The center of gravity in connected-vehicle certification has clearly moved from nice-to-have to pre-market access in recent years. Before, pass if you can; now, without meeting conditions you get no announcement and no launch. 2026 is a key node — several domestic mandatory national standards land and international-regulation contracting parties grow, so knowing what is mandatory is essential.
1. Domestic mandatory national standards land
GB 44495 (information security), GB 44496 (software update), and GB 44497 (automated driving data recording, DSSAD) are three mandatory standards with different execution rhythms. Amendment No. 1 pushes the mandatory node for GB 44495 and GB 44496 on newly type-approved models to 1 July 2026; GB 44497 still follows 1 January 2026 and applies only to M/N category vehicles with automated-driving function (L3 and above) — ordinary connected cars are not forced. Already-announced models have their own remediation nodes, not a single一刀切 date. All three are hard announcement gates; miss one and access fails.
2. International regulations expand
Under UN WP.29, R155 (cybersecurity management) and R156 (software update) are adopted by about 54 contracting parties and growing. R155 is the access basis for the EU, Japan, Korea, etc., but not all Gulf states adopt R155 — some still use local equivalence or transition arrangements, so do not treat it as a uniform ticket. R155/R156 and domestic standards are not mutually recognized; you cannot replace domestic announcement compliance with R155, but process evidence like asset inventories, TARA threat analysis, CSMS, vulnerability management, and change processes can be heavily reused on both sides — only domestic difference clauses (three-channel notice, driving-block, national cryptography) need difference assessment, not two full redos.
二、What is becoming mandatory
The first class is cybersecurity management system and type approval, mapping to R155 and domestic GB 44495. Any connected, OTA-capable vehicle basically cannot avoid it — moved from OEM-optional to pre-access.
1. Software-update compliance
R156 and GB 44496 govern the full OTA process: every update must be notifiable, rollable-back, traceable. GB 44496 prohibits undisclosed silent updates; non-safety, user-confirmed updates are still allowed. Every vehicle's update record must be kept — part of the birth certificate, not optional.
2. Automated-driving data recording
GB 44497 is the DSSAD (automated driving data recording system), not ordinary EDR. EDR captures physical data at the crash instant; DSSAD records decisions and states throughout the automated-driving activation for liability definition. Internationally there is a corresponding EDR regulation; the two are positioned differently and must not be conflated. For L3+ models this is already mandatory, moving from suggestion to requirement.
三、EU wireless cybersecurity is a new gate
In-vehicle modules with wireless function exported to the EU must pass RED Article 3.3(d)(e)(f) and EN 18031, mandatory from August 2025. Here separate the scenarios: when a module is integrated with the whole vehicle and covered by the OEM's R155 whole-vehicle compliance, it does not separately run RED + EN 18031; only when the module is sold as a standalone wireless product and placed on the market separately does it fall into RED + EN 18031. Whether a car communication module or T-Box needs separate assessment first depends on its shipping form.
1. Cyber Resilience Act boundary
The EU CRA targets full-lifecycle product security. A complete vehicle that has passed R155 whole-vehicle type approval is wholly exempt from CRA; CRA governs separately placed in-vehicle digital components, standalone modules, and aftermarket accessories. The whole vehicle is not directly hit by CRA; carmakers should focus on standalone-sold in-vehicle parts, considering both at design stage.
四、Data sovereignty and privacy compliance
Faces, voiceprints, location, and driving habits collected in the car are all personal information. Entering China needs the PIPL; exporting to Europe needs the GDPR. Cross-border data is independent of technical regulation; privacy problems block as surely as technical failure — an unavoidable export step.
1. Data-export security assessment
Domestic rules require security assessment for important-data export; the carmaker's cloud and app data architecture must be considered at design stage. Patching after freeze means changing the cloud, harder than changing the car, and this compliance cost only rises — plan early.
五、Battery and ESG become new variables
Battery passport and carbon-footprint disclosure are battery-level compliance obligations, not whole-vehicle announcement or type-approval items. The battery passport becomes mandatory under the battery regulation from February 2027; carbon footprint is mainly declarative disclosure for now and not yet a hard whole-vehicle access gate. The EU pushes ESG indicators toward mandatory; carmakers can treat it as a potential variable but need not schedule it as whole-vehicle certification now.
1. Software-defined vehicle security testing
Vehicles rely more on software and remote updates; security-left-shift, intrusion detection, and full-lifecycle vulnerability management move from optional to baseline. Patching after freeze leaves almost no architecture room — plan early.
六、How companies should deploy
Do domestic standards and UN regulations together; much testing and documentation can be reused across borders. BlueAsia does connected-vehicle data security and multi-country access coordination; GB standards with R155/R156 can be assessed together, unified planning saving resources versus separate tracks, compressing the overall compliance cycle for cross-border carmakers.
1. Do not patch at the node
Security-left-shift is not empty talk; at kickoff put layered defense, intrusion detection, and vulnerability management in. These are now baseline; patching after freeze doubles cost and the vehicle program has little room. BlueAsia reminds you to see the nodes clearly before deploying.
七、Common misjudgments
Thinking passing R155 automatically satisfies the domestic announcement — wrong, the national standard has finer local requirements and both documents must land; but you need not fully redo two sets, process evidence is reusable. Thinking group standards are non-mandatory so no alignment — wrong, supply-chain audits often use them as reference; misalign and you lose orders.
1. Do not mix privacy and technical
Technical compliance passes but privacy violation still gets fined and delisted. Data compliance is a separate line, implemented separately per market, and designed separately technically — both lines must pass, no assumptions.
BlueAsia provides intelligent connected vehicle data-security and multi-country access coordination, and can assess GB standards together with R155/R156 in one pass, compressing the overall compliance cycle for cross-border carmakers.
Contact: King
Email: king.guo@cblueasia.com
Address: Building C, Hongjingda Industrial Park, No. 107 Beihuan Road, Shiyan Street, Bao'an District, Shenzhen, China
BlueAsia delivers more than service!
相关新闻