UN R155/R156, ISO/SAE 21434, the EU Cyber Resilience Act, NHTSA Best Practices, the BIS Connected Vehicles Rule and TISAX® compared side by side – thoroughly researched, as of July 2026.
Europe and the USA take fundamentally different approaches to securing connected vehicles – with direct consequences for manufacturers, suppliers and their supply chains.
UNECE/WP.29's UN Regulations R155 (Cybersecurity Management System) and R156 (Software Update Management System) are embedded in type-approval law via EU Regulation 2019/2144 and have been mandatory for all newly produced M/N-category vehicles since July 2024. ISO/SAE 21434 and ISO 24089 provide the technical implementation depth and are therefore de facto mandatory. The EU Cyber Resilience Act exempts type-approved vehicles themselves but covers retrofit components and charging infrastructure. NIS2 and TISAX® add organizational and supply-chain security.
NHTSA has published non-binding Cybersecurity Best Practices based on the NIST Cybersecurity Framework since 2016; no type-approval regime comparable to UN R155 exists. In parallel, the US Department of Commerce (BIS) created a binding rule — the "Connected Vehicles Rule" — motivated by national security rather than technical standards, which bans software with a China/Russia nexus from model year 2027 and hardware from model year 2030.
From the binding UN type-approval regime to the contractual supply-chain requirement TISAX®.
A UNECE regulation requiring vehicle manufacturers to operate a certified CSMS across the entire vehicle lifecycle – a precondition for type approval.
Governs the secure management of software updates, including over-the-air (OTA), via cryptographically verified update channels.
Embeds UN R155/R156 into EU type-approval law – without a valid CSMS/SUMS certificate, a vehicle cannot receive type approval in the EU.
Engineering requirements for cybersecurity risk management across the lifecycle (governance, TARA, development, verification) – the key evidence base for UN R155.
The technical counterpart to ISO/SAE 21434 for software update systems – the reference standard for UN R156.
A horizontal cybersecurity regulation for products with digital elements. Type-approved vehicles themselves are exempt – retrofit components, charging infrastructure and apps remain in scope.
Requires automotive manufacturers and suppliers, as operators of important/essential entities, to implement risk management, supply-chain security and incident reporting.
An information-security assessment for the automotive supply chain based on the VDA ISA catalogue of criteria – a precondition for many OEM supply contracts.
See TISAX® details →An OT security standard series for automation and production systems – increasingly required for charging infrastructure and vehicle OT interfaces as well.
Voluntary guidance, technical standards, and one targeted, security-policy-driven regulation.
Non-binding guidance based on the NIST Cybersecurity Framework (Identify–Protect–Detect–Respond–Recover) for OEMs and suppliers.
A cross-industry framework with five core functions – the structural basis for NHTSA's guidance.
The same standard as in the EU, but without legal force in the USA – applied voluntarily or contractually.
The original US framework for automotive cybersecurity engineering, since superseded by ISO/SAE 21434.
Voluntary information sharing between OEMs/suppliers on threat intelligence, governance and incident response.
Not a US-origin standard – but contractually binding for US suppliers and US sites of companies that supply European OEMs.
See TISAX® details →Prohibits the import/sale of vehicle connectivity hardware and software with a sufficient China/Russia nexus – driven by national security rather than technical standardization.
A comprehensive US vehicle safety framework – so far without dedicated, cybersecurity-specific standards.
A California law requiring reasonable security features for connected devices – potentially covering connected vehicle components.
A proposed federal law banning vehicles, parts and software with a China nexus – tightening the BIS rule.
The key differences between the European and US-American approaches, side by side.
TISAX® is neither an EU regulation nor a US federal law, but an industry standard operated by the ENX Association on behalf of the VDA. Its reach, however, extends well beyond Europe: any supplier that delivers to a European OEM – regardless of where it is headquartered – is contractually required to participate in TISAX®. That makes TISAX® directly relevant to US-based Tier-1/2/3 suppliers and to US sites of European groups.
Building and documenting a Cybersecurity Management System under UN R155 – from gap analysis to audit readiness.
Threat Analysis & Risk Assessment for your vehicle architecture – methodically sound and documented for audit.
Preparation for the VDA ISA assessment, including prototype protection and information security management.
More on TISAX® →As a DEKRA-authorized partner, we support you through CADIS certification and surveillance audits – from a single source.
Schedule a no-obligation initial consultation – we'll assess your starting point and show you the shortest path to audit readiness.