ChannelLife UK - Industry insider news for technology resellers
Luxury bentley gt in high tech garage with digital lock symbol

Bentley achieves UNECE cybersecurity compliance for GT range

Today

Bentley Motors has achieved full compliance with United Nations Economic Commission for Europe (UNECE) vehicle cybersecurity and software update regulations (R155 and R156) following a collaboration with MHP Consulting UK.

The project, which spanned approximately 24 months, focused on establishing and certifying Cybersecurity and Software Update Management Systems (CSMS & SUMS) for Bentley's operations. The audit resulted in Bentley being certified with zero non-conformities, allowing its Grand Tourer (GT) range to satisfy the stringent regulatory standards required to sell vehicles in UNECE member states.

Compliance requirements

The UNECE World Forum for Harmonization of Vehicle Regulations mandates that, as of July 2024, original equipment manufacturers (OEMs) must demonstrate compliance with key regulations before they can sell vehicles or related products in 56 member countries. Regulation R155 addresses cybersecurity, while R156 concerns software updates. Compliance requires the introduction and ongoing operation of relevant management systems across the organisation, which must be audited by a recognised technical service.

Bentley's pre-existing systems were considered advanced and generally aligned with the regulatory requirements. However, the company undertook further work to guarantee that all aspects of its CSMS and SUMS conformed fully with the R155 and R156 regulations, especially for purposes of regulatory and type approvals. To support this, Bentley engaged the services of MHP Consulting.

Project phases

The initiative was divided into two main phases. The first involved refining and aligning Bentley's cybersecurity and software update processes with the UNECE rules. Bentley and MHP Consulting worked closely with a technical service to develop concepts and processes that would both satisfy external auditors and reinforce Bentley's regulatory framework.

Audit preparation included the development and execution of a detailed "dress rehearsal," the integration of requirements into new and existing processes, adaptation of group-wide policies such as ISO21434 standards, and implementation of relevant IT tools. Managerial commitment and structured governance were emphasised, resulting in a certification audit that yielded zero non-conformities.

The second phase focused on operationalising the changes made in the first phase. This included establishing a strong governance structure, preparing for the first surveillance audit, collecting evidence of process operationalisation, and ensuring cross-functional cooperation across the business. The running of CSMS and SUMS management was demonstrated using relevant IT tools throughout the organisation.

Program management tools were used to promote transparency and oversight. Cybersecurity culture was also enhanced via awareness and communication initiatives, such as technical talks and monthly reports, to help integrate the management systems into everyday operations within Bentley.

Industry and management perspectives

Bentley's Product Line Director, Chris Cole, commented on the result of the collaborative project:

"We're proud of this close collaboration with MHP Consulting UK, and the fact that Bentley has met the cybersecurity legislative requirements set out by the United Nations Economic Commission for Europe. Not only have our joint teams achieved certification with zero non-conformities, they have pushed the boundaries of innovation, further entrenching cybersecurity as a cultural imperative into the Bentley brand. This is a major achievement for our team and ultimately means that our GT range of vehicles meets the highest cybersecurity and software update management systems."

Bodo Philipp, CEO of MHP Consulting UK, emphasised the commercial and regulatory importance of the achievement:

"Achieving UNECE compliance is crucial for an OEM's market access, and can therefore mean a bottom-line impact of millions, even billions, depending on the brand. It is key for OEMs to work with proven experts that can help them to navigate the regulatory landscape successfully – especially as the industry becomes more and more dependent on data, internet access and connected services." He adds: "Our teams have done incredibly successful transformative work together. They've led the charge on this initiative, and have set new standards within Bentley – a fantastic achievement. Well done!"

This compliance now enables Bentley to market its GT vehicles within all UNECE member territories, ensuring both regulatory approval and strengthened cybersecurity measures for its connected vehicle portfolio.

Follow us on:
Follow us on LinkedIn Follow us on X
Share on:
Share on LinkedIn Share on X