Part 1 — Automotive Software Security Readiness: A Researcher’s Field Guide

November 12, 2025
November 12, 2025

0 min read

Compliance
Part 1 — Automotive Software Security Readiness: A Researcher’s Field Guide

Are You Ready for UN R155? The Real Work Behind Automotive Software Security Compliance

Modern vehicles are software systems on wheels with over 100 ECUs, millions of lines of code, and globally distributed supply chains.

The UNECE regulations R155 and R156 have transformed cybersecurity and software update management into conditions for type approval.

If you build or secure automotive software, you must be able to prove that you can defend it.

The Regulatory Stack That Matters

Each standard ultimately asks the same question: can you show that your controls work?

Readiness Means Proof, Not Paperwork

A defensible security posture aligns three capabilities:

  1. Governance – ownership, accountability, supplier oversight
  2. Engineering – security embedded in code, updates, and telemetry

Response – measurable incident handling and remediation evidence

Control Mapping — From Mandate to Mechanism

Readiness converts regulatory requirements into verifiable engineering artifacts.

Runtime Proof as the New Baseline

Auditors now seek runtime evidence rather than static compliance documents.

Telemetry, exploitability validation, and continuous monitoring demonstrate control effectiveness in real operating conditions.

This closes Part 1.

Part 2 will examine how runtime analysis and exploit intelligence extend these requirements into measurable proof.

References

  • Applied Intuition. (2023). ISO/SAE 21434: Shaping automotive cybersecurity.
  • Cybellum. (2023). Introduction to automotive cybersecurity regulations.
  • European Commission. (2024). Cyber Resilience Act: Proposal and implementation overview.
  • International Organization for Standardization. (2021). ISO/SAE 21434: Road vehicles – Cybersecurity engineering.
  • National Highway Traffic Safety Administration. (2022). Cybersecurity best practices for the safety of modern vehicles (Report DOT HS 813 417).
  • United Nations Economic Commission for Europe. (2021). UN Regulation No. 155: Cybersecurity and cybersecurity management system requirements.
  • United Nations Economic Commission for Europe. (2021). UN Regulation No. 156: Software update processes and management systems.
  • Verband der Automobilindustrie (VDA). (2023). Trusted Information Security Assessment Exchange (TISAX) Assessment Levels Guide.
Table of contents

Related blogs

Navigating 2026 Secure SDLC Regulations

Navigating 2026 Secure SDLC Regulations

The US made secure development attestation optional in January. The EU starts enforcing 24 hour vulnerability reporting in September. Here is what 2026 actually requires, and what it asks you to prove.

August 12, 2026

12

PCI DSS 4.0 Requirement 6.3.2: Why Your SBOM Isn't Enough Without Runtime Context

PCI DSS 4.0 Requirement 6.3.2: Why Your SBOM Isn't Enough Without Runtime Context

PCI DSS 4.0 compliance Requirement 6.3.2 asks for more than an SBOM. See what runtime evidence QSAs actually want in 2026 audits.

June 11, 2026

7

Your CDE Has Grown. Your Scope Document Hasn't. Here's How to Reconcile the Two.

Your CDE Has Grown. Your Scope Document Hasn't. Here's How to Reconcile the Two.

Your cardholder data environment grew with every BaaS partner and embedded program. See how runtime evidence reconciles scope with reality.

June 11, 2026

6

A Primer on Runtime Intelligence

See how Kodem reads what actually loads and executes in your running applications, and why that changes which findings matter.

See the Kodem platform

Kodem shows which vulnerabilities actually load and execute in your running applications, so your team works the risk that is real.

The State of the Application Security Workflow

This report aims to equip readers with actionable insights that can help future-proof their security programs. Kodem, the publisher of this report, purpose built a platform that bridges these gaps by unifying shift-left strategies with runtime monitoring and protection.

3D book mockup of Kodem's State of the Application Security Workflow 2025 report

Get real-time insights across the full stack…code, containers, OS, and memory

Watch how Kodem’s runtime security platform detects and blocks attacks before they cause damage. No guesswork. Just precise, automated protection.

Kodem issues list with a magnified view of insight icons: runtime, ingress, and exploitability
Combined author
Mahesh Babu
Publish date

0 min read

Compliance