UN R155 Copilot
Specialist AI assistant for UN R155 vehicle cybersecurity and CSMS approval
A valid CSMS certificate is a precondition for EU vehicle type approvals in UN R155's scope. Map your R155 process gaps before the next assessment.
What the UN R155 Copilot Can Do
CSMS process documentation across development, production, and post-production phases
Risk identification and treatment drafts structured around the Annex 5 threat categories
Monitoring and incident-response process support for vehicles in service
Supplier and service-provider dependency management documentation (CSMS 7.2.2.5)
Evidence preparation for the CSMS Certificate of Compliance assessment and three-year renewal
Cross-mapping between UN R155 process requirements and ISO/SAE 21434 engineering work
About UN R155 Copilot
UN R155 Copilot helps vehicle manufacturers and suppliers prepare CSMS certification and vehicle type approval under the UNECE regulation on vehicle cybersecurity, with specialist AI guidance on risk management, monitoring, and approval evidence.
CSMS Certificate of Compliance (organisation level)
Assessed and issued by an approval authority, covering the manufacturer's processes across development, production, and post-production
Valid for a maximum of three years, renewable after re-assessment
Can be withdrawn if the requirements are no longer met
Vehicle type approval (per vehicle type)
Requires a valid CSMS certificate for the vehicle type being approved
Demonstrates that cyber risks for the type are identified, treated, and monitored
In the EU, authorities refuse approval or registration for non-compliant vehicles at the Regulation (EU) 2019/2144 Annex II dates
Who it's for
TISAX
TISAX is the industry assessment scheme for organizational information security of automotive suppliers; UN R155 requires a manufacturer CSMS for vehicle type approval. The scopes differ and neither replaces the other.
ISO 27001
As practical guidance: an existing ISMS can provide a starting point for the management-system documentation R155 CSMS evidence builds on.
Cross-framework mappings
Working across UN R155 and another standard? ISMS Mappings is a free public directory of control maps (ISO 27001, SOC 2, NIST, GDPR, and more). A Better ISMS tool, separate from the chat assistant.
Browse free mappingsFrequently Asked Questions
What is UN R155?
UN Regulation No. 155 is the UNECE vehicle cybersecurity regulation requiring manufacturers to operate a certified Cybersecurity Management System (CSMS) before vehicle types can be approved. It entered into force on 22 January 2021, and the version in force since 10 January 2025 (incorporating Supplement 3) applies to vehicles of categories L, M, N and O that carry at least one electronic control unit. In the EU it is mandatory under Regulation (EU) 2019/2144.
Who needs to comply?
Vehicle manufacturers selling in markets that apply UN R155. In the EU, authorities must refuse type approval for non-compliant new category M and N vehicle types since 6 July 2022 and must refuse registration of non-compliant new category M and N vehicles since 7 July 2024. A valid CSMS certificate (maximum three years, renewable) is a precondition for vehicle type approval; for approvals issued before specific cut-off dates, transitional provisions allow alternative evidence of development-phase cybersecurity.
How does the Copilot help with UN R155?
It turns the regulation's CSMS process requirements into concrete documentation: risk identification against the Annex 5 threat categories, risk treatment records, monitoring and incident-response processes for vehicles in service, and supplier dependency management, prepared as approval evidence.
Do I need ISO/SAE 21434 as well?
UN R155 does not mandate a specific engineering standard. ISO/SAE 21434 is a recognized engineering standard that can support the design and evidence of CSMS process requirements. The Copilot helps you connect your 21434 workstreams to the R155 approval evidence an approval authority expects.
Ready to do compliance work faster?
Built for speed, accuracy, and audit-ready output.
