# Automakers Align Cybersecurity Evidence Across Markets

Automotive manufacturers and suppliers face distinct cybersecurity obligations across UNECE-based rules, China’s national standards, the EU Cyber Resilience Act (CRA), and U.S. connected-vehicle restrictions. The CRA is scheduled to apply fully on December 11, 2027, and U.S. software restrictions begin with Model Year 2027. This is regulatory intelligence, not a contract notice or solicitation; its procurement relevance is the need to build reusable cybersecurity and software bill of materials (SBOM) evidence while separately evaluating each market’s scope, reporting, approval, and recordkeeping rules.

- Manufacturers and suppliers should develop reusable cybersecurity and SBOM evidence, then map it to the distinct requirements of each market rather than assume one evidence package satisfies all regimes.
- Procurement teams can account for these obligations in supplier qualification, sourcing documentation, and contract requirements for automotive products and software.
- The CRA’s full application date is **December 11, 2027**; U.S. software restrictions begin with **Model Year 2027**. Companies should factor these dates into product and supplier planning.

**Jurisdictions:** international
**Industries:** Transportation, Information Technology
**Topics:** Cybersecurity, Regulatory Compliance
**Published:** October 05, 2026

### Government Entities
- United Nations Economic Commission for Europe (UNECE)
- European Union (EU)
- U.S. Department of Commerce, Bureau of Industry and Security (BIS)
- Cybersecurity and Infrastructure Security Agency (CISA)
- National Highway Traffic Safety Administration (NHTSA)

### Sources
- [One Vehicle, 4 Regimes | Automotive Cybersecurity](https://www.automotive-iq.com/cybersecurity/articles/one-vehicle-four-regimes-2) - Automotive IQ