| Proposal to amend UN R155 and UN R156 |
| Reference Number: GRVA/2026/30 |
|
Proposal to amend UN R155 by inserting new para. 5.1.3.(e) establishing that the Certificate of Compliance for the Cyber Security Management System shall not be issued by a different Approval Authority than the one granting type approval, and amend UN R156 by inserting new para. 5.4. establishing that Approval Authorities shall not grant type approval if the Certificate of Compliance for the Software Update Management System has not been issued by the same Approval Authority granting type approval. Justification includes ensuring holistic cybersecurity assessment, clarifying reporting obligations under para. 7.2.2.2.(g), addressing unharmonized mutual recognition of management system certificates, maintaining consistency between regulations, and upholding the fundamental principle that approval authorities retain responsibility for all aspects of type approval. |
| Submitted by: France, Germany, Luxembourg, Netherlands, and UK |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 03 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155: Proposal for a Supplement |
| Reference Number: GRVA/2026/28 |
|
Proposal to amend para. 5.3.2. to require notification of assessment methods and criteria including paras. 8.2. and 8.3., insert new paras. 8.2. and 8.3. establishing criteria for equipment installation without further assessment, and amend Annex 1 to require disclosure of equipment excluded from assessment pursuant to paras. 8.2. and 8.3. The amendments clarify that equipment with negligible intrinsic cyber security risk installed according to manufacturer specifications and not introducing cyber security risk, and standard non-automotive equipment connected solely for power supply with no increased cyber security risk, shall not invalidate approval of the original vehicle type under UN Regulation No. 155. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 03 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| UN R155: Proposal for a Supplement |
| Reference Number: GRVA/2026/29 |
|
Proposal to insert new Part C providing guidance for the application of UN R155 to transformed vehicles. Part C addresses identification of cyber-relevant transformations, impact on original vehicle architecture, connection risks, and impact on cyber security management systems. It specifies that transformations require new approval unless the manufacturer provides clear evidence that the original approval remains valid, and outlines critical factors and examples of cyber-relevant actions. It details documentary evidence expected from manufacturers regarding functional descriptions, connections with original vehicle types, added components and functions, and arguments demonstrating negligible intrinsic risk. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 06 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Proposal for amendments to UN Regulations Nos. 13, 13-H, 79, 89, 130, 131, 152, 155, 156, 157, 171, 175, and 178 |
| Reference Number: GRVA/2026/27 |
|
Proposal to insert provisions on Software Identification Numbers and software updates across UN R13, R13-H, R79, R89, R130, R131, R152, R155, R156, R157, R171, R175, and R178 by adding definitions referencing Consolidated Resolution R.E.3 Annex 7 paragraph 2, requiring manufacturers to provide Technical Services with information on hardware and software influencing performance with test reports, permitting vehicle manufacturers to apply for new approvals differentiating software versions for registered vehicles from new vehicles where type approval regulations are updated or hardware changes occur in series production with test duplication avoided where possible, clarifying that production is not considered definitively discontinued if manufacturers obtain subsequent extensions for software updates of registered vehicles, renumbering and inserting new items in approval communication annexes for R13SWIN, R13-HSWIN, R79SWIN, R89SWIN, R130SWIN, R131SWIN, R152SWIN, R155SWIN, R157SWIN, R171SWIN, R175SWIN, and R178SWIN information including whether held on vehicle and relevant parameter identification lists, and amending R157 and R171 to align software update requirements with R156 technical specifications and transitional provisions. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 06 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 13-H | Light-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error |
| Click here to view the full document file |
| Software updates: Proposal to amend GRVA/2026/27 |
| Reference Number: GRVA-26-11 |
|
Proposal to insert definitions for Software Identification Number, insert requirements for manufacturers to provide necessary information allowing the Technical Service to uniquely identify hardware and software configurations, insert provisions allowing vehicle manufacturers to apply for new approvals to differentiate software versions for registered versus new vehicles, amend production discontinuation provisions to clarify that cessation is not deemed definitive if the manufacturer intends to obtain subsequent extensions for software updates of vehicles already registered in the market, renumber and insert new items in approval communication annexes regarding software identification and software updates including RxSWIN, and insert provisions allowing vehicle manufacturers to obtain new approvals for software version differentiation across multiple UN Regulations (13, 13-H, 79, 89, 130, 131, 139, 140, 152, 155, 156, 157, 171, 175, and 178). |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 140 | Electronic Stability Control Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 139 | Brake Assist Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error |
| Click here to view the full document file |
| UN R155: Proposal to amend the Interpretation Document |
| Reference Number: GRVA-26-12 |
|
Proposal to amend paragraph AI to introduce a link between existing text in Part A and new Part C regarding vehicle transformations, insert new Part C providing guidance for the application of UN Regulation No. 155 to transformed vehicles including documentary evidence requirements, and add section 6 clarifying that the requirement for Certificate of Compliance and type approval to be issued by the same Approval Authority applies only within the scope of a specific type approval and its approval holder. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Cyber Security and Software Updates informal group status report to GRVA |
| Reference Number: GRVA-26-18 |
|
Status report on activities of the IWG on CS/OTA since the 25th GRVA session. The IWG reviewed proposals for amendment of UN R155 and its interpretation document for multi-stage vehicles, proposals for approval-authority arrangements and Certificates of Compliance for UN R155 and R156, proposals integrating software identification and update text across several UNRs outlined in RE.3, component and STU approval concepts, and remote operation and automated driving systems. The IWG proposes updating regulatory text and interpretation documents for UN R155, revisions to software identification and update text across several regulations, and revised Terms of Reference for a mandate till November 2029. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 89 | Speed Limitation Devices, WP.29 Regulatory Project | Automated Driving Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| Informal Working Group on Cyber Security and Software Updates: Proposal for Terms of Reference |
| Reference Number: GRVA-26-19 |
|
Proposal to renew the terms for the Informal Working Group on Cyber Security and Software Updates under GRVA. The IWG shall maintain official documents on cyber security and software updates, develop amendments to UN R155 and UN R156 including provisions on software identification, support application across Global Technical Regulations, and provide opportunities for participants to share implementation experience. The IWG will be chaired by the United Kingdom, United States, and Japan, with OICA providing technical secretariat, and will operate until November 2029. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155/R156: Approval Authority for the COC of a CSMS/SUMS and type approval (vehicle type) |
| Reference Number: GRVA-26-20 |
|
Document explains concerns about the approach in GRVA/2026/30 to require a single Approval Authority to issue certificates of compliance for Cyber Security Management Systems and Automated Driving Systems Management Systems and vehicle type approval. The proposed changes would lead to double or triple approvals of management systems, creating administrative burden and unresolved legal consequences regarding challenged certificates of compliance and their effects on other issued certificates for the same management system. The submission proposes clarifying existing wording, documenting implications of challenged certificates, and adding a new paragraph 5.1.5. to UN R155 permitting mutual agreement between Approval Authorities regarding certificate usage. |
| Submitted by: CLCCR, CLEPA, and OICA |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 133 | Light Vehicle Recyclability, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 185 | Approval of vehicles with regard to their Automated Driving Systems |
| Click here to view the full document file |
| Proposal for amendments to the 1958 Agreement regarding the voluntary acceptance of Certificates of Compliance |
| Reference Number: GRVA-26-21 |
|
Proposal to amend Article 2, paragraph 2 to clarify that where a Certificate of Compliance required under a UN Regulation and issued by an Approval Authority of another Contracting Party is accepted by a Contracting Party, the Approval Authority granting the corresponding type approval shall remain responsible for all aspects of that type approval. The amendment addresses management systems and their Certificates of Compliance used in UN Regulations such as UN R155 and UN R156. |
| Submitted by: CLCCR, CLEPA, and OICA |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: United Nations Agreement | 1958 Agreement, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155 and R156: Proposal to amend GRVA/2026/30 |
| Reference Number: GRVA-26-35 |
|
Proposal to amend para. 5.1.3., insert new paras. 5.1.5. and 5.1.5.1. requiring the Approval Authority to refuse type approval unless the Certificate of Compliance for the Cyber Security Management System is issued by the same Approval Authority granting vehicle type approval, while permitting referencing of certificates from other Approval Authorities under specific conditions with documented agreements and clarified responsibilities, and insert new paras. 5.4. and 5.4.1. with equivalent requirements for the Software Update Management System Certificate of Compliance. |
| Submitted by: UK, France, Luxembourg, Germany, and Netherlands |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 17 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155: Proposal to amend GRVA/2026/29 |
| Reference Number: GRVA-26-36/Rev.1 |
|
Proposal to amend paragraph AI to introduce a link between existing text in Part A and new text in Part C regarding vehicle transformations, and insert new Part C providing guidance for the application of UN Regulation No. 155 to transformed vehicles. The proposal adds section 6 clarifying that the requirement for the Certificate of Compliance and type approval to be issued by the same Approval Authority applies only within the scope of the type approval granted to the manufacturer concerned, and does not restrict another manufacturer from obtaining a separate type approval and associated Certificate of Compliance from the responsible Approval Authority. |
| Submitted by: UK |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 18 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Proposal to amend UN R155 and UN R156 |
| Reference Number: GRVA/2026/30 |
|
Proposal to amend UN R155 by inserting new para. 5.1.3.(e) establishing that the Certificate of Compliance for the Cyber Security Management System shall not be issued by a different Approval Authority than the one granting type approval, and amend UN R156 by inserting new para. 5.4. establishing that Approval Authorities shall not grant type approval if the Certificate of Compliance for the Software Update Management System has not been issued by the same Approval Authority granting type approval. Justification includes ensuring holistic cybersecurity assessment, clarifying reporting obligations under para. 7.2.2.2.(g), addressing unharmonized mutual recognition of management system certificates, maintaining consistency between regulations, and upholding the fundamental principle that approval authorities retain responsibility for all aspects of type approval. |
| Submitted by: France, Germany, Luxembourg, Netherlands, and UK |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 03 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155: Proposal for a Supplement |
| Reference Number: GRVA/2026/28 |
|
Proposal to amend para. 5.3.2. to require notification of assessment methods and criteria including paras. 8.2. and 8.3., insert new paras. 8.2. and 8.3. establishing criteria for equipment installation without further assessment, and amend Annex 1 to require disclosure of equipment excluded from assessment pursuant to paras. 8.2. and 8.3. The amendments clarify that equipment with negligible intrinsic cyber security risk installed according to manufacturer specifications and not introducing cyber security risk, and standard non-automotive equipment connected solely for power supply with no increased cyber security risk, shall not invalidate approval of the original vehicle type under UN Regulation No. 155. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 03 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| UN R155: Proposal for a Supplement |
| Reference Number: GRVA/2026/29 |
|
Proposal to insert new Part C providing guidance for the application of UN R155 to transformed vehicles. Part C addresses identification of cyber-relevant transformations, impact on original vehicle architecture, connection risks, and impact on cyber security management systems. It specifies that transformations require new approval unless the manufacturer provides clear evidence that the original approval remains valid, and outlines critical factors and examples of cyber-relevant actions. It details documentary evidence expected from manufacturers regarding functional descriptions, connections with original vehicle types, added components and functions, and arguments demonstrating negligible intrinsic risk. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 06 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Proposal for amendments to UN Regulations Nos. 13, 13-H, 79, 89, 130, 131, 152, 155, 156, 157, 171, 175, and 178 |
| Reference Number: GRVA/2026/27 |
|
Proposal to insert provisions on Software Identification Numbers and software updates across UN R13, R13-H, R79, R89, R130, R131, R152, R155, R156, R157, R171, R175, and R178 by adding definitions referencing Consolidated Resolution R.E.3 Annex 7 paragraph 2, requiring manufacturers to provide Technical Services with information on hardware and software influencing performance with test reports, permitting vehicle manufacturers to apply for new approvals differentiating software versions for registered vehicles from new vehicles where type approval regulations are updated or hardware changes occur in series production with test duplication avoided where possible, clarifying that production is not considered definitively discontinued if manufacturers obtain subsequent extensions for software updates of registered vehicles, renumbering and inserting new items in approval communication annexes for R13SWIN, R13-HSWIN, R79SWIN, R89SWIN, R130SWIN, R131SWIN, R152SWIN, R155SWIN, R157SWIN, R171SWIN, R175SWIN, and R178SWIN information including whether held on vehicle and relevant parameter identification lists, and amending R157 and R171 to align software update requirements with R156 technical specifications and transitional provisions. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 06 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 13-H | Light-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error |
| Click here to view the full document file |
| Software updates: Proposal to amend GRVA/2026/27 |
| Reference Number: GRVA-26-11 |
|
Proposal to insert definitions for Software Identification Number, insert requirements for manufacturers to provide necessary information allowing the Technical Service to uniquely identify hardware and software configurations, insert provisions allowing vehicle manufacturers to apply for new approvals to differentiate software versions for registered versus new vehicles, amend production discontinuation provisions to clarify that cessation is not deemed definitive if the manufacturer intends to obtain subsequent extensions for software updates of vehicles already registered in the market, renumber and insert new items in approval communication annexes regarding software identification and software updates including RxSWIN, and insert provisions allowing vehicle manufacturers to obtain new approvals for software version differentiation across multiple UN Regulations (13, 13-H, 79, 89, 130, 131, 139, 140, 152, 155, 156, 157, 171, 175, and 178). |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 140 | Electronic Stability Control Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 139 | Brake Assist Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error |
| Click here to view the full document file |
| UN R155: Proposal to amend the Interpretation Document |
| Reference Number: GRVA-26-12 |
|
Proposal to amend paragraph AI to introduce a link between existing text in Part A and new Part C regarding vehicle transformations, insert new Part C providing guidance for the application of UN Regulation No. 155 to transformed vehicles including documentary evidence requirements, and add section 6 clarifying that the requirement for Certificate of Compliance and type approval to be issued by the same Approval Authority applies only within the scope of a specific type approval and its approval holder. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Cyber Security and Software Updates informal group status report to GRVA |
| Reference Number: GRVA-26-18 |
|
Status report on activities of the IWG on CS/OTA since the 25th GRVA session. The IWG reviewed proposals for amendment of UN R155 and its interpretation document for multi-stage vehicles, proposals for approval-authority arrangements and Certificates of Compliance for UN R155 and R156, proposals integrating software identification and update text across several UNRs outlined in RE.3, component and STU approval concepts, and remote operation and automated driving systems. The IWG proposes updating regulatory text and interpretation documents for UN R155, revisions to software identification and update text across several regulations, and revised Terms of Reference for a mandate till November 2029. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 89 | Speed Limitation Devices, WP.29 Regulatory Project | Automated Driving Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| Informal Working Group on Cyber Security and Software Updates: Proposal for Terms of Reference |
| Reference Number: GRVA-26-19 |
|
Proposal to renew the terms for the Informal Working Group on Cyber Security and Software Updates under GRVA. The IWG shall maintain official documents on cyber security and software updates, develop amendments to UN R155 and UN R156 including provisions on software identification, support application across Global Technical Regulations, and provide opportunities for participants to share implementation experience. The IWG will be chaired by the United Kingdom, United States, and Japan, with OICA providing technical secretariat, and will operate until November 2029. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155/R156: Approval Authority for the COC of a CSMS/SUMS and type approval (vehicle type) |
| Reference Number: GRVA-26-20 |
|
Document explains concerns about the approach in GRVA/2026/30 to require a single Approval Authority to issue certificates of compliance for Cyber Security Management Systems and Automated Driving Systems Management Systems and vehicle type approval. The proposed changes would lead to double or triple approvals of management systems, creating administrative burden and unresolved legal consequences regarding challenged certificates of compliance and their effects on other issued certificates for the same management system. The submission proposes clarifying existing wording, documenting implications of challenged certificates, and adding a new paragraph 5.1.5. to UN R155 permitting mutual agreement between Approval Authorities regarding certificate usage. |
| Submitted by: CLCCR, CLEPA, and OICA |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 133 | Light Vehicle Recyclability, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 185 | Approval of vehicles with regard to their Automated Driving Systems |
| Click here to view the full document file |
| Proposal for amendments to the 1958 Agreement regarding the voluntary acceptance of Certificates of Compliance |
| Reference Number: GRVA-26-21 |
|
Proposal to amend Article 2, paragraph 2 to clarify that where a Certificate of Compliance required under a UN Regulation and issued by an Approval Authority of another Contracting Party is accepted by a Contracting Party, the Approval Authority granting the corresponding type approval shall remain responsible for all aspects of that type approval. The amendment addresses management systems and their Certificates of Compliance used in UN Regulations such as UN R155 and UN R156. |
| Submitted by: CLCCR, CLEPA, and OICA |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: United Nations Agreement | 1958 Agreement, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155 and R156: Proposal to amend GRVA/2026/30 |
| Reference Number: GRVA-26-35 |
|
Proposal to amend para. 5.1.3., insert new paras. 5.1.5. and 5.1.5.1. requiring the Approval Authority to refuse type approval unless the Certificate of Compliance for the Cyber Security Management System is issued by the same Approval Authority granting vehicle type approval, while permitting referencing of certificates from other Approval Authorities under specific conditions with documented agreements and clarified responsibilities, and insert new paras. 5.4. and 5.4.1. with equivalent requirements for the Software Update Management System Certificate of Compliance. |
| Submitted by: UK, France, Luxembourg, Germany, and Netherlands |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 17 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155: Proposal to amend GRVA/2026/29 |
| Reference Number: GRVA-26-36/Rev.1 |
|
Proposal to amend paragraph AI to introduce a link between existing text in Part A and new text in Part C regarding vehicle transformations, and insert new Part C providing guidance for the application of UN Regulation No. 155 to transformed vehicles. The proposal adds section 6 clarifying that the requirement for the Certificate of Compliance and type approval to be issued by the same Approval Authority applies only within the scope of the type approval granted to the manufacturer concerned, and does not restrict another manufacturer from obtaining a separate type approval and associated Certificate of Compliance from the responsible Approval Authority. |
| Submitted by: UK |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 18 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Proposal to amend UN R155 and UN R156 |
| Reference Number: GRVA/2026/30 |
|
Proposal to amend UN R155 by inserting new para. 5.1.3.(e) establishing that the Certificate of Compliance for the Cyber Security Management System shall not be issued by a different Approval Authority than the one granting type approval, and amend UN R156 by inserting new para. 5.4. establishing that Approval Authorities shall not grant type approval if the Certificate of Compliance for the Software Update Management System has not been issued by the same Approval Authority granting type approval. Justification includes ensuring holistic cybersecurity assessment, clarifying reporting obligations under para. 7.2.2.2.(g), addressing unharmonized mutual recognition of management system certificates, maintaining consistency between regulations, and upholding the fundamental principle that approval authorities retain responsibility for all aspects of type approval. |
| Submitted by: France, Germany, Luxembourg, Netherlands, and UK |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 03 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155: Proposal for a Supplement |
| Reference Number: GRVA/2026/28 |
|
Proposal to amend para. 5.3.2. to require notification of assessment methods and criteria including paras. 8.2. and 8.3., insert new paras. 8.2. and 8.3. establishing criteria for equipment installation without further assessment, and amend Annex 1 to require disclosure of equipment excluded from assessment pursuant to paras. 8.2. and 8.3. The amendments clarify that equipment with negligible intrinsic cyber security risk installed according to manufacturer specifications and not introducing cyber security risk, and standard non-automotive equipment connected solely for power supply with no increased cyber security risk, shall not invalidate approval of the original vehicle type under UN Regulation No. 155. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 03 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| UN R155: Proposal for a Supplement |
| Reference Number: GRVA/2026/29 |
|
Proposal to insert new Part C providing guidance for the application of UN R155 to transformed vehicles. Part C addresses identification of cyber-relevant transformations, impact on original vehicle architecture, connection risks, and impact on cyber security management systems. It specifies that transformations require new approval unless the manufacturer provides clear evidence that the original approval remains valid, and outlines critical factors and examples of cyber-relevant actions. It details documentary evidence expected from manufacturers regarding functional descriptions, connections with original vehicle types, added components and functions, and arguments demonstrating negligible intrinsic risk. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 06 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Proposal for amendments to UN Regulations Nos. 13, 13-H, 79, 89, 130, 131, 152, 155, 156, 157, 171, 175, and 178 |
| Reference Number: GRVA/2026/27 |
|
Proposal to insert provisions on Software Identification Numbers and software updates across UN R13, R13-H, R79, R89, R130, R131, R152, R155, R156, R157, R171, R175, and R178 by adding definitions referencing Consolidated Resolution R.E.3 Annex 7 paragraph 2, requiring manufacturers to provide Technical Services with information on hardware and software influencing performance with test reports, permitting vehicle manufacturers to apply for new approvals differentiating software versions for registered vehicles from new vehicles where type approval regulations are updated or hardware changes occur in series production with test duplication avoided where possible, clarifying that production is not considered definitively discontinued if manufacturers obtain subsequent extensions for software updates of registered vehicles, renumbering and inserting new items in approval communication annexes for R13SWIN, R13-HSWIN, R79SWIN, R89SWIN, R130SWIN, R131SWIN, R152SWIN, R155SWIN, R157SWIN, R171SWIN, R175SWIN, and R178SWIN information including whether held on vehicle and relevant parameter identification lists, and amending R157 and R171 to align software update requirements with R156 technical specifications and transitional provisions. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 06 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 13-H | Light-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error |
| Click here to view the full document file |
| Software updates: Proposal to amend GRVA/2026/27 |
| Reference Number: GRVA-26-11 |
|
Proposal to insert definitions for Software Identification Number, insert requirements for manufacturers to provide necessary information allowing the Technical Service to uniquely identify hardware and software configurations, insert provisions allowing vehicle manufacturers to apply for new approvals to differentiate software versions for registered versus new vehicles, amend production discontinuation provisions to clarify that cessation is not deemed definitive if the manufacturer intends to obtain subsequent extensions for software updates of vehicles already registered in the market, renumber and insert new items in approval communication annexes regarding software identification and software updates including RxSWIN, and insert provisions allowing vehicle manufacturers to obtain new approvals for software version differentiation across multiple UN Regulations (13, 13-H, 79, 89, 130, 131, 139, 140, 152, 155, 156, 157, 171, 175, and 178). |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 140 | Electronic Stability Control Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 139 | Brake Assist Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error |
| Click here to view the full document file |
| UN R155: Proposal to amend the Interpretation Document |
| Reference Number: GRVA-26-12 |
|
Proposal to amend paragraph AI to introduce a link between existing text in Part A and new Part C regarding vehicle transformations, insert new Part C providing guidance for the application of UN Regulation No. 155 to transformed vehicles including documentary evidence requirements, and add section 6 clarifying that the requirement for Certificate of Compliance and type approval to be issued by the same Approval Authority applies only within the scope of a specific type approval and its approval holder. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Cyber Security and Software Updates informal group status report to GRVA |
| Reference Number: GRVA-26-18 |
|
Status report on activities of the IWG on CS/OTA since the 25th GRVA session. The IWG reviewed proposals for amendment of UN R155 and its interpretation document for multi-stage vehicles, proposals for approval-authority arrangements and Certificates of Compliance for UN R155 and R156, proposals integrating software identification and update text across several UNRs outlined in RE.3, component and STU approval concepts, and remote operation and automated driving systems. The IWG proposes updating regulatory text and interpretation documents for UN R155, revisions to software identification and update text across several regulations, and revised Terms of Reference for a mandate till November 2029. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 89 | Speed Limitation Devices, WP.29 Regulatory Project | Automated Driving Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| Informal Working Group on Cyber Security and Software Updates: Proposal for Terms of Reference |
| Reference Number: GRVA-26-19 |
|
Proposal to renew the terms for the Informal Working Group on Cyber Security and Software Updates under GRVA. The IWG shall maintain official documents on cyber security and software updates, develop amendments to UN R155 and UN R156 including provisions on software identification, support application across Global Technical Regulations, and provide opportunities for participants to share implementation experience. The IWG will be chaired by the United Kingdom, United States, and Japan, with OICA providing technical secretariat, and will operate until November 2029. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155/R156: Approval Authority for the COC of a CSMS/SUMS and type approval (vehicle type) |
| Reference Number: GRVA-26-20 |
|
Document explains concerns about the approach in GRVA/2026/30 to require a single Approval Authority to issue certificates of compliance for Cyber Security Management Systems and Automated Driving Systems Management Systems and vehicle type approval. The proposed changes would lead to double or triple approvals of management systems, creating administrative burden and unresolved legal consequences regarding challenged certificates of compliance and their effects on other issued certificates for the same management system. The submission proposes clarifying existing wording, documenting implications of challenged certificates, and adding a new paragraph 5.1.5. to UN R155 permitting mutual agreement between Approval Authorities regarding certificate usage. |
| Submitted by: CLCCR, CLEPA, and OICA |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 133 | Light Vehicle Recyclability, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 185 | Approval of vehicles with regard to their Automated Driving Systems |
| Click here to view the full document file |
| Proposal for amendments to the 1958 Agreement regarding the voluntary acceptance of Certificates of Compliance |
| Reference Number: GRVA-26-21 |
|
Proposal to amend Article 2, paragraph 2 to clarify that where a Certificate of Compliance required under a UN Regulation and issued by an Approval Authority of another Contracting Party is accepted by a Contracting Party, the Approval Authority granting the corresponding type approval shall remain responsible for all aspects of that type approval. The amendment addresses management systems and their Certificates of Compliance used in UN Regulations such as UN R155 and UN R156. |
| Submitted by: CLCCR, CLEPA, and OICA |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: United Nations Agreement | 1958 Agreement, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155 and R156: Proposal to amend GRVA/2026/30 |
| Reference Number: GRVA-26-35 |
|
Proposal to amend para. 5.1.3., insert new paras. 5.1.5. and 5.1.5.1. requiring the Approval Authority to refuse type approval unless the Certificate of Compliance for the Cyber Security Management System is issued by the same Approval Authority granting vehicle type approval, while permitting referencing of certificates from other Approval Authorities under specific conditions with documented agreements and clarified responsibilities, and insert new paras. 5.4. and 5.4.1. with equivalent requirements for the Software Update Management System Certificate of Compliance. |
| Submitted by: UK, France, Luxembourg, Germany, and Netherlands |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 17 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155: Proposal to amend GRVA/2026/29 |
| Reference Number: GRVA-26-36/Rev.1 |
|
Proposal to amend paragraph AI to introduce a link between existing text in Part A and new text in Part C regarding vehicle transformations, and insert new Part C providing guidance for the application of UN Regulation No. 155 to transformed vehicles. The proposal adds section 6 clarifying that the requirement for the Certificate of Compliance and type approval to be issued by the same Approval Authority applies only within the scope of the type approval granted to the manufacturer concerned, and does not restrict another manufacturer from obtaining a separate type approval and associated Certificate of Compliance from the responsible Approval Authority. |
| Submitted by: UK |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 18 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Proposal to amend UN R155 and UN R156 |
| Reference Number: GRVA/2026/30 |
|
Proposal to amend UN R155 by inserting new para. 5.1.3.(e) establishing that the Certificate of Compliance for the Cyber Security Management System shall not be issued by a different Approval Authority than the one granting type approval, and amend UN R156 by inserting new para. 5.4. establishing that Approval Authorities shall not grant type approval if the Certificate of Compliance for the Software Update Management System has not been issued by the same Approval Authority granting type approval. Justification includes ensuring holistic cybersecurity assessment, clarifying reporting obligations under para. 7.2.2.2.(g), addressing unharmonized mutual recognition of management system certificates, maintaining consistency between regulations, and upholding the fundamental principle that approval authorities retain responsibility for all aspects of type approval. |
| Submitted by: France, Germany, Luxembourg, Netherlands, and UK |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 03 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155: Proposal for a Supplement |
| Reference Number: GRVA/2026/28 |
|
Proposal to amend para. 5.3.2. to require notification of assessment methods and criteria including paras. 8.2. and 8.3., insert new paras. 8.2. and 8.3. establishing criteria for equipment installation without further assessment, and amend Annex 1 to require disclosure of equipment excluded from assessment pursuant to paras. 8.2. and 8.3. The amendments clarify that equipment with negligible intrinsic cyber security risk installed according to manufacturer specifications and not introducing cyber security risk, and standard non-automotive equipment connected solely for power supply with no increased cyber security risk, shall not invalidate approval of the original vehicle type under UN Regulation No. 155. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 03 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| UN R155: Proposal for a Supplement |
| Reference Number: GRVA/2026/29 |
|
Proposal to insert new Part C providing guidance for the application of UN R155 to transformed vehicles. Part C addresses identification of cyber-relevant transformations, impact on original vehicle architecture, connection risks, and impact on cyber security management systems. It specifies that transformations require new approval unless the manufacturer provides clear evidence that the original approval remains valid, and outlines critical factors and examples of cyber-relevant actions. It details documentary evidence expected from manufacturers regarding functional descriptions, connections with original vehicle types, added components and functions, and arguments demonstrating negligible intrinsic risk. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 06 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Proposal for amendments to UN Regulations Nos. 13, 13-H, 79, 89, 130, 131, 152, 155, 156, 157, 171, 175, and 178 |
| Reference Number: GRVA/2026/27 |
|
Proposal to insert provisions on Software Identification Numbers and software updates across UN R13, R13-H, R79, R89, R130, R131, R152, R155, R156, R157, R171, R175, and R178 by adding definitions referencing Consolidated Resolution R.E.3 Annex 7 paragraph 2, requiring manufacturers to provide Technical Services with information on hardware and software influencing performance with test reports, permitting vehicle manufacturers to apply for new approvals differentiating software versions for registered vehicles from new vehicles where type approval regulations are updated or hardware changes occur in series production with test duplication avoided where possible, clarifying that production is not considered definitively discontinued if manufacturers obtain subsequent extensions for software updates of registered vehicles, renumbering and inserting new items in approval communication annexes for R13SWIN, R13-HSWIN, R79SWIN, R89SWIN, R130SWIN, R131SWIN, R152SWIN, R155SWIN, R157SWIN, R171SWIN, R175SWIN, and R178SWIN information including whether held on vehicle and relevant parameter identification lists, and amending R157 and R171 to align software update requirements with R156 technical specifications and transitional provisions. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 06 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 13-H | Light-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error |
| Click here to view the full document file |
| Software updates: Proposal to amend GRVA/2026/27 |
| Reference Number: GRVA-26-11 |
|
Proposal to insert definitions for Software Identification Number, insert requirements for manufacturers to provide necessary information allowing the Technical Service to uniquely identify hardware and software configurations, insert provisions allowing vehicle manufacturers to apply for new approvals to differentiate software versions for registered versus new vehicles, amend production discontinuation provisions to clarify that cessation is not deemed definitive if the manufacturer intends to obtain subsequent extensions for software updates of vehicles already registered in the market, renumber and insert new items in approval communication annexes regarding software identification and software updates including RxSWIN, and insert provisions allowing vehicle manufacturers to obtain new approvals for software version differentiation across multiple UN Regulations (13, 13-H, 79, 89, 130, 131, 139, 140, 152, 155, 156, 157, 171, 175, and 178). |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 140 | Electronic Stability Control Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 139 | Brake Assist Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error |
| Click here to view the full document file |
| UN R155: Proposal to amend the Interpretation Document |
| Reference Number: GRVA-26-12 |
|
Proposal to amend paragraph AI to introduce a link between existing text in Part A and new Part C regarding vehicle transformations, insert new Part C providing guidance for the application of UN Regulation No. 155 to transformed vehicles including documentary evidence requirements, and add section 6 clarifying that the requirement for Certificate of Compliance and type approval to be issued by the same Approval Authority applies only within the scope of a specific type approval and its approval holder. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Cyber Security and Software Updates informal group status report to GRVA |
| Reference Number: GRVA-26-18 |
|
Status report on activities of the IWG on CS/OTA since the 25th GRVA session. The IWG reviewed proposals for amendment of UN R155 and its interpretation document for multi-stage vehicles, proposals for approval-authority arrangements and Certificates of Compliance for UN R155 and R156, proposals integrating software identification and update text across several UNRs outlined in RE.3, component and STU approval concepts, and remote operation and automated driving systems. The IWG proposes updating regulatory text and interpretation documents for UN R155, revisions to software identification and update text across several regulations, and revised Terms of Reference for a mandate till November 2029. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 89 | Speed Limitation Devices, WP.29 Regulatory Project | Automated Driving Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| Informal Working Group on Cyber Security and Software Updates: Proposal for Terms of Reference |
| Reference Number: GRVA-26-19 |
|
Proposal to renew the terms for the Informal Working Group on Cyber Security and Software Updates under GRVA. The IWG shall maintain official documents on cyber security and software updates, develop amendments to UN R155 and UN R156 including provisions on software identification, support application across Global Technical Regulations, and provide opportunities for participants to share implementation experience. The IWG will be chaired by the United Kingdom, United States, and Japan, with OICA providing technical secretariat, and will operate until November 2029. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155/R156: Approval Authority for the COC of a CSMS/SUMS and type approval (vehicle type) |
| Reference Number: GRVA-26-20 |
|
Document explains concerns about the approach in GRVA/2026/30 to require a single Approval Authority to issue certificates of compliance for Cyber Security Management Systems and Automated Driving Systems Management Systems and vehicle type approval. The proposed changes would lead to double or triple approvals of management systems, creating administrative burden and unresolved legal consequences regarding challenged certificates of compliance and their effects on other issued certificates for the same management system. The submission proposes clarifying existing wording, documenting implications of challenged certificates, and adding a new paragraph 5.1.5. to UN R155 permitting mutual agreement between Approval Authorities regarding certificate usage. |
| Submitted by: CLCCR, CLEPA, and OICA |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 133 | Light Vehicle Recyclability, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 185 | Approval of vehicles with regard to their Automated Driving Systems |
| Click here to view the full document file |
| Proposal for amendments to the 1958 Agreement regarding the voluntary acceptance of Certificates of Compliance |
| Reference Number: GRVA-26-21 |
|
Proposal to amend Article 2, paragraph 2 to clarify that where a Certificate of Compliance required under a UN Regulation and issued by an Approval Authority of another Contracting Party is accepted by a Contracting Party, the Approval Authority granting the corresponding type approval shall remain responsible for all aspects of that type approval. The amendment addresses management systems and their Certificates of Compliance used in UN Regulations such as UN R155 and UN R156. |
| Submitted by: CLCCR, CLEPA, and OICA |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: United Nations Agreement | 1958 Agreement, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155 and R156: Proposal to amend GRVA/2026/30 |
| Reference Number: GRVA-26-35 |
|
Proposal to amend para. 5.1.3., insert new paras. 5.1.5. and 5.1.5.1. requiring the Approval Authority to refuse type approval unless the Certificate of Compliance for the Cyber Security Management System is issued by the same Approval Authority granting vehicle type approval, while permitting referencing of certificates from other Approval Authorities under specific conditions with documented agreements and clarified responsibilities, and insert new paras. 5.4. and 5.4.1. with equivalent requirements for the Software Update Management System Certificate of Compliance. |
| Submitted by: UK, France, Luxembourg, Germany, and Netherlands |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 17 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155: Proposal to amend GRVA/2026/29 |
| Reference Number: GRVA-26-36/Rev.1 |
|
Proposal to amend paragraph AI to introduce a link between existing text in Part A and new text in Part C regarding vehicle transformations, and insert new Part C providing guidance for the application of UN Regulation No. 155 to transformed vehicles. The proposal adds section 6 clarifying that the requirement for the Certificate of Compliance and type approval to be issued by the same Approval Authority applies only within the scope of the type approval granted to the manufacturer concerned, and does not restrict another manufacturer from obtaining a separate type approval and associated Certificate of Compliance from the responsible Approval Authority. |
| Submitted by: UK |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 18 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Proposal to amend UN R155 and UN R156 |
| Reference Number: GRVA/2026/30 |
|
Proposal to amend UN R155 by inserting new para. 5.1.3.(e) establishing that the Certificate of Compliance for the Cyber Security Management System shall not be issued by a different Approval Authority than the one granting type approval, and amend UN R156 by inserting new para. 5.4. establishing that Approval Authorities shall not grant type approval if the Certificate of Compliance for the Software Update Management System has not been issued by the same Approval Authority granting type approval. Justification includes ensuring holistic cybersecurity assessment, clarifying reporting obligations under para. 7.2.2.2.(g), addressing unharmonized mutual recognition of management system certificates, maintaining consistency between regulations, and upholding the fundamental principle that approval authorities retain responsibility for all aspects of type approval. |
| Submitted by: France, Germany, Luxembourg, Netherlands, and UK |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 03 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155: Proposal for a Supplement |
| Reference Number: GRVA/2026/28 |
|
Proposal to amend para. 5.3.2. to require notification of assessment methods and criteria including paras. 8.2. and 8.3., insert new paras. 8.2. and 8.3. establishing criteria for equipment installation without further assessment, and amend Annex 1 to require disclosure of equipment excluded from assessment pursuant to paras. 8.2. and 8.3. The amendments clarify that equipment with negligible intrinsic cyber security risk installed according to manufacturer specifications and not introducing cyber security risk, and standard non-automotive equipment connected solely for power supply with no increased cyber security risk, shall not invalidate approval of the original vehicle type under UN Regulation No. 155. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 03 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| UN R155: Proposal for a Supplement |
| Reference Number: GRVA/2026/29 |
|
Proposal to insert new Part C providing guidance for the application of UN R155 to transformed vehicles. Part C addresses identification of cyber-relevant transformations, impact on original vehicle architecture, connection risks, and impact on cyber security management systems. It specifies that transformations require new approval unless the manufacturer provides clear evidence that the original approval remains valid, and outlines critical factors and examples of cyber-relevant actions. It details documentary evidence expected from manufacturers regarding functional descriptions, connections with original vehicle types, added components and functions, and arguments demonstrating negligible intrinsic risk. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 06 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Proposal for amendments to UN Regulations Nos. 13, 13-H, 79, 89, 130, 131, 152, 155, 156, 157, 171, 175, and 178 |
| Reference Number: GRVA/2026/27 |
|
Proposal to insert provisions on Software Identification Numbers and software updates across UN R13, R13-H, R79, R89, R130, R131, R152, R155, R156, R157, R171, R175, and R178 by adding definitions referencing Consolidated Resolution R.E.3 Annex 7 paragraph 2, requiring manufacturers to provide Technical Services with information on hardware and software influencing performance with test reports, permitting vehicle manufacturers to apply for new approvals differentiating software versions for registered vehicles from new vehicles where type approval regulations are updated or hardware changes occur in series production with test duplication avoided where possible, clarifying that production is not considered definitively discontinued if manufacturers obtain subsequent extensions for software updates of registered vehicles, renumbering and inserting new items in approval communication annexes for R13SWIN, R13-HSWIN, R79SWIN, R89SWIN, R130SWIN, R131SWIN, R152SWIN, R155SWIN, R157SWIN, R171SWIN, R175SWIN, and R178SWIN information including whether held on vehicle and relevant parameter identification lists, and amending R157 and R171 to align software update requirements with R156 technical specifications and transitional provisions. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 06 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 13-H | Light-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error |
| Click here to view the full document file |
| Software updates: Proposal to amend GRVA/2026/27 |
| Reference Number: GRVA-26-11 |
|
Proposal to insert definitions for Software Identification Number, insert requirements for manufacturers to provide necessary information allowing the Technical Service to uniquely identify hardware and software configurations, insert provisions allowing vehicle manufacturers to apply for new approvals to differentiate software versions for registered versus new vehicles, amend production discontinuation provisions to clarify that cessation is not deemed definitive if the manufacturer intends to obtain subsequent extensions for software updates of vehicles already registered in the market, renumber and insert new items in approval communication annexes regarding software identification and software updates including RxSWIN, and insert provisions allowing vehicle manufacturers to obtain new approvals for software version differentiation across multiple UN Regulations (13, 13-H, 79, 89, 130, 131, 139, 140, 152, 155, 156, 157, 171, 175, and 178). |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 140 | Electronic Stability Control Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 139 | Brake Assist Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error |
| Click here to view the full document file |
| UN R155: Proposal to amend the Interpretation Document |
| Reference Number: GRVA-26-12 |
|
Proposal to amend paragraph AI to introduce a link between existing text in Part A and new Part C regarding vehicle transformations, insert new Part C providing guidance for the application of UN Regulation No. 155 to transformed vehicles including documentary evidence requirements, and add section 6 clarifying that the requirement for Certificate of Compliance and type approval to be issued by the same Approval Authority applies only within the scope of a specific type approval and its approval holder. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Cyber Security and Software Updates informal group status report to GRVA |
| Reference Number: GRVA-26-18 |
|
Status report on activities of the IWG on CS/OTA since the 25th GRVA session. The IWG reviewed proposals for amendment of UN R155 and its interpretation document for multi-stage vehicles, proposals for approval-authority arrangements and Certificates of Compliance for UN R155 and R156, proposals integrating software identification and update text across several UNRs outlined in RE.3, component and STU approval concepts, and remote operation and automated driving systems. The IWG proposes updating regulatory text and interpretation documents for UN R155, revisions to software identification and update text across several regulations, and revised Terms of Reference for a mandate till November 2029. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 89 | Speed Limitation Devices, WP.29 Regulatory Project | Automated Driving Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| Informal Working Group on Cyber Security and Software Updates: Proposal for Terms of Reference |
| Reference Number: GRVA-26-19 |
|
Proposal to renew the terms for the Informal Working Group on Cyber Security and Software Updates under GRVA. The IWG shall maintain official documents on cyber security and software updates, develop amendments to UN R155 and UN R156 including provisions on software identification, support application across Global Technical Regulations, and provide opportunities for participants to share implementation experience. The IWG will be chaired by the United Kingdom, United States, and Japan, with OICA providing technical secretariat, and will operate until November 2029. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155/R156: Approval Authority for the COC of a CSMS/SUMS and type approval (vehicle type) |
| Reference Number: GRVA-26-20 |
|
Document explains concerns about the approach in GRVA/2026/30 to require a single Approval Authority to issue certificates of compliance for Cyber Security Management Systems and Automated Driving Systems Management Systems and vehicle type approval. The proposed changes would lead to double or triple approvals of management systems, creating administrative burden and unresolved legal consequences regarding challenged certificates of compliance and their effects on other issued certificates for the same management system. The submission proposes clarifying existing wording, documenting implications of challenged certificates, and adding a new paragraph 5.1.5. to UN R155 permitting mutual agreement between Approval Authorities regarding certificate usage. |
| Submitted by: CLCCR, CLEPA, and OICA |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 133 | Light Vehicle Recyclability, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 185 | Approval of vehicles with regard to their Automated Driving Systems |
| Click here to view the full document file |
| Proposal for amendments to the 1958 Agreement regarding the voluntary acceptance of Certificates of Compliance |
| Reference Number: GRVA-26-21 |
|
Proposal to amend Article 2, paragraph 2 to clarify that where a Certificate of Compliance required under a UN Regulation and issued by an Approval Authority of another Contracting Party is accepted by a Contracting Party, the Approval Authority granting the corresponding type approval shall remain responsible for all aspects of that type approval. The amendment addresses management systems and their Certificates of Compliance used in UN Regulations such as UN R155 and UN R156. |
| Submitted by: CLCCR, CLEPA, and OICA |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: United Nations Agreement | 1958 Agreement, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155 and R156: Proposal to amend GRVA/2026/30 |
| Reference Number: GRVA-26-35 |
|
Proposal to amend para. 5.1.3., insert new paras. 5.1.5. and 5.1.5.1. requiring the Approval Authority to refuse type approval unless the Certificate of Compliance for the Cyber Security Management System is issued by the same Approval Authority granting vehicle type approval, while permitting referencing of certificates from other Approval Authorities under specific conditions with documented agreements and clarified responsibilities, and insert new paras. 5.4. and 5.4.1. with equivalent requirements for the Software Update Management System Certificate of Compliance. |
| Submitted by: UK, France, Luxembourg, Germany, and Netherlands |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 17 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155: Proposal to amend GRVA/2026/29 |
| Reference Number: GRVA-26-36/Rev.1 |
|
Proposal to amend paragraph AI to introduce a link between existing text in Part A and new text in Part C regarding vehicle transformations, and insert new Part C providing guidance for the application of UN Regulation No. 155 to transformed vehicles. The proposal adds section 6 clarifying that the requirement for the Certificate of Compliance and type approval to be issued by the same Approval Authority applies only within the scope of the type approval granted to the manufacturer concerned, and does not restrict another manufacturer from obtaining a separate type approval and associated Certificate of Compliance from the responsible Approval Authority. |
| Submitted by: UK |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 18 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Proposal to amend UN R155 and UN R156 |
| Reference Number: GRVA/2026/30 |
|
Proposal to amend UN R155 by inserting new para. 5.1.3.(e) establishing that the Certificate of Compliance for the Cyber Security Management System shall not be issued by a different Approval Authority than the one granting type approval, and amend UN R156 by inserting new para. 5.4. establishing that Approval Authorities shall not grant type approval if the Certificate of Compliance for the Software Update Management System has not been issued by the same Approval Authority granting type approval. Justification includes ensuring holistic cybersecurity assessment, clarifying reporting obligations under para. 7.2.2.2.(g), addressing unharmonized mutual recognition of management system certificates, maintaining consistency between regulations, and upholding the fundamental principle that approval authorities retain responsibility for all aspects of type approval. |
| Submitted by: France, Germany, Luxembourg, Netherlands, and UK |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 03 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155: Proposal for a Supplement |
| Reference Number: GRVA/2026/28 |
|
Proposal to amend para. 5.3.2. to require notification of assessment methods and criteria including paras. 8.2. and 8.3., insert new paras. 8.2. and 8.3. establishing criteria for equipment installation without further assessment, and amend Annex 1 to require disclosure of equipment excluded from assessment pursuant to paras. 8.2. and 8.3. The amendments clarify that equipment with negligible intrinsic cyber security risk installed according to manufacturer specifications and not introducing cyber security risk, and standard non-automotive equipment connected solely for power supply with no increased cyber security risk, shall not invalidate approval of the original vehicle type under UN Regulation No. 155. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 03 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| UN R155: Proposal for a Supplement |
| Reference Number: GRVA/2026/29 |
|
Proposal to insert new Part C providing guidance for the application of UN R155 to transformed vehicles. Part C addresses identification of cyber-relevant transformations, impact on original vehicle architecture, connection risks, and impact on cyber security management systems. It specifies that transformations require new approval unless the manufacturer provides clear evidence that the original approval remains valid, and outlines critical factors and examples of cyber-relevant actions. It details documentary evidence expected from manufacturers regarding functional descriptions, connections with original vehicle types, added components and functions, and arguments demonstrating negligible intrinsic risk. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 06 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Proposal for amendments to UN Regulations Nos. 13, 13-H, 79, 89, 130, 131, 152, 155, 156, 157, 171, 175, and 178 |
| Reference Number: GRVA/2026/27 |
|
Proposal to insert provisions on Software Identification Numbers and software updates across UN R13, R13-H, R79, R89, R130, R131, R152, R155, R156, R157, R171, R175, and R178 by adding definitions referencing Consolidated Resolution R.E.3 Annex 7 paragraph 2, requiring manufacturers to provide Technical Services with information on hardware and software influencing performance with test reports, permitting vehicle manufacturers to apply for new approvals differentiating software versions for registered vehicles from new vehicles where type approval regulations are updated or hardware changes occur in series production with test duplication avoided where possible, clarifying that production is not considered definitively discontinued if manufacturers obtain subsequent extensions for software updates of registered vehicles, renumbering and inserting new items in approval communication annexes for R13SWIN, R13-HSWIN, R79SWIN, R89SWIN, R130SWIN, R131SWIN, R152SWIN, R155SWIN, R157SWIN, R171SWIN, R175SWIN, and R178SWIN information including whether held on vehicle and relevant parameter identification lists, and amending R157 and R171 to align software update requirements with R156 technical specifications and transitional provisions. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 06 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 13-H | Light-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error |
| Click here to view the full document file |
| Software updates: Proposal to amend GRVA/2026/27 |
| Reference Number: GRVA-26-11 |
|
Proposal to insert definitions for Software Identification Number, insert requirements for manufacturers to provide necessary information allowing the Technical Service to uniquely identify hardware and software configurations, insert provisions allowing vehicle manufacturers to apply for new approvals to differentiate software versions for registered versus new vehicles, amend production discontinuation provisions to clarify that cessation is not deemed definitive if the manufacturer intends to obtain subsequent extensions for software updates of vehicles already registered in the market, renumber and insert new items in approval communication annexes regarding software identification and software updates including RxSWIN, and insert provisions allowing vehicle manufacturers to obtain new approvals for software version differentiation across multiple UN Regulations (13, 13-H, 79, 89, 130, 131, 139, 140, 152, 155, 156, 157, 171, 175, and 178). |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 140 | Electronic Stability Control Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 139 | Brake Assist Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error |
| Click here to view the full document file |
| UN R155: Proposal to amend the Interpretation Document |
| Reference Number: GRVA-26-12 |
|
Proposal to amend paragraph AI to introduce a link between existing text in Part A and new Part C regarding vehicle transformations, insert new Part C providing guidance for the application of UN Regulation No. 155 to transformed vehicles including documentary evidence requirements, and add section 6 clarifying that the requirement for Certificate of Compliance and type approval to be issued by the same Approval Authority applies only within the scope of a specific type approval and its approval holder. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Cyber Security and Software Updates informal group status report to GRVA |
| Reference Number: GRVA-26-18 |
|
Status report on activities of the IWG on CS/OTA since the 25th GRVA session. The IWG reviewed proposals for amendment of UN R155 and its interpretation document for multi-stage vehicles, proposals for approval-authority arrangements and Certificates of Compliance for UN R155 and R156, proposals integrating software identification and update text across several UNRs outlined in RE.3, component and STU approval concepts, and remote operation and automated driving systems. The IWG proposes updating regulatory text and interpretation documents for UN R155, revisions to software identification and update text across several regulations, and revised Terms of Reference for a mandate till November 2029. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 89 | Speed Limitation Devices, WP.29 Regulatory Project | Automated Driving Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| Informal Working Group on Cyber Security and Software Updates: Proposal for Terms of Reference |
| Reference Number: GRVA-26-19 |
|
Proposal to renew the terms for the Informal Working Group on Cyber Security and Software Updates under GRVA. The IWG shall maintain official documents on cyber security and software updates, develop amendments to UN R155 and UN R156 including provisions on software identification, support application across Global Technical Regulations, and provide opportunities for participants to share implementation experience. The IWG will be chaired by the United Kingdom, United States, and Japan, with OICA providing technical secretariat, and will operate until November 2029. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155/R156: Approval Authority for the COC of a CSMS/SUMS and type approval (vehicle type) |
| Reference Number: GRVA-26-20 |
|
Document explains concerns about the approach in GRVA/2026/30 to require a single Approval Authority to issue certificates of compliance for Cyber Security Management Systems and Automated Driving Systems Management Systems and vehicle type approval. The proposed changes would lead to double or triple approvals of management systems, creating administrative burden and unresolved legal consequences regarding challenged certificates of compliance and their effects on other issued certificates for the same management system. The submission proposes clarifying existing wording, documenting implications of challenged certificates, and adding a new paragraph 5.1.5. to UN R155 permitting mutual agreement between Approval Authorities regarding certificate usage. |
| Submitted by: CLCCR, CLEPA, and OICA |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 133 | Light Vehicle Recyclability, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 185 | Approval of vehicles with regard to their Automated Driving Systems |
| Click here to view the full document file |
| Proposal for amendments to the 1958 Agreement regarding the voluntary acceptance of Certificates of Compliance |
| Reference Number: GRVA-26-21 |
|
Proposal to amend Article 2, paragraph 2 to clarify that where a Certificate of Compliance required under a UN Regulation and issued by an Approval Authority of another Contracting Party is accepted by a Contracting Party, the Approval Authority granting the corresponding type approval shall remain responsible for all aspects of that type approval. The amendment addresses management systems and their Certificates of Compliance used in UN Regulations such as UN R155 and UN R156. |
| Submitted by: CLCCR, CLEPA, and OICA |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: United Nations Agreement | 1958 Agreement, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155 and R156: Proposal to amend GRVA/2026/30 |
| Reference Number: GRVA-26-35 |
|
Proposal to amend para. 5.1.3., insert new paras. 5.1.5. and 5.1.5.1. requiring the Approval Authority to refuse type approval unless the Certificate of Compliance for the Cyber Security Management System is issued by the same Approval Authority granting vehicle type approval, while permitting referencing of certificates from other Approval Authorities under specific conditions with documented agreements and clarified responsibilities, and insert new paras. 5.4. and 5.4.1. with equivalent requirements for the Software Update Management System Certificate of Compliance. |
| Submitted by: UK, France, Luxembourg, Germany, and Netherlands |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 17 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155: Proposal to amend GRVA/2026/29 |
| Reference Number: GRVA-26-36/Rev.1 |
|
Proposal to amend paragraph AI to introduce a link between existing text in Part A and new text in Part C regarding vehicle transformations, and insert new Part C providing guidance for the application of UN Regulation No. 155 to transformed vehicles. The proposal adds section 6 clarifying that the requirement for the Certificate of Compliance and type approval to be issued by the same Approval Authority applies only within the scope of the type approval granted to the manufacturer concerned, and does not restrict another manufacturer from obtaining a separate type approval and associated Certificate of Compliance from the responsible Approval Authority. |
| Submitted by: UK |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 18 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Proposal to amend UN R155 and UN R156 |
| Reference Number: GRVA/2026/30 |
|
Proposal to amend UN R155 by inserting new para. 5.1.3.(e) establishing that the Certificate of Compliance for the Cyber Security Management System shall not be issued by a different Approval Authority than the one granting type approval, and amend UN R156 by inserting new para. 5.4. establishing that Approval Authorities shall not grant type approval if the Certificate of Compliance for the Software Update Management System has not been issued by the same Approval Authority granting type approval. Justification includes ensuring holistic cybersecurity assessment, clarifying reporting obligations under para. 7.2.2.2.(g), addressing unharmonized mutual recognition of management system certificates, maintaining consistency between regulations, and upholding the fundamental principle that approval authorities retain responsibility for all aspects of type approval. |
| Submitted by: France, Germany, Luxembourg, Netherlands, and UK |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 03 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155: Proposal for a Supplement |
| Reference Number: GRVA/2026/28 |
|
Proposal to amend para. 5.3.2. to require notification of assessment methods and criteria including paras. 8.2. and 8.3., insert new paras. 8.2. and 8.3. establishing criteria for equipment installation without further assessment, and amend Annex 1 to require disclosure of equipment excluded from assessment pursuant to paras. 8.2. and 8.3. The amendments clarify that equipment with negligible intrinsic cyber security risk installed according to manufacturer specifications and not introducing cyber security risk, and standard non-automotive equipment connected solely for power supply with no increased cyber security risk, shall not invalidate approval of the original vehicle type under UN Regulation No. 155. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 03 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| UN R155: Proposal for a Supplement |
| Reference Number: GRVA/2026/29 |
|
Proposal to insert new Part C providing guidance for the application of UN R155 to transformed vehicles. Part C addresses identification of cyber-relevant transformations, impact on original vehicle architecture, connection risks, and impact on cyber security management systems. It specifies that transformations require new approval unless the manufacturer provides clear evidence that the original approval remains valid, and outlines critical factors and examples of cyber-relevant actions. It details documentary evidence expected from manufacturers regarding functional descriptions, connections with original vehicle types, added components and functions, and arguments demonstrating negligible intrinsic risk. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 06 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Proposal for amendments to UN Regulations Nos. 13, 13-H, 79, 89, 130, 131, 152, 155, 156, 157, 171, 175, and 178 |
| Reference Number: GRVA/2026/27 |
|
Proposal to insert provisions on Software Identification Numbers and software updates across UN R13, R13-H, R79, R89, R130, R131, R152, R155, R156, R157, R171, R175, and R178 by adding definitions referencing Consolidated Resolution R.E.3 Annex 7 paragraph 2, requiring manufacturers to provide Technical Services with information on hardware and software influencing performance with test reports, permitting vehicle manufacturers to apply for new approvals differentiating software versions for registered vehicles from new vehicles where type approval regulations are updated or hardware changes occur in series production with test duplication avoided where possible, clarifying that production is not considered definitively discontinued if manufacturers obtain subsequent extensions for software updates of registered vehicles, renumbering and inserting new items in approval communication annexes for R13SWIN, R13-HSWIN, R79SWIN, R89SWIN, R130SWIN, R131SWIN, R152SWIN, R155SWIN, R157SWIN, R171SWIN, R175SWIN, and R178SWIN information including whether held on vehicle and relevant parameter identification lists, and amending R157 and R171 to align software update requirements with R156 technical specifications and transitional provisions. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 06 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 13-H | Light-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error |
| Click here to view the full document file |
| Software updates: Proposal to amend GRVA/2026/27 |
| Reference Number: GRVA-26-11 |
|
Proposal to insert definitions for Software Identification Number, insert requirements for manufacturers to provide necessary information allowing the Technical Service to uniquely identify hardware and software configurations, insert provisions allowing vehicle manufacturers to apply for new approvals to differentiate software versions for registered versus new vehicles, amend production discontinuation provisions to clarify that cessation is not deemed definitive if the manufacturer intends to obtain subsequent extensions for software updates of vehicles already registered in the market, renumber and insert new items in approval communication annexes regarding software identification and software updates including RxSWIN, and insert provisions allowing vehicle manufacturers to obtain new approvals for software version differentiation across multiple UN Regulations (13, 13-H, 79, 89, 130, 131, 139, 140, 152, 155, 156, 157, 171, 175, and 178). |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 140 | Electronic Stability Control Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 139 | Brake Assist Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error |
| Click here to view the full document file |
| UN R155: Proposal to amend the Interpretation Document |
| Reference Number: GRVA-26-12 |
|
Proposal to amend paragraph AI to introduce a link between existing text in Part A and new Part C regarding vehicle transformations, insert new Part C providing guidance for the application of UN Regulation No. 155 to transformed vehicles including documentary evidence requirements, and add section 6 clarifying that the requirement for Certificate of Compliance and type approval to be issued by the same Approval Authority applies only within the scope of a specific type approval and its approval holder. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Cyber Security and Software Updates informal group status report to GRVA |
| Reference Number: GRVA-26-18 |
|
Status report on activities of the IWG on CS/OTA since the 25th GRVA session. The IWG reviewed proposals for amendment of UN R155 and its interpretation document for multi-stage vehicles, proposals for approval-authority arrangements and Certificates of Compliance for UN R155 and R156, proposals integrating software identification and update text across several UNRs outlined in RE.3, component and STU approval concepts, and remote operation and automated driving systems. The IWG proposes updating regulatory text and interpretation documents for UN R155, revisions to software identification and update text across several regulations, and revised Terms of Reference for a mandate till November 2029. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 89 | Speed Limitation Devices, WP.29 Regulatory Project | Automated Driving Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| Informal Working Group on Cyber Security and Software Updates: Proposal for Terms of Reference |
| Reference Number: GRVA-26-19 |
|
Proposal to renew the terms for the Informal Working Group on Cyber Security and Software Updates under GRVA. The IWG shall maintain official documents on cyber security and software updates, develop amendments to UN R155 and UN R156 including provisions on software identification, support application across Global Technical Regulations, and provide opportunities for participants to share implementation experience. The IWG will be chaired by the United Kingdom, United States, and Japan, with OICA providing technical secretariat, and will operate until November 2029. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155/R156: Approval Authority for the COC of a CSMS/SUMS and type approval (vehicle type) |
| Reference Number: GRVA-26-20 |
|
Document explains concerns about the approach in GRVA/2026/30 to require a single Approval Authority to issue certificates of compliance for Cyber Security Management Systems and Automated Driving Systems Management Systems and vehicle type approval. The proposed changes would lead to double or triple approvals of management systems, creating administrative burden and unresolved legal consequences regarding challenged certificates of compliance and their effects on other issued certificates for the same management system. The submission proposes clarifying existing wording, documenting implications of challenged certificates, and adding a new paragraph 5.1.5. to UN R155 permitting mutual agreement between Approval Authorities regarding certificate usage. |
| Submitted by: CLCCR, CLEPA, and OICA |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 133 | Light Vehicle Recyclability, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 185 | Approval of vehicles with regard to their Automated Driving Systems |
| Click here to view the full document file |
| Proposal for amendments to the 1958 Agreement regarding the voluntary acceptance of Certificates of Compliance |
| Reference Number: GRVA-26-21 |
|
Proposal to amend Article 2, paragraph 2 to clarify that where a Certificate of Compliance required under a UN Regulation and issued by an Approval Authority of another Contracting Party is accepted by a Contracting Party, the Approval Authority granting the corresponding type approval shall remain responsible for all aspects of that type approval. The amendment addresses management systems and their Certificates of Compliance used in UN Regulations such as UN R155 and UN R156. |
| Submitted by: CLCCR, CLEPA, and OICA |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: United Nations Agreement | 1958 Agreement, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155 and R156: Proposal to amend GRVA/2026/30 |
| Reference Number: GRVA-26-35 |
|
Proposal to amend para. 5.1.3., insert new paras. 5.1.5. and 5.1.5.1. requiring the Approval Authority to refuse type approval unless the Certificate of Compliance for the Cyber Security Management System is issued by the same Approval Authority granting vehicle type approval, while permitting referencing of certificates from other Approval Authorities under specific conditions with documented agreements and clarified responsibilities, and insert new paras. 5.4. and 5.4.1. with equivalent requirements for the Software Update Management System Certificate of Compliance. |
| Submitted by: UK, France, Luxembourg, Germany, and Netherlands |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 17 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155: Proposal to amend GRVA/2026/29 |
| Reference Number: GRVA-26-36/Rev.1 |
|
Proposal to amend paragraph AI to introduce a link between existing text in Part A and new text in Part C regarding vehicle transformations, and insert new Part C providing guidance for the application of UN Regulation No. 155 to transformed vehicles. The proposal adds section 6 clarifying that the requirement for the Certificate of Compliance and type approval to be issued by the same Approval Authority applies only within the scope of the type approval granted to the manufacturer concerned, and does not restrict another manufacturer from obtaining a separate type approval and associated Certificate of Compliance from the responsible Approval Authority. |
| Submitted by: UK |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 18 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Proposal to amend UN R155 and UN R156 |
| Reference Number: GRVA/2026/30 |
|
Proposal to amend UN R155 by inserting new para. 5.1.3.(e) establishing that the Certificate of Compliance for the Cyber Security Management System shall not be issued by a different Approval Authority than the one granting type approval, and amend UN R156 by inserting new para. 5.4. establishing that Approval Authorities shall not grant type approval if the Certificate of Compliance for the Software Update Management System has not been issued by the same Approval Authority granting type approval. Justification includes ensuring holistic cybersecurity assessment, clarifying reporting obligations under para. 7.2.2.2.(g), addressing unharmonized mutual recognition of management system certificates, maintaining consistency between regulations, and upholding the fundamental principle that approval authorities retain responsibility for all aspects of type approval. |
| Submitted by: France, Germany, Luxembourg, Netherlands, and UK |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 03 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155: Proposal for a Supplement |
| Reference Number: GRVA/2026/28 |
|
Proposal to amend para. 5.3.2. to require notification of assessment methods and criteria including paras. 8.2. and 8.3., insert new paras. 8.2. and 8.3. establishing criteria for equipment installation without further assessment, and amend Annex 1 to require disclosure of equipment excluded from assessment pursuant to paras. 8.2. and 8.3. The amendments clarify that equipment with negligible intrinsic cyber security risk installed according to manufacturer specifications and not introducing cyber security risk, and standard non-automotive equipment connected solely for power supply with no increased cyber security risk, shall not invalidate approval of the original vehicle type under UN Regulation No. 155. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 03 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| UN R155: Proposal for a Supplement |
| Reference Number: GRVA/2026/29 |
|
Proposal to insert new Part C providing guidance for the application of UN R155 to transformed vehicles. Part C addresses identification of cyber-relevant transformations, impact on original vehicle architecture, connection risks, and impact on cyber security management systems. It specifies that transformations require new approval unless the manufacturer provides clear evidence that the original approval remains valid, and outlines critical factors and examples of cyber-relevant actions. It details documentary evidence expected from manufacturers regarding functional descriptions, connections with original vehicle types, added components and functions, and arguments demonstrating negligible intrinsic risk. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 06 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Proposal for amendments to UN Regulations Nos. 13, 13-H, 79, 89, 130, 131, 152, 155, 156, 157, 171, 175, and 178 |
| Reference Number: GRVA/2026/27 |
|
Proposal to insert provisions on Software Identification Numbers and software updates across UN R13, R13-H, R79, R89, R130, R131, R152, R155, R156, R157, R171, R175, and R178 by adding definitions referencing Consolidated Resolution R.E.3 Annex 7 paragraph 2, requiring manufacturers to provide Technical Services with information on hardware and software influencing performance with test reports, permitting vehicle manufacturers to apply for new approvals differentiating software versions for registered vehicles from new vehicles where type approval regulations are updated or hardware changes occur in series production with test duplication avoided where possible, clarifying that production is not considered definitively discontinued if manufacturers obtain subsequent extensions for software updates of registered vehicles, renumbering and inserting new items in approval communication annexes for R13SWIN, R13-HSWIN, R79SWIN, R89SWIN, R130SWIN, R131SWIN, R152SWIN, R155SWIN, R157SWIN, R171SWIN, R175SWIN, and R178SWIN information including whether held on vehicle and relevant parameter identification lists, and amending R157 and R171 to align software update requirements with R156 technical specifications and transitional provisions. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 06 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 13-H | Light-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error |
| Click here to view the full document file |
| Software updates: Proposal to amend GRVA/2026/27 |
| Reference Number: GRVA-26-11 |
|
Proposal to insert definitions for Software Identification Number, insert requirements for manufacturers to provide necessary information allowing the Technical Service to uniquely identify hardware and software configurations, insert provisions allowing vehicle manufacturers to apply for new approvals to differentiate software versions for registered versus new vehicles, amend production discontinuation provisions to clarify that cessation is not deemed definitive if the manufacturer intends to obtain subsequent extensions for software updates of vehicles already registered in the market, renumber and insert new items in approval communication annexes regarding software identification and software updates including RxSWIN, and insert provisions allowing vehicle manufacturers to obtain new approvals for software version differentiation across multiple UN Regulations (13, 13-H, 79, 89, 130, 131, 139, 140, 152, 155, 156, 157, 171, 175, and 178). |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 140 | Electronic Stability Control Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 139 | Brake Assist Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error |
| Click here to view the full document file |
| UN R155: Proposal to amend the Interpretation Document |
| Reference Number: GRVA-26-12 |
|
Proposal to amend paragraph AI to introduce a link between existing text in Part A and new Part C regarding vehicle transformations, insert new Part C providing guidance for the application of UN Regulation No. 155 to transformed vehicles including documentary evidence requirements, and add section 6 clarifying that the requirement for Certificate of Compliance and type approval to be issued by the same Approval Authority applies only within the scope of a specific type approval and its approval holder. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Cyber Security and Software Updates informal group status report to GRVA |
| Reference Number: GRVA-26-18 |
|
Status report on activities of the IWG on CS/OTA since the 25th GRVA session. The IWG reviewed proposals for amendment of UN R155 and its interpretation document for multi-stage vehicles, proposals for approval-authority arrangements and Certificates of Compliance for UN R155 and R156, proposals integrating software identification and update text across several UNRs outlined in RE.3, component and STU approval concepts, and remote operation and automated driving systems. The IWG proposes updating regulatory text and interpretation documents for UN R155, revisions to software identification and update text across several regulations, and revised Terms of Reference for a mandate till November 2029. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 89 | Speed Limitation Devices, WP.29 Regulatory Project | Automated Driving Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| Informal Working Group on Cyber Security and Software Updates: Proposal for Terms of Reference |
| Reference Number: GRVA-26-19 |
|
Proposal to renew the terms for the Informal Working Group on Cyber Security and Software Updates under GRVA. The IWG shall maintain official documents on cyber security and software updates, develop amendments to UN R155 and UN R156 including provisions on software identification, support application across Global Technical Regulations, and provide opportunities for participants to share implementation experience. The IWG will be chaired by the United Kingdom, United States, and Japan, with OICA providing technical secretariat, and will operate until November 2029. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155/R156: Approval Authority for the COC of a CSMS/SUMS and type approval (vehicle type) |
| Reference Number: GRVA-26-20 |
|
Document explains concerns about the approach in GRVA/2026/30 to require a single Approval Authority to issue certificates of compliance for Cyber Security Management Systems and Automated Driving Systems Management Systems and vehicle type approval. The proposed changes would lead to double or triple approvals of management systems, creating administrative burden and unresolved legal consequences regarding challenged certificates of compliance and their effects on other issued certificates for the same management system. The submission proposes clarifying existing wording, documenting implications of challenged certificates, and adding a new paragraph 5.1.5. to UN R155 permitting mutual agreement between Approval Authorities regarding certificate usage. |
| Submitted by: CLCCR, CLEPA, and OICA |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 133 | Light Vehicle Recyclability, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 185 | Approval of vehicles with regard to their Automated Driving Systems |
| Click here to view the full document file |
| Proposal for amendments to the 1958 Agreement regarding the voluntary acceptance of Certificates of Compliance |
| Reference Number: GRVA-26-21 |
|
Proposal to amend Article 2, paragraph 2 to clarify that where a Certificate of Compliance required under a UN Regulation and issued by an Approval Authority of another Contracting Party is accepted by a Contracting Party, the Approval Authority granting the corresponding type approval shall remain responsible for all aspects of that type approval. The amendment addresses management systems and their Certificates of Compliance used in UN Regulations such as UN R155 and UN R156. |
| Submitted by: CLCCR, CLEPA, and OICA |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: United Nations Agreement | 1958 Agreement, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155 and R156: Proposal to amend GRVA/2026/30 |
| Reference Number: GRVA-26-35 |
|
Proposal to amend para. 5.1.3., insert new paras. 5.1.5. and 5.1.5.1. requiring the Approval Authority to refuse type approval unless the Certificate of Compliance for the Cyber Security Management System is issued by the same Approval Authority granting vehicle type approval, while permitting referencing of certificates from other Approval Authorities under specific conditions with documented agreements and clarified responsibilities, and insert new paras. 5.4. and 5.4.1. with equivalent requirements for the Software Update Management System Certificate of Compliance. |
| Submitted by: UK, France, Luxembourg, Germany, and Netherlands |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 17 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155: Proposal to amend GRVA/2026/29 |
| Reference Number: GRVA-26-36/Rev.1 |
|
Proposal to amend paragraph AI to introduce a link between existing text in Part A and new text in Part C regarding vehicle transformations, and insert new Part C providing guidance for the application of UN Regulation No. 155 to transformed vehicles. The proposal adds section 6 clarifying that the requirement for the Certificate of Compliance and type approval to be issued by the same Approval Authority applies only within the scope of the type approval granted to the manufacturer concerned, and does not restrict another manufacturer from obtaining a separate type approval and associated Certificate of Compliance from the responsible Approval Authority. |
| Submitted by: UK |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 18 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Proposal to amend UN R155 and UN R156 |
| Reference Number: GRVA/2026/30 |
|
Proposal to amend UN R155 by inserting new para. 5.1.3.(e) establishing that the Certificate of Compliance for the Cyber Security Management System shall not be issued by a different Approval Authority than the one granting type approval, and amend UN R156 by inserting new para. 5.4. establishing that Approval Authorities shall not grant type approval if the Certificate of Compliance for the Software Update Management System has not been issued by the same Approval Authority granting type approval. Justification includes ensuring holistic cybersecurity assessment, clarifying reporting obligations under para. 7.2.2.2.(g), addressing unharmonized mutual recognition of management system certificates, maintaining consistency between regulations, and upholding the fundamental principle that approval authorities retain responsibility for all aspects of type approval. |
| Submitted by: France, Germany, Luxembourg, Netherlands, and UK |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 03 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155: Proposal for a Supplement |
| Reference Number: GRVA/2026/28 |
|
Proposal to amend para. 5.3.2. to require notification of assessment methods and criteria including paras. 8.2. and 8.3., insert new paras. 8.2. and 8.3. establishing criteria for equipment installation without further assessment, and amend Annex 1 to require disclosure of equipment excluded from assessment pursuant to paras. 8.2. and 8.3. The amendments clarify that equipment with negligible intrinsic cyber security risk installed according to manufacturer specifications and not introducing cyber security risk, and standard non-automotive equipment connected solely for power supply with no increased cyber security risk, shall not invalidate approval of the original vehicle type under UN Regulation No. 155. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 03 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| UN R155: Proposal for a Supplement |
| Reference Number: GRVA/2026/29 |
|
Proposal to insert new Part C providing guidance for the application of UN R155 to transformed vehicles. Part C addresses identification of cyber-relevant transformations, impact on original vehicle architecture, connection risks, and impact on cyber security management systems. It specifies that transformations require new approval unless the manufacturer provides clear evidence that the original approval remains valid, and outlines critical factors and examples of cyber-relevant actions. It details documentary evidence expected from manufacturers regarding functional descriptions, connections with original vehicle types, added components and functions, and arguments demonstrating negligible intrinsic risk. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 06 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Proposal for amendments to UN Regulations Nos. 13, 13-H, 79, 89, 130, 131, 152, 155, 156, 157, 171, 175, and 178 |
| Reference Number: GRVA/2026/27 |
|
Proposal to insert provisions on Software Identification Numbers and software updates across UN R13, R13-H, R79, R89, R130, R131, R152, R155, R156, R157, R171, R175, and R178 by adding definitions referencing Consolidated Resolution R.E.3 Annex 7 paragraph 2, requiring manufacturers to provide Technical Services with information on hardware and software influencing performance with test reports, permitting vehicle manufacturers to apply for new approvals differentiating software versions for registered vehicles from new vehicles where type approval regulations are updated or hardware changes occur in series production with test duplication avoided where possible, clarifying that production is not considered definitively discontinued if manufacturers obtain subsequent extensions for software updates of registered vehicles, renumbering and inserting new items in approval communication annexes for R13SWIN, R13-HSWIN, R79SWIN, R89SWIN, R130SWIN, R131SWIN, R152SWIN, R155SWIN, R157SWIN, R171SWIN, R175SWIN, and R178SWIN information including whether held on vehicle and relevant parameter identification lists, and amending R157 and R171 to align software update requirements with R156 technical specifications and transitional provisions. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 06 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 13-H | Light-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error |
| Click here to view the full document file |
| Software updates: Proposal to amend GRVA/2026/27 |
| Reference Number: GRVA-26-11 |
|
Proposal to insert definitions for Software Identification Number, insert requirements for manufacturers to provide necessary information allowing the Technical Service to uniquely identify hardware and software configurations, insert provisions allowing vehicle manufacturers to apply for new approvals to differentiate software versions for registered versus new vehicles, amend production discontinuation provisions to clarify that cessation is not deemed definitive if the manufacturer intends to obtain subsequent extensions for software updates of vehicles already registered in the market, renumber and insert new items in approval communication annexes regarding software identification and software updates including RxSWIN, and insert provisions allowing vehicle manufacturers to obtain new approvals for software version differentiation across multiple UN Regulations (13, 13-H, 79, 89, 130, 131, 139, 140, 152, 155, 156, 157, 171, 175, and 178). |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 140 | Electronic Stability Control Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 139 | Brake Assist Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error |
| Click here to view the full document file |
| UN R155: Proposal to amend the Interpretation Document |
| Reference Number: GRVA-26-12 |
|
Proposal to amend paragraph AI to introduce a link between existing text in Part A and new Part C regarding vehicle transformations, insert new Part C providing guidance for the application of UN Regulation No. 155 to transformed vehicles including documentary evidence requirements, and add section 6 clarifying that the requirement for Certificate of Compliance and type approval to be issued by the same Approval Authority applies only within the scope of a specific type approval and its approval holder. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Cyber Security and Software Updates informal group status report to GRVA |
| Reference Number: GRVA-26-18 |
|
Status report on activities of the IWG on CS/OTA since the 25th GRVA session. The IWG reviewed proposals for amendment of UN R155 and its interpretation document for multi-stage vehicles, proposals for approval-authority arrangements and Certificates of Compliance for UN R155 and R156, proposals integrating software identification and update text across several UNRs outlined in RE.3, component and STU approval concepts, and remote operation and automated driving systems. The IWG proposes updating regulatory text and interpretation documents for UN R155, revisions to software identification and update text across several regulations, and revised Terms of Reference for a mandate till November 2029. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 89 | Speed Limitation Devices, WP.29 Regulatory Project | Automated Driving Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| Informal Working Group on Cyber Security and Software Updates: Proposal for Terms of Reference |
| Reference Number: GRVA-26-19 |
|
Proposal to renew the terms for the Informal Working Group on Cyber Security and Software Updates under GRVA. The IWG shall maintain official documents on cyber security and software updates, develop amendments to UN R155 and UN R156 including provisions on software identification, support application across Global Technical Regulations, and provide opportunities for participants to share implementation experience. The IWG will be chaired by the United Kingdom, United States, and Japan, with OICA providing technical secretariat, and will operate until November 2029. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155/R156: Approval Authority for the COC of a CSMS/SUMS and type approval (vehicle type) |
| Reference Number: GRVA-26-20 |
|
Document explains concerns about the approach in GRVA/2026/30 to require a single Approval Authority to issue certificates of compliance for Cyber Security Management Systems and Automated Driving Systems Management Systems and vehicle type approval. The proposed changes would lead to double or triple approvals of management systems, creating administrative burden and unresolved legal consequences regarding challenged certificates of compliance and their effects on other issued certificates for the same management system. The submission proposes clarifying existing wording, documenting implications of challenged certificates, and adding a new paragraph 5.1.5. to UN R155 permitting mutual agreement between Approval Authorities regarding certificate usage. |
| Submitted by: CLCCR, CLEPA, and OICA |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 133 | Light Vehicle Recyclability, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 185 | Approval of vehicles with regard to their Automated Driving Systems |
| Click here to view the full document file |
| Proposal for amendments to the 1958 Agreement regarding the voluntary acceptance of Certificates of Compliance |
| Reference Number: GRVA-26-21 |
|
Proposal to amend Article 2, paragraph 2 to clarify that where a Certificate of Compliance required under a UN Regulation and issued by an Approval Authority of another Contracting Party is accepted by a Contracting Party, the Approval Authority granting the corresponding type approval shall remain responsible for all aspects of that type approval. The amendment addresses management systems and their Certificates of Compliance used in UN Regulations such as UN R155 and UN R156. |
| Submitted by: CLCCR, CLEPA, and OICA |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: United Nations Agreement | 1958 Agreement, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155 and R156: Proposal to amend GRVA/2026/30 |
| Reference Number: GRVA-26-35 |
|
Proposal to amend para. 5.1.3., insert new paras. 5.1.5. and 5.1.5.1. requiring the Approval Authority to refuse type approval unless the Certificate of Compliance for the Cyber Security Management System is issued by the same Approval Authority granting vehicle type approval, while permitting referencing of certificates from other Approval Authorities under specific conditions with documented agreements and clarified responsibilities, and insert new paras. 5.4. and 5.4.1. with equivalent requirements for the Software Update Management System Certificate of Compliance. |
| Submitted by: UK, France, Luxembourg, Germany, and Netherlands |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 17 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155: Proposal to amend GRVA/2026/29 |
| Reference Number: GRVA-26-36/Rev.1 |
|
Proposal to amend paragraph AI to introduce a link between existing text in Part A and new text in Part C regarding vehicle transformations, and insert new Part C providing guidance for the application of UN Regulation No. 155 to transformed vehicles. The proposal adds section 6 clarifying that the requirement for the Certificate of Compliance and type approval to be issued by the same Approval Authority applies only within the scope of the type approval granted to the manufacturer concerned, and does not restrict another manufacturer from obtaining a separate type approval and associated Certificate of Compliance from the responsible Approval Authority. |
| Submitted by: UK |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 18 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Proposal to amend UN R155 and UN R156 |
| Reference Number: GRVA/2026/30 |
|
Proposal to amend UN R155 by inserting new para. 5.1.3.(e) establishing that the Certificate of Compliance for the Cyber Security Management System shall not be issued by a different Approval Authority than the one granting type approval, and amend UN R156 by inserting new para. 5.4. establishing that Approval Authorities shall not grant type approval if the Certificate of Compliance for the Software Update Management System has not been issued by the same Approval Authority granting type approval. Justification includes ensuring holistic cybersecurity assessment, clarifying reporting obligations under para. 7.2.2.2.(g), addressing unharmonized mutual recognition of management system certificates, maintaining consistency between regulations, and upholding the fundamental principle that approval authorities retain responsibility for all aspects of type approval. |
| Submitted by: France, Germany, Luxembourg, Netherlands, and UK |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 03 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155: Proposal for a Supplement |
| Reference Number: GRVA/2026/28 |
|
Proposal to amend para. 5.3.2. to require notification of assessment methods and criteria including paras. 8.2. and 8.3., insert new paras. 8.2. and 8.3. establishing criteria for equipment installation without further assessment, and amend Annex 1 to require disclosure of equipment excluded from assessment pursuant to paras. 8.2. and 8.3. The amendments clarify that equipment with negligible intrinsic cyber security risk installed according to manufacturer specifications and not introducing cyber security risk, and standard non-automotive equipment connected solely for power supply with no increased cyber security risk, shall not invalidate approval of the original vehicle type under UN Regulation No. 155. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 03 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| UN R155: Proposal for a Supplement |
| Reference Number: GRVA/2026/29 |
|
Proposal to insert new Part C providing guidance for the application of UN R155 to transformed vehicles. Part C addresses identification of cyber-relevant transformations, impact on original vehicle architecture, connection risks, and impact on cyber security management systems. It specifies that transformations require new approval unless the manufacturer provides clear evidence that the original approval remains valid, and outlines critical factors and examples of cyber-relevant actions. It details documentary evidence expected from manufacturers regarding functional descriptions, connections with original vehicle types, added components and functions, and arguments demonstrating negligible intrinsic risk. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 06 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Proposal for amendments to UN Regulations Nos. 13, 13-H, 79, 89, 130, 131, 152, 155, 156, 157, 171, 175, and 178 |
| Reference Number: GRVA/2026/27 |
|
Proposal to insert provisions on Software Identification Numbers and software updates across UN R13, R13-H, R79, R89, R130, R131, R152, R155, R156, R157, R171, R175, and R178 by adding definitions referencing Consolidated Resolution R.E.3 Annex 7 paragraph 2, requiring manufacturers to provide Technical Services with information on hardware and software influencing performance with test reports, permitting vehicle manufacturers to apply for new approvals differentiating software versions for registered vehicles from new vehicles where type approval regulations are updated or hardware changes occur in series production with test duplication avoided where possible, clarifying that production is not considered definitively discontinued if manufacturers obtain subsequent extensions for software updates of registered vehicles, renumbering and inserting new items in approval communication annexes for R13SWIN, R13-HSWIN, R79SWIN, R89SWIN, R130SWIN, R131SWIN, R152SWIN, R155SWIN, R157SWIN, R171SWIN, R175SWIN, and R178SWIN information including whether held on vehicle and relevant parameter identification lists, and amending R157 and R171 to align software update requirements with R156 technical specifications and transitional provisions. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 06 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 13-H | Light-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error |
| Click here to view the full document file |
| Software updates: Proposal to amend GRVA/2026/27 |
| Reference Number: GRVA-26-11 |
|
Proposal to insert definitions for Software Identification Number, insert requirements for manufacturers to provide necessary information allowing the Technical Service to uniquely identify hardware and software configurations, insert provisions allowing vehicle manufacturers to apply for new approvals to differentiate software versions for registered versus new vehicles, amend production discontinuation provisions to clarify that cessation is not deemed definitive if the manufacturer intends to obtain subsequent extensions for software updates of vehicles already registered in the market, renumber and insert new items in approval communication annexes regarding software identification and software updates including RxSWIN, and insert provisions allowing vehicle manufacturers to obtain new approvals for software version differentiation across multiple UN Regulations (13, 13-H, 79, 89, 130, 131, 139, 140, 152, 155, 156, 157, 171, 175, and 178). |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 140 | Electronic Stability Control Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 139 | Brake Assist Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error |
| Click here to view the full document file |
| UN R155: Proposal to amend the Interpretation Document |
| Reference Number: GRVA-26-12 |
|
Proposal to amend paragraph AI to introduce a link between existing text in Part A and new Part C regarding vehicle transformations, insert new Part C providing guidance for the application of UN Regulation No. 155 to transformed vehicles including documentary evidence requirements, and add section 6 clarifying that the requirement for Certificate of Compliance and type approval to be issued by the same Approval Authority applies only within the scope of a specific type approval and its approval holder. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Cyber Security and Software Updates informal group status report to GRVA |
| Reference Number: GRVA-26-18 |
|
Status report on activities of the IWG on CS/OTA since the 25th GRVA session. The IWG reviewed proposals for amendment of UN R155 and its interpretation document for multi-stage vehicles, proposals for approval-authority arrangements and Certificates of Compliance for UN R155 and R156, proposals integrating software identification and update text across several UNRs outlined in RE.3, component and STU approval concepts, and remote operation and automated driving systems. The IWG proposes updating regulatory text and interpretation documents for UN R155, revisions to software identification and update text across several regulations, and revised Terms of Reference for a mandate till November 2029. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 89 | Speed Limitation Devices, WP.29 Regulatory Project | Automated Driving Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| Informal Working Group on Cyber Security and Software Updates: Proposal for Terms of Reference |
| Reference Number: GRVA-26-19 |
|
Proposal to renew the terms for the Informal Working Group on Cyber Security and Software Updates under GRVA. The IWG shall maintain official documents on cyber security and software updates, develop amendments to UN R155 and UN R156 including provisions on software identification, support application across Global Technical Regulations, and provide opportunities for participants to share implementation experience. The IWG will be chaired by the United Kingdom, United States, and Japan, with OICA providing technical secretariat, and will operate until November 2029. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155/R156: Approval Authority for the COC of a CSMS/SUMS and type approval (vehicle type) |
| Reference Number: GRVA-26-20 |
|
Document explains concerns about the approach in GRVA/2026/30 to require a single Approval Authority to issue certificates of compliance for Cyber Security Management Systems and Automated Driving Systems Management Systems and vehicle type approval. The proposed changes would lead to double or triple approvals of management systems, creating administrative burden and unresolved legal consequences regarding challenged certificates of compliance and their effects on other issued certificates for the same management system. The submission proposes clarifying existing wording, documenting implications of challenged certificates, and adding a new paragraph 5.1.5. to UN R155 permitting mutual agreement between Approval Authorities regarding certificate usage. |
| Submitted by: CLCCR, CLEPA, and OICA |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 133 | Light Vehicle Recyclability, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 185 | Approval of vehicles with regard to their Automated Driving Systems |
| Click here to view the full document file |
| Proposal for amendments to the 1958 Agreement regarding the voluntary acceptance of Certificates of Compliance |
| Reference Number: GRVA-26-21 |
|
Proposal to amend Article 2, paragraph 2 to clarify that where a Certificate of Compliance required under a UN Regulation and issued by an Approval Authority of another Contracting Party is accepted by a Contracting Party, the Approval Authority granting the corresponding type approval shall remain responsible for all aspects of that type approval. The amendment addresses management systems and their Certificates of Compliance used in UN Regulations such as UN R155 and UN R156. |
| Submitted by: CLCCR, CLEPA, and OICA |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: United Nations Agreement | 1958 Agreement, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155 and R156: Proposal to amend GRVA/2026/30 |
| Reference Number: GRVA-26-35 |
|
Proposal to amend para. 5.1.3., insert new paras. 5.1.5. and 5.1.5.1. requiring the Approval Authority to refuse type approval unless the Certificate of Compliance for the Cyber Security Management System is issued by the same Approval Authority granting vehicle type approval, while permitting referencing of certificates from other Approval Authorities under specific conditions with documented agreements and clarified responsibilities, and insert new paras. 5.4. and 5.4.1. with equivalent requirements for the Software Update Management System Certificate of Compliance. |
| Submitted by: UK, France, Luxembourg, Germany, and Netherlands |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 17 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155: Proposal to amend GRVA/2026/29 |
| Reference Number: GRVA-26-36/Rev.1 |
|
Proposal to amend paragraph AI to introduce a link between existing text in Part A and new text in Part C regarding vehicle transformations, and insert new Part C providing guidance for the application of UN Regulation No. 155 to transformed vehicles. The proposal adds section 6 clarifying that the requirement for the Certificate of Compliance and type approval to be issued by the same Approval Authority applies only within the scope of the type approval granted to the manufacturer concerned, and does not restrict another manufacturer from obtaining a separate type approval and associated Certificate of Compliance from the responsible Approval Authority. |
| Submitted by: UK |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 18 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Proposal to amend UN R155 and UN R156 |
| Reference Number: GRVA/2026/30 |
|
Proposal to amend UN R155 by inserting new para. 5.1.3.(e) establishing that the Certificate of Compliance for the Cyber Security Management System shall not be issued by a different Approval Authority than the one granting type approval, and amend UN R156 by inserting new para. 5.4. establishing that Approval Authorities shall not grant type approval if the Certificate of Compliance for the Software Update Management System has not been issued by the same Approval Authority granting type approval. Justification includes ensuring holistic cybersecurity assessment, clarifying reporting obligations under para. 7.2.2.2.(g), addressing unharmonized mutual recognition of management system certificates, maintaining consistency between regulations, and upholding the fundamental principle that approval authorities retain responsibility for all aspects of type approval. |
| Submitted by: France, Germany, Luxembourg, Netherlands, and UK |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 03 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155: Proposal for a Supplement |
| Reference Number: GRVA/2026/28 |
|
Proposal to amend para. 5.3.2. to require notification of assessment methods and criteria including paras. 8.2. and 8.3., insert new paras. 8.2. and 8.3. establishing criteria for equipment installation without further assessment, and amend Annex 1 to require disclosure of equipment excluded from assessment pursuant to paras. 8.2. and 8.3. The amendments clarify that equipment with negligible intrinsic cyber security risk installed according to manufacturer specifications and not introducing cyber security risk, and standard non-automotive equipment connected solely for power supply with no increased cyber security risk, shall not invalidate approval of the original vehicle type under UN Regulation No. 155. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 03 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| UN R155: Proposal for a Supplement |
| Reference Number: GRVA/2026/29 |
|
Proposal to insert new Part C providing guidance for the application of UN R155 to transformed vehicles. Part C addresses identification of cyber-relevant transformations, impact on original vehicle architecture, connection risks, and impact on cyber security management systems. It specifies that transformations require new approval unless the manufacturer provides clear evidence that the original approval remains valid, and outlines critical factors and examples of cyber-relevant actions. It details documentary evidence expected from manufacturers regarding functional descriptions, connections with original vehicle types, added components and functions, and arguments demonstrating negligible intrinsic risk. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 06 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Proposal for amendments to UN Regulations Nos. 13, 13-H, 79, 89, 130, 131, 152, 155, 156, 157, 171, 175, and 178 |
| Reference Number: GRVA/2026/27 |
|
Proposal to insert provisions on Software Identification Numbers and software updates across UN R13, R13-H, R79, R89, R130, R131, R152, R155, R156, R157, R171, R175, and R178 by adding definitions referencing Consolidated Resolution R.E.3 Annex 7 paragraph 2, requiring manufacturers to provide Technical Services with information on hardware and software influencing performance with test reports, permitting vehicle manufacturers to apply for new approvals differentiating software versions for registered vehicles from new vehicles where type approval regulations are updated or hardware changes occur in series production with test duplication avoided where possible, clarifying that production is not considered definitively discontinued if manufacturers obtain subsequent extensions for software updates of registered vehicles, renumbering and inserting new items in approval communication annexes for R13SWIN, R13-HSWIN, R79SWIN, R89SWIN, R130SWIN, R131SWIN, R152SWIN, R155SWIN, R157SWIN, R171SWIN, R175SWIN, and R178SWIN information including whether held on vehicle and relevant parameter identification lists, and amending R157 and R171 to align software update requirements with R156 technical specifications and transitional provisions. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 06 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 13-H | Light-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error |
| Click here to view the full document file |
| Software updates: Proposal to amend GRVA/2026/27 |
| Reference Number: GRVA-26-11 |
|
Proposal to insert definitions for Software Identification Number, insert requirements for manufacturers to provide necessary information allowing the Technical Service to uniquely identify hardware and software configurations, insert provisions allowing vehicle manufacturers to apply for new approvals to differentiate software versions for registered versus new vehicles, amend production discontinuation provisions to clarify that cessation is not deemed definitive if the manufacturer intends to obtain subsequent extensions for software updates of vehicles already registered in the market, renumber and insert new items in approval communication annexes regarding software identification and software updates including RxSWIN, and insert provisions allowing vehicle manufacturers to obtain new approvals for software version differentiation across multiple UN Regulations (13, 13-H, 79, 89, 130, 131, 139, 140, 152, 155, 156, 157, 171, 175, and 178). |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 140 | Electronic Stability Control Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 139 | Brake Assist Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error |
| Click here to view the full document file |
| UN R155: Proposal to amend the Interpretation Document |
| Reference Number: GRVA-26-12 |
|
Proposal to amend paragraph AI to introduce a link between existing text in Part A and new Part C regarding vehicle transformations, insert new Part C providing guidance for the application of UN Regulation No. 155 to transformed vehicles including documentary evidence requirements, and add section 6 clarifying that the requirement for Certificate of Compliance and type approval to be issued by the same Approval Authority applies only within the scope of a specific type approval and its approval holder. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Cyber Security and Software Updates informal group status report to GRVA |
| Reference Number: GRVA-26-18 |
|
Status report on activities of the IWG on CS/OTA since the 25th GRVA session. The IWG reviewed proposals for amendment of UN R155 and its interpretation document for multi-stage vehicles, proposals for approval-authority arrangements and Certificates of Compliance for UN R155 and R156, proposals integrating software identification and update text across several UNRs outlined in RE.3, component and STU approval concepts, and remote operation and automated driving systems. The IWG proposes updating regulatory text and interpretation documents for UN R155, revisions to software identification and update text across several regulations, and revised Terms of Reference for a mandate till November 2029. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 89 | Speed Limitation Devices, WP.29 Regulatory Project | Automated Driving Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| Informal Working Group on Cyber Security and Software Updates: Proposal for Terms of Reference |
| Reference Number: GRVA-26-19 |
|
Proposal to renew the terms for the Informal Working Group on Cyber Security and Software Updates under GRVA. The IWG shall maintain official documents on cyber security and software updates, develop amendments to UN R155 and UN R156 including provisions on software identification, support application across Global Technical Regulations, and provide opportunities for participants to share implementation experience. The IWG will be chaired by the United Kingdom, United States, and Japan, with OICA providing technical secretariat, and will operate until November 2029. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155/R156: Approval Authority for the COC of a CSMS/SUMS and type approval (vehicle type) |
| Reference Number: GRVA-26-20 |
|
Document explains concerns about the approach in GRVA/2026/30 to require a single Approval Authority to issue certificates of compliance for Cyber Security Management Systems and Automated Driving Systems Management Systems and vehicle type approval. The proposed changes would lead to double or triple approvals of management systems, creating administrative burden and unresolved legal consequences regarding challenged certificates of compliance and their effects on other issued certificates for the same management system. The submission proposes clarifying existing wording, documenting implications of challenged certificates, and adding a new paragraph 5.1.5. to UN R155 permitting mutual agreement between Approval Authorities regarding certificate usage. |
| Submitted by: CLCCR, CLEPA, and OICA |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 133 | Light Vehicle Recyclability, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 185 | Approval of vehicles with regard to their Automated Driving Systems |
| Click here to view the full document file |
| Proposal for amendments to the 1958 Agreement regarding the voluntary acceptance of Certificates of Compliance |
| Reference Number: GRVA-26-21 |
|
Proposal to amend Article 2, paragraph 2 to clarify that where a Certificate of Compliance required under a UN Regulation and issued by an Approval Authority of another Contracting Party is accepted by a Contracting Party, the Approval Authority granting the corresponding type approval shall remain responsible for all aspects of that type approval. The amendment addresses management systems and their Certificates of Compliance used in UN Regulations such as UN R155 and UN R156. |
| Submitted by: CLCCR, CLEPA, and OICA |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: United Nations Agreement | 1958 Agreement, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155 and R156: Proposal to amend GRVA/2026/30 |
| Reference Number: GRVA-26-35 |
|
Proposal to amend para. 5.1.3., insert new paras. 5.1.5. and 5.1.5.1. requiring the Approval Authority to refuse type approval unless the Certificate of Compliance for the Cyber Security Management System is issued by the same Approval Authority granting vehicle type approval, while permitting referencing of certificates from other Approval Authorities under specific conditions with documented agreements and clarified responsibilities, and insert new paras. 5.4. and 5.4.1. with equivalent requirements for the Software Update Management System Certificate of Compliance. |
| Submitted by: UK, France, Luxembourg, Germany, and Netherlands |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 17 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155: Proposal to amend GRVA/2026/29 |
| Reference Number: GRVA-26-36/Rev.1 |
|
Proposal to amend paragraph AI to introduce a link between existing text in Part A and new text in Part C regarding vehicle transformations, and insert new Part C providing guidance for the application of UN Regulation No. 155 to transformed vehicles. The proposal adds section 6 clarifying that the requirement for the Certificate of Compliance and type approval to be issued by the same Approval Authority applies only within the scope of the type approval granted to the manufacturer concerned, and does not restrict another manufacturer from obtaining a separate type approval and associated Certificate of Compliance from the responsible Approval Authority. |
| Submitted by: UK |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 18 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Proposal to amend UN R155 and UN R156 |
| Reference Number: GRVA/2026/30 |
|
Proposal to amend UN R155 by inserting new para. 5.1.3.(e) establishing that the Certificate of Compliance for the Cyber Security Management System shall not be issued by a different Approval Authority than the one granting type approval, and amend UN R156 by inserting new para. 5.4. establishing that Approval Authorities shall not grant type approval if the Certificate of Compliance for the Software Update Management System has not been issued by the same Approval Authority granting type approval. Justification includes ensuring holistic cybersecurity assessment, clarifying reporting obligations under para. 7.2.2.2.(g), addressing unharmonized mutual recognition of management system certificates, maintaining consistency between regulations, and upholding the fundamental principle that approval authorities retain responsibility for all aspects of type approval. |
| Submitted by: France, Germany, Luxembourg, Netherlands, and UK |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 03 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155: Proposal for a Supplement |
| Reference Number: GRVA/2026/28 |
|
Proposal to amend para. 5.3.2. to require notification of assessment methods and criteria including paras. 8.2. and 8.3., insert new paras. 8.2. and 8.3. establishing criteria for equipment installation without further assessment, and amend Annex 1 to require disclosure of equipment excluded from assessment pursuant to paras. 8.2. and 8.3. The amendments clarify that equipment with negligible intrinsic cyber security risk installed according to manufacturer specifications and not introducing cyber security risk, and standard non-automotive equipment connected solely for power supply with no increased cyber security risk, shall not invalidate approval of the original vehicle type under UN Regulation No. 155. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 03 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| UN R155: Proposal for a Supplement |
| Reference Number: GRVA/2026/29 |
|
Proposal to insert new Part C providing guidance for the application of UN R155 to transformed vehicles. Part C addresses identification of cyber-relevant transformations, impact on original vehicle architecture, connection risks, and impact on cyber security management systems. It specifies that transformations require new approval unless the manufacturer provides clear evidence that the original approval remains valid, and outlines critical factors and examples of cyber-relevant actions. It details documentary evidence expected from manufacturers regarding functional descriptions, connections with original vehicle types, added components and functions, and arguments demonstrating negligible intrinsic risk. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 06 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Proposal for amendments to UN Regulations Nos. 13, 13-H, 79, 89, 130, 131, 152, 155, 156, 157, 171, 175, and 178 |
| Reference Number: GRVA/2026/27 |
|
Proposal to insert provisions on Software Identification Numbers and software updates across UN R13, R13-H, R79, R89, R130, R131, R152, R155, R156, R157, R171, R175, and R178 by adding definitions referencing Consolidated Resolution R.E.3 Annex 7 paragraph 2, requiring manufacturers to provide Technical Services with information on hardware and software influencing performance with test reports, permitting vehicle manufacturers to apply for new approvals differentiating software versions for registered vehicles from new vehicles where type approval regulations are updated or hardware changes occur in series production with test duplication avoided where possible, clarifying that production is not considered definitively discontinued if manufacturers obtain subsequent extensions for software updates of registered vehicles, renumbering and inserting new items in approval communication annexes for R13SWIN, R13-HSWIN, R79SWIN, R89SWIN, R130SWIN, R131SWIN, R152SWIN, R155SWIN, R157SWIN, R171SWIN, R175SWIN, and R178SWIN information including whether held on vehicle and relevant parameter identification lists, and amending R157 and R171 to align software update requirements with R156 technical specifications and transitional provisions. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 06 Jul 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 13-H | Light-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error |
| Click here to view the full document file |
| Software updates: Proposal to amend GRVA/2026/27 |
| Reference Number: GRVA-26-11 |
|
Proposal to insert definitions for Software Identification Number, insert requirements for manufacturers to provide necessary information allowing the Technical Service to uniquely identify hardware and software configurations, insert provisions allowing vehicle manufacturers to apply for new approvals to differentiate software versions for registered versus new vehicles, amend production discontinuation provisions to clarify that cessation is not deemed definitive if the manufacturer intends to obtain subsequent extensions for software updates of vehicles already registered in the market, renumber and insert new items in approval communication annexes regarding software identification and software updates including RxSWIN, and insert provisions allowing vehicle manufacturers to obtain new approvals for software version differentiation across multiple UN Regulations (13, 13-H, 79, 89, 130, 131, 139, 140, 152, 155, 156, 157, 171, 175, and 178). |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 140 | Electronic Stability Control Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 139 | Brake Assist Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error |
| Click here to view the full document file |
| UN R155: Proposal to amend the Interpretation Document |
| Reference Number: GRVA-26-12 |
|
Proposal to amend paragraph AI to introduce a link between existing text in Part A and new Part C regarding vehicle transformations, insert new Part C providing guidance for the application of UN Regulation No. 155 to transformed vehicles including documentary evidence requirements, and add section 6 clarifying that the requirement for Certificate of Compliance and type approval to be issued by the same Approval Authority applies only within the scope of a specific type approval and its approval holder. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Cyber Security and Software Updates informal group status report to GRVA |
| Reference Number: GRVA-26-18 |
|
Status report on activities of the IWG on CS/OTA since the 25th GRVA session. The IWG reviewed proposals for amendment of UN R155 and its interpretation document for multi-stage vehicles, proposals for approval-authority arrangements and Certificates of Compliance for UN R155 and R156, proposals integrating software identification and update text across several UNRs outlined in RE.3, component and STU approval concepts, and remote operation and automated driving systems. The IWG proposes updating regulatory text and interpretation documents for UN R155, revisions to software identification and update text across several regulations, and revised Terms of Reference for a mandate till November 2029. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 89 | Speed Limitation Devices, WP.29 Regulatory Project | Automated Driving Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| Informal Working Group on Cyber Security and Software Updates: Proposal for Terms of Reference |
| Reference Number: GRVA-26-19 |
|
Proposal to renew the terms for the Informal Working Group on Cyber Security and Software Updates under GRVA. The IWG shall maintain official documents on cyber security and software updates, develop amendments to UN R155 and UN R156 including provisions on software identification, support application across Global Technical Regulations, and provide opportunities for participants to share implementation experience. The IWG will be chaired by the United Kingdom, United States, and Japan, with OICA providing technical secretariat, and will operate until November 2029. |
| Submitted by: TFCS |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155/R156: Approval Authority for the COC of a CSMS/SUMS and type approval (vehicle type) |
| Reference Number: GRVA-26-20 |
|
Document explains concerns about the approach in GRVA/2026/30 to require a single Approval Authority to issue certificates of compliance for Cyber Security Management Systems and Automated Driving Systems Management Systems and vehicle type approval. The proposed changes would lead to double or triple approvals of management systems, creating administrative burden and unresolved legal consequences regarding challenged certificates of compliance and their effects on other issued certificates for the same management system. The submission proposes clarifying existing wording, documenting implications of challenged certificates, and adding a new paragraph 5.1.5. to UN R155 permitting mutual agreement between Approval Authorities regarding certificate usage. |
| Submitted by: CLCCR, CLEPA, and OICA |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: UN Regulation No. 133 | Light Vehicle Recyclability, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 185 | Approval of vehicles with regard to their Automated Driving Systems |
| Click here to view the full document file |
| Proposal for amendments to the 1958 Agreement regarding the voluntary acceptance of Certificates of Compliance |
| Reference Number: GRVA-26-21 |
|
Proposal to amend Article 2, paragraph 2 to clarify that where a Certificate of Compliance required under a UN Regulation and issued by an Approval Authority of another Contracting Party is accepted by a Contracting Party, the Approval Authority granting the corresponding type approval shall remain responsible for all aspects of that type approval. The amendment addresses management systems and their Certificates of Compliance used in UN Regulations such as UN R155 and UN R156. |
| Submitted by: CLCCR, CLEPA, and OICA |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 14 Sep 26 |
| Relevant to: United Nations Agreement | 1958 Agreement, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155 and R156: Proposal to amend GRVA/2026/30 |
| Reference Number: GRVA-26-35 |
|
Proposal to amend para. 5.1.3., insert new paras. 5.1.5. and 5.1.5.1. requiring the Approval Authority to refuse type approval unless the Certificate of Compliance for the Cyber Security Management System is issued by the same Approval Authority granting vehicle type approval, while permitting referencing of certificates from other Approval Authorities under specific conditions with documented agreements and clarified responsibilities, and insert new paras. 5.4. and 5.4.1. with equivalent requirements for the Software Update Management System Certificate of Compliance. |
| Submitted by: UK, France, Luxembourg, Germany, and Netherlands |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 17 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155: Proposal to amend GRVA/2026/29 |
| Reference Number: GRVA-26-36/Rev.1 |
|
Proposal to amend paragraph AI to introduce a link between existing text in Part A and new text in Part C regarding vehicle transformations, and insert new Part C providing guidance for the application of UN Regulation No. 155 to transformed vehicles. The proposal adds section 6 clarifying that the requirement for the Certificate of Compliance and type approval to be issued by the same Approval Authority applies only within the scope of the type approval granted to the manufacturer concerned, and does not restrict another manufacturer from obtaining a separate type approval and associated Certificate of Compliance from the responsible Approval Authority. |
| Submitted by: UK |
| Meeting Sessions: 26th GRVA session (14-18 Sep) |
| Document date: 18 Sep 26 |
| Document status: Formal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
GRVA will be briefed on the outcome of the recent meeting(s) of the IWG on Cyber Security and Over-the-Air (CS/OTA) issues.
| GRVA-26-18 | Cyber Security and Software Updates informal group status report to GRVA |
|
GRVA agreed to resume consideration of an amendment proposal to UN Regulations under the purview of GRVA clarifying to introduce provisions on software identification and software updates.
| GRVA-26-11 | Software updates: Proposal to amend GRVA/2026/27 |
|
| GRVA/2026/27 | Proposal for amendments to UN Regulations Nos. 13, 13-H, 79, 89, 130, 131, 152, 155, 156, 157, 171, 175, and 178 |
|
GRVA agreed to resume consideration of an amendment proposal to UN Regulation No. 155 aimed at clarifying its scope.
| GRVA/2026/28 | UN R155: Proposal for a Supplement |
|
| GRVA/2026/29 | UN R155: Proposal for a Supplement |
|
GRVA agreed to resume consideration of an amendment proposal to the Interpretation Documents for UN Regulation No. 155.
| GRVA-26-12 | UN R155: Proposal to amend the Interpretation Document |
|
GRVA may wish to be informed on the outcome of the technical workshop(s) on the implementation of cyber security and software updates provisions.
GRVA agreed to resume consideration of an amendment proposal to UN Regulations Nos. 155 and 156, tabled by the experts from France, Germany, Luxembourg, the Netherlands (Kingdom of) and the United Kingdom of Great Britain and Northern Ireland, clarifying that a Cyber Security Management System and a Software Update Management System should be issued by the Approval Authority granting the type approval.
| GRVA-26-20 | UN R155/R156: Approval Authority for the COC of a CSMS/SUMS and type approval (vehicle type) |
|
| GRVA-26-21 | Proposal for amendments to the 1958 Agreement regarding the voluntary acceptance of Certificates of Compliance |
|
| GRVA-26-35 | UN R155 and R156: Proposal to amend GRVA/2026/30 |
|
| GRVA-26-36/Rev.1 | UN R155: Proposal to amend GRVA/2026/29 |
|
| GRVA/2026/30 | Proposal to amend UN R155 and UN R156 |
|
GRVA may wish to review the proposed amendments to UN Regulations Nos. 155 and 156, if available.
| GRVA-26-19 | Informal Working Group on Cyber Security and Software Updates: Proposal for Terms of Reference |