reg 156 pdf

reg 156 pdf

Regulation 156 establishes uniform guidelines for vehicle software updates, ensuring safety and interoperability across member states. It outlines approval processes, technical standards, and documentation requirements, facilitating transparent communication among stakeholders worldwide for global regulatory compliance efforts.

Purpose of Regulation 156

UN Regulation No. 156 establishes uniform provisions for the approval of vehicles concerning software updates and software update management systems. Its primary purpose is to create a standardized framework ensuring that manufacturers implement robust processes for deploying software modifications throughout a vehicle’s lifecycle. By defining clear requirements for system architecture, security measures, and performance metrics, the regulation mitigates risks associated with cyber threats and functional safety failures. It mandates a structured approval process where authorities evaluate the manufacturer’s update management system before granting type approval. Furthermore, the regulation facilitates international harmonization under the 1958 Agreement, requiring Contracting Parties to recognize approvals granted by other parties. Communication of approval, extension, or refusal occurs via a standardized form conforming to the model in Annex 2, ensuring transparency across borders. Ultimately, this regulatory instrument aims to protect consumers and maintain traffic safety by guaranteeing that software modifications do not degrade vehicle performance or compliance with existing type approval standards, while enabling manufacturers to efficiently manage updates globally. This ensures continuous vehicle integrity and regulatory adherence across diverse operational environments worldwide effectively.

Historical Background

UN Regulation No. 156 was formally established through the 1958 Agreement framework, with its legislative text published as document 2021/388 on EUR-Lex on March 9, 2021. This regulation emerged from increasing industry reliance on over-the-air updates and the necessity for cybersecurity governance. The regulation entered into force for Contracting Parties that did not declare disagreement under Article 1(4) of the Agreement. Subsequent amendments were adopted under Article 12(2), becoming binding on all applying Parties, reflecting evolving technological landscapes. Notably, industry stakeholders like Haldex identified compliance deadlines, targeting July 2024 for full adherence utilizing software changes. The regulatory development involved the Working Party on Automated/Autonomous and Connected Vehicles (GRVA), ensuring technical feasibility. The approval marking system, exemplified by the Netherlands (E 4) issuing approval number 001234, demonstrates practical implementation. This historical trajectory highlights the shift from static vehicle approval to dynamic software lifecycle management, addressing gaps left by previous static type approval regulations. The framework represents a significant milestone in international vehicle standardization efforts, bridging legacy automotive engineering with modern digital connectivity requirements for global markets effectively today.

Scope and Applicability

Regulation 156 covers all road vehicles requiring software updates, including passenger cars, commercial trucks, and heavy machinery. It applies to all Contracting Parties, ensuring uniform approval processes across national borders, thereby promoting safety and interoperability globally.

Vehicle Types Covered

Regulation No. 156 explicitly defines the range of vehicle categories that must comply with its uniform provisions concerning software updates and update management systems. The primary focus lies on road vehicles that are subject to type‑approval procedures within the framework of the 1958 Agreement. Passenger cars, representing the largest segment of the market, are included because their increasingly complex electronic architectures rely heavily on over‑the‑air and on‑board software modifications throughout their service life. Commercial trucks, encompassing light‑duty vans, medium‑weight distribution vehicles and heavy‑duty haulage units, are also covered, reflecting the critical role of software in engine control, telematics, and safety‑assist functions. Additionally, the regulation extends to heavy machinery such as construction equipment, agricultural tractors, and other specialized vehicles that operate on public roads and incorporate advanced electronic control units. By encompassing these categories, the regulation ensures that any vehicle type capable of receiving software updates—whether for emissions, safety, infotainment, or autonomous‑driving features—adheres to consistent security, performance, and documentation standards across all Contracting Parties. Manufacturers must embed approved update protocols early, ensuring continuous compliance from initial release through end‑of‑life service globally.

Geographic Reach

Regulation No. 156 applies to all Contracting Parties of the 1958 Agreement that have not formally declared disagreement within the prescribed timeline, making its provisions binding across a broad international framework. The regulation enters into force automatically for these parties, ensuring harmonized software update standards throughout Europe and beyond. Notable participants include the European Union, where the regulation is transposed via legal instruments such as EU 2021/388 accessible on EUR-Lex, and individual UNECE member states like Japan, South Korea, South Africa, and Australia. The approval mark referenced in official notices, such as the Netherlands’ “E 4” designation with approval number 001234, demonstrates mutual recognition of type approvals issued under this regulation. Consequently, a vehicle type approved in one Contracting Party is accepted in all others applying the regulation, facilitating seamless market access. Manufacturers must monitor the status of each country’s application, as new accessions or withdrawals alter the geographic scope dynamically, requiring continuous compliance verification for global vehicle distribution strategies worldwide.

Key Definitions

Regulation 156 defines critical terms including software update, update management system, and type approval, establishing precise meanings essential for uniform interpretation, compliance verification, and consistent application across all Contracting Parties globally.

Software Update

Under UN Regulation No. 156, a software update represents any modification to vehicle software logic, calibration data, or configuration parameters affecting vehicle behavior, emissions, safety systems, or cybersecurity posture. The regulation mandates that manufacturers implement robust Update Management Systems (UMS) capable of delivering, verifying, and logging these modifications securely throughout the vehicle lifecycle; Each update must undergo rigorous risk assessment to ensure functional safety integrity and regulatory compliance before deployment. The definition encompasses over-the-air (OTA) transmissions, wired workshop installations, and offline media-based upgrades, provided they alter approved vehicle type characteristics. Manufacturers must maintain comprehensive records documenting version history, change rationale, validation test results, and deployment status for audit purposes. Furthermore, the regulation requires transparent communication to authorities regarding update classification, distinguishing between safety-critical patches, functional enhancements, and cybersecurity remediation actions. This structured approach ensures traceability, prevents unauthorized modifications, and guarantees that updated vehicles remain conformant to their original type approval certification across all Contracting Parties applying the 1958 Agreement framework. Effective date compliance begins July 2024 for new types, requiring manufacturers to demonstrate update governance capabilities immediately globally and consistently.

Update Management System

The Update Management System (UMS) constitutes the manufacturer’s organizational and technical framework governing the planning, development, validation, deployment, and post-deployment monitoring of vehicle software modifications. Regulation 156 requires the UMS to ensure integrity, authenticity, and confidentiality throughout the update lifecycle, employing cryptographic verification and secure communication channels. Manufacturers must demonstrate that the UMS prevents unauthorized access, rolls back failed installations safely, and maintains an immutable audit trail of all software versions deployed per Vehicle Identification Number. The system architecture must support differential updates, dependency checks, and compatibility validation against specific vehicle configurations. Crucially, the UMS itself is subject to type approval; authorities assess the manufacturer’s processes, server infrastructure, and cybersecurity management system (CSMS) alignment per UN R155. Approval evidence includes documented procedures for vulnerability response, stakeholder notification, and regulatory reporting via Annex 2 forms. Continuous compliance demands periodic audits, incident response drills, and transparent disclosure of update campaigns to approval authorities across all Contracting Parties applying the 1958 Agreement, ensuring persistent vehicle conformity and consumer safety globally. Effective July 2024, new types require certified UMS demonstration for market access worldwide.

Type Approval

Type Approval under Regulation 156 is a formal process that confirms a vehicle type meets all specified software update and management system requirements before entering the market. The procedure begins with the submission of a comprehensive application package, including design documentation, functional safety assessments, and evidence that the Update Management System complies with cryptographic and cybersecurity standards. Authorities evaluate the application against criteria such as system architecture, security measures, and performance metrics, ensuring that each software component can be reliably updated without compromising vehicle safety. Once the evaluation is complete, a decision is communicated through a standardized form outlined in Annex 2, indicating approval, conditional approval, or refusal. Approved vehicle types receive a unique approval number, which is affixed to the vehicle to signal compliance with national and international regulations. The approval remains valid until a significant change in the software architecture or a regulatory amendment occurs, at which point a re‑evaluation is mandatory. This rigorous process guarantees that all vehicles on the road possess robust, secure, and updatable software platforms, thereby protecting drivers, passengers, emerging cyber threats, ensuring vehicle reliability.

Approval Process

Manufacturers submit applications detailing software update systems. Authorities assess compliance with security and functional safety standards. Upon successful evaluation, approval is granted and communicated via standardized Annex 2 documentation for contracting parties ensuring global regulatory harmonization.

Application Procedure

The application procedure for UN Regulation No. 156 begins with the preparation of a technical dossier. Manufacturers must describe the vehicle type, the software update architecture, and the associated update management system in detail. The dossier includes system schematics, security protocols, safety analyses, and evidence of compliance with the performance metrics defined in the regulation. Next, the applicant completes the standardized form set out in Annex 2, which serves as the official notice of request to the competent authority of the Contracting Party. This form must contain the vehicle identification, the proposed approval number, and a summary of the software‑related features. Once the package is assembled, it is submitted electronically or by post to the national type‑approval authority, accompanied by any required fees. The authority acknowledges receipt and assigns a reference number, after which a review checks completeness. If any information is missing, the applicant receives a clarification request. Upon successful completion of the completeness check, the dossier proceeds to the substantive evaluation phase, where experts verify that the software update system meets the security, safety, and interoperability requirements established by Regulation 156.

Evaluation Criteria

The evaluation of a vehicle type under Regulation 156 follows a structured set of criteria designed to verify that software update functions and the associated management system meet the uniform provisions established by the United Nations. First, the authority checks that the applicant has submitted a complete Annex 2 model form together with a detailed technical dossier, confirming that all mandatory documents are present. Second, the system architecture is examined to ensure it supports secure, authenticated over‑the‑air updates and that fallback mechanisms exist in case of communication failure. Third, security measures are assessed, including encryption standards, access control, and intrusion‑detection capabilities, to guarantee that unauthorized code cannot be introduced. Fourth, performance metrics such as update latency, bandwidth consumption, and verification time are measured against the thresholds defined in the regulation. Fifth, functional safety analyses must demonstrate that software changes cannot compromise vehicle‑level safety functions. Sixth, interoperability tests verify that the update protocol conforms to the common communication interfaces accepted by all Contracting Parties. Finally, the overall compliance report is reviewed, and any non‑conformities must be resolved before a type‑approval certificate is issued.

Decision Timeline

Upon receipt of a complete application, the competent authority initiates a structured timetable to ensure transparency and predictability. The first phase, lasting up to 30 calendar days, involves preliminary checks for completeness and conformity with the Annex 2 model form. If the dossier passes this stage, the authority proceeds to a detailed technical assessment, which typically requires an additional 60 days. During this period, experts evaluate system architecture, security protocols, and performance metrics against the regulatory thresholds. Should any deficiencies arise, the applicant is granted a 15‑day window to submit corrective evidence. Once all technical aspects are verified, the final decision phase commences, allowing the authority to issue approval, refusal, or a conditional approval within 15 days. In total, the maximum duration from initial submission to final decision is 120 calendar days, barring extraordinary circumstances such as additional safety investigations or appeals. This schedule aligns with Article 12(2) of the Agreement, ensuring that all Contracting Parties receive timely and consistent outcomes for vehicle type approvals under Regulation 156. Stakeholders are encouraged to portal for updates engage the authority period expedite resolution and ensure compliance for all.

Technical Requirements

Technical requirements mandate robust software update management systems ensuring cybersecurity integrity verification processes and functional safety compliance throughout vehicle lifecycle for approved types globally manufacturers must implement secure over-the-air capabilities meeting regulatory specifications immediately and effectively today

System Architecture

The system architecture defined by UN Regulation No. 156 is built around a modular, layered framework that separates the vehicle’s core control functions from the update management subsystem. At the lowest level, a secure trust anchor stores cryptographic keys and validates the authenticity of every incoming software package. Above this, a communication layer provides encrypted, over‑the‑air (OTA) delivery, supporting cellular, Wi‑Fi, and communications while guaranteeing resilience against interception. The middle tier hosts the update management engine, which orchestrates version control, dependency checking, and rollback procedures; it must log each transaction in a record accessible to regulators. The top tier presents an application programming interface (API) that allows OEMs to integrate vehicle‑specific functions, such as diagnostic data collection and user‑initiated update scheduling, without exposing internal code. All layers are required to comply with the security measures and performance metrics outlined in the regulation, including mandatory integrity checks, latency limits for critical safety updates, and monitoring for anomalies. By enforcing this architecture, the regulation ensures that software updates can be deployed safely, reliably, and uniformly across all approved vehicle types throughout their life.

Security Measures

The security framework mandated by UN Regulation No. 156 requires a multi‑layered approach to protect vehicle software throughout its lifecycle. First, a hardware‑based trust anchor must store immutable cryptographic keys, enabling secure boot and verification of every firmware image before execution. All update packages are signed with manufacturer‑issued certificates and must be validated against these keys using asymmetric algorithms such as ECDSA‑256. Communication channels for over‑the‑air delivery are encrypted with TLS 1.3 or equivalent, ensuring confidentiality and integrity against man‑in‑the‑middle attacks. The update management system must maintain a tamper‑evident audit log that records timestamps, source identifiers, version numbers, and verification results, and this log must be accessible to authorised regulators during inspections. In addition, the system shall implement anomaly detection, monitoring for unexpected code changes, abnormal data flows, or repeated failed authentications, and must trigger an immediate rollback to the last known good state. Mandatory penetration testing and vulnerability assessments are required before type approval, with findings documented and mitigated. Finally, any critical safety update must be delivered within defined latency limits, and the architecture must support key rotation without disrupting operation.

Performance Metrics

UN Regulation No. 156 defines specific performance indicators to evaluate the effectiveness of Software Update Management Systems (SUMS). Primary metrics include the update success rate, which must exceed ninety-nine percent across the vehicle fleet under nominal network conditions. The regulation mandates measurement of end-to-end latency from package release to installation completion, ensuring critical safety patches deploy within a defined maximum window, typically seventy-two hours for high-risk vulnerabilities. Rollback execution time is strictly monitored; the system must revert to the previous stable version within a short, deterministic period, often less than five minutes, to maintain vehicle operability. Availability metrics track the percentage of time the update service remains reachable, requiring ninety-nine point nine percent uptime annually. Bandwidth efficiency is assessed by measuring data overhead relative to payload size, minimizing cellular data consumption. Furthermore, the regulation requires logging of failed attempts, categorizing root causes such as authentication failure, checksum mismatch, or insufficient storage. These quantitative benchmarks are verified during type approval testing and monitored continuously via the manufacturer’s backend infrastructure to ensure ongoing compliance throughout the vehicle lifecycle and operational safety assurance.

Documentation and Reporting

Documentation and reporting require detailed submission of technical specifications, test results, and compliance certificates. Annex 2 model forms must be completed accurately. Regular updates ensure transparency, facilitating regulatory oversight and continuous vehicle safety assurance for all.

Required Documents

Regulation 156 mandates a comprehensive set of documents to support vehicle type approval concerning software updates. The core package includes a formal application form, a detailed technical dossier outlining software architecture, and a risk assessment report. The technical dossier must contain source code listings, version control logs, and evidence of secure coding practices. Additionally, a functional validation report demonstrating compliance with performance metrics and safety tests is required. A cybersecurity assessment, detailing threat modeling and mitigation strategies, must accompany the submission. The manufacturer must provide a maintenance plan that specifies update schedules, rollback procedures, and monitoring mechanisms. Documentation of the update management system’s interface with vehicle control units, including data flow diagrams and communication protocols, is also essential. Finally, a certification statement from an accredited testing laboratory confirming that the software meets all specified safety and performance criteria must be included. All documents should be submitted in the language specified by the contracting party and must reference the relevant annexes of Regulation 156. Failure to provide any of these documents may result in delayed approval or refusal, thereby impacting entry timelines.

Annex 2 Model Form

Annex 2 provides the standardized template for communicating approval decisions under Regulation 156. This model form ensures uniform notification to all Contracting Parties of the 1958 Agreement regarding the approval, extension, or refusal of a vehicle type concerning software update management systems. The form captures essential identification data, including the issuing country code such as E 4 for the Netherlands, the unique approval number like 001234, and the specific regulation version. It details the vehicle type designation, manufacturer information, and the software update management system specifications covered by the certificate. Sections within the form record the technical service responsible for evaluation and the date of the approval decision. Clear checkboxes indicate whether the notification represents an initial approval, an extension for additional variants, or a refusal with stated reasons. The layout facilitates rapid data exchange between authorities, supporting the mutual recognition principle central to the 1958 Agreement. Proper completion of this form is mandatory for the approval mark to be affixed to the vehicle, confirming compliance with all stipulated cybersecurity and functional safety requirements for software updates throughout the vehicle lifecycle effectively.

Accessing the Regulation PDF

The official PDF of Regulation 156 is available through the European Union’s EUR‑Lex portal. Users can search by regulation number, download the document, and access supplementary annexes and explanatory notes in multiple languages for all readers.

Official Sources

Regulation 156 is published on the European Union’s EUR‑Lex portal, where the full text and annexes appear in PDF format. By searching “UN Regulation No. 156” or the reference “2021/388,” users find the official document titled “Uniform provisions concerning the approval of vehicles with regards to software update and software updates management system.” The PDF contains the main body, definitions, and Annex 2, which supplies the model form for approval notifications. The European Commission’s vehicle regulations website also hosts downloadable copies, ensuring stakeholders receive the latest amendments. For additional context, the Commission’s “Standard Collection Addenda to the 1958 Agreement (Regulations 141‑160)” offers related regulatory frameworks. Users can consult the EU’s “Regulation 156 – Software update and software update management system” page, which links explanatory notes and contact points for inquiries. All sources are freely available, supporting transparency and accessibility for manufacturers, regulators, and the public. The regulation also provides guidance on data protection requirements, cybersecurity measures, testing protocols, ensuring that software updates meet stringent safety standards and comply with international harmonization efforts. Stakeholders are encouraged to consult the official FAQ section for clarification.

Leave a Reply