| Request for guidance on vehicle compliance after the end of production |
| Reference Number: GRVA-25-48 |
|
The document requests guidance on the legal basis for provisions within UN Regulations extending beyond the End-of-Production date and which authority such provisions address. Examples include UN R171 requirements for manufacturers to demonstrate safety management systems to the Type Approval Authority every three years and report annually on Driven Coded Auxiliary System operation until production is discontinued, and UN R155 requirements for Cyber Security Management Systems to apply to the post-production phase when vehicles remain operational but are no longer produced. The document poses an additional question regarding vehicle safety when manufacturers cease operations and cannot fulfill post-deployment safety provisions. |
| Submitted by: Germany |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 21 May 26 |
| Relevant to: United Nations Agreement | 1958 Agreement, WP.29 Regulatory Project | Automated Driving Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS) |
| Click here to view the full document file |
| CS/OTA Task Force: Minutes of the 37th (April 2026) session |
| Reference Number: TFCS-37-12 |
|
The CS/OTA Task Force held its thirty-seventh session on 21-22 April 2026 by video conference. The group adopted the provisional agenda and minutes from the thirty-sixth session. Discussions addressed proposals for amendments to UN R155 concerning multi-stage vehicle approvals and separate technical units, for which a subworking group was established. Proposals were also considered on type approval authority responsibility for cyber security management systems and remote operation of automated driving systems. The group reviewed cyber and software requirements in the ADS GTR and WP.29/2022/60 as amended by WP.29/2023/87, and discussed application of RXSWIN to UN Regulations, selecting option 2 for presentation to GRVA with R155, R156, and R89 square bracketed. The IWG mandate renewal was discussed, with potential new items including component and STU approval and software numbering proposals. |
| Meeting Sessions: 37th TFCS session (21-22 Apr) |
| Document date: 21 May 26 |
| Relevant to: UN Regulation No. 89 | Speed Limitation Devices, WP.29 Regulatory Project | Automated Driving Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| Status of China's vehicle data security standard and proposals for GRVA consideration |
| Reference Number: GRVA-25-39 |
| Submitted by: NTCAS and CATARC |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 20 May 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, WP.29 Regulatory Project | Data Storage Systems for Automated Driving, and WP.29 Discussion Topic | Vehicle data access and protection |
| Click here to view the full document file |
| Cyber Security task force (aka CS/OTA) status report to GRVA |
| Reference Number: GRVA-25-35 |
|
The Informal Working Group on Cyber Security and Software Updates discussed amendments to UN R155 and UN R156 for multi-stage approval, including simplified handling for low-risk devices and clarification of intrinsic cyber risk assessment. The group reviewed proposals from GRVA-25-31 and GRVA-25-32 concerning continued validity of approvals and Certificate of Compliance issuance. A Sub-Working Group was established to develop component and separate technical unit approval concepts. Pending discussion include RXSWIN application to components, STUs, and the extent of application to UN R155 and UN R156, and type-approval numbering for software updates. |
| Submitted by: TFCS |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 20 May 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155: Proposal to amend the Interpretation Document |
| Reference Number: GRVA-25-32 |
|
Proposal to insert new Part C providing guidance on application of UN R155 to transformed vehicles. Part C defines when transformations require new approval, establishes terminology for original vehicle types, transformed vehicle types, transformations, and installations, identifies cyber-relevant transformations by evaluating impact on architecture and connection risks, addresses intrinsic cyber security risks, clarifies non-automotive equipment requirements, and specifies documentary evidence manufacturers must provide to approval authorities or technical services, including functional descriptions, connection details, software modifications, and component lists. |
| Submitted by: TFCS |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 18 May 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| UN R155: Proposal for amendments |
| Reference Number: GRVA-25-31 |
|
Proposal to amend para. 5.3.2. to require approval authorities to notify other approval authorities of methods and criteria used to assess measures taken in accordance with the Regulation, insert new para. 8.2. to exclude equipment with negligible intrinsic cyber security risk from further assessment where installation does not impinge on the cyber security management system and is connected exclusively via an approved interface, insert new para. 8.3. to exclude standard domestic, business or industrial equipment connected only for power from further assessment where the equipment is unmodified and complies with applicable regional and national cyber security requirements, and amend Annex 1 to include any equipment excluded from assessment pursuant to paras. 8.2. and 8.3. |
| Submitted by: TFCS |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 18 May 26 |
| Document status: Informal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Proposal for amendments to UN Regulations Nos. 13, 13-H, 79, 89, 130, 131, 152, 155, 156, 157, 171, 175, and 178 |
| Reference Number: GRVA-25-30 |
|
Proposal to insert provisions on software identification and software updates into UN R13, UN R13-H, UN R79, UN R89, UN R130, UN R131, UN R152, UN R155, UN R156, UN R157, UN R171, UN R175, and UN R178 by adding definitions referencing Consolidated Resolution R.E.3 Annex 7, requiring manufacturers to provide Technical Services with information on hardware and software influencing performance, permitting vehicle manufacturers to apply for new approvals differentiating software versions for registered versus new vehicles, clarifying that production discontinuation does not apply when manufacturers seek approval extensions for software updates of registered vehicles, and amending communication forms to include software identification numbers and related information. |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 18 May 26 |
| Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 13-H | Light-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, United Nations Agreement | RE3 Construction of Vehicles, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error |
| Click here to view the full document file |
| UN R155 and R156: Proposal for amendments |
| Reference Number: GRVA-25-07 |
|
Proposal to amend para. 5.1.3. of UN R155 to add a refusal ground where the Certificate of Compliance for the Cyber Security Management System has not been issued by the same approval authority granting type approval, and insert new para. 5.4. into UN R156 to provide that approval authorities shall not grant any type approval if the Certificate of Compliance for the Software Update Management System has not been issued by the same approval authority granting type approval. The proposal, based on TFCS-37-02, ensures that Certificates of Compliance and type-approvals for UN R155 and UN R156 are issued by the same approval authority to enable holistic assessment and clarify reporting obligations. |
| Submitted by: France, Germany, Luxembourg, Netherlands, and UK |
| Meeting Sessions: 25th GRVA session (18-22 May) |
| Document date: 04 May 26 |
| Document status: Informal GR review |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| CSMS and SUMS: Comments on TFCS-37-02 |
| Reference Number: TFCS-37-11 |
|
Germany proposes that the TAA granting UN R155 or UN R156 type approvals shall be obliged to only use CSMS or SUMS certificates signed by the same TAA. Issues identified include that CSMS and SUMS are Management Systems covering entire manufacturers’ organizations, mandating the same TAA will have huge consequences for OEMs using multiple TAAs, and no such obligation exists for ISO 9001 and ISO 14001. A possible way forward in the short term is to keep text unchanged to allow different TAAs for Management Systems CoC and type approval based on voluntary acceptance and implement wording on information exchange and procedure if different TAAs involved. |
| Submitted by: UK |
| Meeting Sessions: 37th TFCS session (21-22 Apr) |
| Document date: 22 Apr 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management and UN Regulation No. 156 | Software Update Processes and Management Systems |
| Click here to view the full document file |
| UN R155: Proposal for amendments from the workshop discussions |
| Reference Number: TFCS-37-04/Rev.1 |
|
Proposal to amend UN R155 by clarifying its scope to exclude certain equipment. The proposal amends paragraph 5.3.2. to require approval authorities to notify others of assessment methods and criteria. New paragraphs 8.2. and 8.3. establish that vehicle manufacturer installation of equipment with negligible intrinsic cyber security risk, or standard domestic, business or industrial equipment connected only for power, shall not require further assessment under paragraph 7, provided specified criteria are justified. Annex I is amended to include any equipment excluded from assessment pursuant to paragraphs 8.2. and 8.3. |
| Meeting Sessions: 37th TFCS session (21-22 Apr) |
| Document date: 22 Apr 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| CS/OTA Task Force: Agenda for the 37th (April 2026) session |
| Reference Number: TFCS-37-01/Rev.2 |
|
The UN IWG on Cyber Security and OTA will meet April 21-22, 2026 via video conference. The agenda includes adoption of the provisional agenda and minutes from the previous session, proposals for amendments to UN R155 and its interpretation document regarding multistage vehicles and type approval authorities, review of cyber and software requirements in the ADS Regulation, discussion of RXSWIN application, renewal of the IWG mandate expiring November 2026, and confirmation of next steps. |
| Meeting Sessions: 37th TFCS session (21-22 Apr) |
| Document date: 22 Apr 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, and United Nations Agreement | RE3 Construction of Vehicles |
| Click here to view the full document file |
| Proposals to amend UN R13, 13-H, 79, 89, 130, 131, 139, 140, 152, 155, 156, 157, 171, 175, and 178 |
| Reference Number: TFCS-37-03/Rev.1 |
|
Proposal to amend UN R13, 13-H, 79, 89, 130, 131, 139, 140, 152, 155, 156, 157, 171, 175, and 178 by introducing provisions on software identification and software updates. Amendments add new paragraphs referring to Software Identification Number definitions in Consolidated Resolution R.E.3, require manufacturers to provide Technical Services with information on hardware and software influencing performance, permit vehicle manufacturers to apply for new approvals differentiating software versions for registered versus new vehicles while avoiding test duplication, and modify production discontinuation provisions to exclude cases where manufacturers seek approval extensions for software updates of registered vehicles. |
| Submitted by: France |
| Meeting Sessions: 37th TFCS session (21-22 Apr) |
| Document date: 21 Apr 26 |
| Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 13-H | Light-Duty Vehicle Braking, UN Regulation No. 79 | Steering Equipment, UN Regulation No. 89 | Speed Limitation Devices, UN Regulation No. 131 | Advanced Emergency Braking Systems, UN Regulation No. 130 | Lane Departure Warning Systems, UN Regulation No. 140 | Electronic Stability Control Systems, UN Regulation No. 178 | Emergency Lane-Keeping Systems, UN Regulation No. 139 | Brake Assist Systems, UN Regulation No. 155 | Cyber Security and Cyber Security Management, UN Regulation No. 156 | Software Update Processes and Management Systems, UN Regulation No. 152 | Automatic Emergency Braking for M1/N1 vehicles, UN Regulation No. 157 | Automated Lane-Keeping Systems (ALKS), UN Regulation No. 171 | Driver-Control Assistance Systems (DCAS), and UN Regulation No. 175 | Acceleration Control for Pedal Error |
| Click here to view the full document file |
| EV/HFCV Retrofit Systems: Minutes of the 7th (March 2026) session |
| Reference Number: EV/HFCV-07-06 |
|
The Informal Working Group on EV/HFCV Retrofit Systems held its seventh meeting on 5th March 2026. The group adopted the provisional agenda, approved minutes of the previous meeting, and acknowledged ongoing activities under GRPE, GRSP and GRVA. Electrical safety review will continue once clarification regarding UN R100 is available. Cybersecurity discussions covered very old vehicles, older vehicles without cybersecurity provisions, and modern vehicles compliant with UN R155. Braking aspects and the structure of the draft UN Regulation were discussed, including vehicle versus system approval approaches and minimum and maximum vehicle age within the regulation’s scope. |
| Meeting Sessions: 7th EV/HFCV session (5 Mar) |
| Document date: 21 Apr 26 |
| Relevant to: UN Regulation No. 13 | Heavy-Duty Vehicle Braking, UN Regulation No. 13-H | Light-Duty Vehicle Braking, UN Regulation No. 100 | Construction and Safety of Electric Powertrains, UN Regulation No. 155 | Cyber Security and Cyber Security Management, and WP.29 Regulatory Project | Electric and Hydrogen Fuel-Cell Vehicle Retrofit Systems |
| Click here to view the full document file |
| UN R155: Presentation on proposal to address operator risks |
| Reference Number: TFCS-37-10 |
|
UN R155 addresses operator risks in automated driving systems. The ADS Regulation enables operators to offer services using automation and permits remote termination of the ADS. UN R155 mandates that supplier-related risks are managed, but operators are customers, not suppliers, creating downstream risks. An automated vehicle could be susceptible to unauthorised requests from an operator experiencing cyber attack. UN R155 does not define how downstream organisational risks are managed. Manufacturers should identify risks posed by operators and inform Third Party Operators of risks involved and expected minimum-security controls for workstations interfacing with an ADS. This could be achieved via Annex 5. |
| Submitted by: UK |
| Meeting Sessions: 37th TFCS session (21-22 Apr) |
| Document date: 20 Apr 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| UN R155: Proposal on operator risks |
| Reference Number: TFCS-37-09 |
|
Proposal to amend Table A1 of Annex 5 to include high level and sub-level descriptions of vulnerability and threat including spoofing of messages, Sybil attacks, communication channels permitting code injection, manipulation, overwrite and erasure of vehicle held data and code, denial of service attacks, unauthorized access to vehicle systems, viruses in communication media, and malicious messages, and amend Table B1 of Annex 5 to provide corresponding mitigation measures. This proposal is a further elaboration of TFCS-35-07. |
| Submitted by: UK |
| Meeting Sessions: 37th TFCS session (21-22 Apr) |
| Document date: 20 Apr 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| UN R155: Presentation on STU approval concept |
| Reference Number: TFCS-37-08 |
|
TFCS-37-08 presents proposals to amend UN R155 to establish approval routes for electrical/electronic sub-assemblies and separate technical units. The regulation introduces three parts: Part I covers vehicle cyber security approval; Part II covers component and separate technical unit approval; Part III covers installation approval of approved components and separate technical units in vehicles. Updates include new definitions, application procedures by manufacturers or their representatives, approval conditions specifying connection limitations, and cyber security management system requirements. The proposal requests colleague review and feedback. |
| Submitted by: UK |
| Meeting Sessions: 37th TFCS session (21-22 Apr) |
| Document date: 20 Apr 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| UN R155: Concept for STU approvals |
| Reference Number: TFCS-37-07 |
|
This document presents an initial concept for approvals of devices as components or separate technical units according to UN R155, and the installation of such devices on vehicles already holding UN R155 approval, based on Supplement 3 to the original series. The regulation applies to vehicles of categories L1–L7, M1–M3, N1–N3, and O1–O4 with electronic control units, and to approval of components and separate technical units with regard to their cyber security. Approval authorities shall grant type approval only to vehicle or electrical/electronic sub-assembly types that satisfy the regulation’s requirements through document checks and testing. Manufacturers must demonstrate cyber security management systems covering development, production, and post-production phases, including risk assessment, mitigation implementation, monitoring, and response to cyber-attacks. Certificates of Compliance for Cyber Security Management Systems remain valid for three years. |
| Submitted by: UK |
| Meeting Sessions: 37th TFCS session (21-22 Apr) |
| Document date: 20 Apr 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Questions concerning cyber security amendments for approvals of STU |
| Reference Number: TFCS-37-06 |
|
Questions concerning cyber security amendments for approvals of STU submitted by the expert from Japan that address timing of working document submission to GRVA, whether Part II components may include certificated base vehicle equipment under UN R155 multi-stage categorization, whether STU definition includes ECUs within base vehicle E/E architecture, examination of use cases and implementation challenges, consistency of applicant terminology between Section 3.3.1 and Section 7.6, whether approval authorities for Parts I, II, and III must be identical, clarification of end of support period requirements in para. 2.7(b), installation agreement requirements in para. 5.1.2.1(d), and whether total Cyber Security Risk Assessment Process for whole vehicle with other equipment than ESAs is necessary after ESA installation under para. 7.4.10. |
| Submitted by: Japan |
| Meeting Sessions: 37th TFCS session (21-22 Apr) |
| Document date: 20 Apr 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| UN R155: Guidance for transformed vehicles |
| Reference Number: TFCS-37-05 |
|
Proposal to provide guidance on application of UN R155 to transformed vehicles. Transformations require new approval unless clear evidence shows original approval remains valid. Cyber-relevant modifications include addition of electrical/electronic systems, inappropriate interface connections, and wiring protection modifications. The approval authority determines whether transformation is cyber-relevant by assessing impact on original vehicle architecture, connection risks, cybersecurity management systems, and whether non-automotive equipment complies with relevant regulations. Manufacturers must provide documentary evidence including functional descriptions, connection details, software modifications, and compliance with original manufacturer instructions. |
| Meeting Sessions: 37th TFCS session (21-22 Apr) |
| Document date: 16 Apr 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
| Draft guidance for the application of UN R155 to transformed vehicles |
| Reference Number: GRVA-WS-CS-02-09 |
|
Includes changes made during the Workshop. |
| Meeting Sessions: 2nd GRVA-WS-CS session (16-18 Mar) |
| Document date: 17 Mar 26 |
| Relevant to: UN Regulation No. 155 | Cyber Security and Cyber Security Management |
| Click here to view the full document file |
No matching documents.