One team to handle AIS-189/190, UN R155/R156, GB 44495/44496, the EU CRA, ISO/SAE 21434, ISO 24089 and TISAX, for the markets you sell into today, and the ones you're moving into next.
It depends on where you sell. Vehicles in UNECE markets means UN R155/R156; connected products in the EU means the EU CRA; vehicles in India means AIS-189/190. Plenty of manufacturers are facing several of these at once.
Applies to every connected product sold in the EU, including vehicles, ECUs and IoT devices. Full enforcement from December 2027 (reporting duties from September 2026); fines can reach €15 million or 2.5% of global annual turnover, whichever is higher.
EU CRA complianceMandatory for new vehicle type approvals in UNECE markets. You need an approved CSMS (R155) and SUMS (R156).
UN R155/R156 complianceIndia's automotive cybersecurity mandate. AIS-189/190 requires CSMS compliance, and AIS-190 adds software-update security (SUMS). Effective for new vehicle types from October 2026, and all vehicle types from April 2027.
AIS-189/190 complianceISO/SAE 21434 · ISO 26262 · TISAX · EU RED
We map where you stand today against the regulation that applies to you.
A prioritised roadmap that closes every gap, in the order that makes sense.
CSMS/SUMS processes, TARA, and the evidence to back them up.
We prepare your documentation and stand beside you through the assessment itself.
Applies to: new vehicle type approvals (UNECE) · Status: in force · Requires: an approved CSMS and SUMS.
Applies to: connected products sold in the EU (vehicles, ECUs, IoT) · Status: reporting duties from Sept 2026, full enforcement Dec 2027 · Requires: conformity, an SBOM, and vulnerability handling.
Applies to: vehicles sold in India · Status: new types from Oct 2025, all types from Oct 2028 · Requires: a CSMS (189) and SUMS (190).
Applies to: road-vehicle E/E systems · Status: industry standard · Requires: a cybersecurity engineering process.
Applies to: automotive suppliers handling sensitive data · Status: as required by your OEM · Requires: assessed information security.
A gap assessment maps your product against every regulation that applies to it, then gives you back a prioritised compliance roadmap, with no guesswork and no surprises.