Next Friday, the EU Cyber Resilience Act starts demanding fast incident reports from digital vehicle parts, and the exemption many automakers assumed covers their whole product line stops well short of it. Article 2(2)(c) carves out vehicles type-approved under Regulation (EU) 2019/2144, the framework that made UN R155 and R156 compulsory for EU certification. Parts sold apart from that approval are a different story.
Separate products lose the vehicle’s shield once they leave the factory configuration, Automotive IQ’s new analysis warns. A telematics gateway or fleet box fitted after registration connects to a CAN bus whose security was assessed for type approval, yet that pedigree does not transfer. Retrofit hardware such as route optimization units, driver monitors and reefer refrigeration telemetry lands in CRA scope too, along with EV charging stations and standalone diagnostic tools that never qualified for the vehicle rules.
Once in scope, timelines move fast. An actively exploited vulnerability must reach ENISA as an early warning within 24 hours, a fuller notification follows inside 72 hours, and a final report is due within 14 days.
Trucks and buses complicate the boundary. A chassis maker, a body builder and a telematics vendor may each hold a separate slice of one vehicle’s digital architecture, and only the slice inside the 2019/2144 approval escapes CRA duties. Automotive IQ’s yardstick: a component sold on its own invoice line, outside the approved build, is in scope however tightly it later integrates with the vehicle.
The new rhythm clashes with how commercial vehicle security teams work. Most built incident response around R155’s scheduled audits, documentation-heavy and reviewed on a calendar. CRA notifications are event-driven, so an exploited flaw in a telematics product found late on a Friday starts the clock immediately, with no queue slot waiting for Monday’s triage.