The European Union — technology neutral by accident, and the only working multi-root trust list in the world.
Europe has the largest deployed V2X fleet, the most mature multi-party PKI governance, and no C-ITS delegated act. The 2019 attempt was killed by the Council on technology-neutrality grounds and has never been replaced. What filled the gap is more interesting than what was blocked.
Adopted March 2019, objected to in July 2019, never in force.
The Commission adopted a C-ITS Delegated Regulation on 13 March 2019. It never entered into force: the Council of the European Union objected in July 2019, principally on the grounds that the text favoured ITS-G5 over C-V2X. The Parliament's TRAN committee had earlier declined to object; the Council's objection was decisive.
No replacement C-ITS delegated act has been adopted as of August 2026.
Directive (EU) 2023/2661, and a legal basis for the credential system.
Directive (EU) 2023/2661 of 22 November 2023, amending the ITS Directive 2010/40/EU, entered into force 20 December 2023. It mandates digital availability of key road, travel and traffic data — speed limits, traffic circulation plans, roadworks — and requires essential safety-related services to be available to drivers along the TEN-T network.
Its significance for V2X is legal rather than technical. The CAR 2 CAR Communication Consortium's assessment is that the Directive “creates a legal basis for the already now operational EU security credential management system, which will run under the responsibility of the European Commission.” That is the anchoring the 2019 delegated act failed to deliver.
The ITS Directive Working Programme 2024–2028, Commission Implementing Decision C/2024/6798, adopted 12 November 2024, schedules C-ITS common specifications — including specifications for the EU C-ITS security credential management system — for 2024–2027. The Commission's delegated-act empowerment runs to 20 December 2028.
The transposition deadline for Directive 2023/2661 and the Annex III mandatory-data dates could not be confirmed and are therefore not stated. Adoption and entry into force are confirmed.
60 MHz in the band, 50 of it for road ITS, and the top 10 not for road at all.
Commission Implementing Decision (EU) 2020/1426 of 7 October 2020 extended the ITS band from 5875–5905 MHz to 5875–5935 MHz, with member states required to designate it no later than 30 June 2021. The 60 MHz figure is the band; it is not what road ITS gets, and the difference is where most summaries go wrong.
- Article 3(1) requires 5925–5935 MHz to be limited to urban rail ITS. Road ITS therefore has 5875–5925 MHz — 50 MHz.
- Article 3(2) gives road ITS priority below 5915 MHz and urban rail ITS priority above it, so that whichever has priority is protected.
- Article 3(3) limits road ITS access to 5915–5925 MHz to infrastructure-to-vehicle connectivity only, coordinated with urban rail ITS where appropriate.
- Article 3(4) makes urban rail access to 5925–5935 MHz shared and subject to national circumstances, including coordination with the fixed service.
The Decision is written technology-neutrally, explicitly acknowledging both ITS-G5 and LTE-V2X, and noting ETSI work on co-channel and adjacent-channel coexistence.
Its Annex was replaced in full on 24 July 2026 by Commission Implementing Decision (EU) 2026/1800, published in the Official Journal on 28 July 2026 and notified as C(2026) 5125. The change: two adjacent 10 MHz blocks may now be combined into one contiguous 20 MHz channel for road ITS. The condition attached: the 20 MHz channel formed within 5905–5925 MHz shall be limited to infrastructure-to-vehicle communications, because its upper half falls inside the 5915–5925 MHz range Article 3(3) already restricts. Recital 6 records that this stands pending solutions that protect urban rail ITS in that range, following CEPT Report 91 of 7 November 2025. The replaced Annex also adds an unwanted-emissions limit above 5925 MHz of −30 dBm/MHz EIRP for road ITS, and restates transmit power control as an ability to reduce total power from maximum to 3 dBm EIRP rather than as a 30 dB range. The channel conditions in detail →
A Union designation is still not a national permission. Member states implement it through their own instruments, and those can be narrower: Germany's general assignment opens 5875–5915 MHz, requires an individual assignment above that, carries no 20 MHz pairing provision and expires on 31 December 2026.
The other live spectrum file in 2026 is adjacent-band coexistence: Commission Implementing Decision (EU) 2025/913 of 20 May 2025 relaxed very-low-power out-of-band emissions below 5935 MHz from −45 to −37 dBm/MHz, conditional on frequency-selection mechanisms prioritising blocks above 6105 MHz, expressly to protect urban rail ITS in 5905–5935 MHz. All jurisdictions compared →
Governance per the C-ITS Certificate Policy, Release 3.0, May 2024.
- CPA — Certificate Policy Authority; owns the policy, authorises PKI participants, approves or rejects root CAs on audit.
- TLM — Trust List Manager; a single entity appointed by the CPA, compiling and cryptographically signing the European Certificate Trust List.
- CPOC — C-ITS Point of Contact, operated by the Joint Research Centre; receives root CA certificate submissions and publishes the ECTL. The CPOC Protocol is at Release 1.1.
- Root CAs → EA → AA → C-ITS stations. Multi-root by design; the Certificate Policy deliberately fixes no number of root CAs.
A companion C-ITS Security Policy was issued in December 2017.
This is the model we think India should adopt. Trust is a list, not a single root. That property is worth more than any technical detail in the whole architecture. Why →
ETSI ITS Release 2, and the two UNECE regulations that already bind.
ETSI ITS Release 2 is the current baseline and is actively maintained into 2026: TS 103 300-3 V2.3.1 (December 2025) for VRU awareness, TS 103 301 V2.3.1 (April 2026) for infrastructure services, TS 103 900 V2.3.1 (May 2026) for cooperative awareness, TS 103 097 V2.2.1 (March 2026) for security, and TS 103 759 V2.2.1 (January 2026) for misbehaviour reporting. Release 2 adds collective perception, VRU awareness, manoeuvre coordination and multi-channel operation over Release 1's CAM and DENM core. The message set →
UNECE R155 and R156 both entered into force January 2021. Under EU Regulation 2019/2144, R155 became mandatory for new whole-vehicle type approvals in July 2022 and extended to all new vehicles registered in the EU in July 2024. R155 requires a certified Cybersecurity Management System; R156 requires a Software Update Management System and provides the legal basis for OTA updates. They apply across the 1958 Agreement contracting parties, including the UK, Japan and South Korea. An on-board unit sits squarely inside both. What that means for the device →
C-Roads, and the largest deployed fleet in the world.
C-Roads Platform, founded 2016. Figures published on c-roads.eu, dated 19 February 2026:
- 6,000+ roadside units deployed
- 30% of the TEN-T road network covered
- 3,500+ public transport vehicles equipped
- 850+ C-Roads experts
The C-ITS Specification Release 3.2.1 was published 6 July 2026. On 26 March 2026 C-Roads formally recognised Australia's adoption of C-Roads specifications, with Queensland as an associated member — a genuinely significant development for a European harmonisation body. A C-Roads X-Test cross-border testing event is scheduled for Vienna, 20–22 October 2026. The Australian position →
C2C-CC claimed 1.5 million V2X-equipped vehicles and over 20,000 km of equipped motorway in Europe as of December 2023. Volkswagen alone passed two million Car2X-equipped vehicles produced in October 2025. Europe's installed base remains predominantly ITS-G5, with hybrid ITS-G5-plus-cellular as the C-Roads architecture. Who ships what →
Regulation (EU) 2024/2847 — the reporting obligations have applied since 11 September 2026.
The Cyber Resilience Act (CRA) is horizontal product legislation for “products with digital elements”, not a V2X or vehicle instrument. It is on this page because one part of it is already live, because ENISA's reporting platform opened the same day, and because whether a given piece of V2X hardware is inside or outside it turns on a scope rule that is easy to get wrong in both directions.
What applies when. Article 71 sets three dates. Chapter IV, on the notification of conformity assessment bodies (Articles 35 to 51), has applied since 11 June 2026. Article 14, the manufacturer's reporting obligations, has applied since 11 September 2026. Everything else — the essential requirements, conformity assessment, CE marking — applies from 11 December 2027. Article 69(3) makes the reporting duty reach products already on the market before that date: a manufacturer of an in-scope product placed on the EU market in 2024 is under Article 14 today, even though the product never had to meet the essential requirements.
The two clocks. Article 14 creates two parallel three-stage notification tracks, one for an actively exploited vulnerability and one for a severe incident having an impact on the security of the product. Both start when the manufacturer becomes aware. Each stage is due only where the relevant information has not already been provided, and the CSIRT that first receives a notification may ask for an intermediate status report in between.
| Stage | Actively exploited vulnerability — Art. 14(2) | Severe security incident — Art. 14(4) |
|---|---|---|
| Early warning | Within 24 hours of becoming aware. Indicates, where applicable, the Member States in which the product has been made available. | Within 24 hours of becoming aware. States at least whether the incident is suspected to be caused by unlawful or malicious acts. |
| Notification | Within 72 hours of becoming aware. General information on the product, the nature of the exploit and vulnerability, and corrective or mitigating measures taken and available to users. | Within 72 hours of becoming aware. Nature of the incident, an initial assessment, and corrective or mitigating measures taken and available to users. |
| Final report | No later than 14 days after a corrective or mitigating measure is available. Description of the vulnerability, severity and impact; any known malicious actor; details of the fix. | Within one month after the submission of the incident notification — the 72-hour stage, not the incident itself. Detailed description, likely root cause, applied and ongoing mitigation. |
| Sent to | Simultaneously to the CSIRT designated as coordinator and to ENISA, through the single reporting platform of Article 16, using the electronic end-point of the CSIRT for the Member State in which the manufacturer has its main establishment in the Union. A manufacturer with no Union establishment follows the fall-back order in Article 14(7). | |
| Users | Article 14(8): after becoming aware, the manufacturer informs the impacted users — and where appropriate all users — of the vulnerability or incident and of any risk-mitigation and corrective measures they can deploy. | |
An incident is severe under Article 14(5) when it negatively affects, or is capable of negatively affecting, the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or when it has led or could lead to the execution of malicious code in the product or in a user's network and information systems. Neither track collapses into a single “report everything within 72 hours” rule: the early warning and the notification have different content, and the two final-report deadlines run from different events.
The platform. Article 16 requires ENISA to establish and operate a single reporting platform with national electronic notification end-points, so that a manufacturer submits once and the coordinating CSIRT disseminates. ENISA announced the CRA Single Reporting Platform as operational on 11 September 2026, describing the launch as its initial operating capability; the platform's own FAQ records the same date. Commission Delegated Regulation (EU) 2026/881 supplies the cybersecurity-related grounds on which dissemination of a notification may be delayed, under Article 14(9). No implementing act on the format and procedure of notifications under Article 14(10) had been located on the Commission's implementation pages at the date of this review.
Where automotive and V2X products stand
The CRA is not a blanket exclusion of “automotive”. Article 2(2)(c) removes from its scope products with digital elements to which Regulation (EU) 2019/2144 — the General Safety Regulation for vehicle type approval — applies; the recital explains this by the cybersecurity requirements that regulation already imposes through UN Regulation No. 155 and the type-approval conformity procedures. Regulation 2019/2144 applies to vehicles of categories M, N and O and to systems, components and separate technical units designed and constructed for them. Commission Delegated Regulation (EU) 2025/1535 extended the exclusion to products within Regulation (EU) No 168/2013 — L-category vehicles — except pedal-assist L1e cycles. Article 2(6) separately exempts spare parts that replace identical components and are made to the same specification.
The Regulation says nothing about how the vehicle exclusion applies to a component sold on its own. The Commission's guidance of 27 July 2026, C(2026) 5252, addresses exactly that point in its section on vehicles. In its reading, a component is outside the CRA only where it is exclusively designed and constructed for integration into vehicles covered by those regulations, and clearly intended and suitable only for that integration; it makes no difference whether it is sold to the vehicle manufacturer or to another operator in the automotive supply chain. A generic component that can be integrated into other kinds of product is in scope. And the guidance treats the sales channel as objective evidence: a component offered through channels open to customers outside the automotive supply chain — general retail, or online ordering by the public — is in scope irrespective of any statements concerning its intended use, while restricted business-to-business distribution within the automotive supply chain may indicate exclusivity. On spare parts, the guidance adds that a replacement differing in security-relevant characteristics such as algorithms, protocols, cryptographic mechanisms or access control is not “identical” and is a product with digital elements in its own right.
| Product situation | Position on the primary texts |
|---|---|
| Type-approved M, N, O vehicle; L-category vehicle | Outside the CRA — Art. 2(2)(c); Delegated Regulation 2025/1535 (pedal-assist L1e excepted) |
| On-board unit or other component built exclusively for integration into such vehicles, supplied within the automotive chain | Outside the CRA on the Commission's guidance, whoever in the chain buys it |
| Component that can be integrated into other products, or sold through channels open to the public | Inside the CRA on the Commission's guidance, whatever the stated intended use |
| Roadside unit, test equipment, development kit, standalone module placed on the EU market | Not vehicle systems, components or separate technical units under 2019/2144 — nothing in the primary texts takes them out of scope. Assess as products with digital elements in their own right |
| Aftermarket unit that is both type-approved as a separate technical unit and sold openly | Not reconciled in any text located: Art. 2(2)(c) on its face would exclude it; the guidance's channel test would include it |
| Software or a back-end service supplied separately | Not addressed in the vehicle section of the guidance; under Art. 3(1) software placed on the market separately is a product with digital elements |
The honest summary is the one the primary texts support: whether a specific automotive or V2X product falls within the CRA depends on how it is placed on the EU market and whether it is already covered by the applicable sector-specific vehicle type-approval regime. The Commission's guidance is interpretive rather than binding, and the aftermarket boundary is genuinely open. This page does not state that every V2X device is in scope, and it does not state that being “automotive” takes a device out.
Why it matters to a V2X engineering team either way
A 24-hour clock that starts on becoming aware is not met by a reporting form; it is met by an organisation that already knows what it ships, where, and with which components, and that can tell an exploited vulnerability from a rumour inside a working day. For a connected-product team the operational content is the same whether the CRA, UN R155 or a customer contract is the driver:
- a vulnerability intake route that is published and monitored, and a product security incident response function behind it;
- a product and software inventory, with dependency and SBOM visibility, so that a disclosed component flaw can be mapped to affected units in hours;
- triage criteria that distinguish an actively exploited vulnerability and a severe incident from the rest;
- supplier escalation paths for silicon, module and stack components, with agreed response times;
- preservation of incident evidence in a form that survives the final report;
- a remediation workflow that reaches deployed units — which is where a secure update architecture stops being a feature and becomes the mechanism by which a final report can ever be filed;
- a coordinated-disclosure position, and regulatory-reporting readiness rehearsed against the clock rather than read about after it starts.
None of this is part of any V2X standard. The V2X-specific material on this site — the documented attacks, misbehaviour reporting, key protection — is the technical layer; the CRA is the organisational one. It is also a different regulatory system in a different jurisdiction from India's Draft AIS-230, which is a vehicle type-approval standard for on-board units and carries no vulnerability-reporting regime of this kind; nothing in this section is part of AIS-230 compliance. Draft AIS-230, explained →
Sources. Regulation (EU) 2024/2847, Articles 2, 3, 14, 16, 69 and 71, and recitals 27, 29, 65 and 69 · Commission Delegated Regulation (EU) 2025/1535 · Commission Delegated Regulation (EU) 2026/881 · Commission guidance C(2026) 5252, 27 July 2026, sections 4.2 and 9.3.1 · Commission, CRA reporting obligations · Commission, CRA implementation FAQ · ENISA, 11 September 2026 · ENISA, Single Reporting Platform. Retrieved 17 September 2026.
The documents, one record each.
Each identifier links to its canonical record in the V2X standards library, where the edition, dates, band, access conditions and verification note are held once. Status and binding effect are separate: a published document is not automatically a legal requirement.
| Document | Title | Type | Status | Binding effect |
|---|---|---|---|---|
| Decision (EU) 2020/1426 | Commission Implementing Decision (EU) 2020/1426 on the harmonised use of radio spectrum in the 5 875-5 935 MHz frequency band for safety-related applications of intelligent transport systems (ITS) and repealing Decision 2008/671/EC | Spectrum | Published final | Mandatory |
| Decision (EU) 2026/1800 | Commission Implementing Decision (EU) 2026/1800 amending Implementing Decision (EU) 2020/1426 as regards introducing wider frequency channels in the Union-harmonised 5,9 GHz frequency band for safety-related applications of road intelligent transport systems | Spectrum | Published final | Mandatory |
| ETSI EN 303 613 | Intelligent Transport Systems (ITS); LTE-V2X Access layer specification for Intelligent Transport Systems operating in the 5 GHz frequency band | Radio and access | Published final | Voluntary |
| EU C-ITS Certificate Policy | Certificate Policy for Deployment and Operation of European Cooperative Intelligent Transport Systems (C-ITS) | Security | Published final | Guidance |
Where this fits.
SCMS vs CCMS
The CCMS entity map, and the argument for a trust list over a single root.
DSRC vs C-V2X
Why Europe's installed base is on the other radio.
Message sets
ETSI Release 2, message by message and version by version.
The OEM landscape
Volkswagen's two million, and what the rest of Europe has done.
Spectrum
The 60 MHz band, and the urban rail sharing arrangement.
Test and certification
C-Roads cross-border testing and ETSI Plugtests.
Last reviewed: 17 September 2026. Section 7 was added at this review; sections 1 to 6 were re-read and not changed. The C-ITS common specifications are scheduled within a 2024–2027 window; this page should be reviewed quarterly.
Questions this page answers.
Is V2X mandatory in the EU?
No. There is no fleet fitment mandate. Directive (EU) 2023/2661 mandates the digital availability of road and traffic data and requires safety-related services along the TEN-T network, but does not require vehicles to carry V2X radios.
Which technology does the EU use, ITS-G5 or C-V2X?
Both are legally permitted; the EU is formally technology-neutral, a position cemented when the Council rejected the 2019 delegated act on those grounds. The deployed installed base is overwhelmingly ITS-G5, with Volkswagen's two million Car2X vehicles the largest single contribution.
Does the EU Cyber Resilience Act apply to V2X equipment?
It depends on how the product is placed on the EU market. Article 2(2)(c) of Regulation (EU) 2024/2847 excludes products with digital elements to which the vehicle type-approval Regulation (EU) 2019/2144 applies, and Delegated Regulation (EU) 2025/1535 extends that to L-category vehicles. The Commission's July 2026 guidance treats a component as excluded only where it is exclusively designed and constructed for integration into such vehicles; a generic component, or one sold through channels open to the public, is in scope. Roadside units, development kits and standalone modules are not vehicle components under 2019/2144. Since 11 September 2026 an in-scope manufacturer must give early warning of an actively exploited vulnerability or severe incident within 24 hours of becoming aware, a fuller notification within 72 hours, and a final report afterwards, through ENISA's single reporting platform.
What is the ECTL?
The European Certificate Trust List — a list of approved root certificate authorities, compiled and cryptographically signed by the Trust List Manager and published by the C-ITS Point of Contact operated by the Joint Research Centre. It is what makes a multi-root V2X trust model work: a receiver trusts a certificate because its chain terminates at a root that appears on a TLM-signed list, and the whole chain resolves offline from locally held material.
Last updated 2026-09-30 · Technical reference maintained by Ambimat Electronics, Ahmedabad, India. Corrections: v2x@ambimat.com