UNECE WP.29 R155
UN Regulation on Cybersecurity for vehicles
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (18)
Assurance
| Code | Title |
|---|---|
| R155-VTA-ASSURANCE | Independent assurance and approval authority interaction |
CSMS governance
| Code | Title |
|---|---|
| R155-CSMS-GOV | Cyber Security Management System governance |
Change management
| Code | Title |
|---|---|
| R155-CSMS-CHANGE | Change management for vehicle types and CSMS |
Incident management
| Code | Title |
|---|---|
| R155-CSMS-INCIDENT | Incident response and reporting to approval authority |
People
| Code | Title |
|---|---|
| R155-CSMS-COMP | Competence and training of personnel |
Post-production
| Code | Title |
|---|---|
| R155-VTA-POSTPROD | Post-production cybersecurity management |
Risk management
| Code | Title |
|---|---|
| R155-CSMS-RISK | Risk identification, assessment, treatment |
Supply chain
| Code | Title |
|---|---|
| R155-CSMS-CONTRACTING | Outsourced processes and joint development |
| R155-CSMS-SUPPLIER | Management of supplier-related cybersecurity |
Threat coverage
| Code | Title |
|---|---|
| R155-ANNEX5-BACKEND | Threats regarding back-end servers |
| R155-ANNEX5-DATA | Threats to vehicle data and code |
| R155-ANNEX5-EXT | Threats to external connectivity and connections |
| R155-ANNEX5-UPDATE | Threats to the update process |
Threat intelligence
| Code | Title |
|---|---|
| R155-CSMS-MONITOR | Monitoring of cyber threats, vulnerabilities, and attacks |
UNECE WP.29 R155: Access Control
Logical and physical access controls (UNECE WP.29 R155)
| Code | Title |
|---|---|
| WP29-R155-11 | Access control policy and enforcement |
| WP29-R155-12 | User access management and provisioning |
| WP29-R155-13 | Authentication and password management |
| WP29-R155-14 | Privileged access management |
| WP29-R155-15 | Access review and recertification |
UNECE WP.29 R155: Asset Management
Information asset management (UNECE WP.29 R155)
| Code | Title |
|---|---|
| WP29-R155-06 | Asset inventory and ownership |
| WP29-R155-07 | Acceptable use of assets |
| WP29-R155-08 | Information classification and labeling |
| WP29-R155-09 | Asset handling procedures |
| WP29-R155-10 | Media management and disposal |
UNECE WP.29 R155: Communications Security
Network and communications security (UNECE WP.29 R155)
| Code | Title |
|---|---|
| WP29-R155-27 | Network security management |
| WP29-R155-28 | Network service security |
| WP29-R155-29 | Segregation in networks |
| WP29-R155-30 | Information transfer policies |
| WP29-R155-31 | Secure messaging |
UNECE WP.29 R155: Cryptography
Cryptographic controls (UNECE WP.29 R155)
| Code | Title |
|---|---|
| WP29-R155-16 | Cryptographic policy and key management |
| WP29-R155-17 | Encryption of data at rest |
| WP29-R155-18 | Encryption of data in transit |
| WP29-R155-19 | Certificate management |
| WP29-R155-20 | Key lifecycle management |
UNECE WP.29 R155: Information Security Policies
Organizational information security policies (UNECE WP.29 R155)
| Code | Title |
|---|---|
| WP29-R155-01 | Information security policy framework |
| WP29-R155-02 | Management direction and commitment |
| WP29-R155-03 | Policy review and update procedures |
| WP29-R155-04 | Roles and responsibilities definition |
| WP29-R155-05 | Contact with authorities and special interest groups |
UNECE WP.29 R155: Operations Security
Secure operations and monitoring (UNECE WP.29 R155)
| Code | Title |
|---|---|
| WP29-R155-21 | Operational procedures and responsibilities |
| WP29-R155-22 | Protection from malware |
| WP29-R155-23 | Backup and recovery procedures |
| WP29-R155-24 | Logging and monitoring |
| WP29-R155-25 | Technical vulnerability management |
| WP29-R155-26 | Audit considerations |
Vehicle type approval
| Code | Title |
|---|---|
| R155-VTA-MITIGATIONS | Implementation of proportionate mitigations |
| R155-VTA-RISK | Vehicle type cybersecurity risk identification |
Verification and validation
| Code | Title |
|---|---|
| R155-VTA-TEST | Testing the cybersecurity of the vehicle type |
Your Compliance Coverage
If you comply with UNECE WP.29 R155, you already cover:
ISO/SAE 21434
35%
17 controls mapped
Compare →PTES
35%
17 controls mapped
Compare →OWASP ASVS
35%
17 controls mapped
Compare →+ 282 more: NIST SP 800-61 (35%), OWASP SAMM (35%)
See all 285 mapped frameworks ↓Maps to 285 other frameworks
Frequently Asked Questions
What is UNECE WP.29 R155?
UNECE WP.29 R155 is a compliance framework from International with 18 domains and 48 controls. UN Regulation on Cybersecurity for vehicles It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does UNECE WP.29 R155 have?
UNECE WP.29 R155 has 48 controls organised across 18 domains. The largest domains are UNECE WP.29 R155: Operations Security (6 controls), UNECE WP.29 R155: Access Control (5 controls), UNECE WP.29 R155: Asset Management (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does UNECE WP.29 R155 map to?
UNECE WP.29 R155 maps to 285 other compliance frameworks. The top mapping partners are ISO/SAE 21434 (35% coverage), PTES (35% coverage), OWASP ASVS (35% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with UNECE WP.29 R155 compliance?
Start your UNECE WP.29 R155 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about UNECE WP.29 R155 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 48 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 701 frameworks.
Get Started Free →Free forever — no credit card required