UNECE WP.29 R156
UN Regulation on Software Updates for vehicles
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (24)
Approval lifecycle
| Code | Title |
|---|---|
| R156-EXTEND-APPROVAL | Extension of type approval after software update |
Audit
| Code | Title |
|---|---|
| R156-AUDIT | Internal audit and continual improvement |
Change management
| Code | Title |
|---|---|
| R156-CHANGE | Change management of SUMS itself |
Configuration
| Code | Title |
|---|---|
| R156-RXSWIN-MGMT | RXSWIN management and traceability |
Execution
| Code | Title |
|---|---|
| R156-SW-EXECUTION | Safe and reliable update execution |
Market surveillance
| Code | Title |
|---|---|
| R156-MARKET-SURV | Cooperation with market surveillance authorities |
OTA
| Code | Title |
|---|---|
| R156-OTA-WIRELESS | Additional requirements for OTA updates |
People
| Code | Title |
|---|---|
| R156-COMPETENCE | Competence of personnel for software updates |
Pre-update checks
| Code | Title |
|---|---|
| R156-SW-COMPAT | Pre-update compatibility and dependency check |
Privacy
| Code | Title |
|---|---|
| R156-PRIVACY | Data minimisation in update telemetry |
R155 linkage
| Code | Title |
|---|---|
| R156-CYBER-LINK | Interaction with R155 cybersecurity processes |
Records
| Code | Title |
|---|---|
| R156-RECORDS | Records of updates per vehicle |
SUMS governance
| Code | Title |
|---|---|
| R156-SUMS-GOV | Software Update Management System governance |
Software inventory
| Code | Title |
|---|---|
| R156-SW-INVENTORY | Software identification and documentation |
Supply chain
| Code | Title |
|---|---|
| R156-SUPPLIER | Supplier-delivered software management |
Type approval impact
| Code | Title |
|---|---|
| R156-SW-IMPACT | Assessment of impact on type approval and safety |
UNECE WP.29 R156: Access Control
Logical and physical access controls (UNECE WP.29 R156)
| Code | Title |
|---|---|
| WP29-R156-11 | Access control policy and enforcement |
| WP29-R156-12 | User access management and provisioning |
| WP29-R156-13 | Authentication and password management |
| WP29-R156-14 | Privileged access management |
| WP29-R156-15 | Access review and recertification |
UNECE WP.29 R156: Asset Management
Information asset management (UNECE WP.29 R156)
| Code | Title |
|---|---|
| WP29-R156-06 | Asset inventory and ownership |
| WP29-R156-07 | Acceptable use of assets |
| WP29-R156-08 | Information classification and labeling |
| WP29-R156-09 | Asset handling procedures |
| WP29-R156-10 | Media management and disposal |
UNECE WP.29 R156: Communications Security
Network and communications security (UNECE WP.29 R156)
| Code | Title |
|---|---|
| WP29-R156-27 | Network security management |
| WP29-R156-28 | Network service security |
| WP29-R156-29 | Segregation in networks |
| WP29-R156-30 | Information transfer policies |
| WP29-R156-31 | Secure messaging |
UNECE WP.29 R156: Cryptography
Cryptographic controls (UNECE WP.29 R156)
| Code | Title |
|---|---|
| WP29-R156-16 | Cryptographic policy and key management |
| WP29-R156-17 | Encryption of data at rest |
| WP29-R156-18 | Encryption of data in transit |
| WP29-R156-19 | Certificate management |
| WP29-R156-20 | Key lifecycle management |
UNECE WP.29 R156: Information Security Policies
Organizational information security policies (UNECE WP.29 R156)
| Code | Title |
|---|---|
| WP29-R156-01 | Information security policy framework |
| WP29-R156-02 | Management direction and commitment |
| WP29-R156-03 | Policy review and update procedures |
| WP29-R156-04 | Roles and responsibilities definition |
| WP29-R156-05 | Contact with authorities and special interest groups |
UNECE WP.29 R156: Operations Security
Secure operations and monitoring (UNECE WP.29 R156)
| Code | Title |
|---|---|
| WP29-R156-21 | Operational procedures and responsibilities |
| WP29-R156-22 | Protection from malware |
| WP29-R156-23 | Backup and recovery procedures |
| WP29-R156-24 | Logging and monitoring |
| WP29-R156-25 | Technical vulnerability management |
| WP29-R156-26 | Audit considerations |
Update security
| Code | Title |
|---|---|
| R156-SW-INTEGRITY | Integrity and authenticity of software updates |
User communication
| Code | Title |
|---|---|
| R156-SW-USERINFO | Information to the user before and after the update |
Your Compliance Coverage
If you comply with UNECE WP.29 R156, you already cover:
PTES
35%
17 controls mapped
Compare →ISO/SAE 21434
35%
17 controls mapped
Compare →SIG (Shared Assessments)
35%
17 controls mapped
Compare →+ 265 more: ISO 27043 (35%), OpenSSF Scorecard (35%)
See all 268 mapped frameworks ↓Maps to 268 other frameworks
Frequently Asked Questions
What is UNECE WP.29 R156?
UNECE WP.29 R156 is a compliance framework from International with 24 domains and 49 controls. UN Regulation on Software Updates for vehicles It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does UNECE WP.29 R156 have?
UNECE WP.29 R156 has 49 controls organised across 24 domains. The largest domains are UNECE WP.29 R156: Operations Security (6 controls), UNECE WP.29 R156: Access Control (5 controls), UNECE WP.29 R156: Asset Management (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does UNECE WP.29 R156 map to?
UNECE WP.29 R156 maps to 268 other compliance frameworks. The top mapping partners are PTES (35% coverage), ISO/SAE 21434 (35% coverage), SIG (Shared Assessments) (35% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with UNECE WP.29 R156 compliance?
Start your UNECE WP.29 R156 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about UNECE WP.29 R156 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 49 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 701 frameworks.
Get Started Free →Free forever — no credit card required