Back to engagement patterns
    Engagement pattern

    Product cybersecurity under R155, ISO 21434 and the CRA

    One product, three instruments. How the management system, the per-product file and the reporting clocks are built so a single evidence set answers all three.

    Compliance3 Sept 20265 min read

    ISO/SAE 21434:2021Regulation (EU) 2024/2847UN Regulation No 155
    On this page

    Scope

    Three instruments reach the same product from different directions. R155 approves a vehicle type and requires a certified management system behind it. ISO/SAE 21434:2021 describes the engineering that produces the evidence. The Cyber Resilience Act binds the manufacturer of any product with digital elements.

    R155 and the CRA are law and set outcomes; the standard sets method. Showing only method makes for a harder audit.

    In scope: the management system, the per-product risk and evidence file, the supplier interface, the monitoring capability, and the reporting clocks.

    Out of scope: the type-approval decision itself, software update management under R156, and national market surveillance procedure.

    Phases

    PhasePurposePlanning horizonCloses when
    1. Instrument mappingDecide which instruments bind this product, and which apply on what dateusually planned over 3–4 weeksAn applicability statement names each instrument and its trigger
    2. Management systemBuild the processes R155 paragraph 7.2.2.2 lists, against the clause 5 to 8 structure of the standardusually planned over 4–7 monthsThe process set covers development, production and post-production
    3. Product fileRisk assessment, mitigation, verification and the technical documentationusually planned over 3–6 monthsEvery identified risk has a treatment and a test result
    4. Field and reporting readinessStand up monitoring, the reporting chain and the annual reportusually planned over 6–10 weeksA rehearsal produces each notification on its statutory clock
    Horizons are planning input. They describe how this shape of work is scheduled, never how long anything took.

    Deliverables

    DeliverableRequired byWho maintains it afterwards
    Management system process setR155 paragraph 7.2.2.2, points (a) to (h) 1Process owner
    Certificate of Compliance for the CSMSR155 paragraph 6.7, valid for at most three years 2Compliance owner
    Per-product risk assessment and treatment recordR155 paragraph 7.3.3 and CRA Article 13(2) and (3)Product security owner
    Mitigation and verification evidenceR155 paragraphs 7.3.4 and 7.3.6, against Annex 5 Parts B and CEngineering
    Supplier interface recordR155 paragraph 7.2.2.5 3Procurement and engineering
    Technical documentation carrying the risk assessmentCRA Articles 13(4) and 31, content per Annex VII 4Product security owner
    Support-period statement and end dateCRA Article 13(8), at least five years 5Product management
    Monitoring outputs and the annual report to the authorityR155 paragraph 7.4.1Product security owner

    Roles

    RoleSideAccountable for
    Approval authority or technical serviceAuthorityAssessing the management system and the vehicle type
    Process ownerOrganisationThe management system and its records
    Product security ownerOrganisationRisk assessment, technical documentation, reporting
    SuppliersContracted third partiesTheir part of the risk picture and their notification duties
    AdviserExternalMethod, gap assessment, rehearsal design

    What the authority asks

    Failure modes

    Mapping

    ObligationR155ISO/SAE 21434:2021CRA
    Have a governed management system7.2.1, 7.2.2.1Clause 5, Organizational cybersecurity managementArticle 13(1)
    Run it per project or product7.3.1Clause 6, Project dependent cybersecurity managementArticle 13(2)
    Govern distributed work with suppliers7.2.2.5, 7.3.2Clause 7, Distributed cybersecurity activitiesArticle 13(5) and 13(6)
    Assess and treat product risk7.3.3, 7.3.4Clause 9, ConceptArticle 13(2) and 13(3)
    Monitor and handle vulnerabilities7.2.2.2(g), 7.3.7Clause 8, Continual cybersecurity activitiesArticle 13(8)
    Report on a clock7.4.1, annualClause 8 event evaluationArticle 14(2): 24 hours, 72 hours, 14 days 6
    One obligation, three instruments. R155 uses paragraphs, the CRA uses articles.

    References

    1. UN Regulation No 155, OJ L 82, 9.3.2021, pp. 30–59 7.
    2. Regulation (EU) 2024/2847 (Cyber Resilience Act). Application dates are set in Article 71(2) 8.
    3. ISO/SAE 21434:2021, Road vehicles — Cybersecurity engineering. ISO/TC 22/SC 32 with SAE International, 2021-08. https://www.iso.org/standard/70918.html, accessed 2026-09-03. Clause titles come from the free ISO Online Browsing Platform contents listing; clauses beyond 9 were not readable, so none is cited 9.

    Sources

    1. 1UN R155, para. 7.2.2.2, CELEX 42021X0387 · verified 2026-09-03
    2. 2UN R155, para. 6.7, CELEX 42021X0387 · verified 2026-09-03
    3. 3UN R155, para. 7.2.2.5, CELEX 42021X0387 · verified 2026-09-03
    4. 4Regulation (EU) 2024/2847, Art. 13(4) and Annex VII, CELEX 32024R2847 · verified 2026-09-03
    5. 5Regulation (EU) 2024/2847, Art. 13(8), CELEX 32024R2847 · verified 2026-09-03
    6. 6Regulation (EU) 2024/2847, Art. 14(2), CELEX 32024R2847 · verified 2026-09-03
    7. 7UN R155, full text, CELEX 42021X0387 · verified 2026-09-03
    8. 8Regulation (EU) 2024/2847, Art. 71(2), CELEX 32024R2847 · verified 2026-09-03
    9. 9ISO OBP, ISO/SAE 21434:2021 clause titles 5 to 9 · verified 2026-09-03