CarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Notification
  • Autonomous Driving
  • Automotive Ethernet
  • BMS
  • ECU
  • EV
  • ISO/SAE 21434
  • Infotainment
  • OTA Updates
  • OBD-II
  • Pwn2Own
  • RCE
  • SDVs
  • TCU
  • UNECE R155
Cybersecurity

Boston police tested Motorola and Axon readers as Flock exited

Cybersecurity

Leapmotor EVs carry cameras from a supplier Australia banned

Policy & Compliance

BYD rewrites Australian privacy policy after Four Corners questions

Cybersecurity

A passwordless port let a researcher command a moving BYD ute

Font ResizerAa
CarThreatCarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Sign In Sign In
Follow US
© 2026 Carthreat.com. All right reserved.
Policy & Compliance

EU incident reporting rules for car add-ons take effect September 11

Type-approved vehicles escape the EU Cyber Resilience Act, but telematics boxes and retrofit gear bolted on later face its fast incident reporting from September 11.

CarThreat Staff
Last updated: September 6, 2026 8:59 pm
By
ctadmin
2 Min Read
SHARE

Next Friday, the EU Cyber Resilience Act starts demanding fast incident reports from digital vehicle parts, and the exemption many automakers assumed covers their whole product line stops well short of it. Article 2(2)(c) carves out vehicles type-approved under Regulation (EU) 2019/2144, the framework that made UN R155 and R156 compulsory for EU certification. Parts sold apart from that approval are a different story.

Separate products lose the vehicle’s shield once they leave the factory configuration, Automotive IQ’s new analysis warns. A telematics gateway or fleet box fitted after registration connects to a CAN bus whose security was assessed for type approval, yet that pedigree does not transfer. Retrofit hardware such as route optimization units, driver monitors and reefer refrigeration telemetry lands in CRA scope too, along with EV charging stations and standalone diagnostic tools that never qualified for the vehicle rules.

Once in scope, timelines move fast. An actively exploited vulnerability must reach ENISA as an early warning within 24 hours, a fuller notification follows inside 72 hours, and a final report is due within 14 days.

Trucks and buses complicate the boundary. A chassis maker, a body builder and a telematics vendor may each hold a separate slice of one vehicle’s digital architecture, and only the slice inside the 2019/2144 approval escapes CRA duties. Automotive IQ’s yardstick: a component sold on its own invoice line, outside the approved build, is in scope however tightly it later integrates with the vehicle.

The new rhythm clashes with how commercial vehicle security teams work. Most built incident response around R155’s scheduled audits, documentation-heavy and reviewed on a calendar. CRA notifications are event-driven, so an exploited flaw in a telematics product found late on a Friday starts the clock immediately, with no queue slot waiting for Monday’s triage.

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
TAGGED:Connected VehiclesCybersecurityISO/SAE 21434RegulationsSoftware-Defined Vehicles (SDVs)UNECE R155
SOURCES:Automotive IQ
Share This Article
Facebook Email Copy Link

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

You Might Also Like

PCA finds 345 auto vulnerabilities as high-severity flaws double
Cybersecurity

PCA finds 345 auto vulnerabilities as high-severity flaws double

By
ctadmin
August 1, 2026
Cybersecurity

Qualcomm critical Wi-Fi flaw reaches car cockpit chips

By
ctadmin
August 7, 2026
Cybersecurity

Ford sued over key fobs a laptop can clone

By
ctadmin
September 14, 2026
Anime illustration of a highway plate reader camera sweeping a scan beam over blank falling documents
Policy & Compliance

California leaves plate reader rules dead for a fifth straight year

By
ctadmin
September 3, 2026
Cybersecurity

Slimmed-down AI detector lifts CAN bus replay attack catch rate

By
ctadmin
August 13, 2026
Cybersecurity

Automotive Cybersecurity Market Forecast Predicts $3.14 Billion by 2033 as Connected Vehicle Risks Mount

By
ctadmin
June 19, 2026

CarThreat

Intelligence for the EV and automotive security market
  • News
  • Features
  • Spotlight
  • Events
  • About Carthreat
  • Our Mission
  • Services
  • Contact Us
  • OBD-II
  • Automotive Ethernet
  • TCU
  • Infotainment Systems
  • SDVs
  • BMS
  • ECU Security
  • CAN Bus
  • Threat Intelligence
  • Cybersecurity
  • Digital Keys
  • Bluetooth Security
  • OTA Updates
  • Vulnerabilities
  • Relay Attacks
  • RCE
  • Data Privacy
  • EVs
  • Autonomous Driving
  • Pwn2Own Automotive
  • ISO/SAE 21434
  • UNECE R155
  • Regulations

© 2026 Carthreat.com. All right reserved.  Privacy Policy | Legal

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?