How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

UNECE WP.29

Statute United Nations / EU / adopting states

UN Regulations 155 and 156, developed under UNECE WP.29, require vehicle manufacturers to operate a certified Cyber Security Management System and Software Update Management System as a condition of type approval. They make how a manufacturer governs software a regulated question rather than an internal one.

R155 and R156 are the first regulations to make software governance a condition of selling a vehicle. Not the software itself — the management system around it: how vulnerabilities are handled, how updates are validated and delivered, how the whole arrangement is audited.

  • CSMS - A certified cybersecurity management system covering the vehicle lifecycle, including suppliers.
  • SUMS - A certified software-update management system, with integrity and rollback obligations.
  • Type approval as leverage - Non-compliance blocks the market, which is why adoption was rapid.
  • Reaches the supply chain - Manufacturers push the obligations to component and software suppliers.

These regulations are the closest thing in this market to the operational-governance facets the Kin Score measures — versioning, change communication, controlled updates — arriving as a legal requirement rather than a developer-experience nicety. The State of Robotics & Autonomous Systems APIs scores the autonomous vehicle segment at 13.1 with a market-wide governance facet of 2.4, so the discipline exists in regulated documents and not yet in anything published.