UDS Negative Response Code Decoder
Decode a UDS negative response in a second: paste 7F 27 35 or a bare code and get the ISO 14229 name, the rejected service and what it means on the bench. Full NRC table.
Updated This page as Markdown
In short
This tool decodes UDS negative response codes (NRCs) per ISO 14229-1 Annex A. Paste a complete negative response such as 7F 27 35, or a bare code such as 33, and it shows the ISO name, the service that was rejected and what the code usually means when you test an ECU. The full table below the tool is searchable and includes the codes used by the Authentication service (0x29).
Paste the full response (7F 27 35) or just the code (35). Hex, spaces optional.
Decoded
0x35 invalidKey
Rejected service: 0x27 SecurityAccess
The key sent for SecurityAccess did not match the seed. Count these: a weak implementation does not limit attempts.
All negative response codes
| Code | ISO name | What it means on the bench |
|---|---|---|
| 0x10 | generalReject | The ECU rejected the request without a more specific reason. Often a catch-all in the server implementation. |
| 0x11 | serviceNotSupported | The service identifier is unknown to this ECU, in any session. Useful for enumeration: the service does not exist here. |
| 0x12 | subFunctionNotSupported | The service exists but this sub-function does not, in any session. |
| 0x13 | incorrectMessageLengthOrInvalidFormat | Wrong number of bytes for this request. Also what a well-behaved ECU should answer to most fuzzed messages. |
| 0x14 | responseTooLong | The response would exceed the transport layer limit. |
| 0x21 | busyRepeatRequest | The ECU is busy; the tester may repeat the request later. |
| 0x22 | conditionsNotCorrect | A precondition is not met, for example vehicle speed, engine running or a required session or state. |
| 0x24 | requestSequenceError | The request came out of order, for example a SecurityAccess key without a preceding seed request, or TransferData without RequestDownload. |
| 0x25 | noResponseFromSubnetComponent | A gateway forwarded the request but the target ECU did not answer. |
| 0x26 | failurePreventsExecutionOfRequestedAction | A failure in the ECU (for example a stored fault) prevents the action. |
| 0x31 | requestOutOfRange | A parameter is outside the valid range: an unknown DID or RID, an invalid memory address or an unsupported value. Also what an ECU answers when a DID exists but not in this session, so it is useful for mapping. |
| 0x33 | securityAccessDenied | The ECU is locked. The service or data needs a successful SecurityAccess (0x27) first. For a tester, this marks the protected surface. |
| 0x34 | authenticationRequired | The service needs a successful Authentication (0x29) first. |
| 0x35 | invalidKey | The key sent for SecurityAccess did not match the seed. Count these: a weak implementation does not limit attempts. |
| 0x36 | exceedNumberOfAttempts | Too many wrong keys; the ECU has locked SecurityAccess for a while. This is the correct behaviour. |
| 0x37 | requiredTimeDelayNotExpired | The delay after a failed attempt or after power-up has not expired yet. |
| 0x38 | secureDataTransmissionRequired | The request must be sent through SecuredDataTransmission (0x84). |
| 0x39 | secureDataTransmissionNotAllowed | This request must not be sent through SecuredDataTransmission. |
| 0x3A | secureDataVerificationFailed | Verification of a secured data transmission failed. |
| 0x50 | certificateVerificationFailedInvalidTimePeriod | Authentication (0x29): certificate not valid at this time. |
| 0x51 | certificateVerificationFailedInvalidSignature | Authentication (0x29): certificate signature invalid. |
| 0x52 | certificateVerificationFailedInvalidChainOfTrust | Authentication (0x29): certificate chain not trusted. |
| 0x53 | certificateVerificationFailedInvalidType | Authentication (0x29): wrong certificate type. |
| 0x54 | certificateVerificationFailedInvalidFormat | Authentication (0x29): certificate format invalid. |
| 0x55 | certificateVerificationFailedInvalidContent | Authentication (0x29): certificate content invalid. |
| 0x56 | certificateVerificationFailedInvalidScope | Authentication (0x29): certificate scope does not cover this. |
| 0x57 | certificateVerificationFailedInvalidCertificate | Authentication (0x29): certificate revoked or otherwise invalid. |
| 0x58 | ownershipVerificationFailed | Authentication (0x29): proof of ownership failed. |
| 0x59 | challengeCalculationFailed | Authentication (0x29): the ECU could not calculate the challenge. |
| 0x5A | settingAccessRightsFailed | Authentication (0x29): access rights could not be set. |
| 0x5B | sessionKeyCreationOrDerivationFailed | Authentication (0x29): session key derivation failed. |
| 0x5C | configurationDataUsageFailed | Authentication (0x29): configuration data could not be used. |
| 0x5D | deAuthenticationFailed | Authentication (0x29): de-authentication failed. |
| 0x70 | uploadDownloadNotAccepted | RequestDownload or RequestUpload refused: wrong address, length, format or state. |
| 0x71 | transferDataSuspended | The data transfer was suspended by the ECU. |
| 0x72 | generalProgrammingFailure | Writing to memory failed during programming. |
| 0x73 | wrongBlockSequenceCounter | TransferData block counter out of sequence. |
| 0x78 | requestCorrectlyReceived-ResponsePending | Not an error: the ECU needs more time and will send the final response later. The tester extends its P2* timeout. Watch for ECUs that never follow up. |
| 0x7E | subFunctionNotSupportedInActiveSession | The sub-function exists but not in the current session. Switch session (0x10) and try again. |
| 0x7F | serviceNotSupportedInActiveSession | The service exists but not in the current session. Classic marker for services that live in extended or programming session. |
| 0x81 | rpmTooHigh | Engine speed too high for this action. |
| 0x82 | rpmTooLow | Engine speed too low for this action. |
| 0x83 | engineIsRunning | Not allowed while the engine runs. |
| 0x84 | engineIsNotRunning | Only allowed while the engine runs. |
| 0x85 | engineRunTimeTooLow | Engine has not run long enough. |
| 0x86 | temperatureTooHigh | Temperature too high for this action. |
| 0x87 | temperatureTooLow | Temperature too low for this action. |
| 0x88 | vehicleSpeedTooHigh | Vehicle speed too high for this action. The usual guard on actuator tests. |
| 0x89 | vehicleSpeedTooLow | Vehicle speed too low for this action. |
| 0x8A | throttle/PedalTooHigh | Throttle or pedal position too high. |
| 0x8B | throttle/PedalTooLow | Throttle or pedal position too low. |
| 0x8C | transmissionRangeNotInNeutral | Transmission must be in neutral. |
| 0x8D | transmissionRangeNotInGear | Transmission must be in gear. |
| 0x8F | brakeSwitch(es)NotClosed | Brake pedal must be pressed. |
| 0x90 | shifterLeverNotInPark | Shift lever must be in park. |
| 0x91 | torqueConverterClutchLocked | Torque converter clutch is locked. |
| 0x92 | voltageTooHigh | Supply voltage too high, often during programming. |
| 0x93 | voltageTooLow | Supply voltage too low, often during programming. |
| 0x94 | resourceTemporarilyNotAvailable | A needed resource is busy; try again later. |
How it works
A UDS negative response is always three bytes: 7F, the service identifier (SID) of the rejected request, and the negative response code. The tool accepts the full response or just the code, looks it up in the ISO 14229-1 table and adds what the code usually tells you when you test an ECU, written from the tester’s point of view rather than the ECU’s.
The table covers all codes defined in ISO 14229-1:2020 Annex A, including the range 0x50 to 0x5D used by the Authentication service (0x29) and the vehicle-condition codes 0x81 to 0x94. Codes outside the table are manufacturer-specific or reserved.
How to read the result
Three codes carry most of the information during enumeration. 0x11 serviceNotSupported means the service does not exist on this ECU at all. 0x7F serviceNotSupportedInActiveSession means it exists but needs another session, typically extended (0x03) or programming (0x02). 0x33 securityAccessDenied marks the surface that is protected by SecurityAccess. An ECU that answers 0x12 or 0x7E for sub-functions, and 0x31 for unknown identifiers, is telling you its map one response at a time.
During SecurityAccess testing, count 0x35 invalidKey responses. After the configured number of attempts the ECU must answer 0x36 exceedNumberOfAttempts and then 0x37 requiredTimeDelayNotExpired. An ECU that keeps answering 0x35 has no attempt counter, which is a finding.
Limits
The tool knows the standard codes, not what your ECU does with them. Some implementations answer 0x10 generalReject to everything they do not understand, which hides the structure. Some mislabel conditions. AutoST’s enumeration treats the responses statistically across sessions, which is how it maps services and identifiers even on such ECUs.
FAQ
Frequently asked questions
What is the structure of a UDS negative response?
Three bytes: 0x7F, the service identifier of the request that was rejected, and the negative response code. A tester that sends 27 03 (SecurityAccess, requestSeed level 3) and receives 7F 27 7E learns that sub-function 03 exists but not in the active session.
Is 0x78 an error?
No. requestCorrectlyReceived-ResponsePending tells the tester the ECU needs more time; the tester extends its P2* timeout and waits for the final response. ECUs that send 0x78 and then never answer are a finding, because the tester hangs.
Why do some ECUs answer 0x31 instead of 0x7F for unknown DIDs?
requestOutOfRange (0x31) is the correct answer to a DID the ECU does not support, while serviceNotSupportedInActiveSession (0x7F) means the whole service is unavailable in the current session. Mixing them up is common and makes enumeration harder; AutoST interprets both.
Sources
Related pages
- GlossaryNRC (Negative Response Code)A UDS negative response is 7F, the rejected SID and a negative response code (NRC) such as 0x11, 0x33 or 0x7F. What the codes in ISO 14229-1 Annex A mean on the bench.
- GlossaryUDS (Unified Diagnostic Services)UDS (ISO 14229) is the diagnostic protocol of most automotive ECUs: sessions, services, DIDs and SecurityAccess. What it defines and why it is the first attack surface.
- Free toolsUDS Message DecoderPaste UDS bytes from a trace and see what they mean: service, sub-function, session, DIDs, routine identifier, SecurityAccess level or NRC, per ISO 14229-1.
- PlatformKnow every door into the ECU.AutoST enumerates an ECU over UDS: diagnostic endpoints, sessions, all 255 services and readable DIDs, plus XCP/CCP discovery. Risky services are flagged automatically.
- PlatformDoes your seed/key actually hold?AutoST probes UDS SecurityAccess: seed randomness, weak seed-to-key algorithms, default keys, brute-force lockout and sequence enforcement. Bounded and non-destructive.
