|
20 Sep 2023
|
UN R155: Proposal for a new Supplement (France and UK)
|
GRVA-17-13
|
2023-09-20 |
Inclusion of vehicles of Categories L, R, S and T into the scope if fitted with at least one electronic control unit. France UK |
|
28 Sep 2023
|
UN R155: Proposal for a Supplement (France, IMMA, Italy, and UK)
|
GRVA-17-43
|
2023-09-28 |
Proposal to expand the scope of the Regulation to include all Category L and O vehicles if fitted with an electronic control unit. France IMMA Italy UK |
|
4 May
|
UN R155 and R156: Proposal for amendments (UK, Netherlands, Luxembourg, Germany, and France)
|
GRVA-25-07
|
2026-05-04 |
Proposal to amend UN R155 and UN R156 regarding approval authority requirements:<ul><li>Add a refusal ground to para. 5.1.3. of UN R155 where the Certificate of Compliance for the Cyber Security Management System has not been issued by the same approval authority granting type approval</li><li>Insert new para. 5.4. into UN R156 to provide that approval authorities shall not grant any type approval if the Certificate of Compliance for the Software Update Management System has not been issued by the same approval authority granting type approval.</li></ul> UK Netherlands Luxembourg Germany France |
|
11 Mar
|
UN R155: Proposal on cyber security of separate technical units (UK)
|
GRVA-WS-CS-02-02
|
2026-03-11 |
UK |
|
16 Mar
|
Cyber Security: Multi-stage vehicles proposal for the Interpretation Document (UK)
|
GRVA-WS-CS-02-04/Rev.1
|
2026-03-16 |
UK |
|
13 Mar
|
UN R155: Proposal for amendments (UK)
|
GRVA-WS-CS-02-06
|
2026-03-13 |
UK |
|
1 Nov 2023
|
UN R155: Proposal for a Supplement (France, UK, Italy, and IMMA)
|
GRVA/2024/4
|
2023-11-01 |
Proposal to extend the scope of UN R155 to include all vehicles of Category L. France UK Italy IMMA |
|
1 Nov 2023
|
UN R155: Proposal to amend the UN R155 Interpretation Document (UK, Italy, IMMA, and France)
|
GRVA/2024/5
|
2023-11-01 |
Proposal to align the UN R155 Interpretation Document with the proposal to extend the scope of UN R155 to Category L vehicles. UK Italy IMMA France |
|
6 Jul
|
Proposal to amend UN R155 and UN R156 (France, Germany, Luxembourg, Netherlands, and UK)
|
GRVA/2026/30
|
2026-07-06 |
Proposal to amend UN R155 by inserting new para. 5.1.3.(e) establishing that the Certificate of Compliance for the Cyber Security Management System shall not be issued by a different Approval Authority than the one granting type approval, and amend UN R156 by inserting new para. 5.4. establishing that Approval Authorities shall not grant type approval if the Certificate of Compliance for the Software Update Management System has not been issued by the same Approval Authority granting type approval. Justification includes ensuring holistic cybersecurity assessment, clarifying reporting obligations under para. 7.2.2.2.(g), addressing unharmonized mutual recognition of management system certificates, maintaining consistency between regulations, and upholding the fundamental principle that approval authorities retain responsibility for all aspects of type approval. France Germany Luxembourg Netherlands UK |
|
12 Nov 2016
|
UK views on cybersecurity and data protection (UK)
|
ITS/AD-10-05
|
2016-11-12 |
UK |
|
20 Sep 2016
|
UK comments on the draft cybersecurity and data protection guidelines (UK)
|
ITS/AD-AH-01-06
|
2016-09-20 |
UK |
|
2 May 2018
|
Draft terms of reference for the Automated Vehicles task force (UK)
|
TFAV-01-06
|
2018-05-02 |
UK |
|
23 Oct 2018
|
TFAV SG1: UK proposal for amended terms of reference (UK)
|
TFAV-SG1-03-09
|
2018-10-23 |
Revised terms of reference submitted by the UK for the subgroup on physical certification and auditing of automated vehicles and driving systems. UK |
|
15 Feb 2017
|
Draft list of terms and definitions related to cybersecurity and data protection (UK)
|
TFCS-03-05/Rev.1
|
2017-02-15 |
UK |
|
4 May 2017
|
UK reasoning behind its additions to the cybersecurity threats matrix (UK)
|
TFCS-05-10
|
2017-05-04 |
UK |
|
11 May 2017
|
Summary of UNECE cybersecurity mitigations (UK)
|
TFCS-05-14
|
2017-05-11 |
This is an extraction and abridged summary of recommendations from papers on vehicle cybersecurity. UK |
|
11 May 2017
|
Table of cybersecurity threats and principles (UK)
|
TFCS-05-16
|
2017-05-11 |
UK |
|
8 Jun 2017
|
Table of cybersecurity threats with principles for cybersecurity (UK)
|
TFCS-06-05/Rev.1
|
2017-06-08 |
UK |
|
11 Jun 2018
|
Cybersecurity: UK revised Recommendations paper Annex C (UK)
|
TFCS-ahRCSP2-04
|
2018-06-11 |
UK |
|
6 Aug 2019
|
Proposal for answer to GRVA Cybersecurity/Software Updates tasks and questions (UK)
|
TFCS-15-22
|
2019-08-06 |
Reissued on 16 August for filing reasons. UK |
|
7 Nov 2019
|
Cybersecurity draft regulation: UK amendment (UK)
|
TFCS-16-15
|
2019-11-07 |
UK |
|
7 Nov 2019
|
Template for cybersecurity regulation Declaration of Compliance (OICA and UK)
|
TFCS-16-26
|
2019-11-07 |
Draft "Manufacturer’s declaration of compliance with the requirements for the Cyber Security Management System" OICA UK |
|
24 Jul 2020
|
Cybersecurity: Proposal to amend the draft Interpretation Document (UK)
|
TFCS-ahID3-03
|
2020-07-24 |
UK |
|
18 Nov 2024
|
CS/OTA task force: Proposal to update the terms of reference (UK)
|
TFCS-33-06/Rev.1
|
2024-11-18 |
UK |
|
1 Sep 2025
|
UN R155: Separate technical units, component approvals, and multistage vehicles (UK)
|
TFCS-35-06
|
2025-09-01 |
UK |
|
1 Sep 2025
|
UN R155: Proposal for a Supplement (software development and fleet operation) (UK)
|
TFCS-35-07
|
2025-09-01 |
Proposal to address two gaps identified in the requirements of UNR 155 regarding:<ol class="alpha"><li>Software development and</li><li>Vehicle with an ADS Feature of Type 2 where vehicle operation is overseen by an organisation responsible for operating the vehicle or fleet of vehicles.</li></ol>
UK |
|
20 Apr
|
UN R155: Concept for STU approvals (UK)
|
TFCS-37-07
|
2026-04-20 |
This document presents an initial concept for approvals of devices as components or separate technical units according to UN R155, and the installation of such devices on vehicles already holding UN R155 approval, based on Supplement 3 to the original series. The regulation applies to vehicles of categories L<sub>1</sub>–L<sub>7</sub>, M<sub>1</sub>–M<sub>3</sub>, N<sub>1</sub>–N<sub>3</sub>, and O<sub>1</sub>–O<sub>4</sub> with electronic control units, and to approval of components and separate technical units with regard to their cyber security. Approval authorities shall grant type approval only to vehicle or electrical/electronic sub-assembly types that satisfy the regulation's requirements through document checks and testing. Manufacturers must demonstrate cyber security management systems covering development, production, and post-production phases, including risk assessment, mitigation implementation, monitoring, and response to cyber-attacks. Certificates of Compliance for Cyber Security Management Systems remain valid for three years. UK |
|
20 Apr
|
UN R155: Presentation on STU approval concept (UK)
|
TFCS-37-08
|
2026-04-20 |
TFCS-37-08 presents proposals to amend UN R155 to establish approval routes for electrical/electronic sub-assemblies and separate technical units. The regulation introduces three parts: Part I covers vehicle cyber security approval; Part II covers component and separate technical unit approval; Part III covers installation approval of approved components and separate technical units in vehicles. Updates include new definitions, application procedures by manufacturers or their representatives, approval conditions specifying connection limitations, and cyber security management system requirements. The proposal requests colleague review and feedback. UK |
|
20 Apr
|
UN R155: Proposal on operator risks (UK)
|
TFCS-37-09
|
2026-04-20 |
Proposal to amend Table A1 of Annex 5 to include high level and sub-level descriptions of vulnerability and threat including spoofing of messages, Sybil attacks, communication channels permitting code injection, manipulation, overwrite and erasure of vehicle held data and code, denial of service attacks, unauthorized access to vehicle systems, viruses in communication media, and malicious messages, and amend Table B1 of Annex 5 to provide corresponding mitigation measures. This proposal is a further elaboration of TFCS-35-07. UK |
|
20 Apr
|
UN R155: Presentation on proposal to address operator risks (UK)
|
TFCS-37-10
|
2026-04-20 |
UN R155 addresses operator risks in automated driving systems. The ADS Regulation enables operators to offer services using automation and permits remote termination of the ADS. UN R155 mandates that supplier-related risks are managed, but operators are customers, not suppliers, creating downstream risks. An automated vehicle could be susceptible to unauthorised requests from an operator experiencing cyber attack. UN R155 does not define how downstream organisational risks are managed. Manufacturers should identify risks posed by operators and inform Third Party Operators of risks involved and expected minimum-security controls for workstations interfacing with an ADS. This could be achieved via Annex 5. UK |
|
22 Apr
|
CSMS and SUMS: Comments on TFCS-37-02 (UK)
|
TFCS-37-11
|
2026-04-22 |
Germany proposes that the TAA granting UN R155 or UN R156 type approvals shall be obliged to only use CSMS or SUMS certificates signed by the same TAA. Issues identified include that CSMS and SUMS are Management Systems covering entire manufacturers' organizations, mandating the same TAA will have huge consequences for OEMs using multiple TAAs, and no such obligation exists for ISO 9001 and ISO 14001. A possible way forward in the short term is to keep text unchanged to allow different TAAs for Management Systems CoC and type approval based on voluntary acceptance and implement wording on information exchange and procedure if different TAAs involved. UK |
|
23 Jun
|
UN R155: Questions concerning separate technical units (UK)
|
TFCS-38-04
|
2026-06-23 |
Questions address whether minimum vehicle architecture approval should be required before Part III can be used for additional devices; whether approved ESAs can be incorporated in original vehicle approval or as an extension to Part I approval; whether different terminology should replace CSMS for Part III approvals; whether second Part III approvals are permissible for vehicles already approved to Parts I and III; and what implications arise from end-of-support by ESA manufacturers. UK |
|
23 Jun
|
UN R155: Response to questions concerning separate technical unit approvals (UK)
|
TFCS-38-05
|
2026-06-23 |
Answers to questions on separate technical unit approvals under UN R155 clarify that a base vehicle must already hold an R155 type approval before an ESA can be added at Part III; approval authorities for different parts may differ with mutual recognition applying; the end of support period for an ESA manufacturer must be communicated to the vehicle manufacturer, with implications to be discussed by the IWG; installation of ESAs must follow vehicle manufacturer instructions without necessarily requiring separate agreement; STU data sharing agreements are required; and after ESA installation, a whole vehicle cyber security risk assessment is not necessary, though Part III must consider risks where ESA and base vehicle interactions occur. A working document is planned for submission to GRVA in January 2027. The IWG will explore whether Part II components may include equipment from certificated base vehicles under UN R155 multi-stage categorization and discuss incorporating STU into original approvals. UK |
|
29 Jun
|
UN R155: Proposal to amend GRVA-25-32 (UK)
|
TFCS-38-10
|
2026-06-29 |
Amend para. AI to replace the heading "Examples of documents/evidence that could be provided" with "Explanation of the requirement" and insert text stating that Part C of this document provides further guidance on the application of the Regulation to vehicles which have been modified by carrying out a transformation of the vehicle. UK |
|
1 Jul
|
Cyber security: Vehicle modification use cases (UK)
|
TFCS-38-11
|
2026-07-01 |
The document presents vehicle modification use cases categorized into four cases and additional scenarios. Case 1 covers components with negligible risk or cyber-relevant non-automotive devices. Case 2 addresses cyber-relevant automotive devices approved to specific regulatory requirements, requiring installation approval and vehicle type re-approval. Case 3a addresses cyber-relevant devices not approved to specific requirements, requiring component or STU approval. Case 3b covers devices controlling vehicle functions, also requiring component or STU approval. Case 4 encompasses invasive modifications or complex interactions not covered by other cases. UK |
|
3 Jun 2019
|
UK comments on cybersecurity interpretation document (UK)
|
TFCS-TPahCS2-05
|
2019-06-03 |
UK |
|
11 Jun 2019
|
Cybersecurity regulation interpretation document-combined comments (UK)
|
TFCS-TPahCS2-07
|
2019-06-11 |
UK |
|
8 Mar 2017
|
Japan and UK input for the table of cybersecurity threats (Japan and UK)
|
TFCS-ahT-01-03
|
2017-03-08 |
Japan UK |
|
14 Dec 2021
|
ADS: Proposal to address cyber security under in-service monitoring/reporting (UK)
|
VMAD-SG3-16-07
|
2021-12-14 |
Proposal to confirm that the aspects of the CSMS related to the cyber security monitoring activities, as defined in paragraph 7.2.2.2.(g), continue to be applied properly after Development Phase and that the relevant cyber security mitigations implemented continue to be effective.
UK |
|
20 Apr 2020
|
Cybersecurity: Proposal to amend document WP.29/2020/79 (France, UK, Spain, Russia, Japan, Italy, Germany, and EC)
|
WP.29/2020/97
|
2020-04-20 |
Proposal agreed by interested Contracting Parties to resolve concerns regarding "peer review" of cybersecurity type approvals. France UK Spain Russia Japan Italy Germany EC |