INDUSTRY · Automotive
Automotive: functional safety, cybersecurity and type approval
The vehicle itself has its own dedicated regulatory stack; CRA relevance in automotive concentrates on non-type-approved connected accessories and aftermarket products.
LAST REVIEWED
Regulatory picture
Vehicle functional safety is governed by ISO 26262, which uses Automotive Safety Integrity Levels (ASIL) derived from severity, exposure and controllability. Automotive cybersecurity engineering is governed by ISO/SAE 21434, closely linked to UN Regulation No. 155, which requires vehicle manufacturers seeking type approval to operate a Cybersecurity Management System (CSMS) covering the vehicle lifecycle. UN Regulation No. 156 sets equivalent requirements for a Software Update Management System (SUMS). The CRA excludes products already covered by these type-approval frameworks where the exclusion criteria are met, meaning the vehicle itself sits largely outside CRA scope, while connected products sold separately from the type-approved vehicle — aftermarket telematics units, connected dashcams, diagnostic dongles — generally fall within CRA scope as ordinary products with digital elements.
Typical engineering challenges
- Coordinating ASIL-driven safety analysis with ISO/SAE 21434 threat analysis and risk assessment (TARA) where a security compromise could affect a safety-related function.
- Extending supplier assurance requirements through multi-tier automotive supply chains, where Tier 2 and Tier 3 suppliers may have limited cybersecurity engineering maturity.
- Meeting UN R155 CSMS audit expectations across the full vehicle lifecycle, including post-production monitoring and incident response, not just development.
- Managing over-the-air software updates under UN R156 while maintaining the safety case validity for any updated safety-related function.
- Distinguishing which connected components are part of the type-approved vehicle system and which are separate products subject to the CRA directly.
How CRA interacts with sector rules
A vehicle manufacturer's core type-approval scope is generally excluded from the CRA, but the same manufacturer's separately sold connected accessories, mobile apps and telematics platforms are not automatically excluded and should be scoped individually. Tier 1 suppliers producing electronic control units integrated into type-approved vehicles typically work to their customer's ISO 26262 and ISO/SAE 21434 requirements contractually, while any variant of their product sold as a standalone aftermarket item takes on direct CRA manufacturer obligations.
What a typical engagement covers
- Integrated safety and TARA process design linking ISO 26262 hazard analysis with ISO/SAE 21434 threat analysis.
- CRA applicability scoping across a manufacturer's or supplier's full product range, separating type-approved vehicle scope from standalone connected products.
- Supplier assurance framework design for multi-tier automotive supply chains.
- Safety case and cybersecurity case structuring for regulatory and customer audit readiness.
Frequently asked questions
Does the CRA apply to cars?
Vehicles covered by type-approval legislation that already addresses cybersecurity, notably UN Regulation No. 155, are generally excluded from the CRA. Products sold separately from the type-approved vehicle, such as aftermarket telematics devices, are not automatically covered by this exclusion and should be assessed individually.
What is the difference between ASIL and the risk ratings used in ISO/SAE 21434?
ASIL is derived from severity, exposure and controllability of a safety hazard under ISO 26262. ISO/SAE 21434 uses impact and attack feasibility ratings within its threat analysis and risk assessment (TARA) method. The two are not directly interchangeable and require separate, coordinated analysis where a security issue could affect a safety function.
What does UN R155 require of a vehicle manufacturer?
UN Regulation No. 155 requires a manufacturer seeking type approval to operate a certified Cybersecurity Management System covering risk identification, mitigation and monitoring across the vehicle's design, production and post-production lifecycle, including supply chain risk management.
Do Tier 1 and Tier 2 suppliers need to comply with the CRA directly?
Where a supplier's component is integrated into a type-approved vehicle and covered by the vehicle manufacturer's UN R155 scope, direct CRA obligations may not apply to that specific use. Where the same or a similar product is sold separately as a standalone product with digital elements, the supplier takes on CRA manufacturer obligations for that product.