Engineering interpretation. “Cybersecurity evidence chain” is our engineering model for protecting data from sensor to regulatory record. Regulation (EU) 2024/1257 requires cybersecurity measures for relevant transmitted data but does not use this phrase as a defined regulatory term.

The regulation expands the digital compliance surface

Regulation (EU) 2024/1257 introduces Euro 7 requirements that extend beyond tailpipe limits. It requires onboard monitoring, fuel and energy consumption data, battery state-of-health information and off-board communication of data used for compliance and inspection purposes.

The same regulation explicitly requires manufacturers to minimise vulnerabilities that could enable tampering with ECUs, traction batteries, OBD, onboard monitoring and other emissions-relevant systems. It also requires secure transmission of emissions and battery-durability data using cybersecurity measures aligned with UN Regulation No. 155.

That changes the assurance question. A regulatory record can be corrupted without physically defeating the emissions hardware if an attacker can manipulate a sensor input, calibration, diagnostic function, data store or backend path used to establish compliance.

What this diagram shows

The integrity problem spans sensing, ECU processing, diagnostics, telemetry and the regulatory record; assurance has to survive each hand-off.

Trust and authority pathEuro 7 Turns Emissions Compliance into a Cybersecurity Evidence Chain
Trust pressure / decision point Governed state or evidence domain
Authority and evidence flow
Evidence domainSensor / ECUPhysical state is measured
Evidence domainSoftware + calibrationApproved code interprets the state
Trust pressureOBD / OBM dataEvidence is stored or transmitted
Evidence domainRegulatory recordCompliance relies on the resulting record
Decision gate

Can the organisation prove which software, calibration and sensor state produced the compliance data being relied upon?

YESThe decision can rely on bounded, auditable trust.
NOThe residual authority or evidence gap remains material.
How to read this: the dark node marks the point where trust can be lost or authority can expand. Arrows represent control, evidence or dependency relationships, not necessarily direct network links.

Protect the chain, not only the endpoint

The evidence path now spans physical sensors, embedded software, diagnostic interfaces, software updates, cryptographic identities and off-board services. Each transition should preserve provenance: what generated the data, under which software/calibration state, and whether that state was authorised.

UN Regulation No. 156 adds a complementary requirement around software update management, software identification, compatibility and update integrity. Together, the two UN regulations and Euro 7 make version traceability a practical control for both cybersecurity and regulatory assurance.

A mature architecture therefore links emissions evidence to software identity, calibration identity, secure time, tamper detection and backend integrity. The objective is not to cryptographically sign every byte indiscriminately. It is to ensure that a compliance decision can be reconstructed from trustworthy records.

Euro 7 compliance is not only about what the vehicle emits. It is also about whether the evidence describing that behaviour remains trustworthy.
The decision
Treat Euro 7 evidence as a product-security asset with end-to-end provenance, not merely as telemetry.
Operational checks
  • Bind compliance data to software and calibration versions.
  • Protect diagnostic write paths that can alter emissions-relevant state.
  • Use secure update and rollback controls for regulated functions.
  • Detect implausible or discontinuous compliance data.
  • Retain evidence that can support type-approval and incident reconstruction.
Related episodeListen to the podcast versionLinkedInJoin the discussion
Source record

Sources & further reading

3 cited sourcesHow we source →
← All analysisCompanion episode →