WP.29 Consulting

UNECE WP.29 regulations for automotive cybersecurity

The first-ever regulation requiring vehicle type approval with regards to cybersecurity. Are you prepared?

In June 2020, the United Nations (UN) officially adopted two new regulations regarding automotive cybersecurity. Set out by UNECE WP.29, UN R155 mandates an automotive cybersecurity management system (CSMS), while UN R156 requires a software update management system (SUMS) for all vehicles. As mandatory requirements for vehicle type approval, the regulations affect the production of every single vehicle across the globe.

From OEMs, Tier-1 suppliers, all the way to software providers – everyone needs to be prepared.

Although many may think that “WP.29” refers to the newer regulations released in 2020, WP.29 is originally a ”Working Party on the Construction of Vehicles” that was established in 1952. It became officially known as WP.29 in March 2000 and the objective has always been to initiate and pursue actions for worldwide harmony in terms of the development of regulations for vehicles. The Working Party is the largest international vehicle regulatory system in the world.

While WP.29 has several working regulations for vehicles, the two regulations released in June 2020 are the first regulations that mandate cybersecurity for connected and autonomous vehicles, signaling the growing importance of securing intelligent transport systems.


All You Need to Know About WP.29 Compliance

and stay prepared with AUTOCRYPT

Effects on the Automotive Industry

If the vehicle in question…
  • Utilizes a wired or wireless connection to the vehicle’s internal communication network
  • Utilizes a wired or wireless connection to the external communication network of the vehicle
  • Connects indirectly to the vehicle network
  • Utilizes electronic or optoelectronic hardware
  • Includes software
  • Includes sensors
page image
page image

WP.29 Regulation Checklist

While countries are beginning the steps towards full implementation, those in the automotive industry (including OEMs, Tier-1 Suppliers, Service Providers, etc.) can take it upon themselves to ensure that they are prepared for WP.29’s stipulations.

Cyber Security Management Systems (CSMS)

For Automotive Industry/Sector

For Manufacturers

Software Update Management Systems (SUMS)

For Automotive Industry/Sector

For Manufacturers

For Over-the-Air (OTA) Software Updates

DISCLAIMER: This document is for informational purposes only. Information is general in nature, and is not intended to and should not be relied upon or construed as legal opinion or legal advice regarding any specific issue or factual circumstance. Information may not contain the most up-to-date information. Reader of the document should contact their cyber security provider for the most up-to-date information to obtain advice with respect to regulation compliance.

AUTOCRYPT's Solution for WP.29

Many companies have already begun to map out a timeline implementing changes to their existing supply chains to ensure that new vehicle models will be compliant with the regulations. However, the comprehensive nature of the compliance regulations can prove to be roadblocks for many, requiring additional assistance.

As an automotive cybersecurity solutions provider, AUTOCRYPT offers a three-fold, comprehensive approach to CSMS compliance, beginning with consultation, all the way to regular testing.

Consulting and Training

AUTOCRYPT’s security experts will work with you to conduct:

  • Overview of existing CSMS
  • TARA-based risk assessment
  • Recommendations for security engineering
Security Product

AUTOCRYPT’s in-vehicle security solution provides security for ECUs and an Intrusion Detection System (IDS) for CAN bus network messages.


AUTOCRYPT’s red team will perform regular CSMS testing with:

  • Vulnerability Scanning
  • Fuzz Testing
  • Penetration Testing

Manufacturers, suppliers, and service providers should be looking to get a head start on structuring their Cyber Security Management Systems, and preparing for type approval. Ultimately, AUTOCRYPT and WP.29’s goals are one and the same: security should be a priority before any vehicles go on the road.



AUTOCRYPT can fulfill WP.29’s new regulations through its comprehensive In-Vehicle Systems Security solution. By protecting ECUs and implementing an intrusion detection system (IDS) for the CAN Bus network system, AUTOCRYPT ensures that the CSMS requirements for WP.29 are met.

page image

Security reinforcement and monitoring for ECUs

page image

Abnormal behavior / attack detection for internal and external communication networks

TARA Template for Siemens Polarion

Polarion-based cybersecurity TARA template

AUTOCRYPT’s Cybersecurity TARA Template for Automotive is a project management tool for conducting Threat Analysis and Risk Assessment (TARA). The tool is available as an extension on Siemens’ Polarion ALM application lifecycle management platform, enabling users to effectively implement TARA activities.

Optimized for the Polarion platform, the extension allows users to automatically connect their work items to the template, where they can benefit from the step-by-step manual and calculation tools.

In compliance with ISO/SAE 21434 and UN R155, the tool analyzes potential cyberattack objectives, vectors, and threats, followed by an assessment of their risk and severity levels based on its embedded calculation tools.

tara template