Japan delayed its mandatory cybersecurity and software-update rules for existing models
The transport ministry moved the September 1 application date to November 1 for vehicles already in production, citing earthquake damage to suppliers that left ordered cars unbuilt.
Japan’s Ministry of Land, Infrastructure, Transport and Tourism postponed by two months the date on which a set of new mandatory requirements applies to continuing-production vehicles, in a notice promulgated and taking effect on August 31. The requirements had been due to apply from September 1 and now apply from November 1.
The postponed list, set out in an attachment to the notice, includes mandatory cybersecurity performance and mandatory software-update performance. It also covers the introduction of digital key requirements, the mandate for collision-damage-reduction braking on passenger cars, an added automatic-actuation requirement for electric parking brakes, and the mandate for event data recorders.
The ministry gave the reason as production delay: companies involved in vehicle manufacturing were damaged by the Kumamoto earthquake, and as a result vehicles already ordered could not be built before the new requirements took effect. The change was made by amending the public notice that governs how chapters two and three of the Safety Regulations for Road Vehicles are applied. It was issued by the vehicle standards and international division of the ministry’s logistics and automobile bureau.
The notice names no company and cites no United Nations regulation, though Japan’s mandatory cybersecurity and software-update requirements were introduced as the country’s adoption of UN Regulations 155 and 156, which the ministry set out when it announced them in December 2020. The automotive chip supplier Renesas Electronics, whose Kumamoto site was affected, published what it labeled a final update on the earthquake’s impact on its operations on August 24.
Source: Japan MLIT