Automotive
TISAX, safety standards, and connected vehicle compliance
The automotive industry faces cybersecurity requirements from TISAX, functional safety standards, and emerging connected vehicle regulations. Thalorin supports automotive companies with compliance infrastructure addressing the full spectrum of automotive cybersecurity from manufacturing to vehicle systems.
Model year 2027 is the one that bites. Under 15 CFR part 791 subpart D, the Bureau of Industry and Security prohibits connected vehicle manufacturers from knowingly importing into or selling within the United States completed connected vehicles incorporating covered software designed, developed, manufactured or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia. The exemption at 15 CFR 791.308 reaches only vehicles manufactured before model year 2027. VCS hardware has longer: model year 2030, or 1 January 2029 for units carrying no model year.
Three regimes assess three different objects, and none accepts another's evidence. UN Regulation 155 is built on a cyber security management system, paired by the Department for Transport with Regulation 156 on software updates, and Great Britain is phasing both into the GB type approval scheme — 1 June 2026 for new vehicle types, 1 June 2027 for complete and incomplete vehicles, 1 June 2028 for completed vehicles under R.155 and 7 July 2029 under R.156. TISAX assesses how one site handles another company's information. BIS asks who wrote the code.
The filing obligation is what catches people. Under 15 CFR 791.305 a connected vehicle manufacturer or a VCS hardware importer must submit a Declaration of Conformity to BIS at least 60 days before the first import or sale of each model year, certifying that the hardware or software was not supplied by a person owned or controlled by, or subject to the jurisdiction or direction of, the PRC or Russia, that due diligence informed the certification, and that supporting documentation is retained. A material change discovered later requires a revised declaration within 60 days.
Three readings, one record. A supplier ownership and jurisdiction file supports the 791.305 certification and answers a demand for reports under 791.313, which BIS may take under oath and which must be retained for ten years. The same component record carries the threat analysis and risk assessment work products ISO/SAE 21434 expects. And each TISAX assessment scope carries its own state: the locations inside it, the objectives it was granted against, and the catalogue version its assessment was ordered under.
Manufacturing faces evolving cyber risks
A declaration due 60 days early
15 CFR 791.305 requires the Declaration of Conformity to reach BIS at least 60 days before the first import or sale of each model year, not alongside it. The certification rests on ownership and jurisdiction facts that take longer to establish.
Model year 2027 is in production now
The covered software exemption at 15 CFR 791.308 ends with vehicles manufactured before model year 2027. Sourcing decisions for those vehicles were locked long before anyone in engineering read the rule.
TISAX labels expire into a new catalogue
VDA ISA2027 published on 1 July 2026 and is the basis for assessments ordered from 2027, with March 2027 the final date to open an initial assessment under ISA 6. Labels run three years, so renewals straddle the change.
A management system, not a part
UN Regulation 155 turns on a cyber security management system the manufacturer holds. A supplier's component evidence does not discharge it, and nothing that management system demonstrates says anything about who owns the firm that wrote the code.
How Thalorin helps
TISAX assessment support
Control state is held per assessment scope — its locations, the assessment objectives granted, and the catalogue version the assessment was ordered under — so a scope on VDA ISA 6.0.3 and one preparing under ISA2027 coexist.
ISO/SAE 21434 compliance
Threat analysis and risk assessment work products, cybersecurity goals and the argument connecting them are held against the item and its components, so the engineering record and the process evidence an R.155 audit reads are one record.
Connected vehicle security
Vehicle-side controls and the software update process are tracked against the type approval they support, including which software versions are approved for which vehicle type under UN Regulation 156.
Manufacturing security
Production sites handling an OEM's confidential information sit inside a TISAX scope of their own, and where pre-series parts and prototype vehicles are built, the proto parts and proto vehicles objectives apply on top of the information security ones.
Supply chain for automotive
Supplier ownership, control and jurisdiction records are maintained as evidence, because that is what the 791.305 certification rests on and what a BIS request for reports under 791.313 would ask you to produce.
Functional safety integration
A cybersecurity change to a safety-related item reopens the safety argument, so the change record carries both, and a patch decision is taken with the ISO 26262 consequence visible rather than discovered at release.
Automotive: common questions
We only import head units. Do we have to file a Declaration of Conformity?
Eventually, and possibly not yet. Under 15 CFR 791.308 a VCS hardware importer is exempt from the declaration requirement while the hardware is associated with a vehicle model year before 2030, or imported in a connected vehicle of a model year before 2030, or brought in for repair or warranty on such a vehicle. For units not associated with any model year, the exemption runs until 1 January 2029. Once a shipment falls outside those conditions, 791.305 applies and the declaration is due 60 days ahead.
Does a TISAX label cover our whole company?
No. A TISAX label attaches to an assessment scope, and the scope names which parts of the company and which locations are inside it, so a supplier running five plants and two engineering offices commonly holds several labels with different objectives and expiry dates. A result is valid for three years. Renewal timing matters more than usual now: VDA ISA2027 published on 1 July 2026 and is the basis for assessments ordered from 2027, so a scope renewing across that line prepares against a different catalogue.
When do we have to move from VDA ISA 6 to ISA2027?
ENX has set March 2027 as the final date to open an initial assessment under ISA 6, and assessments ordered before 1 January 2027 may still be performed against it. VDA ISA2027 published on 1 July 2026 and is the basis for assessments ordered from 2027 onward. In practice a scope whose label expires in late 2027 or later should be building evidence against ISA2027 now, while one completing an ISA 6 assessment before the cut-off carries the older catalogue for three years.
Is ISO/SAE 21434 certification required for type approval?
No. UN Regulation 155 is the regulatory instrument and approval is granted by a type approval authority rather than a standards body; what it turns on is a cyber security management system the manufacturer must hold and demonstrate. ISO/SAE 21434 is the engineering standard the industry uses to produce that evidence in a form approval authorities recognise, and OEMs flow it down contractually. Suppliers are usually asked for the standard, not the approval.
Does UN Regulation 155 apply to vehicles sold in Great Britain?
Yes, and the phasing is already under way. The Department for Transport confirmed in its government response of 16 September 2025 that R.155 and R.156 would be mandated in the GB type approval scheme for new vehicle types from 1 June 2026, for complete and incomplete vehicles from 1 June 2027, for completed vehicles from 1 June 2028 under R.155 and 7 July 2029 under R.156, and for special purpose vehicles from 7 July 2029.
Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.
Talk to us about Automotive.
See how one evidence artifact satisfies Automotive requirements alongside every other framework you carry.