Skip to content
AutoST by Zyberum GmbH
Menu
GlossaryUDS

NRC (Negative Response Code)

A UDS negative response is 7F, the rejected SID and a negative response code (NRC) such as 0x11, 0x33 or 0x7F. What the codes in ISO 14229-1 Annex A mean on the bench.

Updated This page as Markdown

In short

A negative response code (NRC) is the third byte of a UDS negative response, 7F <SID> <NRC>, and tells the tester why the ECU rejected a request: 0x11 serviceNotSupported, 0x12 subFunctionNotSupported, 0x13 incorrectMessageLengthOrInvalidFormat, 0x22 conditionsNotCorrect, 0x31 requestOutOfRange, 0x33 securityAccessDenied, 0x35 invalidKey, 0x7E and 0x7F for the wrong session, 0x78 for response pending. ISO 14229-1 Annex A lists them all. For a tester, NRCs are the map of the ECU.

What is an NRC?

When an ECU cannot or will not execute a UDS request, it answers with a negative response: 7F, the service identifier of the rejected request and one negative response code. 7F 27 35 says SecurityAccess was called with an invalid key, 7F 22 31 says ReadDataByIdentifier was asked for a DID that is out of range, 7F 10 12 says the requested session sub-function is not supported.

The codes that matter most on a test bench are 0x10 generalReject, 0x11 serviceNotSupported, 0x12 subFunctionNotSupported, 0x13 incorrectMessageLengthOrInvalidFormat, 0x14 responseTooLong, 0x21 busyRepeatRequest, 0x22 conditionsNotCorrect, 0x24 requestSequenceError, 0x31 requestOutOfRange, 0x33 securityAccessDenied, 0x34 authenticationRequired, 0x35 invalidKey, 0x36 exceedNumberOfAttempts, 0x37 requiredTimeDelayNotExpired, 0x70 uploadDownloadNotAccepted, 0x72 generalProgrammingFailure, 0x73 wrongBlockSequenceCounter, 0x78 requestCorrectlyReceived-ResponsePending, 0x7E subFunctionNotSupportedInActiveSession and 0x7F serviceNotSupportedInActiveSession.

Where is it defined?

ISO 14229-1:2020 Annex A lists every negative response code with its name and meaning; clause 7.5 defines when a server sends a negative response and the order in which it checks a request (service, length, sub-function, session, security, conditions). Codes 0x81 to 0x8F and 0x92 to 0x94 describe vehicle conditions such as rpm, temperature and voltage ranges. 0x50 to 0x5D were added for the Authentication service (0x29). Each service clause lists the subset of NRCs that service may return, and the suppressPosRspMsgIndicationBit never suppresses a negative response.

What it means in practice

NRCs are the richest signal an ECU gives away for free. A sweep of all service identifiers in a session produces a pattern: 0x11 for services that are absent, 0x7F for services waiting in another session, 0x33 for the surface behind SecurityAccess, 0x13 for services that exist and would run with the right length. The same applies to sub-functions (0x12 versus 0x7E) and to identifiers (0x31). Reading these codes carefully is enumeration.

During SecurityAccess testing the sequence 0x35, 0x35, 0x36, then 0x37 shows a working attempt counter and delay. We regularly see ECUs that keep answering 0x35 indefinitely, which means unlimited key guesses, and ECUs that answer 0x10 generalReject to everything they do not understand, which hides the structure from a casual look but not from a statistical one. Another repeat finding: 0x78 followed by silence, which hangs any tester that honours P2*.

How AutoST tests it

AutoST’s enumeration engine classifies every response in every session from its NRC: supported, security access denied, not supported in this session, conditions not correct or not supported. The SecurityAccess engine counts 0x35, 0x36 and 0x37 to judge the lockout, and the fuzzing engine treats missing responses and transport errors after a payload as crash indicators. The free NRC decoder on this site explains any single code.

Common misunderstandings

A negative response is not a failed test. It is the ECU doing its job, and the right NRC in the right situation is exactly what a secure implementation looks like. The finding is the wrong code: a positive response where 0x33 belonged, or 0x35 where 0x36 was due.

FAQ

Frequently asked questions

What is the difference between 0x11 and 0x7F?

serviceNotSupported (0x11) means the service does not exist on this ECU in any session. serviceNotSupportedInActiveSession (0x7F) means it exists but not in the current one, usually because it needs the extended or programming session. The same pair exists for sub-functions: 0x12 and 0x7E.

Is 0x78 an error?

No. requestCorrectlyReceived-ResponsePending tells the tester the ECU needs more time and to wait up to P2* for the final response. An ECU that sends 0x78 and then nothing is a finding, because the tester hangs. ECUs may send several 0x78 in a row.

Why do I get no response at all instead of an NRC?

On functionally addressed requests ISO 14229-1 tells the ECU to stay silent instead of answering 0x11, 0x12, 0x31, 0x7E or 0x7F, so that one tester broadcast does not trigger a flood of negative responses. On physically addressed requests, silence usually means the ECU crashed, the ISO-TP address is wrong or the request never arrived.

Sources

Related pages

See it on your ECU

A term that matters for your ECU?

In 15 minutes we tell you how AutoST tests it, what a finding looks like and what it means for your ISO/SAE 21434 evidence.

  • Direct answer from an ECU security engineer
  • Which test covers the term
  • Free and without obligation
Tom Zaubermann

Your demo is withTom ZaubermannFounder of Zyberum, ex-lead of the VW InCar Security Testing Lab

Already trusted by Tier 1, Tier 2 suppliers and OEMs. References on request.

Call us: +49 176 439 17074automotive@zyberum.com

Or send us a message

We reply within one business day.

Call usAsk the AutoST team

Pick a time that suits you

Open in a new tab