Skip to content
AutoST by Zyberum GmbH
Menu
GlossaryCompliance

UN R156 (UN Regulation No. 156, Software Update)

UN R156 is the UNECE regulation on software updates and the Software Update Management System. What it requires of OTA updates and how it connects to ECU testing.

Updated This page as Markdown

In short

UN Regulation No. 156 is the UNECE regulation on software updates and the Software Update Management System (SUMS). A vehicle manufacturer needs a certified SUMS and must show for each vehicle type that software versions are identified and protected, that updates are delivered safely and securely, and that an update cannot put the vehicle in an unsafe state. It is the companion to UN R155. ECU update mechanisms, RxSWIN identification and the diagnostic download path are where testing meets the regulation.

What is UN R156?

UN R156 sets the requirements for how a manufacturer manages and delivers software updates to vehicles. Like R155 it has an organisational part, the Software Update Management System (SUMS) that must be certified, and a vehicle-type part, the proof that update processes and technical measures are in place for the specific type.

Where is it defined?

The regulation text is the source. Paragraph 7.1 sets the SUMS requirements: recording software and hardware versions, identifying the software relevant to type approval (RxSWIN), assessing whether an update affects a type-approved system, and keeping records. Paragraph 7.2 sets the vehicle requirements: protecting the integrity and authenticity of the update, protecting the RxSWIN, informing the user, and ensuring the vehicle can carry out the update safely, including that a failed or interrupted update does not leave the vehicle in an unsafe state. In the EU R156 applies to new vehicle types since July 2022 and to all newly registered vehicles since July 2024, in step with R155.

What it means in practice

For a test team R156 turns the update path into a test target with safety and security requirements. The diagnostic download services (RequestDownload 0x34, TransferData 0x36, RequestTransferExit 0x37) are the wired side of that path on most ECUs, and they must enforce authentication, integrity checks and a safe recovery if a transfer breaks off. Version identifiers have to be readable and tamper-evident.

On the bench this means checking that a download requires the right session and SecurityAccess, that the ECU verifies the image before activating it, and that an interrupted TransferData leaves the ECU recoverable rather than bricked.

How AutoST tests it

AutoST tests the diagnostic and bus-facing side of the update path, not the cryptographic internals of the bootloader. It checks whether the download services are reachable without the required session or SecurityAccess, probes the robustness of the transfer under malformed or oversized TransferData, and reads the version and identification data identifiers. It does not verify signatures or key management; that is firmware and penetration-test work.

Common misunderstandings

R156 is not only about over-the-air updates; a wired flash counts too. A readable RxSWIN is a requirement, not a leak. And passing R156 is about the manufacturer process and the type approval, so a test tool supplies evidence rather than compliance.

FAQ

Frequently asked questions

What is the difference between UN R155 and UN R156?

R155 is about cyber security over the vehicle lifecycle, R156 is about software updates specifically. R155 requires a CSMS, R156 requires a SUMS. Both are conditions for type approval under the UNECE framework and are usually handled together.

What is RxSWIN?

The Regulation X Software Identification Number, a value that identifies the software relevant to a type-approved regulation. R156 requires that software versions can be read and verified, and RxSWIN is the mechanism for the software behind a regulation; it is often readable over UDS as a data identifier.

Does R156 apply to over-the-air updates only?

No. It covers all software updates, over the air and through a wired diagnostic connection. The requirements on integrity, version identification and safe installation apply regardless of how the update reaches the ECU.

Sources

Related pages

See it on your ECU

A term that matters for your ECU?

In 15 minutes we tell you how AutoST tests it, what a finding looks like and what it means for your ISO/SAE 21434 evidence.

  • Direct answer from an ECU security engineer
  • Which test covers the term
  • Free and without obligation
Tom Zaubermann

Your demo is withTom ZaubermannFounder of Zyberum, ex-lead of the VW InCar Security Testing Lab

Already trusted by Tier 1, Tier 2 suppliers and OEMs. References on request.

Call us: +49 176 439 17074automotive@zyberum.com

Or send us a message

We reply within one business day.

Call usAsk the AutoST team

Pick a time that suits you

Open in a new tab