# ControlDTCSetting (0x85)

> ControlDTCSetting (0x85) turns the storing of diagnostic trouble codes on an ECU on or off, so a test does not fill the fault memory with its own side effects. The sub-function selects on (01) or off (02). The request 85 02 stops DTC storage, the positive response C5 02 confirms it. It needs the extended session, and the ECU must turn DTC storage back on when the session ends or the ECU resets.

UDS ControlDTCSetting (0x85) turns fault-code storage on an ECU on or off during a test. The sub-functions, request and response bytes and what to validate.

Source: https://auto-st.com/glossary/control-dtc-setting-0x85 · Updated: 2026-10-07

## What is ControlDTCSetting (0x85)?

ControlDTCSetting turns the recording of diagnostic trouble codes on or off. The sub-function byte selects the state: on resumes normal DTC storage, off suspends it for the duration of the session.

A normal exchange:

| Direction | Bytes | Meaning |
|---|---|---|
| Request | `85 02` | DTC setting off |
| Positive response | `C5 02` | accepted, storage suspended |
| Negative response | `7F 85 7F` | serviceNotSupportedInActiveSession |

Other typical negative responses are `7F 85 12` (subFunctionNotSupported), `7F 85 13` (incorrectMessageLengthOrInvalidFormat) and `7F 85 22` (conditionsNotCorrect).

## Where is it defined?

ISO 14229-1:2020 defines ControlDTCSetting (0x85) in the Diagnostic and communication management functional unit. The standard specifies the on and off sub-functions, the optional DTCSettingControlOptionRecord and the rule that the service is session-dependent, so the setting is tied to the active session and restored on return to the default session. The transport on CAN is ISO 15765-2. The faults themselves are read with ReadDTCInformation (0x19).

## What it means in practice

ControlDTCSetting belongs to a tester that is about to do something that would otherwise set faults, so it lives in the extended session and is not meant to be reachable by default. In validation, engineers check:

- the service answers only in the intended session and gives NRC 0x7F in the default session;
- an unknown sub-function gives NRC 0x12 and a wrong length gives NRC 0x13;
- DTC storage resumes on session timeout, session change and reset;
- with storage off, side-effect faults are genuinely suppressed and real monitoring is restored afterwards.

The security-relevant failure is an ECU that leaves DTC storage off after the tester is gone, because a fault that occurs later would then not be recorded. We regularly see this alongside other session-handling bugs where state does not reset on an S3 timeout.

## How AutoST tests it

AutoST records ControlDTCSetting during enumeration, including in which sessions it answers and with which negative response codes, and checks that DTC storage returns to on when the session ends. The session-survival check in enumeration surfaces an ECU that keeps the setting off after an S3 timeout or reset, and the DTC-count monitor in the fuzzing engine reads 0x19 so it can tell whether fault storage is behaving as expected during a run.

## FAQ

**What are the two sub-functions?**

ControlDTCSetting defines on (0x01), which resumes DTC storage, and off (0x02), which suspends it. An optional DTCSettingControlOptionRecord can scope the control to a group of DTCs on ECUs that support it.

**Why turn DTC setting off during a test?**

A diagnostic session, a routine or a reset can set faults that are side effects of testing, not real failures. Turning DTC storage off keeps the fault memory clean, and turning it back on restores normal behaviour afterwards.

**What must happen when the session ends?**

DTC storage must return to on. An ECU that leaves fault-code storage off after the session times out or the ECU resets has a session-handling bug, because a real fault could then go unrecorded.

## Sources

- [ISO 14229-1:2020 Road vehicles, Unified diagnostic services (UDS), Part 1: Application layer, Diagnostic and communication management functional unit, ControlDTCSetting (0x85)](https://www.iso.org/standard/72439.html)
- [ISO 15765-2 Road vehicles, Diagnostic communication over CAN (DoCAN), Part 2: Transport protocol and network layer services](https://www.iso.org/standard/84211.html)

## Related

- [DTC (Diagnostic Trouble Code)](https://auto-st.com/glossary/dtc)
- [ReadDTCInformation (0x19)](https://auto-st.com/glossary/read-dtc-information-0x19)
- [Diagnostic session (DiagnosticSessionControl 0x10)](https://auto-st.com/glossary/diagnostic-session)
- [Know every door into the ECU.](https://auto-st.com/uds-enumeration)
- [ECU reset and session handling bugs, and how to test them](https://auto-st.com/insights/ecu-reset-and-session-handling-bugs)
- [UDS Message Decoder](https://auto-st.com/tools/uds-message-decoder)

---
AutoST by Zyberum. Canonical page: https://auto-st.com/glossary/control-dtc-setting-0x85
