The regulation expands the digital compliance surface
Regulation (EU) 2024/1257 introduces Euro 7 requirements that extend beyond tailpipe limits. It requires onboard monitoring, fuel and energy consumption data, battery state-of-health information and off-board communication of data used for compliance and inspection purposes.
The same regulation explicitly requires manufacturers to minimise vulnerabilities that could enable tampering with ECUs, traction batteries, OBD, onboard monitoring and other emissions-relevant systems. It also requires secure transmission of emissions and battery-durability data using cybersecurity measures aligned with UN Regulation No. 155.
That changes the assurance question. A regulatory record can be corrupted without physically defeating the emissions hardware if an attacker can manipulate a sensor input, calibration, diagnostic function, data store or backend path used to establish compliance.
The integrity problem spans sensing, ECU processing, diagnostics, telemetry and the regulatory record; assurance has to survive each hand-off.
Can the organisation prove which software, calibration and sensor state produced the compliance data being relied upon?
Protect the chain, not only the endpoint
The evidence path now spans physical sensors, embedded software, diagnostic interfaces, software updates, cryptographic identities and off-board services. Each transition should preserve provenance: what generated the data, under which software/calibration state, and whether that state was authorised.
UN Regulation No. 156 adds a complementary requirement around software update management, software identification, compatibility and update integrity. Together, the two UN regulations and Euro 7 make version traceability a practical control for both cybersecurity and regulatory assurance.
A mature architecture therefore links emissions evidence to software identity, calibration identity, secure time, tamper detection and backend integrity. The objective is not to cryptographically sign every byte indiscriminately. It is to ensure that a compliance decision can be reconstructed from trustworthy records.
- Bind compliance data to software and calibration versions.
- Protect diagnostic write paths that can alter emissions-relevant state.
- Use secure update and rollback controls for regulated functions.
- Detect implausible or discontinuous compliance data.
- Retain evidence that can support type-approval and incident reconstruction.
