Independent information resource Product security · EU CRA
CRA and overlapping EU regulation / 08

Cyber Resilience Act and Automotive Cybersecurity

How the Cyber Resilience Act interacts with Regulation (EU) 2019/2144 on vehicle general safety and mandatory vehicle cybersecurity requirements, including the CRA Article 2 exclusion, UN Regulation No 155, cybersecurity management systems, software updates, type approval and product boundaries.

IN BRIEF

The CRA automotive exclusion is product-specific. Regulation (EU) 2019/2144 introduces mandatory cybersecurity requirements within vehicle type approval, including lifecycle organisational processes, protection against cyberattacks and software-update controls through the applicable UN regulatory framework. The key boundary question is whether the particular product with digital elements is one to which Regulation (EU) 2019/2144 applies. A supplier's tool, backend, diagnostic product or standalone component should not be assumed excluded merely because its customer is a vehicle manufacturer.

01 / 11

CRA Article 2 Expressly Excludes Products Covered by Regulation (EU) 2019/2144

CRA Article 2(2)(c) excludes products with digital elements to which Regulation (EU) 2019/2144 applies. This means the covered vehicle product follows the automotive type-approval cybersecurity framework rather than CRA product conformity for the same regulated product.

02 / 11

CRA Recital 27 Explains the Automotive Cybersecurity Framework

Recital 27 points to Regulation (EU) 2019/2144 and its type-approval cybersecurity requirements, including a certified cybersecurity management system and software-update controls across the lifecycle of vehicles, equipment and services. It specifically references UN Regulation No 155 as part of the technical cybersecurity framework.

03 / 11

Regulation (EU) 2019/2144 Requires Protection Against Cyberattacks

The General Safety Regulation requires vehicles, systems, components and separate technical units to comply with applicable Annex II requirements, including requirements concerning protection against unauthorised use and cyberattacks. Cybersecurity is therefore embedded in vehicle type approval rather than being left to general corporate IT controls.

04 / 11

UN Regulation No 155 Uses a Cybersecurity Management System

The automotive framework requires manufacturers to manage cybersecurity through documented organisational processes across the vehicle lifecycle and to demonstrate that vehicle types are protected against identified cyber risks. This management-system and type-approval structure differs from the CRA product-conformity model even though both address lifecycle cybersecurity.

05 / 11

Software Updates Are Part of the Automotive Regulatory Model

Vehicle connectivity and over-the-air software changes create risks of unauthorised modification and altered vehicle functionality. The EU automotive framework therefore incorporates specific software-update requirements alongside cybersecurity requirements. Vehicle software maintenance should be managed through that type-approval system for covered products rather than through CRA security-update obligations.

06 / 11

The Exclusion Does Not Automatically Cover Every Automotive Supplier Product

CRA Article 2(2)(c) follows products to which Regulation (EU) 2019/2144 applies. A standalone software tool, cloud service, workshop product, aftermarket device or supplier component can require a separate legal analysis. Selling into the automotive sector is not itself enough to create the exclusion.

07 / 11

Separate the Vehicle Type-Approval Boundary From the Corporate System Boundary

A vehicle manufacturer may operate development platforms, backend services, internal tools and supplier portals that are not themselves products covered by vehicle type approval. Each externally supplied product with digital elements should be mapped to determine whether the automotive exclusion applies or whether CRA scope remains possible.

08 / 11

L-Category Vehicle Cybersecurity Has Been Brought Into the Sectoral Framework

The EU has extended mandatory UN Regulation No 155 cybersecurity requirements to a broad range of L-category vehicles through the relevant type-approval framework, with new vehicle types subject from 11 December 2027 and existing vehicle types from 11 June 2029. This sectoral development is intended to maintain the automotive exclusion logic as cybersecurity coverage expands.

09 / 11

Supplier Evidence May Support the Vehicle Manufacturer's Type Approval

Vehicle manufacturers can depend on suppliers for software inventories, interface descriptions, vulnerability information, test evidence and update records. A supplier may therefore need to provide substantial cybersecurity evidence even where the final vehicle is outside CRA scope. The supplier's own product obligations still depend on its separate legal classification.

10 / 11

Do Not Treat CRA Exclusion as an Exemption From Lifecycle Security

The automotive exclusion exists because a sector-specific cybersecurity and type-approval framework already applies. Vehicle manufacturers still need lifecycle cyber-risk processes, vulnerability monitoring, software-update governance and evidence supporting type approval and continuing compliance.

11 / 11

Document Exactly Which Product Receives the Automotive Exclusion

The compliance record should identify the vehicle, system, component or separate technical unit, explain how Regulation (EU) 2019/2144 applies and cite CRA Article 2(2)(c). Related supplier products and digital services should be listed separately so the exclusion is not accidentally extended beyond its legal product boundary.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.