# NRC (Negative Response Code)

> A negative response code (NRC) is the third byte of a UDS negative response, 7F <SID> <NRC>, and tells the tester why the ECU rejected a request: 0x11 serviceNotSupported, 0x12 subFunctionNotSupported, 0x13 incorrectMessageLengthOrInvalidFormat, 0x22 conditionsNotCorrect, 0x31 requestOutOfRange, 0x33 securityAccessDenied, 0x35 invalidKey, 0x7E and 0x7F for the wrong session, 0x78 for response pending. ISO 14229-1 Annex A lists them all. For a tester, NRCs are the map of the ECU.

A UDS negative response is 7F, the rejected SID and a negative response code (NRC) such as 0x11, 0x33 or 0x7F. What the codes in ISO 14229-1 Annex A mean on the bench.

Source: https://auto-st.com/glossary/nrc · Updated: 2026-10-07

## What is an NRC?

When an ECU cannot or will not execute a UDS request, it answers with a negative response: `7F`, the service identifier of the rejected request and one negative response code. `7F 27 35` says SecurityAccess was called with an invalid key, `7F 22 31` says ReadDataByIdentifier was asked for a DID that is out of range, `7F 10 12` says the requested session sub-function is not supported.

The codes that matter most on a test bench are `0x10` generalReject, `0x11` serviceNotSupported, `0x12` subFunctionNotSupported, `0x13` incorrectMessageLengthOrInvalidFormat, `0x14` responseTooLong, `0x21` busyRepeatRequest, `0x22` conditionsNotCorrect, `0x24` requestSequenceError, `0x31` requestOutOfRange, `0x33` securityAccessDenied, `0x34` authenticationRequired, `0x35` invalidKey, `0x36` exceedNumberOfAttempts, `0x37` requiredTimeDelayNotExpired, `0x70` uploadDownloadNotAccepted, `0x72` generalProgrammingFailure, `0x73` wrongBlockSequenceCounter, `0x78` requestCorrectlyReceived-ResponsePending, `0x7E` subFunctionNotSupportedInActiveSession and `0x7F` serviceNotSupportedInActiveSession.

## Where is it defined?

ISO 14229-1:2020 Annex A lists every negative response code with its name and meaning; clause 7.5 defines when a server sends a negative response and the order in which it checks a request (service, length, sub-function, session, security, conditions). Codes `0x81` to `0x8F` and `0x92` to `0x94` describe vehicle conditions such as rpm, temperature and voltage ranges. `0x50` to `0x5D` were added for the Authentication service (`0x29`). Each service clause lists the subset of NRCs that service may return, and the suppressPosRspMsgIndicationBit never suppresses a negative response.

## What it means in practice

NRCs are the richest signal an ECU gives away for free. A sweep of all service identifiers in a session produces a pattern: `0x11` for services that are absent, `0x7F` for services waiting in another session, `0x33` for the surface behind SecurityAccess, `0x13` for services that exist and would run with the right length. The same applies to sub-functions (`0x12` versus `0x7E`) and to identifiers (`0x31`). Reading these codes carefully is enumeration.

During SecurityAccess testing the sequence `0x35`, `0x35`, `0x36`, then `0x37` shows a working attempt counter and delay. We regularly see ECUs that keep answering `0x35` indefinitely, which means unlimited key guesses, and ECUs that answer `0x10` generalReject to everything they do not understand, which hides the structure from a casual look but not from a statistical one. Another repeat finding: `0x78` followed by silence, which hangs any tester that honours P2*.

## How AutoST tests it

AutoST's enumeration engine classifies every response in every session from its NRC: supported, security access denied, not supported in this session, conditions not correct or not supported. The SecurityAccess engine counts `0x35`, `0x36` and `0x37` to judge the lockout, and the fuzzing engine treats missing responses and transport errors after a payload as crash indicators. The free NRC decoder on this site explains any single code.

## Common misunderstandings

A negative response is not a failed test. It is the ECU doing its job, and the right NRC in the right situation is exactly what a secure implementation looks like. The finding is the wrong code: a positive response where `0x33` belonged, or `0x35` where `0x36` was due.

## FAQ

**What is the difference between 0x11 and 0x7F?**

serviceNotSupported (0x11) means the service does not exist on this ECU in any session. serviceNotSupportedInActiveSession (0x7F) means it exists but not in the current one, usually because it needs the extended or programming session. The same pair exists for sub-functions: 0x12 and 0x7E.

**Is 0x78 an error?**

No. requestCorrectlyReceived-ResponsePending tells the tester the ECU needs more time and to wait up to P2* for the final response. An ECU that sends 0x78 and then nothing is a finding, because the tester hangs. ECUs may send several 0x78 in a row.

**Why do I get no response at all instead of an NRC?**

On functionally addressed requests ISO 14229-1 tells the ECU to stay silent instead of answering 0x11, 0x12, 0x31, 0x7E or 0x7F, so that one tester broadcast does not trigger a flood of negative responses. On physically addressed requests, silence usually means the ECU crashed, the ISO-TP address is wrong or the request never arrived.

## Sources

- [ISO 14229-1:2020 Road vehicles, Unified diagnostic services (UDS), Part 1: Application layer, clause 7.5 (negative response behaviour) and Annex A (negative response codes)](https://www.iso.org/standard/72439.html)
- [ISO 14229-2:2021 Road vehicles, Unified diagnostic services (UDS), Part 2: Session layer services (P2 and P2* timing)](https://www.iso.org/standard/79608.html)

## Related

- [SID (Service Identifier)](https://auto-st.com/glossary/sid)
- [UDS (Unified Diagnostic Services)](https://auto-st.com/glossary/uds)
- [Diagnostic session (DiagnosticSessionControl 0x10)](https://auto-st.com/glossary/diagnostic-session)
- [UDS Negative Response Code Decoder](https://auto-st.com/tools/uds-nrc-decoder)
- [Know every door into the ECU.](https://auto-st.com/uds-enumeration)
- [Does your seed/key actually hold?](https://auto-st.com/security-access-testing)

---
AutoST by Zyberum. Canonical page: https://auto-st.com/glossary/nrc
