Product cybersecurity under R155, ISO 21434 and the CRA
One product, three instruments. How the management system, the per-product file and the reporting clocks are built so a single evidence set answers all three.
Compliance3 Sept 20265 min read
On this page
Scope
Three instruments reach the same product from different directions. R155 approves a vehicle type and requires a certified management system behind it. ISO/SAE 21434:2021 describes the engineering that produces the evidence. The Cyber Resilience Act binds the manufacturer of any product with digital elements.
R155 and the CRA are law and set outcomes; the standard sets method. Showing only method makes for a harder audit.
In scope: the management system, the per-product risk and evidence file, the supplier interface, the monitoring capability, and the reporting clocks.
Out of scope: the type-approval decision itself, software update management under R156, and national market surveillance procedure.
Phases
| Phase | Purpose | Planning horizon | Closes when |
|---|---|---|---|
| 1. Instrument mapping | Decide which instruments bind this product, and which apply on what date | usually planned over 3–4 weeks | An applicability statement names each instrument and its trigger |
| 2. Management system | Build the processes R155 paragraph 7.2.2.2 lists, against the clause 5 to 8 structure of the standard | usually planned over 4–7 months | The process set covers development, production and post-production |
| 3. Product file | Risk assessment, mitigation, verification and the technical documentation | usually planned over 3–6 months | Every identified risk has a treatment and a test result |
| 4. Field and reporting readiness | Stand up monitoring, the reporting chain and the annual report | usually planned over 6–10 weeks | A rehearsal produces each notification on its statutory clock |
Deliverables
| Deliverable | Required by | Who maintains it afterwards |
|---|---|---|
| Management system process set | R155 paragraph 7.2.2.2, points (a) to (h) 1 | Process owner |
| Certificate of Compliance for the CSMS | R155 paragraph 6.7, valid for at most three years 2 | Compliance owner |
| Per-product risk assessment and treatment record | R155 paragraph 7.3.3 and CRA Article 13(2) and (3) | Product security owner |
| Mitigation and verification evidence | R155 paragraphs 7.3.4 and 7.3.6, against Annex 5 Parts B and C | Engineering |
| Supplier interface record | R155 paragraph 7.2.2.5 3 | Procurement and engineering |
| Technical documentation carrying the risk assessment | CRA Articles 13(4) and 31, content per Annex VII 4 | Product security owner |
| Support-period statement and end date | CRA Article 13(8), at least five years 5 | Product management |
| Monitoring outputs and the annual report to the authority | R155 paragraph 7.4.1 | Product security owner |
Roles
| Role | Side | Accountable for |
|---|---|---|
| Approval authority or technical service | Authority | Assessing the management system and the vehicle type |
| Process owner | Organisation | The management system and its records |
| Product security owner | Organisation | Risk assessment, technical documentation, reporting |
| Suppliers | Contracted third parties | Their part of the risk picture and their notification duties |
| Adviser | External | Method, gap assessment, rehearsal design |
What the authority asks
Failure modes
Mapping
| Obligation | R155 | ISO/SAE 21434:2021 | CRA |
|---|---|---|---|
| Have a governed management system | 7.2.1, 7.2.2.1 | Clause 5, Organizational cybersecurity management | Article 13(1) |
| Run it per project or product | 7.3.1 | Clause 6, Project dependent cybersecurity management | Article 13(2) |
| Govern distributed work with suppliers | 7.2.2.5, 7.3.2 | Clause 7, Distributed cybersecurity activities | Article 13(5) and 13(6) |
| Assess and treat product risk | 7.3.3, 7.3.4 | Clause 9, Concept | Article 13(2) and 13(3) |
| Monitor and handle vulnerabilities | 7.2.2.2(g), 7.3.7 | Clause 8, Continual cybersecurity activities | Article 13(8) |
| Report on a clock | 7.4.1, annual | Clause 8 event evaluation | Article 14(2): 24 hours, 72 hours, 14 days 6 |
References
- UN Regulation No 155, OJ L 82, 9.3.2021, pp. 30–59 7.
- Regulation (EU) 2024/2847 (Cyber Resilience Act). Application dates are set in Article 71(2) 8.
- ISO/SAE 21434:2021, Road vehicles — Cybersecurity engineering. ISO/TC 22/SC 32 with SAE International, 2021-08.
https://www.iso.org/standard/70918.html, accessed 2026-09-03. Clause titles come from the free ISO Online Browsing Platform contents listing; clauses beyond 9 were not readable, so none is cited 9.
Sources
- 1UN R155, para. 7.2.2.2, CELEX 42021X0387 · verified 2026-09-03
- 2UN R155, para. 6.7, CELEX 42021X0387 · verified 2026-09-03
- 3UN R155, para. 7.2.2.5, CELEX 42021X0387 · verified 2026-09-03
- 4Regulation (EU) 2024/2847, Art. 13(4) and Annex VII, CELEX 32024R2847 · verified 2026-09-03
- 5Regulation (EU) 2024/2847, Art. 13(8), CELEX 32024R2847 · verified 2026-09-03
- 6Regulation (EU) 2024/2847, Art. 14(2), CELEX 32024R2847 · verified 2026-09-03
- 7UN R155, full text, CELEX 42021X0387 · verified 2026-09-03
- 8Regulation (EU) 2024/2847, Art. 71(2), CELEX 32024R2847 · verified 2026-09-03
- 9ISO OBP, ISO/SAE 21434:2021 clause titles 5 to 9 · verified 2026-09-03