General Safety Regulation, Protection of Vehicles Against Cyberattacks (Annex II, Item D4)
Regulation (EU) 2019/2144, Art. 4(5)(d) and Annex II, item D4
In force since .
A product security requirements rule binding public and private bodies.
- Obligation class
- Security
As of .
What it requires
- It reaches you if you are a manufacturer of vehicles, or of the systems, components and separate technical units designed and constructed for them, in the categories for which Annex II marks item D4: ensure that the vehicle, system, component or separate technical unit complies with the requirement for protection of the vehicle against cyberattacks listed there (Articles 2 and 4(5), point (d)).
- Meet that requirement from the dates in note B of Annex II: national authorities refuse EU type-approval to a new type that does not comply from , and prohibit the registration of vehicles that do not comply, and the placing on the market and entry into service of components and separate technical units that do not comply, from (Article 16).
Who enforces it
Enforcement body
The national authorities of the Member States, which under Article 16 refuse type-approval to a new type that does not comply and prohibit the registration of vehicles and the placing on the market of components and separate technical units that do not.
What this law does
Article 2 applies the General Safety Regulation to vehicles of categories M, N and O, as defined in Article 4 of Regulation (EU) 2018/858, and to systems, components and separate technical units designed and constructed for such vehicles. Article 3 applies the definitions laid down in Article 3 of Regulation (EU) 2018/858 to the General Safety Regulation.
Article 4(5) requires manufacturers to ensure that vehicles, systems, components and separate technical units comply with the applicable requirements listed in Annex II with effect from the dates specified in that Annex, including the requirements relating to on-board instruments, electrical system, vehicle lighting and protection against unauthorized use including cyberattacks.
Annex II lists item D4, Protection of vehicle against cyberattacks, under the heading of on-board instruments, electrical system, vehicle lighting and protection against unauthorized use, including cyberattacks, and marks it with the date note B. Note B gives as the date for refusal to grant EU type-approval and as the date for the prohibition of the registration of vehicles, and of the placing on the market and entry into service of components and separate technical units.
Article 16 requires national authorities, with effect from the dates specified in Annex II, to refuse EU type-approval or national type-approval to a new type of vehicle, system, component or separate technical unit that does not comply with a requirement listed there. It also requires them, from those dates, to consider certificates of conformity for new vehicles that do not comply to be no longer valid and to prohibit the registration of such vehicles.
Recital 26 states that, in view of the risk of unauthorized remote access to in-vehicle data and of illegal modification of software over the air, UN Regulations or other regulatory acts on cyber security should be applied on a mandatory basis as soon as possible after their entry into force. Article 19 provides that the Regulation applies from .
Recital 2 states that the administrative provisions of Regulation (EU) 2018/858, including the provisions on corrective measures and penalties, are fully applicable to the General Safety Regulation.
When LexLint raises it
When your app profile says your app distributes a software product.