UN Regulations 155 and 156, developed under UNECE WP.29, require vehicle manufacturers to operate a certified Cyber Security Management System and Software Update Management System as a condition of type approval. They make how a manufacturer governs software a regulated question rather than an internal one.
UNECE WP.29
Statute United Nations / EU / adopting states
R155 and R156 are the first regulations to make software governance a condition of selling a vehicle. Not the software itself — the management system around it: how vulnerabilities are handled, how updates are validated and delivered, how the whole arrangement is audited.
- CSMS - A certified cybersecurity management system covering the vehicle lifecycle, including suppliers.
- SUMS - A certified software-update management system, with integrity and rollback obligations.
- Type approval as leverage - Non-compliance blocks the market, which is why adoption was rapid.
- Reaches the supply chain - Manufacturers push the obligations to component and software suppliers.
These regulations are the closest thing in this market to the operational-governance facets the Kin Score measures — versioning, change communication, controlled updates — arriving as a legal requirement rather than a developer-experience nicety. The State of Robotics & Autonomous Systems APIs scores the autonomous vehicle segment at 13.1 with a market-wide governance facet of 2.4, so the discipline exists in regulated documents and not yet in anything published.
Referenced in API Evangelist papers
This regulation shows up in my published research. These reports read the machine-readable evidence provider by provider — and put this regulation in the context of a real sector.
The State of Robotics & Autonomous Systems APIs
Makes software governance a condition of type approval — the same discipline the governance facet measures, arriving as law while the market's governance facet sits at 2.4.