|
UN R155: Guidance for transformed vehicles
|
|
Reference Number: TFCS-37-05
|
|
Proposal to provide guidance on application of UN R155 to transformed vehicles. Transformations require new approval unless clear evidence shows original approval remains valid. Cyber-relevant modifications include addition of electrical/electronic systems, inappropriate interface connections, and wiring protection modifications. The approval authority determines whether transformation is cyber-relevant by assessing impact on original vehicle architecture, connection risks, cybersecurity management systems, and whether non-automotive equipment complies with relevant regulations. Manufacturers must provide documentary evidence including functional descriptions, connection details, software modifications, and compliance with original manufacturer instructions.
|
|
Meeting Sessions: 37th TFCS session (21-22
Apr)
|
|
Document date: 16 Apr 26
|
|
Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management
|
|
Click here to view the full document file
|
|
UN R155: Proposal on operator risks
|
|
Reference Number: TFCS-37-09
|
|
Proposal to amend Table A1 of Annex 5 to include high level and sub-level descriptions of vulnerability and threat including spoofing of messages, Sybil attacks, communication channels permitting code injection, manipulation, overwrite and erasure of vehicle held data and code, denial of service attacks, unauthorized access to vehicle systems, viruses in communication media, and malicious messages, and amend Table B1 of Annex 5 to provide corresponding mitigation measures. This proposal is a further elaboration of TFCS-35-07.
|
|
Submitted by:
UK
|
|
Meeting Sessions: 37th TFCS session (21-22
Apr)
|
|
Document date: 20 Apr 26
|
|
Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management
|
|
Click here to view the full document file
|
|
UN R155: Presentation on proposal to address operator risks
|
|
Reference Number: TFCS-37-10
|
|
UN R155 addresses operator risks in automated driving systems. The ADS Regulation enables operators to offer services using automation and permits remote termination of the ADS. UN R155 mandates that supplier-related risks are managed, but operators are customers, not suppliers, creating downstream risks. An automated vehicle could be susceptible to unauthorised requests from an operator experiencing cyber attack. UN R155 does not define how downstream organisational risks are managed. Manufacturers should identify risks posed by operators and inform Third Party Operators of risks involved and expected minimum-security controls for workstations interfacing with an ADS. This could be achieved via Annex 5.
|
|
Submitted by:
UK
|
|
Meeting Sessions: 37th TFCS session (21-22
Apr)
|
|
Document date: 20 Apr 26
|
|
Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management
|
|
Click here to view the full document file
|
|
UN R155: Presentation on STU approval concept
|
|
Reference Number: TFCS-37-08
|
|
TFCS-37-08 presents proposals to amend UN R155 to establish approval routes for electrical/electronic sub-assemblies and separate technical units. The regulation introduces three parts: Part I covers vehicle cyber security approval; Part II covers component and separate technical unit approval; Part III covers installation approval of approved components and separate technical units in vehicles. Updates include new definitions, application procedures by manufacturers or their representatives, approval conditions specifying connection limitations, and cyber security management system requirements. The proposal requests colleague review and feedback.
|
|
Submitted by:
UK
|
|
Meeting Sessions: 37th TFCS session (21-22
Apr)
|
|
Document date: 20 Apr 26
|
|
Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management
|
|
Click here to view the full document file
|
|
UN R155: Concept for STU approvals
|
|
Reference Number: TFCS-37-07
|
|
This document presents an initial concept for approvals of devices as components or separate technical units according to UN R155, and the installation of such devices on vehicles already holding UN R155 approval, based on Supplement 3 to the original series. The regulation applies to vehicles of categories L1–L7, M1–M3, N1–N3, and O1–O4 with electronic control units, and to approval of components and separate technical units with regard to their cyber security. Approval authorities shall grant type approval only to vehicle or electrical/electronic sub-assembly types that satisfy the regulation’s requirements through document checks and testing. Manufacturers must demonstrate cyber security management systems covering development, production, and post-production phases, including risk assessment, mitigation implementation, monitoring, and response to cyber-attacks. Certificates of Compliance for Cyber Security Management Systems remain valid for three years.
|
|
Submitted by:
UK
|
|
Meeting Sessions: 37th TFCS session (21-22
Apr)
|
|
Document date: 20 Apr 26
|
|
Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management
|
|
Click here to view the full document file
|
|
Questions concerning cyber security amendments for approvals of STU
|
|
Reference Number: TFCS-37-06
|
|
Questions concerning cyber security amendments for approvals of STU submitted by the expert from Japan that address timing of working document submission to GRVA, whether Part II components may include certificated base vehicle equipment under UN R155 multi-stage categorization, whether STU definition includes ECUs within base vehicle E/E architecture, examination of use cases and implementation challenges, consistency of applicant terminology between Section 3.3.1 and Section 7.6, whether approval authorities for Parts I, II, and III must be identical, clarification of end of support period requirements in para. 2.7(b), installation agreement requirements in para. 5.1.2.1(d), and whether total Cyber Security Risk Assessment Process for whole vehicle with other equipment than ESAs is necessary after ESA installation under para. 7.4.10.
|
|
Submitted by:
Japan
|
|
Meeting Sessions: 37th TFCS session (21-22
Apr)
|
|
Document date: 20 Apr 26
|
|
Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management
|
|
Click here to view the full document file
|
|
Proposals to amend UN R13, 13-H, 79, 89, 130, 131, 139, 140, 152, 155, 156, 157, 171, 175, and 178
|
|
Reference Number: TFCS-37-03/Rev.1
|
|
Proposal to amend UN R13, 13-H, 79, 89, 130, 131, 139, 140, 152, 155, 156, 157, 171, 175, and 178 by introducing provisions on software identification and software updates. Amendments add new paragraphs referring to Software Identification Number definitions in Consolidated Resolution R.E.3, require manufacturers to provide Technical Services with information on hardware and software influencing performance, permit vehicle manufacturers to apply for new approvals differentiating software versions for registered versus new vehicles while avoiding test duplication, and modify production discontinuation provisions to exclude cases where manufacturers seek approval extensions for software updates of registered vehicles.
|
|
Submitted by:
France
|
|
Meeting Sessions: 37th TFCS session (21-22
Apr)
|
|
Document date: 21 Apr 26
|
|
Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 13-H | Light-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 140 | Electronic Stability Control Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 139 | Brake Assist Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error
|
|
Click here to view the full document file
|
|
UN R155: Proposal for amendments from the workshop discussions
|
|
Reference Number: TFCS-37-04/Rev.1
|
|
Proposal to amend UN R155 by clarifying its scope to exclude certain equipment. The proposal amends paragraph 5.3.2. to require approval authorities to notify others of assessment methods and criteria. New paragraphs 8.2. and 8.3. establish that vehicle manufacturer installation of equipment with negligible intrinsic cyber security risk, or standard domestic, business or industrial equipment connected only for power, shall not require further assessment under paragraph 7, provided specified criteria are justified. Annex I is amended to include any equipment excluded from assessment pursuant to paragraphs 8.2. and 8.3.
|
|
Meeting Sessions: 37th TFCS session (21-22
Apr)
|
|
Document date: 22 Apr 26
|
|
Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management
|
|
Click here to view the full document file
|
|
UN R155 and R156: Approvals for ‘out-of-scope’ vehicles
|
|
Reference Number: TFCS-38-03
|
|
Vehicles of categories M1, N, O, R, S and T may fall out of scope of UN R155 or UN R156 if they lack ECUs or do not permit software updates. Approval authorities currently make individual determinations regarding whether vehicles are in or out of scope, and justification for out-of-scope decisions must be recorded to ensure vehicles remain out of scope during the lifetime of whole vehicle approval. UN Regulation No. 10 provides precedent by allowing approvals for vehicles where certain equipment is not relevant. A similar provision could be incorporated into UN R155 and UN R156 by amending the scope and adding provisions to section 5 allowing manufacturers to obtain approvals for vehicles that do not permit software updates, with requirements of paragraph 7 not applying.
|
|
Submitted by:
VCA
|
|
Meeting Sessions: 38th TFCS session (30 Jun-1
Jul)
|
|
Document date: 23 Jun 26
|
|
Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems
|
|
Click here to view the full document file
|
|
UN R155: Questions concerning separate technical units
|
|
Reference Number: TFCS-38-04
|
|
Questions address whether minimum vehicle architecture approval should be required before Part III can be used for additional devices; whether approved ESAs can be incorporated in original vehicle approval or as an extension to Part I approval; whether different terminology should replace CSMS for Part III approvals; whether second Part III approvals are permissible for vehicles already approved to Parts I and III; and what implications arise from end-of-support by ESA manufacturers.
|
|
Submitted by:
UK
|
|
Meeting Sessions: 38th TFCS session (30 Jun-1
Jul)
|
|
Document date: 23 Jun 26
|
|
Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management
|
|
Click here to view the full document file
|
|
UN R155: Response to questions concerning separate technical unit approvals
|
|
Reference Number: TFCS-38-05
|
|
Answers to questions on separate technical unit approvals under UN R155 clarify that a base vehicle must already hold an R155 type approval before an ESA can be added at Part III; approval authorities for different parts may differ with mutual recognition applying; the end of support period for an ESA manufacturer must be communicated to the vehicle manufacturer, with implications to be discussed by the IWG; installation of ESAs must follow vehicle manufacturer instructions without necessarily requiring separate agreement; STU data sharing agreements are required; and after ESA installation, a whole vehicle cyber security risk assessment is not necessary, though Part III must consider risks where ESA and base vehicle interactions occur. A working document is planned for submission to GRVA in January 2027. The IWG will explore whether Part II components may include equipment from certificated base vehicles under UN R155 multi-stage categorization and discuss incorporating STU into original approvals.
|
|
Submitted by:
UK
|
|
Meeting Sessions: 38th TFCS session (30 Jun-1
Jul)
|
|
Document date: 23 Jun 26
|
|
Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management
|
|
Click here to view the full document file
|
|
UN R156: Question on 01 series of amendments interpretation
|
|
Reference Number: TFCS-38-07
|
|
The document clarifies two interpretation points regarding UN R156-01. First, software updates to registered vehicles require that an RXSWIN be assigned to every Regulation No. X type approval assessed during the update process, unless the manufacturer does not plan software updates for that particular system Regulation. Second, regarding para. 7.2.1.2.2., it is proposed to delete the requirement that software version changes be declared each time they are updated, since software versions are declared for each regulation subject to software updates following amendments to RE.3 Annex 7.
|
|
Submitted by:
NTSEL
|
|
Meeting Sessions: 38th TFCS session (30 Jun-1
Jul)
|
|
Document date: 26 Jun 26
|
|
Relevant to: UN Regulation No. 156 | Software Update Processes and Management Systems
|
|
Click here to view the full document file
|
|
UN R155: Review of points for approval of separate technical units
|
|
Reference Number: TFCS-38-06
|
|
A comprehensive cyber security risk assessment without gaps between Parts I, II, and III is required for component or separate technical unit approval. Risk assessment is difficult for manufacturers alone; contracts are required to share vulnerability information. Identification of realistic installation use cases, information sharing between approval authorities, and clarification of responsibilities are necessary. Components with no communication to the vehicle or only mechanical and power connection do not require new approval. Components sending data to the vehicle or controlling it require Part II approval and joint risk analysis by the original equipment manufacturer and installer.
|
|
Submitted by:
NTSEL
|
|
Meeting Sessions: 38th TFCS session (30 Jun-1
Jul)
|
|
Document date: 26 Jun 26
|
|
Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management
|
|
Click here to view the full document file
|
|
UN R155: Proposal to address approvals by one or more authorities
|
|
Reference Number: TFCS-38-08
|
|
Proposal to add para. 3.2.3.1. requiring manufacturers to provide additional information on the Cyber Security Management System at request of the Approval Authority when the Certificate of Compliance for CSMS is issued by a different Approval Authority, add para. 5.1.5. allowing the Approval Authority to refuse type approval if insufficient information on the CSMS and its implementation was provided, and add para. 7.4.1.1. requiring all granting Approval Authorities to be included in reporting when different Approval Authorities are used for the Certificate of Compliance for CSMS and type approval of the vehicle type.
|
|
Submitted by:
OICA and CLEPA
|
|
Meeting Sessions: 38th TFCS session (30 Jun-1
Jul)
|
|
Document date: 29 Jun 26
|
|
Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management
|
|
Click here to view the full document file
|
|
Component/STU type approval under UN R155
|
|
Reference Number: TFCS-38-09
|
|
CLEPA welcomes questions raised by Japanese experts under doc TFCS-37-06 and identifies points requiring further clarification regarding component and STU type approval scope, technical integration, STU definition, implementation, risk assessment, impact and benefit, and post-market monitoring. CLEPA proposes that components or STUs required for initial vehicle type approval under Part I should not be subject to separate approval under Part II, noting that vehicle cybersecurity depends on vehicle-level system interactions and E/E architecture, the OEM has full visibility of system architecture, and Part I approval ensures integrated assessment.
|
|
Submitted by:
CLEPA
|
|
Meeting Sessions: 38th TFCS session (30 Jun-1
Jul)
|
|
Document date: 29 Jun 26
|
|
Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management
|
|
Click here to view the full document file
|
|
Cyber security: Modifications to GRVA-25-30
|
|
Reference Number: TFCS-38-12
|
|
Proposal to insert provisions on software identification and software updates into UN R13, UN R13-H, UN R79, UN R89, UN R130, UN R131, UN R152, UN R156, UN R157, UN R171, UN R175, and UN R178 by adding definitions referencing Consolidated Resolution R.E.3 Annex 7, requiring manufacturers to provide Technical Services with information on hardware and software influencing performance, permitting vehicle manufacturers to apply for new approvals differentiating software versions for registered versus new vehicles, clarifying that production discontinuation does not apply when manufacturers seek approval extensions for software updates of registered vehicles, and amending communication forms to include software identification numbers and related information.
|
|
Meeting Sessions: 38th TFCS session (30 Jun-1
Jul)
|
|
Document date: 30 Jun 26
|
|
Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 13-H | Light-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error
|
|
Click here to view the full document file
|
|
CS/OTA: Draft updated terms of reference
|
|
Reference Number: TFCS-38-02/Rev.1
|
|
The Informal Working Group on Cyber Security and Software Updates will continue to consider how cyber security and software updates have a bearing on automotive safety and security, and whether any changes are necessary to the Regulations and guidance it has produced under WP.29. In particular, the IWG shall maintain official documents regarding UN R155, UN R156, and Recommendations on uniform provisions concerning cyber security and software updates; develop amendments to relevant documents; develop a proposal to amend UN Regulations under the responsibility of GRVA to record details of an RXSWIN where applicable which have been mandated by the 01 series of UN Regulation No. 156; develop proposals to amend UN Regulation No. 155 and its interpretation document to support application in national/regional frameworks for aspects such as multi-stage manufacturing; consider and develop deliverables regarding software updates after registration potentially creating a proposal for modification to the type approval numbering or a classification of update categories; support and review the application of cyber security and software update provisions across GRs notably for the Global Technical Regulation on Automated Driving Systems; and provide opportunities to participants to share knowledge, experience and ideas from implementation of national regulation/standards regarding CS/OTA as well as UN R155 and R156. The IWG will continue its activities until November 2029.
|
|
Meeting Sessions: 38th TFCS session (30 Jun-1
Jul)
|
|
Document date: 30 Jun 26
|
|
Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems
|
|
Click here to view the full document file
|
|
Cyber security: Vehicle modification use cases
|
|
Reference Number: TFCS-38-11
|
|
The document presents vehicle modification use cases categorized into four cases and additional scenarios. Case 1 covers components with negligible risk or cyber-relevant non-automotive devices. Case 2 addresses cyber-relevant automotive devices approved to specific regulatory requirements, requiring installation approval and vehicle type re-approval. Case 3a addresses cyber-relevant devices not approved to specific requirements, requiring component or STU approval. Case 3b covers devices controlling vehicle functions, also requiring component or STU approval. Case 4 encompasses invasive modifications or complex interactions not covered by other cases.
|
|
Submitted by:
UK
|
|
Meeting Sessions: 38th TFCS session (30 Jun-1
Jul)
|
|
Document date: 01 Jul 26
|
|
Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management
|
|
Click here to view the full document file
|
Documents 2026
20 Jan 2026
CS/OTA Task Force: Minutes of the 36th (October 2025) session
TFCS-36-06
12 Mar 2026
Proposal to amend UN R155 and UN R156
TFCS-37-02
16 Apr 2026
UN R155: Guidance for transformed vehicles
TFCS-37-05
20 Apr 2026
UN R155: Proposal on operator risks
TFCS-37-09
20 Apr 2026
UN R155: Presentation on proposal to address operator risks
TFCS-37-10
20 Apr 2026
UN R155: Presentation on STU approval concept
TFCS-37-08
20 Apr 2026
UN R155: Concept for STU approvals
TFCS-37-07
20 Apr 2026
Questions concerning cyber security amendments for approvals of STU
TFCS-37-06
21 Apr 2026
Proposals to amend UN R13, 13-H, 79, 89, 130, 131, 139, 140, 152, 155, 156, 157, 171, 175, and 178
TFCS-37-03/Rev.1
22 Apr 2026
UN R155: Proposal for amendments from the workshop discussions
TFCS-37-04/Rev.1
22 Apr 2026
CSMS and SUMS: Comments on TFCS-37-02
TFCS-37-11
22 Apr 2026
CS/OTA Task Force: Agenda for the 37th (April 2026) session
TFCS-37-01/Rev.2
21 May 2026
CS/OTA Task Force: Minutes of the 37th (April 2026) session
TFCS-37-12
23 Jun 2026
UN R155 and R156: Approvals for ‘out-of-scope’ vehicles
TFCS-38-03
23 Jun 2026
UN R155: Questions concerning separate technical units
TFCS-38-04
23 Jun 2026
UN R155: Response to questions concerning separate technical unit approvals
TFCS-38-05
26 Jun 2026
UN R156: Question on 01 series of amendments interpretation
TFCS-38-07
26 Jun 2026
UN R155: Review of points for approval of separate technical units
TFCS-38-06
29 Jun 2026
CS/OTA Task Force: Agenda for the 38th (June 2026) session
TFCS-38-01/Rev.3
29 Jun 2026
UN R155: Proposal to address approvals by one or more authorities
TFCS-38-08
29 Jun 2026
Component/STU type approval under UN R155
TFCS-38-09
29 Jun 2026
UN R155: Proposal to amend GRVA-25-32
TFCS-38-10
30 Jun 2026
Cyber security: Modifications to GRVA-25-30
TFCS-38-12
30 Jun 2026
CS/OTA: Draft updated terms of reference
TFCS-38-02/Rev.1
1 Jul 2026
Cyber security: Vehicle modification use cases
TFCS-38-11