| UN R155 and R156: Proposal for amendments |
| Reference Number: GRVA-25-07 |
|
Proposal to amend para. 5.1.3. of UN R155 to add a refusal ground where the Certificate of Compliance for the Cyber Security Management System has not been issued by the same approval authority granting type approval, and insert new para. 5.4. into UN R156 to provide that approval authorities shall not grant any type approval if the Certificate of Compliance for the Software Update Management System has not been issued by the same approval authority granting type approval. The proposal, based on TFCS-37-02, ensures that Certificates of Compliance and type-approvals for UN R155 and UN R156 are issued by the same approval authority to enable holistic assessment and clarify reporting obligations. |
| Submitted by: France, Germany, Luxembourg, Netherlands, and UK |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 04 May 26 |
| Document status: Informal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| Proposal for amendments to UN Regulations Nos. 13, 13-H, 79, 89, 130, 131, 152, 155, 156, 157, 171, 175, and 178 |
| Reference Number: GRVA-25-30 |
|
Proposal to insert provisions on software identification and software updates into UN R13, UN R13-H, UN R79, UN R89, UN R130, UN R131, UN R152, UN R155, UN R156, UN R157, UN R171, UN R175, and UN R178 by adding definitions referencing Consolidated Resolution R.E.3 Annex 7, requiring manufacturers to provide Technical Services with information on hardware and software influencing performance, permitting vehicle manufacturers to apply for new approvals differentiating software versions for registered versus new vehicles, clarifying that production discontinuation does not apply when manufacturers seek approval extensions for software updates of registered vehicles, and amending communication forms to include software identification numbers and related information. |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 18 May 26 |
| Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 13-H | Light-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, United Nations Agreement | RE3 Construction of Vehicles, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error |
| Click here to view the full document file |
| UN R155: Proposal for amendments |
| Reference Number: GRVA-25-31 |
|
Proposal to amend para. 5.3.2. to require approval authorities to notify other approval authorities of methods and criteria used to assess measures taken in accordance with the Regulation, insert new para. 8.2. to exclude equipment with negligible intrinsic cyber security risk from further assessment where installation does not impinge on the cyber security management system and is connected exclusively via an approved interface, insert new para. 8.3. to exclude standard domestic, business or industrial equipment connected only for power from further assessment where the equipment is unmodified and complies with applicable regional and national cyber security requirements, and amend Annex 1 to include any equipment excluded from assessment pursuant to paras. 8.2. and 8.3. |
| Submitted by: TFCS |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 18 May 26 |
| Document status: Informal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| UN R155: Proposal to amend the Interpretation Document |
| Reference Number: GRVA-25-32 |
|
Proposal to insert new Part C providing guidance on application of UN R155 to transformed vehicles. Part C defines when transformations require new approval, establishes terminology for original vehicle types, transformed vehicle types, transformations, and installations, identifies cyber-relevant transformations by evaluating impact on architecture and connection risks, addresses intrinsic cyber security risks, clarifies non-automotive equipment requirements, and specifies documentary evidence manufacturers must provide to approval authorities or technical services, including functional descriptions, connection details, software modifications, and component lists. |
| Submitted by: TFCS |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 18 May 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Cyber Security task force (aka CS/OTA) status report to GRVA |
| Reference Number: GRVA-25-35 |
|
The Informal Working Group on Cyber Security and Software Updates discussed amendments to UN R155 and UN R156 for multi-stage approval, including simplified handling for low-risk devices and clarification of intrinsic cyber risk assessment. The group reviewed proposals from GRVA-25-31 and GRVA-25-32 concerning continued validity of approvals and Certificate of Compliance issuance. A Sub-Working Group was established to develop component and separate technical unit approval concepts. Pending discussion include RXSWIN application to components, STUs, and the extent of application to UN R155 and UN R156, and type-approval numbering for software updates. |
| Submitted by: TFCS |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 20 May 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| EV and Hydrogen Fuel-Cell Vehicle Retrofits: Comments on GRVA-25-07 |
| Reference Number: GRVA-25-41 |
|
OICA-CLEPA-EME comments on German proposal GRVA-25-07 to require the approval authority granting UN R155 or UN R156 type approvals to use CSMS or SUMS certificates signed by the same approval authority. OICA-CLEPA-EME identify that CSMS and SUMS are Management Systems covering entire manufacturer organizations, and mandating the same approval authority for Management Systems certificates and approvals will have significant consequences for original equipment manufacturers typically using multiple approval authorities in homologation. The submission proposes keeping text unchanged to allow different approval authorities for Management Systems certificates and type approval based on voluntary acceptance, implementing wording on information exchange if different approval authorities are involved, and establishing a horizontal approach for Management Systems with mutual recognition aspects considered. |
| Submitted by: EME, OICA, and CLEPA |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 20 May 26 |
| Relevant to: WP.29 Regulatory Project | Electric and Hydrogen Fuel-Cell Vehicle Retrofit Systems |
| Click here to view the full document file |
| UN R155 and R156: Proposal for amendments |
| Reference Number: GRVA-25-07 |
|
Proposal to amend para. 5.1.3. of UN R155 to add a refusal ground where the Certificate of Compliance for the Cyber Security Management System has not been issued by the same approval authority granting type approval, and insert new para. 5.4. into UN R156 to provide that approval authorities shall not grant any type approval if the Certificate of Compliance for the Software Update Management System has not been issued by the same approval authority granting type approval. The proposal, based on TFCS-37-02, ensures that Certificates of Compliance and type-approvals for UN R155 and UN R156 are issued by the same approval authority to enable holistic assessment and clarify reporting obligations. |
| Submitted by: France, Germany, Luxembourg, Netherlands, and UK |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 04 May 26 |
| Document status: Informal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| Proposal for amendments to UN Regulations Nos. 13, 13-H, 79, 89, 130, 131, 152, 155, 156, 157, 171, 175, and 178 |
| Reference Number: GRVA-25-30 |
|
Proposal to insert provisions on software identification and software updates into UN R13, UN R13-H, UN R79, UN R89, UN R130, UN R131, UN R152, UN R155, UN R156, UN R157, UN R171, UN R175, and UN R178 by adding definitions referencing Consolidated Resolution R.E.3 Annex 7, requiring manufacturers to provide Technical Services with information on hardware and software influencing performance, permitting vehicle manufacturers to apply for new approvals differentiating software versions for registered versus new vehicles, clarifying that production discontinuation does not apply when manufacturers seek approval extensions for software updates of registered vehicles, and amending communication forms to include software identification numbers and related information. |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 18 May 26 |
| Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 13-H | Light-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, United Nations Agreement | RE3 Construction of Vehicles, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error |
| Click here to view the full document file |
| UN R155: Proposal for amendments |
| Reference Number: GRVA-25-31 |
|
Proposal to amend para. 5.3.2. to require approval authorities to notify other approval authorities of methods and criteria used to assess measures taken in accordance with the Regulation, insert new para. 8.2. to exclude equipment with negligible intrinsic cyber security risk from further assessment where installation does not impinge on the cyber security management system and is connected exclusively via an approved interface, insert new para. 8.3. to exclude standard domestic, business or industrial equipment connected only for power from further assessment where the equipment is unmodified and complies with applicable regional and national cyber security requirements, and amend Annex 1 to include any equipment excluded from assessment pursuant to paras. 8.2. and 8.3. |
| Submitted by: TFCS |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 18 May 26 |
| Document status: Informal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| UN R155: Proposal to amend the Interpretation Document |
| Reference Number: GRVA-25-32 |
|
Proposal to insert new Part C providing guidance on application of UN R155 to transformed vehicles. Part C defines when transformations require new approval, establishes terminology for original vehicle types, transformed vehicle types, transformations, and installations, identifies cyber-relevant transformations by evaluating impact on architecture and connection risks, addresses intrinsic cyber security risks, clarifies non-automotive equipment requirements, and specifies documentary evidence manufacturers must provide to approval authorities or technical services, including functional descriptions, connection details, software modifications, and component lists. |
| Submitted by: TFCS |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 18 May 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Cyber Security task force (aka CS/OTA) status report to GRVA |
| Reference Number: GRVA-25-35 |
|
The Informal Working Group on Cyber Security and Software Updates discussed amendments to UN R155 and UN R156 for multi-stage approval, including simplified handling for low-risk devices and clarification of intrinsic cyber risk assessment. The group reviewed proposals from GRVA-25-31 and GRVA-25-32 concerning continued validity of approvals and Certificate of Compliance issuance. A Sub-Working Group was established to develop component and separate technical unit approval concepts. Pending discussion include RXSWIN application to components, STUs, and the extent of application to UN R155 and UN R156, and type-approval numbering for software updates. |
| Submitted by: TFCS |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 20 May 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| EV and Hydrogen Fuel-Cell Vehicle Retrofits: Comments on GRVA-25-07 |
| Reference Number: GRVA-25-41 |
|
OICA-CLEPA-EME comments on German proposal GRVA-25-07 to require the approval authority granting UN R155 or UN R156 type approvals to use CSMS or SUMS certificates signed by the same approval authority. OICA-CLEPA-EME identify that CSMS and SUMS are Management Systems covering entire manufacturer organizations, and mandating the same approval authority for Management Systems certificates and approvals will have significant consequences for original equipment manufacturers typically using multiple approval authorities in homologation. The submission proposes keeping text unchanged to allow different approval authorities for Management Systems certificates and type approval based on voluntary acceptance, implementing wording on information exchange if different approval authorities are involved, and establishing a horizontal approach for Management Systems with mutual recognition aspects considered. |
| Submitted by: EME, OICA, and CLEPA |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 20 May 26 |
| Relevant to: WP.29 Regulatory Project | Electric and Hydrogen Fuel-Cell Vehicle Retrofit Systems |
| Click here to view the full document file |
| UN R155 and R156: Proposal for amendments |
| Reference Number: GRVA-25-07 |
|
Proposal to amend para. 5.1.3. of UN R155 to add a refusal ground where the Certificate of Compliance for the Cyber Security Management System has not been issued by the same approval authority granting type approval, and insert new para. 5.4. into UN R156 to provide that approval authorities shall not grant any type approval if the Certificate of Compliance for the Software Update Management System has not been issued by the same approval authority granting type approval. The proposal, based on TFCS-37-02, ensures that Certificates of Compliance and type-approvals for UN R155 and UN R156 are issued by the same approval authority to enable holistic assessment and clarify reporting obligations. |
| Submitted by: France, Germany, Luxembourg, Netherlands, and UK |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 04 May 26 |
| Document status: Informal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| Proposal for amendments to UN Regulations Nos. 13, 13-H, 79, 89, 130, 131, 152, 155, 156, 157, 171, 175, and 178 |
| Reference Number: GRVA-25-30 |
|
Proposal to insert provisions on software identification and software updates into UN R13, UN R13-H, UN R79, UN R89, UN R130, UN R131, UN R152, UN R155, UN R156, UN R157, UN R171, UN R175, and UN R178 by adding definitions referencing Consolidated Resolution R.E.3 Annex 7, requiring manufacturers to provide Technical Services with information on hardware and software influencing performance, permitting vehicle manufacturers to apply for new approvals differentiating software versions for registered versus new vehicles, clarifying that production discontinuation does not apply when manufacturers seek approval extensions for software updates of registered vehicles, and amending communication forms to include software identification numbers and related information. |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 18 May 26 |
| Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 13-H | Light-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, United Nations Agreement | RE3 Construction of Vehicles, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error |
| Click here to view the full document file |
| UN R155: Proposal for amendments |
| Reference Number: GRVA-25-31 |
|
Proposal to amend para. 5.3.2. to require approval authorities to notify other approval authorities of methods and criteria used to assess measures taken in accordance with the Regulation, insert new para. 8.2. to exclude equipment with negligible intrinsic cyber security risk from further assessment where installation does not impinge on the cyber security management system and is connected exclusively via an approved interface, insert new para. 8.3. to exclude standard domestic, business or industrial equipment connected only for power from further assessment where the equipment is unmodified and complies with applicable regional and national cyber security requirements, and amend Annex 1 to include any equipment excluded from assessment pursuant to paras. 8.2. and 8.3. |
| Submitted by: TFCS |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 18 May 26 |
| Document status: Informal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| UN R155: Proposal to amend the Interpretation Document |
| Reference Number: GRVA-25-32 |
|
Proposal to insert new Part C providing guidance on application of UN R155 to transformed vehicles. Part C defines when transformations require new approval, establishes terminology for original vehicle types, transformed vehicle types, transformations, and installations, identifies cyber-relevant transformations by evaluating impact on architecture and connection risks, addresses intrinsic cyber security risks, clarifies non-automotive equipment requirements, and specifies documentary evidence manufacturers must provide to approval authorities or technical services, including functional descriptions, connection details, software modifications, and component lists. |
| Submitted by: TFCS |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 18 May 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Cyber Security task force (aka CS/OTA) status report to GRVA |
| Reference Number: GRVA-25-35 |
|
The Informal Working Group on Cyber Security and Software Updates discussed amendments to UN R155 and UN R156 for multi-stage approval, including simplified handling for low-risk devices and clarification of intrinsic cyber risk assessment. The group reviewed proposals from GRVA-25-31 and GRVA-25-32 concerning continued validity of approvals and Certificate of Compliance issuance. A Sub-Working Group was established to develop component and separate technical unit approval concepts. Pending discussion include RXSWIN application to components, STUs, and the extent of application to UN R155 and UN R156, and type-approval numbering for software updates. |
| Submitted by: TFCS |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 20 May 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| EV and Hydrogen Fuel-Cell Vehicle Retrofits: Comments on GRVA-25-07 |
| Reference Number: GRVA-25-41 |
|
OICA-CLEPA-EME comments on German proposal GRVA-25-07 to require the approval authority granting UN R155 or UN R156 type approvals to use CSMS or SUMS certificates signed by the same approval authority. OICA-CLEPA-EME identify that CSMS and SUMS are Management Systems covering entire manufacturer organizations, and mandating the same approval authority for Management Systems certificates and approvals will have significant consequences for original equipment manufacturers typically using multiple approval authorities in homologation. The submission proposes keeping text unchanged to allow different approval authorities for Management Systems certificates and type approval based on voluntary acceptance, implementing wording on information exchange if different approval authorities are involved, and establishing a horizontal approach for Management Systems with mutual recognition aspects considered. |
| Submitted by: EME, OICA, and CLEPA |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 20 May 26 |
| Relevant to: WP.29 Regulatory Project | Electric and Hydrogen Fuel-Cell Vehicle Retrofit Systems |
| Click here to view the full document file |
| UN R155 and R156: Proposal for amendments |
| Reference Number: GRVA-25-07 |
|
Proposal to amend para. 5.1.3. of UN R155 to add a refusal ground where the Certificate of Compliance for the Cyber Security Management System has not been issued by the same approval authority granting type approval, and insert new para. 5.4. into UN R156 to provide that approval authorities shall not grant any type approval if the Certificate of Compliance for the Software Update Management System has not been issued by the same approval authority granting type approval. The proposal, based on TFCS-37-02, ensures that Certificates of Compliance and type-approvals for UN R155 and UN R156 are issued by the same approval authority to enable holistic assessment and clarify reporting obligations. |
| Submitted by: France, Germany, Luxembourg, Netherlands, and UK |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 04 May 26 |
| Document status: Informal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| Proposal for amendments to UN Regulations Nos. 13, 13-H, 79, 89, 130, 131, 152, 155, 156, 157, 171, 175, and 178 |
| Reference Number: GRVA-25-30 |
|
Proposal to insert provisions on software identification and software updates into UN R13, UN R13-H, UN R79, UN R89, UN R130, UN R131, UN R152, UN R155, UN R156, UN R157, UN R171, UN R175, and UN R178 by adding definitions referencing Consolidated Resolution R.E.3 Annex 7, requiring manufacturers to provide Technical Services with information on hardware and software influencing performance, permitting vehicle manufacturers to apply for new approvals differentiating software versions for registered versus new vehicles, clarifying that production discontinuation does not apply when manufacturers seek approval extensions for software updates of registered vehicles, and amending communication forms to include software identification numbers and related information. |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 18 May 26 |
| Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 13-H | Light-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, United Nations Agreement | RE3 Construction of Vehicles, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error |
| Click here to view the full document file |
| UN R155: Proposal for amendments |
| Reference Number: GRVA-25-31 |
|
Proposal to amend para. 5.3.2. to require approval authorities to notify other approval authorities of methods and criteria used to assess measures taken in accordance with the Regulation, insert new para. 8.2. to exclude equipment with negligible intrinsic cyber security risk from further assessment where installation does not impinge on the cyber security management system and is connected exclusively via an approved interface, insert new para. 8.3. to exclude standard domestic, business or industrial equipment connected only for power from further assessment where the equipment is unmodified and complies with applicable regional and national cyber security requirements, and amend Annex 1 to include any equipment excluded from assessment pursuant to paras. 8.2. and 8.3. |
| Submitted by: TFCS |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 18 May 26 |
| Document status: Informal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| UN R155: Proposal to amend the Interpretation Document |
| Reference Number: GRVA-25-32 |
|
Proposal to insert new Part C providing guidance on application of UN R155 to transformed vehicles. Part C defines when transformations require new approval, establishes terminology for original vehicle types, transformed vehicle types, transformations, and installations, identifies cyber-relevant transformations by evaluating impact on architecture and connection risks, addresses intrinsic cyber security risks, clarifies non-automotive equipment requirements, and specifies documentary evidence manufacturers must provide to approval authorities or technical services, including functional descriptions, connection details, software modifications, and component lists. |
| Submitted by: TFCS |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 18 May 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Cyber Security task force (aka CS/OTA) status report to GRVA |
| Reference Number: GRVA-25-35 |
|
The Informal Working Group on Cyber Security and Software Updates discussed amendments to UN R155 and UN R156 for multi-stage approval, including simplified handling for low-risk devices and clarification of intrinsic cyber risk assessment. The group reviewed proposals from GRVA-25-31 and GRVA-25-32 concerning continued validity of approvals and Certificate of Compliance issuance. A Sub-Working Group was established to develop component and separate technical unit approval concepts. Pending discussion include RXSWIN application to components, STUs, and the extent of application to UN R155 and UN R156, and type-approval numbering for software updates. |
| Submitted by: TFCS |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 20 May 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| EV and Hydrogen Fuel-Cell Vehicle Retrofits: Comments on GRVA-25-07 |
| Reference Number: GRVA-25-41 |
|
OICA-CLEPA-EME comments on German proposal GRVA-25-07 to require the approval authority granting UN R155 or UN R156 type approvals to use CSMS or SUMS certificates signed by the same approval authority. OICA-CLEPA-EME identify that CSMS and SUMS are Management Systems covering entire manufacturer organizations, and mandating the same approval authority for Management Systems certificates and approvals will have significant consequences for original equipment manufacturers typically using multiple approval authorities in homologation. The submission proposes keeping text unchanged to allow different approval authorities for Management Systems certificates and type approval based on voluntary acceptance, implementing wording on information exchange if different approval authorities are involved, and establishing a horizontal approach for Management Systems with mutual recognition aspects considered. |
| Submitted by: EME, OICA, and CLEPA |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 20 May 26 |
| Relevant to: WP.29 Regulatory Project | Electric and Hydrogen Fuel-Cell Vehicle Retrofit Systems |
| Click here to view the full document file |
| UN R155 and R156: Proposal for amendments |
| Reference Number: GRVA-25-07 |
|
Proposal to amend para. 5.1.3. of UN R155 to add a refusal ground where the Certificate of Compliance for the Cyber Security Management System has not been issued by the same approval authority granting type approval, and insert new para. 5.4. into UN R156 to provide that approval authorities shall not grant any type approval if the Certificate of Compliance for the Software Update Management System has not been issued by the same approval authority granting type approval. The proposal, based on TFCS-37-02, ensures that Certificates of Compliance and type-approvals for UN R155 and UN R156 are issued by the same approval authority to enable holistic assessment and clarify reporting obligations. |
| Submitted by: France, Germany, Luxembourg, Netherlands, and UK |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 04 May 26 |
| Document status: Informal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| Proposal for amendments to UN Regulations Nos. 13, 13-H, 79, 89, 130, 131, 152, 155, 156, 157, 171, 175, and 178 |
| Reference Number: GRVA-25-30 |
|
Proposal to insert provisions on software identification and software updates into UN R13, UN R13-H, UN R79, UN R89, UN R130, UN R131, UN R152, UN R155, UN R156, UN R157, UN R171, UN R175, and UN R178 by adding definitions referencing Consolidated Resolution R.E.3 Annex 7, requiring manufacturers to provide Technical Services with information on hardware and software influencing performance, permitting vehicle manufacturers to apply for new approvals differentiating software versions for registered versus new vehicles, clarifying that production discontinuation does not apply when manufacturers seek approval extensions for software updates of registered vehicles, and amending communication forms to include software identification numbers and related information. |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 18 May 26 |
| Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 13-H | Light-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, United Nations Agreement | RE3 Construction of Vehicles, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error |
| Click here to view the full document file |
| UN R155: Proposal for amendments |
| Reference Number: GRVA-25-31 |
|
Proposal to amend para. 5.3.2. to require approval authorities to notify other approval authorities of methods and criteria used to assess measures taken in accordance with the Regulation, insert new para. 8.2. to exclude equipment with negligible intrinsic cyber security risk from further assessment where installation does not impinge on the cyber security management system and is connected exclusively via an approved interface, insert new para. 8.3. to exclude standard domestic, business or industrial equipment connected only for power from further assessment where the equipment is unmodified and complies with applicable regional and national cyber security requirements, and amend Annex 1 to include any equipment excluded from assessment pursuant to paras. 8.2. and 8.3. |
| Submitted by: TFCS |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 18 May 26 |
| Document status: Informal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| UN R155: Proposal to amend the Interpretation Document |
| Reference Number: GRVA-25-32 |
|
Proposal to insert new Part C providing guidance on application of UN R155 to transformed vehicles. Part C defines when transformations require new approval, establishes terminology for original vehicle types, transformed vehicle types, transformations, and installations, identifies cyber-relevant transformations by evaluating impact on architecture and connection risks, addresses intrinsic cyber security risks, clarifies non-automotive equipment requirements, and specifies documentary evidence manufacturers must provide to approval authorities or technical services, including functional descriptions, connection details, software modifications, and component lists. |
| Submitted by: TFCS |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 18 May 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Cyber Security task force (aka CS/OTA) status report to GRVA |
| Reference Number: GRVA-25-35 |
|
The Informal Working Group on Cyber Security and Software Updates discussed amendments to UN R155 and UN R156 for multi-stage approval, including simplified handling for low-risk devices and clarification of intrinsic cyber risk assessment. The group reviewed proposals from GRVA-25-31 and GRVA-25-32 concerning continued validity of approvals and Certificate of Compliance issuance. A Sub-Working Group was established to develop component and separate technical unit approval concepts. Pending discussion include RXSWIN application to components, STUs, and the extent of application to UN R155 and UN R156, and type-approval numbering for software updates. |
| Submitted by: TFCS |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 20 May 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| EV and Hydrogen Fuel-Cell Vehicle Retrofits: Comments on GRVA-25-07 |
| Reference Number: GRVA-25-41 |
|
OICA-CLEPA-EME comments on German proposal GRVA-25-07 to require the approval authority granting UN R155 or UN R156 type approvals to use CSMS or SUMS certificates signed by the same approval authority. OICA-CLEPA-EME identify that CSMS and SUMS are Management Systems covering entire manufacturer organizations, and mandating the same approval authority for Management Systems certificates and approvals will have significant consequences for original equipment manufacturers typically using multiple approval authorities in homologation. The submission proposes keeping text unchanged to allow different approval authorities for Management Systems certificates and type approval based on voluntary acceptance, implementing wording on information exchange if different approval authorities are involved, and establishing a horizontal approach for Management Systems with mutual recognition aspects considered. |
| Submitted by: EME, OICA, and CLEPA |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 20 May 26 |
| Relevant to: WP.29 Regulatory Project | Electric and Hydrogen Fuel-Cell Vehicle Retrofit Systems |
| Click here to view the full document file |
| UN R155 and R156: Proposal for amendments |
| Reference Number: GRVA-25-07 |
|
Proposal to amend para. 5.1.3. of UN R155 to add a refusal ground where the Certificate of Compliance for the Cyber Security Management System has not been issued by the same approval authority granting type approval, and insert new para. 5.4. into UN R156 to provide that approval authorities shall not grant any type approval if the Certificate of Compliance for the Software Update Management System has not been issued by the same approval authority granting type approval. The proposal, based on TFCS-37-02, ensures that Certificates of Compliance and type-approvals for UN R155 and UN R156 are issued by the same approval authority to enable holistic assessment and clarify reporting obligations. |
| Submitted by: France, Germany, Luxembourg, Netherlands, and UK |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 04 May 26 |
| Document status: Informal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| Proposal for amendments to UN Regulations Nos. 13, 13-H, 79, 89, 130, 131, 152, 155, 156, 157, 171, 175, and 178 |
| Reference Number: GRVA-25-30 |
|
Proposal to insert provisions on software identification and software updates into UN R13, UN R13-H, UN R79, UN R89, UN R130, UN R131, UN R152, UN R155, UN R156, UN R157, UN R171, UN R175, and UN R178 by adding definitions referencing Consolidated Resolution R.E.3 Annex 7, requiring manufacturers to provide Technical Services with information on hardware and software influencing performance, permitting vehicle manufacturers to apply for new approvals differentiating software versions for registered versus new vehicles, clarifying that production discontinuation does not apply when manufacturers seek approval extensions for software updates of registered vehicles, and amending communication forms to include software identification numbers and related information. |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 18 May 26 |
| Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 13-H | Light-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, United Nations Agreement | RE3 Construction of Vehicles, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error |
| Click here to view the full document file |
| UN R155: Proposal for amendments |
| Reference Number: GRVA-25-31 |
|
Proposal to amend para. 5.3.2. to require approval authorities to notify other approval authorities of methods and criteria used to assess measures taken in accordance with the Regulation, insert new para. 8.2. to exclude equipment with negligible intrinsic cyber security risk from further assessment where installation does not impinge on the cyber security management system and is connected exclusively via an approved interface, insert new para. 8.3. to exclude standard domestic, business or industrial equipment connected only for power from further assessment where the equipment is unmodified and complies with applicable regional and national cyber security requirements, and amend Annex 1 to include any equipment excluded from assessment pursuant to paras. 8.2. and 8.3. |
| Submitted by: TFCS |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 18 May 26 |
| Document status: Informal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| UN R155: Proposal to amend the Interpretation Document |
| Reference Number: GRVA-25-32 |
|
Proposal to insert new Part C providing guidance on application of UN R155 to transformed vehicles. Part C defines when transformations require new approval, establishes terminology for original vehicle types, transformed vehicle types, transformations, and installations, identifies cyber-relevant transformations by evaluating impact on architecture and connection risks, addresses intrinsic cyber security risks, clarifies non-automotive equipment requirements, and specifies documentary evidence manufacturers must provide to approval authorities or technical services, including functional descriptions, connection details, software modifications, and component lists. |
| Submitted by: TFCS |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 18 May 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Cyber Security task force (aka CS/OTA) status report to GRVA |
| Reference Number: GRVA-25-35 |
|
The Informal Working Group on Cyber Security and Software Updates discussed amendments to UN R155 and UN R156 for multi-stage approval, including simplified handling for low-risk devices and clarification of intrinsic cyber risk assessment. The group reviewed proposals from GRVA-25-31 and GRVA-25-32 concerning continued validity of approvals and Certificate of Compliance issuance. A Sub-Working Group was established to develop component and separate technical unit approval concepts. Pending discussion include RXSWIN application to components, STUs, and the extent of application to UN R155 and UN R156, and type-approval numbering for software updates. |
| Submitted by: TFCS |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 20 May 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| EV and Hydrogen Fuel-Cell Vehicle Retrofits: Comments on GRVA-25-07 |
| Reference Number: GRVA-25-41 |
|
OICA-CLEPA-EME comments on German proposal GRVA-25-07 to require the approval authority granting UN R155 or UN R156 type approvals to use CSMS or SUMS certificates signed by the same approval authority. OICA-CLEPA-EME identify that CSMS and SUMS are Management Systems covering entire manufacturer organizations, and mandating the same approval authority for Management Systems certificates and approvals will have significant consequences for original equipment manufacturers typically using multiple approval authorities in homologation. The submission proposes keeping text unchanged to allow different approval authorities for Management Systems certificates and type approval based on voluntary acceptance, implementing wording on information exchange if different approval authorities are involved, and establishing a horizontal approach for Management Systems with mutual recognition aspects considered. |
| Submitted by: EME, OICA, and CLEPA |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 20 May 26 |
| Relevant to: WP.29 Regulatory Project | Electric and Hydrogen Fuel-Cell Vehicle Retrofit Systems |
| Click here to view the full document file |
GRVA will be briefed on the outcome of the recent meeting(s) of the IWG on Cyber Security and Over-the-Air (CS/OTA) issues.
| GRVA-25-35 | Cyber Security task force (aka CS/OTA) status report to GRVA |
|
GRVA may wish to be informed on the outcome of the technical workshop(s) on the implementation of cyber security and software updates provisions.
| GRVA-25-30 | Proposal for amendments to UN Regulations Nos. 13, 13-H, 79, 89, 130, 131, 152, 155, 156, 157, 171, 175, and 178 |
|
GRVA may wish to review the proposed amendments to UN Regulations Nos. 155 and 156, if any.
| GRVA-25-07 | UN R155 and R156: Proposal for amendments |
|
| GRVA-25-31 | UN R155: Proposal for amendments |
|
| GRVA-25-32 | UN R155: Proposal to amend the Interpretation Document |
|
| GRVA-25-41 | EV and Hydrogen Fuel-Cell Vehicle Retrofits: Comments on GRVA-25-07 |
|