UN R155 and UN R156 Certified Your Vehicles. Who’s Certifying Your Fleet?
- ktaylor
- Jul 10
- 7 min read
The three cybersecurity layers ASEAN fleet operators own, only one of which UN R155 and UN R156 touch

When an ASEAN fleet operator opens a supplier tender today, UN R155 and UN R156 often appear in the specifications as documented compliance. The vehicles being offered are certified, and the telematics supplier references UN R155 alignment. At face value, the fleet’s cybersecurity position looks covered.
So what is covered, exactly?
The answer is more specific than the tender makes it look. UN R155 and UN R156 are UN Regulations governing vehicle cybersecurity and software update management. They apply to vehicles at the point of type approval in markets that have adopted them, and do not apply to fleet operators anywhere.
For ASEAN fleet operators, that distinction matters. The regulation covers your vehicles; everything above them, from the aftermarket devices you install to the personal data your operations generate, sits under a different set of frameworks and legal obligations. TTMI has published reference guides on UN R155 and UN R156 covering the regulatory details.
What UN R155 and UN R156 Actually Apply To
UN R155 requires vehicle manufacturers to operate a certified Cybersecurity Management System (CSMS) covering the vehicle lifecycle from design through production to post-production. UN R156 requires a Software Update Management System (SUMS) governing how updates reach the vehicle across its operational life. Both were adopted in 2020 under the UNECE 1958 Agreement and entered into force on 22 January 2021 [1, 2].
Enforcement rolled out in two phases: new vehicle types submitted for type approval from July 2022, then all new vehicles in production from July 2024 [1]. CSMS and SUMS certificates are valid for three years and require ongoing surveillance. Categories M, N, and O vehicles are in scope: passenger cars, vans, trucks, buses, and trailers. Motorcycles (Category L) are proposed for December 2027 for new vehicle types and June 2029 for existing types.
Adopting markets are the European Union, the United Kingdom, Japan, and Australia. South Korea is a 1958 Agreement contracting party but has formally declared it does not consider itself bound by UN Regulations; it applies its own national cybersecurity regulation with parallel enforcement. China has developed its own mandatory standard, GB 44495, following the UNECE blueprint [4].
No ASEAN country has adopted UN R155 or UN R156 into its national vehicle type-approval regime. The regulations do not reach ASEAN as a direct legal obligation on the fleet operator, the vehicle manufacturer, or anyone in between operating within its jurisdictions.

How UN R155 and UN R156 Reach ASEAN Fleet Operators
That does not put the regulations out of ASEAN’s operational picture. Vehicles arriving from UN R155-adopting markets carry the certification with them.
Japanese OEMs including Toyota, Honda, Nissan, Isuzu, Hino, and Mitsubishi Fuso build their commercial vehicles to UN R155 and UN R156 to meet Japan’s own regulatory requirements; Korean commercial OEMs face parallel requirements at home. European commercial OEMs (Mercedes-Benz, Scania, Volvo, DAF, MAN) carry the same documentation from EU obligations. Those vehicles arrive in ASEAN already certified, having earned that certification in their home markets.
Telematics suppliers and fleet system vendors also reference UN R155 and UN R156 in tenders sent to ASEAN buyers. The OEMs those suppliers serve require the evidence, so it becomes part of their standard commercial material. Cybersecurity documentation will accompany vehicle sales in ASEAN much as emissions compliance does today, and more so as UN R155 adoption matures in other markets.
For the ASEAN fleet operator, UN R155 and UN R156 will appear in vehicle specifications and supplier tenders regardless of national adoption. Knowing what the certification actually covers matters, even where the regulation itself does not apply directly.

What UN R155 Doesn’t Reach for Fleet Operators
UN R155 addresses cybersecurity of the vehicle itself; UN R156 addresses the software update mechanisms that maintain it over time [1, 2]. What sits above the vehicle is a different question entirely.
Four categories that UN R155 does not cover:
Aftermarket telematics installed after purchase. If a device modifies the vehicle’s cybersecurity profile, the manufacturer’s CSMS assessment may extend to it in theory, but the confirmation burden falls on the fleet operator and the device supplier. The manufacturer has no obligation to assess something installed after the vehicle left the factory without prior notice.
The fleet management platform itself. A software product connecting to vehicles, typically delivered as SaaS, sits outside UN R155’s reach. The EU’s Cyber Resilience Act, effective December 2027, begins to address this gap in European markets [4]; ASEAN has no equivalent, so general cybersecurity and data protection law applies instead.
Cloud back-ends operated by the fleet operator. UN R155’s Annex 5 Part C covers the OEM’s own back-end infrastructure [1]. Any back-end you or a third-party fleet platform operate falls outside that scope.
Mobile companion apps. Unless the app is directly integrated into the vehicle’s type approval, it is not covered.
The industry frameworks that apply to this fleet management layer are ISO/IEC 27001:2022 [3], the international standard for Information Security Management Systems, and SOC 2, the Service Organization Controls framework covering the five Trust Services Criteria. ISO 27001 is the internationally recognised standard for platforms serving customers across regions; SOC 2 is more common where North American customers are involved [5]. Fleet management platforms with international customer bases often hold both.
For an ASEAN fleet operator, the practical implication is direct: certified vehicles arrive at your yard, but everything above them, from platform to aftermarket devices to personal data, sits under frameworks the certification never touches.
Security-Focused Fleet Operations: A Bolt-On Security Layer Security-focused fleet operations adds GPS spoofing detection, driver behaviour baselines, and AI threat monitoring above the vehicle layer that UN R155 already covers.
The Direct Obligation: PDPA Across ASEAN
Fleet operations generate personal data continuously: driver names, licence numbers, delivery addresses, customer contact details, location trails, and dashcam footage that may show identifiable persons. Each item is regulated at the national level across ASEAN, and this is where fleet operators face their most direct legal obligations.
Singapore. The Personal Data Protection Act 2012, amended in 2021, is administered by the Personal Data Protection Commission (PDPC) [6]. Financial penalties for breaches of the Data Protection Provisions can reach SGD 1 million or 10% of an organisation’s annual Singapore turnover, whichever is higher, following the enhanced framework that took effect on 1 October 2022 [7]. In November 2022, the Singapore High Court awarded SGD 8.7 million in damages to a customer against an IT vendor over a data leak, showing how far vendor liability can extend under the enforcement regime [7].
Malaysia. The Personal Data Protection Act 2010, known as Act 709, is administered by the Personal Data Protection Department [8]. Penalties reach MYR 500,000 in fines and up to three years imprisonment for failure to register with the department, with separate thresholds for other categories of PDPA breach [11]. Notices and consents must be issued in bilingual form covering English and Bahasa Malaysia.

Thailand. The Personal Data Protection Act B.E. 2562 (2019) took effect in June 2022 and is administered by the Personal Data Protection Committee (PDPC Thailand) [9]. A 72-hour breach notification requirement applies. The Act’s reach is explicitly extraterritorial: organisations located outside Thailand are covered if they offer goods or services to Thai data subjects or monitor their behaviour in Thailand.
Vietnam. Data protection is governed by the Law on Personal Data Protection (Law No. 91/2025/QH15), effective 1 January 2026, which replaced Decree 13/2023/ND-CP [10]. The regulator is the Ministry of Public Security’s Department of Cybersecurity and High-Tech Crime Prevention. A 72-hour breach notification requirement applies and extraterritorial reach covers foreign organisations processing personal data of Vietnamese citizens. Administrative fines can reach 10 times the revenue from the violation or VND 3 billion, whichever is higher; for personal data trading, up to 5% of total revenue in Vietnam.
TTMI Cybersecurity as Standard Under PDPA, the fleet operator is the data controller and the platform provider is the data processor. TTMI builds threat detection into SAAN Mobility’s architecture from the outset, covering every product, feature, and data exchange.
UN R155 and UN R156 do not enter this territory. Every part of it is a direct legal obligation on the fleet operator, with enforceable penalties that scale to organisational turnover. A vehicle’s UN R155 certification says nothing about the operator’s PDPA compliance; the two questions are separate.
The Three Layers, Re-stacked
For an ASEAN fleet operator reading a supplier tender, the accurate picture looks like this:
Layer 1: Vehicle and update pipeline. Governed by UN R155 (CSMS) and UN R156 (SUMS). The manufacturer is bound in their home market, and the certified vehicle carries that compliance with it into ASEAN. Not a direct fleet-operator obligation.
Layer 2: Fleet management platform, aftermarket devices, cloud back-end. Governed by ISO/IEC 27001 and SOC 2 as the industry frameworks. The platform provider adopts them by choice, not by ASEAN law. The fleet operator’s role is vendor selection.
Layer 3: Personal data of drivers, customers, and deliveries. Governed by PDPA across ASEAN. This is where the fleet operator’s own direct obligations sit; enforcement runs against the operator, not the platform provider.
So when a supplier claims UN R155 or UN R156 alignment, that statement covers Layer 1 only. At procurement, ask what their Layer 2 posture looks like, and what protections they offer for the personal data they will process on your behalf under Layer 3.
TTMI Cybersecurity Reference Library Regulatory detail on UN R155, UN R156, ISO/SAE 21434, and ISO 27001, and how each shapes fleet cybersecurity.
SAAN Mobility is TTMI’s fleet management platform, aligned with ISO 27001 principles and designed with awareness of UN R155 and UN R156 requirements. For ASEAN fleet operators looking at where their Layer 2 and Layer 3 obligations meet the platform they choose, SAAN Mobility is where to start.
References
[1] UNECE, "Addendum 154: UN Regulation No. 155, Uniform provisions concerning the approval of vehicles with regards to cyber security and cyber security management system," entry into force 22 January 2021. https://unece.org/sites/default/files/2023-02/R155e%20(2).pdf
[2] UNECE, "UN Regulation No. 156: Software Update and Software Update Management System," 2021.
[3] ISO/IEC 27001:2022, "Information security, cybersecurity and privacy protection: Information security management systems: Requirements," International Organization for Standardization, 2022.
[4] Automotive IQ, "EU Cyber Resilience Act Explained for Automotive: What Changes for Connected Vehicles?", May 2026. https://www.automotive-iq.com/cybersecurity/articles/automotive-cyber-resilience-act-explained-what-changes-for-connected-vehicles
[5] StrongDM, "ISO 27001 vs. SOC 2: Understanding the Difference," October 2025. https://www.strongdm.com/blog/iso-27001-vs-soc-2
[6] Parliament of Singapore, Personal Data Protection Act 2012 (as amended 2021). https://sso.agc.gov.sg
[7] Data Protection Report (Norton Rose Fulbright), "A Look Back On Five Key Developments in Cybersecurity and Data Protection in Southeast Asia in 2022," January 2023. https://www.dataprotectionreport.com/2023/01/a-look-back-on-five-key-developments-in-cybersecurity-and-data-protection-in-southeast-asia-in-2022/
[8] Parliament of Malaysia, Personal Data Protection Act 2010 (Act 709). https://www.agc.gov.my
[9] Royal Thai Government, Personal Data Protection Act B.E. 2562 (2019). Effective 1 June 2022.
[10] National Assembly of Vietnam, Law on Personal Data Protection (Law No. 91/2025/QH15). Effective 1 January 2026. Superseded Decree 13/2023/ND-CP of 17 April 2023.
[11] Rouse, "Data Localisation and Transfer Issues in Southeast Asia: What Businesses Need to Know," September 2025. https://rouse.com/insights/news/2025/data-localisation-and-transfer-issues-in-southeast-asia-what-businesses-need-to-know



Comments