WP.29 Type Approval Software | Vehicle Compliance & CSMS Automation | Certivo - Certivo
UNECE WP.29 Type Approval
Over 160 UN Regulations. 54+ Contracting Parties. Does Your Supply Chain Have the Evidence to Prove Type Approval Compliance?
UNECE WP.29 type approval requires documented compliance evidence across safety, emissions, cybersecurity, and environmental regulations—from every supplier tier. The framework now includes over 160 UN Regulations with continuous amendments. R155/R156 cybersecurity mandates are fully enforced. Scope expansion to motorcycles begins December 2027.
Certivo automates supplier compliance evidence collection from declaration through type approval documentation.
160+
UN Regulations under the 1958 Agreement (2026)
54+
Contracting parties with mutual type approval recognition
3 years
CSMS/SUMS certificate validity before mandatory recertification
Regulation Overview
- Jurisdiction: 54+ UNECE Contracting Parties (EU, UK, Japan, South Korea, Australia; parallel standards in China, US)
- Regulatory Body: UNECE World Forum for Harmonization of Vehicle Regulations (WP.29)
- Regulation Number: 1958 Agreement (Type Approval); 1998 Agreement (GTRs); 1997 Agreement (Periodic Inspections)
- Effective Date: 1958 Agreement (revised 1995); R155/R156 mandatory for all new vehicles from July 2024
- Official Source: UNECE Transport Regulations
- Key Threshold: Dual CSMS + SUMS certification required for vehicle type approval
What Is UNECE WP.29 Type Approval?
UNECE WP.29 type approval is the global regulatory framework governing vehicle safety, emissions, cybersecurity, and environmental performance. For supply chain teams, the primary obligation is providing documented compliance evidence across over 160 UN Regulations—covering everything from braking systems and lighting to cybersecurity management and software updates.
The 1958 Agreement provides the legal basis for type approval and mutual recognition across 54+ contracting parties. As of 2026, WP.29 continues to adopt new regulations and amend existing ones at an accelerating pace—with cybersecurity (R155), software updates (R156), automated driving systems, and emissions standards driving the most significant compliance burdens. Manufacturers placing vehicles on markets governed by WP.29 must hold valid type approvals and maintain conformity of production evidence throughout the vehicle lifecycle.
WP.29 type approval requires component-level and system-level evidence—test reports, certificates, supplier declarations, and management system certifications—from every relevant supplier tier. When regulations are amended or new ones adopted, your entire vehicle portfolio requires reassessment against current requirements.
Key Components / Sub-Frameworks
- Obligation: Compliance with applicable UN Regulations for market access
- 1958 Agreement: Legal framework for type approval and mutual recognition
- Obligation: Mandatory CSMS audit and 3-year recertification
- UN R155 (CSMS): Cybersecurity Management System certification
- Obligation: Mandatory SUMS audit alongside CSMS for type approval
- UN R156 (SUMS): Software Update Management System certification
- Obligation: Must be addressed in manufacturer's TARA process
- Annex 5 (R155): 69 attack vectors across 7 threat categories
- Obligation: Streamlined whole-vehicle approval across contracting parties
- IWVTA (R0): International Whole Vehicle Type Approval
- Obligation: Continuous evidence that production matches type approval specs
- Conformity of Production: Ongoing manufacturing compliance verification
WP.29 Expands R155 Scope to Motorcycles from December 2027
The GRVA working party adopted Category L expansion for UN R155 in January 2026, bringing motorcycles, scooters, and electric bicycles under cybersecurity type approval requirements from December 2027. A new UN Regulation on Automated Driving Systems (ADS) is under formal development for submission to WP.29. CSMS certificates expire every three years. Supplier evidence from prior audit cycles may no longer reflect current regulatory requirements.
Key Compliance Requirements
Who Must Comply
- Vehicle manufacturers (OEMs) seeking type approval in any UNECE contracting party
- Importers placing vehicles on markets governed by WP.29 regulations
- Tier 1, Tier 2, and Tier 3 suppliers providing safety-critical and cybersecurity-relevant components
- Non-UNECE manufacturers exporting to EU, UK, Japan, South Korea, or Australia
- Motorcycle and two-wheeler OEMs (from December 2027 for new types under R155)
- Software providers delivering OTA update infrastructure and backend services
Key Thresholds
- CSMS + SUMS Certification: Dual certification required before any vehicle type approval application
- 3-Year Recertification: CSMS and SUMS certificates must be renewed every 3 years
- 69 Attack Vectors: Annex 5 threat categories must be addressed in manufacturer's TARA
- Conformity of Production: Ongoing evidence that production matches type approval specifications
Core Obligations
CSMS Certification (R155): Demonstrate organizational cybersecurity processes, risk management, and supply chain governanceDEADLINE: Before type approval application
SUMS Certification (R156): Demonstrate secure software update processes, OTA security, and version trackingDEADLINE: Before type approval application
Vehicle Type Approval: Submit complete evidence package with architecture, TARA, and test results to Technical ServiceDEADLINE: Before market entry in contracting party markets
Conformity of Production: Maintain manufacturing processes matching type approval specificationsDEADLINE: Ongoing throughout production
Post-Production Monitoring: Continuous monitoring for new vulnerabilities and cybersecurity incidentsDEADLINE: Throughout vehicle service life (12–25 years)
WP.29 Type Approval-Specific Pain Points
The Multi-Regulation Evidence Scramble
WP.29 type approval requires compliance evidence across dozens of applicable UN Regulations simultaneously. Each regulation demands specific test reports, certificates, and supplier declarations—but evidence is scattered across emails, legacy systems, and disconnected supplier portals. Your compliance team spends weeks compiling documentation for a single type approval application, then months reconciling inconsistencies across supplier tiers.
The 3-Year Recertification Clock
Your CSMS certificate expires in six months. Since the last audit, you've onboarded 40 new suppliers, introduced three ECU platforms, and updated your OTA infrastructure. Every change requires updated evidence—security concepts, TARA revisions, and supplier self-assessments. Your team is rebuilding the evidence package from scratch because no centralized compliance data backbone was established.
The Supplier Tier Visibility Gap
While OEMs bear type approval responsibility, compliance depends entirely on supplier cooperation across every tier. A Tier 2 ECU supplier claims cybersecurity compliance but provides no documentation. A Tier 1 integrator passes through declarations without validation. Without multi-tier supply chain transparency, evidence gaps persist through the audit—and a single missing supplier certificate can block type approval.
The Conformity of Production Burden
Type approval doesn't end at certification. Conformity of production requires continuous evidence that every manufactured vehicle matches the approved specifications. With hundreds of component suppliers, software versions, and production sites, maintaining traceable evidence at scale is unsustainable through manual processes. Regulatory amendments mean approved configurations can become non-compliant between audit cycles.
Certivo In Action
Certivo in Action—WP.29 Type Approval Workflow
GET EVIDENCE IN
Collect Compliance Evidence from Every Supplier Tier—Without the Chasing
CORA launches targeted campaigns to collect type approval compliance evidence from multi-tier automotive suppliers, follows up automatically, and accepts responses in any format.
- Launch evidence collection campaigns to hundreds of suppliers with one click
- CORA-powered outreach in suppliers' native languages
- Accept any format: test reports, certificates, security concepts, TARA documents, self-assessments
- Track response rates and escalate non-responders automatically
MAKE SENSE OF IT
Know Instantly Which Suppliers Have Gaps in Type Approval Evidence
CORA extracts compliance data from every supplier document, validates against applicable UN Regulation requirements, and flags evidence gaps automatically.
- CORA parses certificates, test reports, and declarations to extract compliance status and validity dates
- Automatic validation against applicable UN Regulations including R155, R156, and safety requirements
- Real-time alerts when supplier certificates expire or evidence gaps emerge
- BOM-level compliance intelligence mapping components to regulatory requirements
⚠️
PROVE COMPLIANCE OUT
Generate Type Approval Packages in Hours, Not Months
Compile complete type approval documentation and CSMS audit evidence instantly from validated supplier data.
- One-click CSMS audit evidence packages with full traceability
- Pre-structured documentation aligned with Technical Service requirements
- Annex 5 coverage reports mapping threat vectors to mitigations
- Complete audit trail for every validation and response
Key Statistics
- 160+ UN Regulations tracked with automatic regulatory sync
- 99.2% Compliance evidence extraction accuracy from supplier documents
- 95% Supplier response rate with CORA-powered campaigns
Frequently Asked Questions
What vehicles and companies are subject to WP.29 type approval obligations?
Any manufacturer seeking to sell vehicles in UNECE contracting party markets—including the EU, UK, Japan, South Korea, and Australia—must hold valid type approvals under applicable UN Regulations. This covers passenger cars, commercial vehicles, buses, trailers with ECUs, and from December 2027, motorcycles. While type approval responsibility sits with OEMs, the regulation cascades to every supplier tier.
What happens if an OEM fails to meet WP.29 type approval requirements?
Without valid type approvals—including CSMS and SUMS certification under R155/R156—a vehicle cannot legally be sold in any UNECE contracting party market. Several OEMs have already discontinued specific vehicle models due to R155 compliance challenges. National type approval authorities can also revoke existing approvals if conformity of production obligations are not maintained.
How does Certivo manage supplier evidence across multiple UN Regulations?
CORA launches targeted evidence collection campaigns to suppliers across all tiers, following up automatically in suppliers' native languages. Certivo accepts any evidence format—test reports, certificates, security concepts, TARA documents, and freeform declarations. AI document parsing and certificate validation extracts structured compliance data, maps it to applicable UN Regulation requirements, and flags gaps automatically through supplier risk scoring and due diligence.
Does Certivo support WP.29 alongside China's GB 44495 and EU-specific requirements?
Yes. Certivo validates supplier evidence against WP.29 UN Regulations, China's GB 44495:2024, the EU Cyber Resilience Act, and the EU General Safety Regulation simultaneously. The same supplier submission is validated across multiple regulatory frameworks—eliminating duplicate evidence collection campaigns.
How does Certivo handle CSMS recertification and conformity of production obligations?
Certivo maintains continuous tracking of CSMS and SUMS certificate validity, supplier evidence freshness, and regulatory amendments. When recertification is due, CORA automatically identifies outdated supplier evidence, triggers targeted re-collection campaigns, and generates updated audit packages.