Law / European Union

L-Category Vehicles, Protection Against Cyberattacks Under UN Regulation No 155 (Annex XVIII to Delegated Regulation (EU) No 44/2014)

Commission Delegated Regulation (EU) 2025/1455, Annex XVIII to Delegated Regulation (EU) No 44/2014

A product security requirements rule binding public and private bodies.

Obligation class
Security

As of .

What it requires

  • This duty takes effect on for new vehicle types and on for existing vehicle types (point 1.3 of Annex XVIII to Delegated Regulation (EU) No 44/2014, added by Delegated Regulation (EU) 2025/1455).
  • It reaches you if you are a manufacturer of two- and three-wheel vehicles and quadricycles of categories L1e, L2e, L3e, L4e, L5e, L6e or L7e, other than L1e vehicles designed to pedal referred to in Article 3, point (94)(b), of Regulation (EU) No 168/2013: ensure the vehicle meets all the relevant requirements of UN Regulation No 155 on cyber security and cyber security management system (point 1.2).
  • Have a Cyber Security Management System that covers the development, production and post-production phases, and hold a valid Certificate of Compliance for it for the vehicle type being approved (UN Regulation No 155, paragraphs 7.2.2.1 and 7.3.1).
  • Identify the critical elements of the vehicle type, perform an exhaustive risk assessment, and protect the vehicle type against the risks identified with proportionate mitigations that include the relevant mitigations of Annex 5, Parts B and C (paragraphs 7.3.3 and 7.3.4).
  • Implement measures to detect and prevent cyber-attacks against vehicles of the type, support your monitoring of threats, vulnerabilities and cyber-attacks, and provide data forensic capability; mitigate threats and vulnerabilities that require a response within a reasonable timeframe, and monitor continually, including vehicles after first registration (paragraphs 7.3.7, 7.2.2.3 and 7.2.2.4).
  • Report at least once a year, or more frequently if relevant, the outcome of your monitoring activities, including information on new cyber-attacks, and confirm that the mitigations implemented are still effective (paragraph 7.4.1).
  • For type approvals of vehicles of category L first issued before , and each extension of them, if you can demonstrate that the vehicle type could not be developed in compliance with the Cyber Security Management System, demonstrate instead that cyber security was adequately considered during the development phase (paragraph 7.3.1).

Who enforces it

Enforcement body

The market surveillance authorities of the Member States, which perform documentary checks on type-approved L-category vehicles, systems, components and separate technical units under Article 8(1) of Regulation (EU) No 168/2013.

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Delegated Regulation (EU) 2025/1455 amends Delegated Regulation (EU) No 44/2014 by adding UN Regulation No 155 on cyber security and cyber security management system to the table in Annex I and by adding an Annex XVIII on the protection of vehicles against cyberattacks. Recital 1 states that the scope of UN Regulation No 155 has been extended to include rules on cybersecurity for L-category vehicles, meaning two- and three-wheel vehicles and quadricycles.

Point 1.2 of Annex XVIII requires vehicles of categories L1e, L2e, L3e, L4e, L5e, L6e and L7e, except L1e vehicles designed to pedal referred to in Article 3, point (94)(b), of Regulation (EU) No 168/2013, to meet all the relevant requirements of UN Regulation No 155.

Point 1.1 of Annex XVIII defines a type of vehicle with regard to cybersecurity as a category of vehicles which do not differ in the manufacturer's designation of the vehicle type or in essential aspects of the electric and electronic architecture and external interfaces with respect to cyber security. Point 1.3 of Annex XVIII applies points 1.1 and 1.2 to new vehicle types from and to existing vehicle types from .

Annex I to Delegated Regulation (EU) No 44/2014, as amended, lists UN Regulation No 155 in the version Supplement 3 to the 00 series of amendments, published in the Official Journal on as 2025/5. The Official Journal text of UN Regulation No 155 is a documentation copy, since only the original UN/ECE texts have legal effect under international public law.

Paragraph 1.1 of UN Regulation No 155 applies it to vehicles, with regard to cyber security, of categories L, M, N and O, if fitted with at least one electronic control unit. Paragraph 7.2.2.1 requires the vehicle manufacturer to demonstrate that its Cyber Security Management System applies to the development phase, the production phase and the post-production phase.

Paragraph 7.3.1 requires the manufacturer to have a valid Certificate of Compliance for the Cyber Security Management System relevant to the vehicle type being approved.

For type approvals of vehicles of category L first issued before , and each extension of them, a manufacturer that can demonstrate that the vehicle type could not be developed in compliance with the Cyber Security Management System must instead demonstrate that cyber security was adequately considered during the development phase.

Paragraph 7.3.3 requires the manufacturer to identify the critical elements of the vehicle type and perform an exhaustive risk assessment for it, treating the identified risks appropriately. Paragraph 7.3.4 requires the manufacturer to protect the vehicle type against the risks identified in its risk assessment, with proportionate mitigations that include all mitigations referred to in Annex 5, Parts B and C that are relevant for those risks.

Paragraph 7.3.7 requires measures to detect and prevent cyber-attacks against vehicles of the type, to support the manufacturer's monitoring of threats, vulnerabilities and cyber-attacks, and to provide data forensic capability to enable analysis of attempted or successful cyber-attacks. Paragraph 7.2.2.3 requires the manufacturer's processes to ensure that cyber threats and vulnerabilities which require a response are mitigated within a reasonable timeframe.

Paragraph 7.2.2.4 requires the monitoring of cyber-attacks, threats and vulnerabilities to be continual and to include vehicles after first registration. Paragraph 7.4.1 requires the manufacturer to report at least once a year, or more frequently if relevant, the outcome of its monitoring activities, including information on new cyber-attacks, and to confirm that the mitigations implemented are still effective.

Recital 3 states that L1e category vehicles designed to pedal are subject to the requirements of Regulation (EU) 2024/2847 under Commission Delegated Regulation (EU) 2025/1535. Article 18(1) of Regulation (EU) No 168/2013 requires L-category vehicles and the systems, components and separate technical units intended for them to comply with the requirements listed in its Annexes II to VIII applicable to the relevant vehicle sub-categories.

Article 76(1) of Regulation (EU) No 168/2013 leaves the penalties for infringement of that Regulation and its delegated acts to the Member States, which the Article requires to be effective, proportionate and dissuasive.

When LexLint raises it

When your app profile says your app distributes a software product.

Back to the example  ·  Lint your app