A vehicle sold globally in 2026 must satisfy cybersecurity rules written in Geneva, Beijing, Brussels, and Washington. The four regimes share vocabulary but not legal text, and treating them as one compliance program is a common, costly assumption. This article maps where they align, where they diverge, and what to do about it.
Figure 1. Four regimes, one set of underlying artifacts and practices.
The Shared Backbone: UN R155 and R156
UN Regulation No. 155 requires a certified Cyber Security Management System (CSMS) covering the vehicle lifecycle, plus a documented threat analysis and risk assessment for each vehicle type. UN R156 adds a Software Update Management System (SUMS) for over-the-air and workshop updates.
Both were developed under UNECE's WP.29 forum. In the EU, they have applied to new vehicle types since July 2022 and to newly registered vehicles within scope since July 2024. Japan, the UK, and other UNECE 1958 Agreement contracting parties have incorporated or may apply UN R155/R156 through their national type-approval frameworks, with scope and implementation varying by jurisdiction. Japan incorporated the requirements into its domestic type-approval system rather than issuing a separate national standard.
Outside China and the United States, R155/R156 is an important reference baseline, while market-specific applicability must be confirmed. ISO/SAE 21434 is the engineering standard most teams use to support compliance with R155/R156.
China: A Parallel, Not an Adoption
China did not adopt the UN text. GB 44495-2024 covers vehicle cybersecurity and management-system requirements; GB 44496-2024 covers software-update-management requirements; and GB 44497-2024 covers cybersecurity and data-security requirements for automated-driving data recording.
The three standards apply to new vehicle type approvals from January 1, 2026. The transition date for existing, in-production models requires confirmation against the applicable Chinese implementation provisions; secondary sources cite later dates, including 2027 and 2028. A manufacturer selling in both markets runs two independent compliance programs, not one CSMS that satisfies both by reference.
GB 44495 and GB 44496 closely mirror the R155/R156 structure, but they are fully independent mandatory Chinese national standards. GB 44497 is a different category: it concerns cybersecurity and data-security requirements for automated-driving data recording, sometimes referred to as DSSAD. It is neither a CSMS nor SUMS equivalent, and it has no direct UN R155/R156 counterpart.
EU Cyber Resilience Act
The Cyber Resilience Act (Regulation (EU) 2024/2847) is horizontal legislation for products with digital elements. Its Article 2(2)(c) exclusion covers products already governed by Regulation (EU) 2019/2144, the EU type-approval regulation under which R155/R156 operate. The exclusion is not simply for "R155-approved vehicles" as a category.
Connected components, aftermarket devices, standalone software, and other products outside Regulation (EU) 2019/2144's scope can still fall under the CRA. For each automotive product, applicability should be assessed under CRA Article 2 and the relevant sectoral type-approval legislation.
The obligations arrive in stages. Since September 11, 2026, manufacturers in scope must report actively exploited vulnerabilities and severe incidents. This includes an early warning within 24 hours, a fuller notification within 72 hours, and a final report within the required statutory timeframe. Full application follows on December 11, 2027. For a telematics unit or an aftermarket dongle, scope under Article 2—not compliance effort—is the first question.
The US: Supply Chain as Security Policy
The U.S. Commerce Department's Connected Vehicles Rule is a national-security measure, not a technical cybersecurity standard. It restricts specified transactions involving covered Vehicle Connectivity System software, covered VCS hardware, and certain connected-vehicle manufacturers with a China or Russia nexus.
The software-related restrictions begin with Model Year 2027. Covered VCS-hardware restrictions begin with Model Year 2030, or January 1, 2029 for hardware not associated with a model year. The rule applies to connected passenger vehicles under 10,001 pounds.
Manufacturers and relevant VCS-hardware importers file annual Declarations of Conformity and must retain records demonstrating compliance, including supply-chain due-diligence documentation, for ten years. Software and hardware bills of materials may be important supporting evidence, but they are not routinely submitted with the declaration.
The rule can affect globally assembled vehicles sold or imported into the United States. A vehicle assembled in Europe or Mexico may still be covered if its VCS hardware or covered software has the relevant China or Russia nexus.
Alongside it, NHTSA's non-binding 2022 cybersecurity best practices remain federal technical guidance, and SEC rules require public companies to disclose material cybersecurity incidents within four business days. Proposals in Congress could extend comparable restrictions to commercial vehicles; their status and final scope should be confirmed before relying on them as a compliance requirement.
SBOM: The Common Thread
Software bills of materials are where the regimes converge. CISA published updated 2026 Minimum Elements for a Software Bill of Materials in July 2026. The update adds fields and practices intended to improve traceability, integrity, and automated exchange, including SBOM author signature, data-format name and version, generation context, tool details, and component hashes.
The CRA requires manufacturers of in-scope products to identify and document components, including by drawing up an SBOM in a commonly used, machine-readable format covering at least top-level dependencies. The BIS rule requires retention of compliance and due-diligence records for ten years; SBOMs and hardware inventories may be important evidence supporting that recordkeeping.
Auto-ISAC guidance addresses the multi-tier automotive supply chain specifically. Open implementation questions include exchange format, such as SPDX or CycloneDX, and whether one governed SBOM dataset can meet each regime's differing scope, content, retention, and disclosure expectations without jurisdiction-specific tailoring.
Figure 2. Compliance milestones across the four regimes. Note: the China transition marker for existing vehicle types is based on secondary sources and should be verified against the applicable official Chinese implementation provisions before citation.
What Teams Should Do Now
- Build one engineering backbone. Base the TARA and CSMS on ISO/SAE 21434 and R155, then map GB 44495 as a jurisdiction-specific delta while maintaining the evidence needed for an independent Chinese compliance assessment.
- Generate SBOMs to CISA's 2026 minimum elements, then test them against CRA requirements before fixing a format.
- Check CRA scope under Article 2 for every connected, standalone, or aftermarket product, especially telematics units, dongles, and separately marketed software.
- Audit the supply chain for a China or Russia nexus ahead of Model Year 2027 and prepare the records necessary to support the BIS Declaration of Conformity.
- Watch GB 44497. No direct international counterpart exists yet, but automated-driving data-recording and data-security mandates may spread.
The Takeaway
None of these regimes is going away, and they are converging on shared artifacts: threat analysis, software inventories and SBOMs, update-management evidence, vulnerability handling, and incident response. Teams that design those artifacts once, then map and govern them per jurisdiction, will spend less and respond faster than teams that treat each regime as a separate project.
The important qualification is that reusable engineering artifacts do not automatically create reusable legal compliance. Scope assessments, approvals, declarations, reporting channels, supplier evidence, and market-specific documentation still require jurisdiction-specific treatment.
Sources
- UNECE, Vehicle Regulations Hub—UN R155 and R156
- EUR-Lex, UN Regulation No. 155—Cyber Security and Cyber Security Management System
- UK Vehicle Certification Agency, Cyber Security and Software Updating
- EUR-Lex, Regulation (EU) 2024/2847—Cyber Resilience Act
- European Commission, Cyber Resilience Act: Reporting Obligations
- CISA, 2026 Minimum Elements for a Software Bill of Materials
- U.S. Department of Commerce, Bureau of Industry and Security—Connected Vehicles
- U.S. Federal Register, Securing the ICTS Supply Chain: Connected Vehicles
- NHTSA cybersecurity best practices, Docket NHTSA-2020-0087
- ISO/SAE 21434:2021, Road vehicles—Cybersecurity engineering
- Auto-ISAC
- Official Chinese standards publications and implementation notices for GB 44495-2024, GB 44496-2024, and GB 44497-2024