Skip to content
16 September 2026

How VicOne helps OEMs and suppliers comply with UN R155

VicOne combines threat intelligence and AI‑driven tools to safeguard every stage of a vehicle’s life while guiding manufacturers through UN R155 compliance.

How VicOne helps OEMs and suppliers comply with UN R155

The automotive world is racing toward full connectivity, with forecasts estimating the software and electronics market to surge past US$462 billion by 2030. As cars become rolling data hubs—hosting telematics, V2X radios, infotainment units and over-the-air update mechanisms—their exposure to cyber threats expands dramatically. Manufacturers, tier-1 suppliers and even charging-station operators now share the responsibility of defending a vehicle from the sketch-pad to the scrapyard, a duty reinforced by a wave of new regulations worldwide.

Modern vehicles no longer resemble isolated machines; they are integrated components of a broader digital ecosystem. This shift has introduced a spectrum of vulnerabilities that mirror those found in traditional IT environments—ransomware, data breaches, malicious firmware, and supply-chain attacks. At the same time, legacy automotive architectures, designed before the era of constant connectivity, often lack built-in defenses, making them attractive targets for sophisticated adversaries.

Accelerating attack surface across the connected car

The shift to software-centric designs has turned everyday car components into potential entry points. Vehicle-to-everything (V2X) radios can be intercepted, in-vehicle infotainment (IVI) systems may host compromised apps, and on-board diagnostics (OBD) ports are vulnerable to man-in-the-middle exploits. Even external services such as electric-vehicle chargers have been demonstrated as vectors for injection attacks, while over-the-air (OTA) update pipelines can be hijacked to deliver malicious code. A recent series of incidents highlighted the danger of compromised mobile applications that silently communicate with vehicle ECUs, exposing drivers to privacy breaches and remote control threats.

Beyond the vehicle itself, the supply chain adds another layer of risk. A single vulnerable third-party library can propagate across dozens of models, and ransomware targeting a supplier’s backend servers can cascade into production delays and safety concerns. According to industry analyses, ransomware and data-theft incidents rank among the top challenges for automotive firms, underscoring the need for holistic, lifecycle-spanning protection.

Understanding UN Regulation 155 and its impact

UN Regulation No. 155 (UN R155) is a regulatory framework introduced by the UNECE Working Party 29 in January . It obliges manufacturers to embed a cybersecurity management system (CSMS) throughout a vehicle’s design, production and post-production phases. The regulation applies to the 54 UNECE member countries—including the EU, the United Kingdom, Japan and South Korea—and any market that adopts its standards.

UN R155 outlines 69 distinct attack vectors grouped into six focus areas: back-end server security, internal communication channels, update procedures, human error, external connectivity, and data/code integrity. Manufacturers must conduct thorough risk assessments, harden vulnerabilities, and demonstrate continuous monitoring capabilities. Compliance also aligns closely with ISO/SAE 21434 meaning that a robust CSMS satisfying one standard typically satisfies the other.

The regulation’s reach extends to a wide range of vehicle categories: passenger cars, vans, trucks, buses, and light four-wheelers equipped with at least Level 3 automation. While existing models certified before the rule’s enforcement are exempt, any new type approval after the rollout must prove that the CSMS is active and effective. Tier-1 and Tier-2 suppliers are not required to obtain separate approvals, but they must furnish evidence that their components meet the OEM’s cybersecurity requirements.

VicOne’s portfolio for a compliant and secure vehicle ecosystem

Built on decades of threat intelligence, VicOne (a Trend Micro subsidiary) offers a modular suite that protects the entire vehicle lifecycle. The platform fuses machine-learning detection, behavior analytics and real-time response, giving OEMs centralized visibility into complex, multi-vendor ecosystems. Its capabilities map directly to the obligations set out in UN R155, helping manufacturers achieve and maintain CSMS certification.

Solutions for OEMs and tier-1 partners

For original equipment manufacturers, VicOne delivers vulnerability scanning, malware detection and backdoor analysis across all software components. The system can virtually patch identified flaws, allowing suppliers to focus on permanent fixes while keeping the vehicle secure during the interim. Integrated reporting aligns with ISO 21434 and UN R155 audit requirements, simplifying the path to type approval.

Tier-1 suppliers benefit from tools that pinpoint risks in supplied ECUs and assess supply-chain exposure. VicOne’s compliance module ensures that each component meets the OEM’s security specifications, providing the documentation necessary to demonstrate adherence to UN R155 without requiring a separate certification.

Smart-cockpit and AI-driven applications

As generative AI finds its way into infotainment and driver-assist features, VicOne safeguards large language model (LLM) integrations against data leakage, phishing and remote-code execution. The solution continuously monitors browsers, URLs and API calls, blocking suspicious activity before personal information or proprietary code is exposed.

EV-charging infrastructure protection

Charging-point operators and EVSE manufacturers receive multilayered defense without hardware changes. Real-time intrusion detection and prevention (IDS/IPS) flag zero-day exploits, while continuous vulnerability intelligence keeps the charging network one step ahead of attackers targeting firmware or communication protocols.

By providing end-to-end protection—from design-time risk assessment to post-sale monitoring—VicOne enables the automotive industry to meet regulatory expectations, protect driver data, and preserve brand reputation in an increasingly connected world.

Author

James Whitfield

James Whitfield grew up in Manchester watching Sunday football, then carved a career covering Premier League weekends and F1 paddocks. Knows the difference between xG noise and signal.