UNECE Regulation R156:
The New Era of Secure Software Updates in the Automotive Industry

The automotive sector is undergoing a radical transformation: the vehicle is no longer just a mechanical machine, but a software platform on wheels. With the increase in connected features, ADAS (Advanced Driver Assistance Systems), and Over-The-Air (OTA) updates, software security has become critical. To address this challenge, the United Nations Economic Commission for Europe (UNECE) introduced two companion regulations: R155 (Cybersecurity) and R156.

The UNECE Regulation R156 represents the essential regulatory framework for managing vehicle software updates in a safe, traceable, and compliant manner.

What is UNECE R156?

R156, officially titled “Uniform provisions concerning the approval of vehicles with regard to software update and software updates management system,” governs the entire lifecycle of a vehicle’s software, from its creation until the final update at the customer level.

The central element of R156 is the obligation for Manufacturers (OEMs) to implement and obtain certification for a Software Update Management System (SUMS).

The Crucial Role of the SUMS (Software Update Management System)

The SUMS is not just a technical system; it is a set of organizational and management processes that must ensure:

  • Security and Integrity: Software updates (both via OTA and in workshops) must be protected from tampering. The SUMS must guarantee the authenticity and integrity of the software (that it has not been altered), through encryption and digital signatures.
  • Compliance and Traceability: Every update affecting type-approval related parameters must be managed through a formal process. The SUMS ensures the traceability of all relevant software versions for type approval, using a unique identifier (RxSWIN).
  • Functionality and Driving Safety: Specific requirements are set for Over-The-Air (OTA) updates. The vehicle must be capable of:
    • Executing the update only under safe conditions (e.g., stationary and with sufficient power).
    • Having a recovery mechanism in case the update fails.
    • Clearly informing the user about the changes and necessary steps.

R156 and R155: A Dual Obligation for Type Approval

R156 works in tandem with UNECE R155 (Cybersecurity). To obtain type approval for a new vehicle type (and sales in adhering markets, such as the EU), dual certification is required:

  1. CSMS Certification (R155): Guarantees the management of cybersecurity across the entire supply chain.
  2. SUMS Certification (R156): Guarantees the security and compliance of the software update process.

Manufacturers who do not comply with both regulations will no longer be able to obtain type approval for new vehicle types in Europe.

ATS Group's Support in Regulatory Compliance

The entry into force of these regulations makes expertise in Automotive Cybersecurity and Regulatory Compliance (R155/R156) a fundamental prerequisite. This is where specialized support comes in.

ATS Group positions itself as a strategic partner for compliance, providing companies (OEMs and suppliers) with direct and comprehensive support:

  • Comprehensive support for obtaining Type Approval certificates: ATS Group assists companies with certification of vehicles and their systems. This includes obtaining the necessary system certifications (SUMS and CSMS) and providing assistance with the complex Type Approval processes required by international markets.

  • Audits and Verification: The Group supports the integration of security and compliance principles into corporate processes by conducting on-site audits and verifications to ensure the SUMS is correctly implemented and maintained over time in accordance with Regulations.

ATS Group’s approach ensures that companies in the automotive sector not only obtain the necessary certifications but also integrate software security and traceability requirements into their operational processes.

why choose ats group?

ATS Group is a group of companies operating in the field
of Inspections, Certifications and Type Approvals in the Automotive sector.

ATS Group, through its companies designated by e24 and e5 marks, is able to issue the type approval of complete vehicles.

With the type approval Approval Authority designations (E57), (E5) and (E24) ATS Group is able to carry out approvals of components, systems and technical units of vehicles in general.

ATS Europe, as a Certification Body accredited under ISO 17021-1: 2015 as a Certification Body for Quality Management Systems under ISO 9001: 2015, has become a leading company in the field of certifications.

The test laboratories affiliated with ATS Group are ISO 17025 accredited, ensuring reliability, accuracy, and compliance with international standards.

ats-app

ats app

Our proprietary online platform can manage the whole approval process, fron the quotation till the direct download on the final Type Approval Certificate.

ATS Group offers competitive prices and fast turnaround times, ensuring an efficient and high-quality service to meet customer needs promptly.