How India's mandate lines up with UN R155/R156, and where it doesn't.
Under UN R155/R156, you don't get vehicle type approval without an audited Cybersecurity Management System. The regulation is less about any single control and more about proving you have a working process.
A CSMS is the set of processes a manufacturer operates to manage cybersecurity risk across the vehicle lifecycle, concept, development, production and the years the vehicle is on the road. Auditors are checking that the system exists, is used, and produces evidence.
What an assessor looks for
- Risk management. A repeatable TARA (Threat Analysis and Risk Assessment) that drives your security requirements, aligned with ISO/SAE 21434.
- Monitoring. A way to detect new threats and vulnerabilities affecting vehicles already in the field.
- Incident response. A defined process to triage, fix and disclose issues, including field response.
- Supply-chain control. Evidence that cybersecurity responsibilities are flowed down to and met by your suppliers.
Where suppliers fit
An OEM owns the type approval, but most of the software and hardware comes from Tier-1 and Tier-2 suppliers. So the OEM has to demonstrate control over that supply chain, and suppliers have to provide the evidence, interface agreements, their own risk assessments, and cybersecurity cases for the components they deliver. A CSMS that stops at the factory gate will not pass.
Building it to last
Treat the CSMS as a living system, not an approval artefact. The vehicles you approve today have to stay secured for a decade, so the monitoring and response loops matter as much as the initial paperwork.
To see where your processes stand against R155/R156 today, start with a compliance gap assessment.