Automotive Cybersecurity Compliance, Across Every Mandate

One team to handle AIS-189/190, UN R155/R156, GB 44495/44496, the EU CRA, ISO/SAE 21434, ISO 24089 and TISAX, for the markets you sell into today, and the ones you're moving into next.

Choose Your Regulation

It depends on where you sell. Vehicles in UNECE markets means UN R155/R156; connected products in the EU means the EU CRA; vehicles in India means AIS-189/190. Plenty of manufacturers are facing several of these at once.

Find the Regulation That Applies to You

EU Cyber Resilience Act (EU CRA)

Applies to every connected product sold in the EU, including vehicles, ECUs and IoT devices. Full enforcement from December 2027 (reporting duties from September 2026); fines can reach €15 million or 2.5% of global annual turnover, whichever is higher.

EU CRA compliance

UN R155 / R156

Mandatory for new vehicle type approvals in UNECE markets. You need an approved CSMS (R155) and SUMS (R156).

UN R155/R156 compliance

AIS-189/190 (India)

India's automotive cybersecurity mandate. AIS-189/190 requires CSMS compliance, and AIS-190 adds software-update security (SUMS). Effective for new vehicle types from October 2026, and all vehicle types from April 2027.

AIS-189/190 compliance

Also supported

ISO/SAE 21434 · ISO 26262 · TISAX · EU RED

From Gap to Certificate

  1. Gap Assessment

    We map where you stand today against the regulation that applies to you.

  2. Remediation Plan

    A prioritised roadmap that closes every gap, in the order that makes sense.

  3. Implementation Support

    CSMS/SUMS processes, TARA, and the evidence to back them up.

  4. Audit & Type-Approval Readiness

    We prepare your documentation and stand beside you through the assessment itself.

Which Regulations Apply to Your Product?

UN R155 / R156

Applies to: new vehicle type approvals (UNECE) · Status: in force · Requires: an approved CSMS and SUMS.

EU CRA

Applies to: connected products sold in the EU (vehicles, ECUs, IoT) · Status: reporting duties from Sept 2026, full enforcement Dec 2027 · Requires: conformity, an SBOM, and vulnerability handling.

AIS-189/190

Applies to: vehicles sold in India · Status: new types from Oct 2025, all types from Oct 2028 · Requires: a CSMS (189) and SUMS (190).

ISO/SAE 21434

Applies to: road-vehicle E/E systems · Status: industry standard · Requires: a cybersecurity engineering process.

TISAX

Applies to: automotive suppliers handling sensitive data · Status: as required by your OEM · Requires: assessed information security.

Common Questions

It depends on where you sell. Vehicles in UNECE markets means UN R155/R156; connected products in the EU means the EU CRA; vehicles in India means AIS-189/190. Plenty of manufacturers are facing several of these at once.
Full enforcement begins in December 2027, and non-compliant connected products can face market restrictions and fines up to €15 million or 2.5% of global annual turnover, whichever is higher.
It's aligned with UN R155/R156, but it's India-specific, not identical. If you sell in both markets you have to satisfy each one, though a lot of the underlying CSMS work carries over between them.
It depends on your product's complexity and how far along you already are. Building a compliant CSMS often takes many months, so the earlier you start the better. A gap assessment gives you a realistic, prioritised timeline.

Know Exactly Where You Stand

A gap assessment maps your product against every regulation that applies to it, then gives you back a prioritised compliance roadmap, with no guesswork and no surprises.