UN Regulations 155 and 156, developed under UNECE WP.29, require vehicle manufacturers to operate a certified Cyber Security Management System and Software Update Management System as a condition of type approval. They make how a manufacturer governs software a regulated question rather than an internal one.
UNECE WP.29
Statute United Nations / EU / adopting states
R155 and R156 are the first regulations to make software governance a condition of selling a vehicle. Not the software itself — the management system around it: how vulnerabilities are handled, how updates are validated and delivered, how the whole arrangement is audited.
- CSMS - A certified cybersecurity management system covering the vehicle lifecycle, including suppliers.
- SUMS - A certified software-update management system, with integrity and rollback obligations.
- Type approval as leverage - Non-compliance blocks the market, which is why adoption was rapid.
- Reaches the supply chain - Manufacturers push the obligations to component and software suppliers.
These regulations are the closest thing in this market to the operational-governance facets the Kin Score measures — versioning, change communication, controlled updates — arriving as a legal requirement rather than a developer-experience nicety. The State of Robotics & Autonomous Systems APIs scores the autonomous vehicle segment at 13.1 with a market-wide governance facet of 2.4, so the discipline exists in regulated documents and not yet in anything published.