By EJN Labs · 23 Jul 2026 · 8 min read
UN R155 penetration testing is the technical evidence approval authorities expect when a vehicle maker applies for type approval. The regulation requires a certified cyber security management system and proof that the vehicle type has been tested against identified threats. In the UK, the VCA assesses this evidence. Typical UK testing costs run from £6,000 to £28,000 depending on scope.
Why UN R155 penetration testing matters for vehicle makers
UN R155 penetration testing matters because approval authorities will not take a manufacturer’s word that mitigations work. Regulation 155 requires a cyber security management system plus evidence that the specific vehicle type is protected against the threats in its risk assessment.
Independent penetration testing is one of the clearest forms that evidence can take. This is the point where a paperwork exercise becomes an engineering one, and the cyber security management system (CSMS) obligation under UNECE Regulation 155 applies to manufacturers of applicable vehicle types.
For a certification manager or cyber lead inside a vehicle maker, the practical question is rarely “do we need to test” but “what will the authority actually look at”. This post walks through that question for UK approvals, where the Vehicle Certification Agency (VCA) is the approval authority.
The regulatory driver: what UN R155 actually requires
UN R155 is a UNECE regulation, and it is mandatory for applicable vehicle types seeking approval in markets that apply it, including the UK. Approval works in two stages, and both generate scrutiny of your security evidence.
- CSMS certificate. The manufacturer must show it operates a management system covering the full vehicle lifecycle: development, production and post-production. The authority assesses processes for risk identification, risk treatment, testing, and monitoring of new threats and vulnerabilities.
- Vehicle type approval. For each vehicle type, the manufacturer must show that the risks identified in its threat analysis have been mitigated, and that the mitigations have been verified through appropriate and sufficient testing.
The regulation’s annexed threat catalogue lists categories of attack the risk assessment is expected to consider, spanning back-end servers, communication channels, update procedures, external connectivity and the vehicle’s own data and software. It does not prescribe a single test methodology, but its position on testing is explicit: the manufacturer must perform appropriate and sufficient testing to verify the effectiveness of the security measures implemented. In practice, approval authorities and their technical services expect structured technical testing evidence, and penetration test reports against the connected components of the vehicle are the most direct way to provide it.
One honest caveat: R155 mandates that testing happens and that it is adequate; it does not mandate that an external firm performs it. Many manufacturers still commission independent testing, because a report from an accredited third party carries more weight with a technical service, and because internal teams rarely cover embedded, wireless, mobile, API and cloud surfaces in one exercise.
What approval authorities check, and what to test
Approval authorities check whether your testing evidence traces back to the risk assessment. Evidence that lands well has three properties: it maps test cases to identified threats, it covers the attack surfaces the threat catalogue describes, and it shows findings were remediated and retested.
When the VCA or a technical service reviews a type approval submission, the security questions cluster around exactly that traceability.
Mapped onto a modern connected vehicle programme, that translates into testing across four surfaces.
Telematics and connectivity units
The telematics control unit and any connectivity gateway are the vehicle’s external face. Testing covers the cellular, Wi-Fi and Bluetooth interfaces, exposed debug ports, firmware extraction resistance, and whether a compromise of the unit can reach safety-relevant networks inside the vehicle.
Backend platforms and APIs
The threat catalogue treats back-end servers as a first-class attack surface, because they hold fleet data and often push commands and updates to vehicles. API penetration testing against the vehicle-to-cloud interfaces, plus cloud penetration testing of the hosting environment, produces evidence directly aligned to those threat categories.
Companion mobile apps
Remote unlock, pre-conditioning and vehicle status all flow through a mobile app and its authentication chain. Mobile application testing checks whether tokens, pairing flows and stored credentials let an attacker act on a vehicle they do not own.
Software update mechanisms
Update procedures get their own category in the threat catalogue, and they interact with UN R156, the parallel regulation on software update management systems. Testing verifies update packages are authenticated, integrity-checked and cannot be rolled back or substituted in transit.
How an R155-aligned engagement runs
Start from your threat analysis and risk assessment, not a generic checklist. A useful engagement takes the risk assessment output for the vehicle type, the architecture of the connected stack and any prior testing evidence, then builds a test plan whose cases reference your identified threats.
That traceability is what makes the report usable in a type approval file.
Delivery typically runs in phases: scoping and threat mapping, testing against each in-scope surface, a draft report with severity-rated findings, remediation support, and retesting of fixed issues so the final report shows closure. For a wider view of what a structured engagement should include at each stage, our penetration testing checklist sets out the questions to settle before testing starts.
What it costs and how scope drives the price
UK penetration testing is priced by effort, with day rates typically running £1,200 to £1,400. For R155 evidence, price is driven by the number of connected components, whether hardware-level ECU testing is in scope, and how many backend and mobile surfaces sit behind the vehicle.
| Scope | Typical effort | Typical UK cost |
|---|---|---|
| Single connected ECU or telematics unit | 5 to 8 days | £6,000 to £11,200 |
| Companion mobile app plus vehicle APIs | 6 to 10 days | £7,200 to £14,000 |
| Backend cloud platform and update infrastructure | 5 to 9 days | £6,000 to £12,600 |
| Full connected-vehicle stack for a type approval file | 12 to 20 days | £14,400 to £28,000 |
These are typical UK ranges; the quickest way to a firm price is a scoping call. For a broader breakdown of what drives testing prices, see our guide to penetration testing cost in the UK.
How EJN Labs approaches UN R155 testing evidence
EJN Labs is a UK firm delivering CREST-accredited penetration testing with UK-based testers, and we hold Cyber Essentials Plus and ISO 27001 ourselves, so we understand what it means to have evidence assessed by an external authority. When we scope an automotive engagement, we start by walking the connected architecture with your engineering lead: which units talk to the outside world, what the trust boundaries are between the telematics domain and safety-relevant networks, and which backend services can issue commands to vehicles. That conversation usually reshapes the scope, because the riskiest paths are often the integration seams between supplier components rather than any single unit.
Our reports are written for two audiences at once: engineers who need to reproduce and fix findings, and the approval file, where each test case is traced to the threat it exercises. We rate findings by exploitability and vehicle impact, and include retesting so the file shows remediation, not just discovery. Sector-specific evidence expectations run across regulated industries; our work on cyber security for financial services follows the same principle of testing shaped by the regulator’s expectations.
Frequently Asked Questions
Does UN R155 require penetration testing?
Not by name. UN R155 requires the manufacturer to verify, through appropriate and sufficient testing, that the security measures protecting the vehicle type are effective. Independent penetration test reports are, in our experience, the most direct way to provide that evidence.
The regulation does not name penetration testing as the only acceptable method, but structured technical testing evidence is what approval authorities expect to see.
What does UN R155 penetration testing cost in the UK?
Expect £6,000 to £28,000, based on UK day rates of £1,200 to £1,400. A single connected ECU or telematics unit is usually 5 to 8 days (£6,000 to £11,200), while a full connected-vehicle stack for a type approval file runs 12 to 20 days (£14,400 to £28,000).
Component count and hardware access drive the effort.
Who checks UN R155 compliance in the UK?
The Vehicle Certification Agency (VCA) is the UK approval authority. It assesses the manufacturer’s cyber security management system for certification and reviews the vehicle type evidence, including testing results, before granting approval. Technical services acting for the authority may also examine test reports.
That examination can go deep, including how test cases trace back to the manufacturer’s risk assessment.
What should be in scope for R155 testing?
Scope should follow your threat analysis and risk assessment. In most programmes that means the telematics and connectivity units, the vehicle-to-cloud APIs and backend platform, the companion mobile app, and the software update mechanism, with evidence spanning each surface in the threat catalogue.
The regulation’s threat catalogue covers back-end servers, communication channels, update procedures and external connectivity, so testing evidence should span all of those surfaces.
Do component suppliers need their own R155 testing?
No, the approval obligation sits with the vehicle manufacturer, not the supplier. In practice, though, manufacturers pass evidence requirements down the supply chain, so component vendors are increasingly asked to provide testing evidence for their units before integration into the vehicle.
A supplier with an independent penetration test report for its component makes the manufacturer’s approval file stronger and shortens procurement conversations.
Build testing evidence your approval file can stand on
If you are preparing a type approval submission or a supplier evidence pack and need testing that traces to your risk assessment, we can scope it with your engineering team and give you a fixed price. Request a CREST pentesting quote and we will come back with a scoped proposal, or start with our CREST penetration testing service to see how we work.




Leave a Reply