155 apply to?
It applies to vehicle manufacturers seeking type approval in markets that adopt the regulation. Suppliers are affected indirectly, because the manufacturer must flow cybersecurity requirements and assurance down the supply chain through interface agreements.
What is UN R156?
UN Regulation No. 156 covers software update processes and requires a software update management system. It is a separate approval from UN R155 and is what makes delivering cybersecurity fixes to type-approved vehicles a governed activity.
Does either instrument replace the Cyber Resilience Act?
No. Vehicles under EU type-approval cybersecurity requirements are excluded from the corresponding CRA obligations, but connected accessories, aftermarket products and standalone software outside type approval can still fall within CRA scope.