DE|EN Competitive Edge Through Knowledge and Experience
Automotive Cybersecurity Compliance

Automotive Security Standards: regulatory clarity for Europe and the USA

UN R155/R156, ISO/SAE 21434, the EU Cyber Resilience Act, NHTSA Best Practices, the BIS Connected Vehicles Rule and TISAX® compared side by side – thoroughly researched, as of July 2026.

19 standards & regulations analyzed Europe & USA compared directly Legal status as of July 2026 DEKRA-authorized CADIS partner
Context

Two philosophies of vehicle cybersecurity

Europe and the USA take fundamentally different approaches to securing connected vehicles – with direct consequences for manufacturers, suppliers and their supply chains.

Europe: a binding, type-approval-based approach

UNECE/WP.29's UN Regulations R155 (Cybersecurity Management System) and R156 (Software Update Management System) are embedded in type-approval law via EU Regulation 2019/2144 and have been mandatory for all newly produced M/N-category vehicles since July 2024. ISO/SAE 21434 and ISO 24089 provide the technical implementation depth and are therefore de facto mandatory. The EU Cyber Resilience Act exempts type-approved vehicles themselves but covers retrofit components and charging infrastructure. NIS2 and TISAX® add organizational and supply-chain security.

USA: a voluntary approach, complemented by targeted security regulation

NHTSA has published non-binding Cybersecurity Best Practices based on the NIST Cybersecurity Framework since 2016; no type-approval regime comparable to UN R155 exists. In parallel, the US Department of Commerce (BIS) created a binding rule — the "Connected Vehicles Rule" — motivated by national security rather than technical standards, which bans software with a China/Russia nexus from model year 2027 and hardware from model year 2030.

Europe

Standards & regulations in Europe

From the binding UN type-approval regime to the contractual supply-chain requirement TISAX®.

UN R155 – Cybersecurity Management System (CSMS)

binding

A UNECE regulation requiring vehicle manufacturers to operate a certified CSMS across the entire vehicle lifecycle – a precondition for type approval.

Binding since 07/2022 (new types) / 07/2024 (all new vehicles) · Categories M, N (L from 12/2027)

UN R156 – Software Update Management System (SUMS)

binding

Governs the secure management of software updates, including over-the-air (OTA), via cryptographically verified update channels.

Same deadlines as UN R155 · Small-series vehicles from 07/2026

Regulation (EU) 2019/2144 (General Safety Regulation)

binding

Embeds UN R155/R156 into EU type-approval law – without a valid CSMS/SUMS certificate, a vehicle cannot receive type approval in the EU.

Also the legal basis for the CRA's vehicle exemption

ISO/SAE 21434:2021 – Cybersecurity Engineering

de facto binding

Engineering requirements for cybersecurity risk management across the lifecycle (governance, TARA, development, verification) – the key evidence base for UN R155.

Formally voluntary, de facto binding via its reference in UN R155

ISO 24089:2023 – Software Update Engineering

de facto binding

The technical counterpart to ISO/SAE 21434 for software update systems – the reference standard for UN R156.

Formally voluntary, de facto binding via its reference in UN R156

EU Cyber Resilience Act (Regulation (EU) 2024/2847)

binding

A horizontal cybersecurity regulation for products with digital elements. Type-approved vehicles themselves are exempt – retrofit components, charging infrastructure and apps remain in scope.

Reporting duties from approx. 09/2026 · full application from 12/2027

NIS2 Directive (EU) 2022/2555

binding

Requires automotive manufacturers and suppliers, as operators of important/essential entities, to implement risk management, supply-chain security and incident reporting.

Transposed at national level (in Germany: NIS2UmsuCG)

TISAX® / VDA ISA

contractually binding

An information-security assessment for the automotive supply chain based on the VDA ISA catalogue of criteria – a precondition for many OEM supply contracts.

Current catalogue version VDA ISA 6.x · Publisher: ENX Association / VDA
See TISAX® details →

IEC 62443 series (OT security)

voluntary

An OT security standard series for automation and production systems – increasingly required for charging infrastructure and vehicle OT interfaces as well.

Voluntary, increasingly required contractually
USA

Standards & regulations in the USA

Voluntary guidance, technical standards, and one targeted, security-policy-driven regulation.

NHTSA Cybersecurity Best Practices

voluntary

Non-binding guidance based on the NIST Cybersecurity Framework (Identify–Protect–Detect–Respond–Recover) for OEMs and suppliers.

Current version 2022 · Publisher: NHTSA

NIST Cybersecurity Framework (CSF)

voluntary

A cross-industry framework with five core functions – the structural basis for NHTSA's guidance.

Not an automotive-specific standard

ISO/SAE 21434:2021 (US application)

voluntary

The same standard as in the EU, but without legal force in the USA – applied voluntarily or contractually.

No UN type-approval requirement in the USA (self-certification under FMVSS)

SAE J3061 (historical)

voluntary

The original US framework for automotive cybersecurity engineering, since superseded by ISO/SAE 21434.

Now only a historical reference

Auto-ISAC Best Practice Guides

voluntary

Voluntary information sharing between OEMs/suppliers on threat intelligence, governance and incident response.

Explicitly cited by NHTSA as a resource

TISAX® / VDA ISA (for US suppliers)

contractually binding

Not a US-origin standard – but contractually binding for US suppliers and US sites of companies that supply European OEMs.

Publisher: ENX Association / VDA (Germany)
See TISAX® details →

BIS Connected Vehicles Rule (15 CFR Part 791)

binding

Prohibits the import/sale of vehicle connectivity hardware and software with a sufficient China/Russia nexus – driven by national security rather than technical standardization.

Software from model year 2027 · hardware from model year 2030 / Jan. 1, 2029

FMVSS – Federal Motor Vehicle Safety Standards

binding

A comprehensive US vehicle safety framework – so far without dedicated, cybersecurity-specific standards.

No counterpart to UN R155

California SB-327 (IoT Security Law)

binding

A California law requiring reasonable security features for connected devices – potentially covering connected vehicle components.

In force since 2020 · not automotive-specific

Connected Vehicle Security Act of 2026

draft bill

A proposed federal law banning vehicles, parts and software with a China nexus – tightening the BIS rule.

Introduced 04/2026 · legislative process ongoing
Comparison

Europe vs. USA at a glance

The key differences between the European and US-American approaches, side by side.

Regulatory approach
EuropeBinding type-approval regime (UN R155/R156)
USAPrimarily voluntary guidance (NHTSA/NIST CSF)
Central regulation
EuropeUN R155 (CSMS) + UN R156 (SUMS)
USANHTSA Best Practices – no counterpart to UN R155
Technical reference standard
EuropeISO/SAE 21434 – de facto binding
USAISO/SAE 21434 – applied voluntarily
Enforcement
EuropeNo type approval = no market access
USAUnder the BIS rule: import ban/fines; otherwise no direct enforcement
Geopolitical dimension
EuropeNo comparable framework established so far
USABIS Connected Vehicles Rule (China/Russia ban)
Supply chain & organization
EuropeNIS2 Directive, TISAX® / VDA ISA
USAAuto-ISAC (voluntary), TISAX® contractually for EU-linked suppliers
In focus

TISAX® – the underrated link between Europe and the USA

Cross-border relevance

Not a law – but hard to avoid contractually

TISAX® is neither an EU regulation nor a US federal law, but an industry standard operated by the ENX Association on behalf of the VDA. Its reach, however, extends well beyond Europe: any supplier that delivers to a European OEM – regardless of where it is headquartered – is contractually required to participate in TISAX®. That makes TISAX® directly relevant to US-based Tier-1/2/3 suppliers and to US sites of European groups.

FAQ

Frequently asked questions

Does UN R155 apply to vehicles exported to the USA?
No. UN R155/R156 only apply in contracting states of the UNECE 1958 Agreement (including the EU, UK, Japan and South Korea). The USA is not a contracting state and regulates vehicle safety through self-certification under FMVSS; cybersecurity there remains at the level of voluntary NHTSA guidance.
Does a US-based supplier need to be TISAX® certified?
If it supplies a European OEM, generally yes. TISAX® is a contractual requirement that applies across the entire supply chain of European automotive manufacturers, regardless of where a supplier is headquartered.
Does ISO/SAE 21434 replace the UN R155 obligation?
No. The standard does not replace the regulation, but it provides the technical implementation depth that type-approval authorities accept as evidence of a conformant Cybersecurity Management System.
What does the BIS Connected Vehicles Rule mean for European suppliers?
European suppliers with US business and a China/Russia nexus in software or connectivity hardware should review their supply chains: from model year 2027, affected software, and from model year 2030, affected hardware, will be prohibited in the USA.
How does CONSUVATION support automotive security compliance?
We support you in building and evidencing a CSMS under UN R155, implementing TARA under ISO/SAE 21434, and preparing for TISAX® as an experienced consultant. For CADIS, we additionally act as a DEKRA-authorized auditor.
Services

How CONSUVATION can help, in practice

ISO/SAE 21434 TARA workshops

Threat Analysis & Risk Assessment for your vehicle architecture – methodically sound and documented for audit.

TISAX® preparation

Preparation for the VDA ISA assessment, including prototype protection and information security management.

More on TISAX® →

CADIS audit support (DEKRA)

As a DEKRA-authorized partner, we support you through CADIS certification and surveillance audits – from a single source.

Ready for automotive security compliance?

Schedule a no-obligation initial consultation – we'll assess your starting point and show you the shortest path to audit readiness.

Schedule a consultation +49 (0) 7031.4181-860