CRA for Automotive Suppliers: UN R155/R156 and Aftermarket

How the CRA applies to automotive suppliers and aftermarket parts: the vehicle type-approval exemption, ISO/SAE 21434 alignment, and which components need CRA.

CRA Evidence Team Published January 11, 2026 Updated July 6, 2026
CRA for Automotive Suppliers: UN R155/R156 and Aftermarket
In this article

The automotive industry has its own cybersecurity regulations, specifically UN R155 (CSMS) and R156 (SUMS) for vehicle type approval. However, many automotive-related products still fall under CRA. Understanding which regulation applies is essential for OEMs, tier suppliers, and aftermarket product manufacturers.

This guide clarifies CRA applicability for automotive products.

Summary

  • Vehicles covered by Reg (EU) 2019/2144 type-approval (M, N, O categories) are exempt from CRA under Art 2(2)(c); following UN R155/R156 alone does not exempt a product
  • Components integrated into type-approved vehicles at production are covered by that exemption
  • Aftermarket products (dash cams, OBD dongles, charging equipment) typically need CRA compliance
  • Spare parts may be exempt if they're replacement parts for original components
  • ISO/SAE 21434 provides strong foundation for CRA where it applies

The Automotive Exemption in CRA

What the CRA Says

CRA Article 2(2) exempts certain motor vehicle products:

"This Regulation does not apply to products with digital elements to which the following Union legal acts apply: (c) Regulation (EU) 2019/2144." (Article 2(2))

Key exemption (Art 2(2)(c)): The exemption applies to products to which Reg (EU) 2019/2144 applies, meaning whole vehicles type-approved under the EU framework (M, N, and O categories) and components covered by that type-approval. The EU type-approval framework implements UN R155/R156 for those vehicle categories. Following UN R155/R156 does not by itself exempt a product from CRA. Standalone aftermarket connected products are generally in CRA scope, subject only to the identical spare-part carve-out.

Why the Exemption Exists

UN R155 and R156 already require:

  • Cybersecurity management system (CSMS)
  • Software update management system (SUMS)
  • Type-approval cybersecurity assessment
  • Ongoing cybersecurity monitoring

The EU avoided double regulation by exempting type-approved automotive products from CRA.

Understanding What's Exempt

Type-Approved Vehicles and Components

EXEMPT from CRA:

Product or channelCRA statusWhy
Complete vehiclesExemptPassenger cars, buses, trucks and trailers covered by vehicle type approval.
OEM components fitted to new vehiclesExempt when covered by type approvalECUs, OEM infotainment, ADAS, telematics, navigation, body control modules and gateway ECUs can be covered through the vehicle approval.
Spare parts replacing original partsExempt when the specification is the sameReplacement ECUs and original equipment replacement parts need a documented exemption basis.

Products NOT Exempt (CRA Applies)

Product or channelCRA statusExamples
Aftermarket connected productsCRA appliesDash cameras, OBD-II dongles, GPS trackers, third-party infotainment, smartphone integration, alarms and tuning devices.
Charging infrastructureCRA appliesEV charging stations, home charging equipment, charging management software and smart charging controllers.
Fleet managementCRA appliesRetrofit telematics, fleet tracking, driver behaviour monitoring and asset tracking equipment.
AccessoriesCRA appliesAftermarket tyre pressure monitors, diagnostic tools, automotive WiFi hotspots and aftermarket connected features.

The Tier Supplier Question

Are Tier 1/2/3 Suppliers Exempt?

It depends on how the component is sold:

1. OEM channel

Component to OEM to type-approved vehicle. The component is covered by the vehicle type approval, and UN R155/R156 apply through the OEM. CRA does not apply directly to the supplier, but the OEM will still require CSMS evidence.

2. Repair market

Component to distribution to end user or workshop. The product is outside the type-approval process, so CRA applies to you as manufacturer.

3. Dual-use components

The same component is sold to OEM and aftermarket channels. OEM supply may be covered by type approval. Aftermarket supply needs CRA. Separate product variants may be the cleaner route.

OEM Requirements Flow Down

Even if CRA doesn't apply directly, OEMs will require cybersecurity evidence:

UN R155 requires OEMs to:

  • Identify and manage supplier risks.
  • Ensure supplier cybersecurity capabilities.
  • Verify supplier processes.

This typically means:

  • CSMS evidence requirements.
  • ISO/SAE 21434 compliance requests.
  • Security assessments and audits.
  • Vulnerability handling agreements.
  • SBOM requirements, increasingly.
Practical outcome

Even without a direct CRA obligation, you will need similar capabilities to supply automotive OEMs.

ISO/SAE 21434 and CRA Alignment

What Is ISO/SAE 21434?

ISO/SAE 21434 "Road vehicles: Cybersecurity engineering" is the automotive cybersecurity standard covering:

  • Cybersecurity management
  • Risk assessment methodology
  • Product development
  • Production and operations
  • Incident response

ISO/SAE 21434 ↔ CRA Mapping

For aftermarket products where CRA applies:

CRA Requirement ISO/SAE 21434 Coverage Gap?
Security by design Clause 10-11 (development) Strong
Risk assessment Clause 8 (TARA) Strong
Vulnerability handling Clause 13 (incident response) Strong
Security updates Clause 12 (production/ops) Partial
No known vulnerabilities Clause 13 Process aligned
Access control Covered in TARA outcomes Strong
SBOM Not explicitly required Gap
ENISA reporting Not covered Gap
CE marking Not covered Gap
Support period (at least 5 yrs, longer for long-life components) Not specified Gap

Using ISO/SAE 21434 for CRA

ISO/SAE 21434  CRA COMPLIANCE

IF you have ISO/SAE 21434 implementation:
 Strong technical security foundation
 Reuse threat analysis and risk assessment
 Leverage development process evidence
 Use incident response capabilities

ADDITIONAL FOR CRA:
[ ] SBOM generation (not in ISO 21434)
[ ] ENISA reporting capability
[ ] CE marking process
[ ] Support period commitment (at least 5 years per Art 13(8); must reflect expected use time; longer for long-life vehicle components)
[ ] Consumer documentation (if applicable)

Aftermarket Products Deep Dive

Dash Cameras and DVRs

DASH CAMERA CRA COMPLIANCE

CLASSIFICATION: Typically Default category

APPLIES BECAUSE:
- Not part of type-approved vehicle
- Sold directly to consumers/fleet operators
- Aftermarket installation

KEY REQUIREMENTS:
- Secure by default (WiFi, Bluetooth)
- Privacy protection (video data)
- Update mechanism
- No default passwords
- SBOM for firmware
- Support period of at least 5 years (Art 13(8)); must reflect expected use time and can exceed 5 years for long-life vehicle components

ADDITIONAL CONSIDERATIONS:
- Video privacy (GDPR alignment)
- Cloud storage security (if applicable)
- App security (companion apps)

OBD-II Devices

OBD-II DONGLE CRA COMPLIANCE

CLASSIFICATION: Potentially Important Class I
(interface with vehicle systems)

APPLIES BECAUSE:
- Aftermarket product
- Connects to vehicle but not type-approved
- Consumer/fleet market

KEY REQUIREMENTS:
- Vehicle network security (critical!)
- Data protection (vehicle data is sensitive)
- Secure communication
- No unauthorized vehicle commands
- Firmware security
- SBOM

SPECIAL CONSIDERATIONS:
- Access to safety-critical networks
- Potential vehicle immobilization risks
- Insurance and liability implications
- Consider industry guidelines (SAE J3061)

EV Charging Equipment

EV CHARGING STATION CRA COMPLIANCE

CLASSIFICATION: Default (Module A) unless a specific
core function maps to an Annex III/IV item. A product
is Important only where it has the core functionality
of an Annex III category (Art 7(1)). There is no
"energy infrastructure" class in Annex III.

APPLIES BECAUSE:
- Not part of vehicle type-approval
- Separate infrastructure product
- Digital connectivity

KEY REQUIREMENTS:
- Grid security (energy infrastructure)
- Payment security (if applicable)
- Communication protocol security (OCPP)
- Physical security
- Update mechanism
- SBOM

STANDARDS ALIGNMENT:
- IEC 61851 (EV charging)
- OCPP security guidelines
- Smart grid standards
- CRA essential requirements

Fleet Telematics

FLEET TELEMATICS CRA COMPLIANCE

CLASSIFICATION: Default or Important Class I

APPLIES BECAUSE:
- Retrofit/aftermarket installation
- Not type-approved with vehicle
- Separate product

KEY REQUIREMENTS:
- Vehicle data protection
- Location privacy
- Communication security
- Management platform security
- Device firmware security
- SBOM

COMMERCIAL CONSIDERATIONS:
- B2B product (may affect documentation)
- Fleet customer requirements
- Integration with fleet management platforms

Spare Parts Considerations

When Are Spare Parts Exempt?

SPARE PARTS ANALYSIS

EXEMPT (Likely):
- Direct replacement for OEM part
- Same specification as original
- Sold as replacement for type-approved vehicle
- Maintains vehicle's type-approval status

NOT EXEMPT:
- Upgraded/enhanced versions
- Different specifications
- Not matching original approval
- Performance modifications

GRAY AREA:
- Remanufactured parts
- Third-party equivalent parts
- Parts with software changes

RECOMMENDATION:
Document the exemption basis clearly.
If in doubt, consider CRA compliance.

Practical Compliance Paths

For Aftermarket Product Manufacturers

AFTERMARKET PRODUCT CRA PATH

ASSESSMENT:
[ ] Confirm not covered by type-approval
[ ] Classify per CRA categories
[ ] Identify applicable standards

COMPLIANCE APPROACH:
[ ] Leverage ISO/SAE 21434 if already implemented
[ ] Implement CRA essential requirements
[ ] Generate SBOM
[ ] Establish vulnerability handling
[ ] Prepare Article 14 reporting from 11 September 2026, including for in-scope products already on the market

DOCUMENTATION:
[ ] Technical file
[ ] Risk assessment
[ ] User documentation
[ ] Declaration of Conformity
[ ] CE marking

For Tier Suppliers with Dual Channels

TIER SUPPLIER WITH OEM + AFTERMARKET

STRATEGY 1: Separate Products
- OEM variant: supply under type-approval flow
- Aftermarket variant: CRA compliant
- Clear product differentiation

STRATEGY 2: CRA Compliance for All
- Apply CRA to all variants
- Exceeds OEM requirements anyway
- Simplified compliance management
- Single product documentation

STRATEGY 3: Tiered Approach
- Base security for all (ISO 21434)
- Additional CRA elements for aftermarket
- Shared core documentation

For OEMs Managing Supplier Requirements

OEM SUPPLIER MANAGEMENT

UN R155 REQUIREMENTS:
- Verify supplier cybersecurity capabilities
- Assess supplier processes
- Monitor supplier risks

PRACTICAL APPROACH:
- Require ISO/SAE 21434 compliance
- Request security assessment evidence
- Include SBOM requirements in contracts
- Establish vulnerability sharing agreements
- Define incident notification requirements

ALIGNMENT WITH CRA:
Even though CRA doesn't apply to type-approved
components, requiring CRA-like evidence from
suppliers strengthens your UN R155 compliance

Industry Standards and Resources

Relevant Standards

AUTOMOTIVE CYBERSECURITY STANDARDS

ISO/SAE 21434: Road vehicles - Cybersecurity engineering
UN Regulation 155: Cybersecurity (CSMS)
UN Regulation 156: Software Update (SUMS)

SUPPORTING STANDARDS:
ISO/SAE 8000: CSMS auditing
ISO 24089: Software Update Engineering
AUTOSAR cybersecurity specifications
SAE J3061: Cybersecurity Guidebook

CHARGING-SPECIFIC:
IEC 61851: EV charging
OCPP (Open Charge Point Protocol)
ISO 15118: V2G communication

Industry Organizations

Organization Focus Website
Auto-ISAC Threat intelligence sharing automotiveisac.com
CLEPA European automotive suppliers clepa.eu
VDA German automotive vda.de
ACEA European automobile manufacturers acea.auto
ChargePoint EV charging industry chargepoint.com

Checklist for Automotive Products

AUTOMOTIVE PRODUCT CRA CHECKLIST

CLASSIFICATION:
[ ] Is product covered by type-approval? (Exempt if yes)
[ ] Is it an aftermarket product? (CRA applies)
[ ] Is it a spare part? (Assess exemption basis)
[ ] Is it charging infrastructure? (Usually CRA)

IF CRA APPLIES:
[ ] CRA classification determined
[ ] Conformity assessment path selected
[ ] Technical documentation prepared

TECHNICAL COMPLIANCE:
[ ] ISO/SAE 21434 alignment used
[ ] Security-by-default implementation
[ ] Vehicle network security (if applicable)
[ ] Update mechanism
[ ] SBOM generation
[ ] Vulnerability handling

DOCUMENTATION:
[ ] Risk assessment (TARA methodology works)
[ ] Security architecture
[ ] User documentation
[ ] Declaration of Conformity
[ ] CE marking

SPECIAL CONSIDERATIONS:
[ ] Vehicle data privacy (GDPR)
[ ] Safety implications assessed
[ ] OEM requirements (if supplying)

Key Resources

AUTOMOTIVE CYBERSECURITY RESOURCES

REGULATIONS:
UN Regulation 155 (CSMS)
UN Regulation 156 (SUMS)
https://unece.org/transport/vehicle-regulations

EU Type-Approval:
Regulation (EU) 2018/858
https://eur-lex.europa.eu

STANDARDS:
ISO/SAE 21434:2021
Available from ISO or SAE

GUIDANCE:
ENISA Good Practices for Security of Smart Cars
Auto-ISAC Best Practices

INDUSTRY:
CLEPA Position Papers
VDA Automotive Cybersecurity

Important: Vehicles are exempt from CRA (covered by UN R155/R156). However, aftermarket accessories, diagnostic tools, and connected services ARE in scope.

Tip: If you supply components to automotive OEMs AND sell aftermarket products, you may need CRA compliance only for the aftermarket line.

Related guides:

How CRA Evidence Helps

For aftermarket automotive products requiring CRA compliance:

  • ISO/SAE 21434 mapping: Leverage existing automotive security work
  • SBOM for embedded: Support for automotive firmware components
  • Vulnerability tracking: Automotive supply chain coordination
  • Multi-product management: Handle product families across channels
  • Technical file generation: Automotive-appropriate templates

Start your CRA compliance at craevidence.com.


This article is for informational purposes only and does not constitute legal advice. For specific compliance guidance, particularly regarding type-approval boundaries, consult with qualified regulatory counsel.

CRA Automotive
Share

Does the CRA apply to your product?

Answer 6 simple questions to find out if your product falls under the EU Cyber Resilience Act scope. Get your result in under 2 minutes.

Ready to achieve CRA compliance?

Start managing your SBOMs and compliance documentation with CRA Evidence.

Deep dive into CRA topics

Evergreen guides covering the specific requirements, processes, and roles defined by the Cyber Resilience Act.