AIS-189 vs UN R155: a clause-level comparison
Where India's AIS-189 follows UN R155 and where the Indian route differs — for teams carrying both files
The short answer
AIS-189 is aligned to UN R155, so the two agree on almost everything an engineering team cares about: a Cyber Security Management System that is assessed, a maintained threat analysis, risk treatment, supplier flow-down, and monitoring after launch. Where they differ is not in the technical bar but in the legal machinery — who issues the standard, who assesses against it, and how the resulting approval is recognised. If you are carrying both files, the work is largely shared; the paperwork and the venue are not.
Same substance
Both standards require a CSMS rather than a document, and both expect the same building blocks:
- Governance and a named owner of the CSMS.
- A risk-assessment method (TARA), kept current per vehicle type.
- Treatment of the threats catalogued in R155 Annex 5.
- Cybersecurity requirements traced through to verification.
- Flow-down of requirements and evidence to Tier-1 and Tier-2 suppliers.
- Detection, response and monitoring across post-production.
In each case ISO/SAE 21434 supplies the practical detail. A team that has built a genuine R155 CSMS has, in engineering terms, done the bulk of AIS-189, and vice versa. This is why we describe the two as one route with two certificates in AIS-189 explained.
Where the routes diverge
The differences are institutional. They matter for planning, cost and recognition — not for how you engineer the vehicle.
| Dimension | UN R155 | AIS-189 |
|---|---|---|
| Type of instrument | UNECE regulation under the 1958 Agreement | Indian national standard (AIS) under the CMVR |
| Issued / maintained by | UNECE WP.29 | ARAI for the AISC under the CMVR-TSC |
| Underlying engineering | ISO/SAE 21434 | ISO/SAE 21434 |
| CSMS certificate | Certificate of Compliance, valid 3 years, plus per-vehicle-type approval | Assessed under the Indian regime |
| Who assesses | Approval authority / technical service in a Contracting Party | Indian test agency named under the CMVR, meeting the AIS-189 competence clause |
| Recognition | Travels among UNECE Contracting Parties | Confers Indian approval |
| Enforcement dates | EU: new types 6 Jul 2022; all new vehicles 7 Jul 2024 (via GSR (EU) 2019/2144) | India: draft G.S.R. 503(E) — phased Oct 2026 → Oct 2029, not yet final |
| Software-update sibling | UN R156 | AIS-190 |
Two lines in that table deserve emphasis.
Recognition does not cross over. A UNECE approval travels among Contracting Parties because they have all acceded to the same regulation. India runs its own regime, so an Indian approval confers Indian approval and a UNECE approval is what UNECE markets require. Neither substitutes for the other, which is why exporters carry both.
Dates. R155 dates have already bitten in the EU. AIS-189 enforcement is now proposed in MoRTH draft G.S.R. 503(E) (17 June 2026), which inserts Rule 125-T with a phased timeline from October 2026 — but it is open for public comment and not yet finalised in the gazette. We keep an honest running status in India's automotive cybersecurity timeline; the short version is: plan against the draft schedule, but build to capability, because the draft can still move.
The Certificate of Compliance and what "valid 3 years" means
Under R155 the CSMS is confirmed by a Certificate of Compliance that is valid for three years, sitting alongside the per-vehicle-type approval. Two certificates, then, do two jobs: one says the organisation runs a compliant management system, the other says a particular vehicle type was developed under it. The three-year validity is a reminder that a CSMS is not a one-time hurdle — it has to keep operating, and it is re-examined. AIS-189, being aligned to R155, carries the same logic of an assessed management system standing behind each type approval rather than a certificate frozen at launch. For a team, the operational consequence is the same on both files: the monitoring, the maintained TARA and the update pipeline have to keep producing records long after the first approval, because both regimes expect the system to be alive.
The competence clause is the sharpest Indian-specific point
One AIS-189 provision has no direct R155 analogue in day-to-day practice: clause 5.3.1 requires the assessing agency to hold automotive cybersecurity and risk-assessment competence of its own. Being named as a test agency under the CMVR does not by itself confer cybersecurity scope. For an OEM this reframes the question "who can assess us?" from a list-membership question to a competence question — the agency in the room needs the domain depth, not only the CMVR listing.
What this means for a team carrying both
- Build the CSMS once. The engineering is shared; do not run two disconnected programmes.
- Plan for two assessments. Budget the venues and the certificates separately, even though the evidence pack overlaps almost entirely.
- Watch RxSWIN and updates together. The cybersecurity file and the software-update file interlock; the same logic applies to the software-update standards, which we compare in AIS-190 vs UN R156.
- Do not wait for the Indian date. Because it is unnotified and the capability takes months, start on your own timeline.
The AutoSifu view
AutoSifu runs both files as one route — compliance, secure solutioning, and CoC/VTA support — so an OEM builds a single CSMS and takes it to the venue each market requires. Working with CIRT as a strategic partner, we keep the approval body in the room from the start, which is the fastest way to close the institutional gap between an R155 approval and an AIS-189 assessment. One programme, two certificates, no duplicated engineering.
Questions
- Is AIS-189 identical to UN R155?
- No. AIS-189 is aligned to UN R155 and follows its structure and intent closely, but it is a distinct Indian national standard assessed within India's own type-approval regime. The differences are mainly institutional — who issues it, who assesses it, and how the approval is recognised — rather than differences in the engineering a CSMS must contain.
- Does an Indian OEM exporting to the EU need both AIS-189 and UN R155?
- In practice, yes. A UN R155 approval is what the EU and other UNECE Contracting Parties require, while AIS-189 governs the Indian regime. Because the two are separate legal instruments issued under different frameworks, a manufacturer selling in both markets generally has to satisfy both, even though the underlying CSMS is largely the same.
- Does a UN R155 approval satisfy AIS-189?
- Not automatically. Holding an R155 CSMS certificate means most of the engineering AIS-189 looks for is already done, but AIS-189 is assessed under the Indian regime by an Indian test agency, so a separate Indian assessment is still required. The reverse is also true: an Indian approval does not itself travel to UNECE markets.
