EU Regulation 2026/699: What Independent ECU Workshops Should Prepare
Secure vehicle access is becoming an operational issue, not just a login screen. An independent workshop can own a compatible interface and still discover that the tool maker, operator identity, job record or OEM access route is not ready for the requested programming task. A new EU regulation now gives that problem a more detailed legal framework.
Practical answer: Commission Delegated Regulation (EU) 2026/699 entered into force on June 23, 2026 and amends Annex X of Regulation (EU) 2018/858. It sets conditions under which vehicle manufacturers may secure access to OBD information while preserving standardized, non-discriminatory access for independent operators. The detailed duties are not identical for repairers, diagnostic-tool manufacturers and vehicle manufacturers. An independent shop should identify its role, inventory its access methods, confirm supplier credential plans, tighten operator authorization and retain a defensible record for every reprogramming job. Several implementation dates extend beyond entry into force, including December 23, 2026 provisions.
What Regulation 2026/699 is trying to balance
The official EUR-Lex text of Regulation 2026/699 starts from two requirements that can pull in different directions. Regulation 2018/858 requires access for independent operators to OBD information, tools, applicable software and repair and maintenance information. At the same time, modern vehicle cybersecurity rules require manufacturers to protect vehicles against unauthorized access and software changes.
The delegated regulation creates a more specific structure for authentication, traceability, diagnostic-tool security, credentials and access records. It was adopted on March 23, published in the Official Journal on June 3 and entered into force twenty days later. Entry into force does not mean that every software interface and process appeared on June 23; the annex includes later deadlines for particular information and implementation measures.
| Party | Main practical concern | What a workshop should ask |
|---|---|---|
| Vehicle manufacturer | Secure, proportionate and non-discriminatory OBD access conditions. | Which official portal and authentication route applies to this operation? |
| Diagnostic-tool manufacturer | Tool authentication, cybersecurity requirements, interoperability and access credentials. | Does the supplier support this OEM, vehicle type and requested function under the new route? |
| Independent operator | Authorized staff, legitimate repair purpose, identity evidence and job traceability. | Who is permitted to perform the job, and what evidence must be retained? |
| Individual technician | Using assigned credentials for an approved task. | Are the account, employment status and authorization current? |
The European Commission's repair and maintenance information overview explains the wider principle: independent operators should receive easy, standardized access without discrimination compared with authorized repairers.

Do not confuse a tool-maker obligation with a workshop certificate
One of the easiest mistakes is to read every cybersecurity condition as a direct certification requirement for the local repair shop. Section 6 of the new annex says vehicle manufacturers may, for relevant access categories, require the diagnostic tool to meet applicable requirements under Regulation (EU) 2024/2847 and may require the diagnostic-tool manufacturer to comply with TISAX at the specified level or ISO 27001.
That wording concerns the diagnostic tool and its manufacturer. It does not say that every independent garage must obtain ISO 27001 before reading a fault code. Different access categories carry different conditions, and the exact route depends on whether the operation merely reads information, changes vehicle state, installs software or alters configuration beyond the repair session.
For persistent software or configuration changes, a vehicle manufacturer may require alignment with its Software Update Management System implementation under UN Regulation No. 156. Again, the requirement must not exceed what the manufacturer applies to its own diagnostic tool, suppliers and organization, and it must be applied without discrimination.
Our existing authorized secure-gateway checklist covers the day-to-day identity and access workflow. Regulation 2026/699 adds the EU legal context around which parties can be asked to authenticate, record and validate access.
What may be recorded during an authorized job?
The regulation allows traceability to increase with the consequence of the operation. For relevant access, the tool manufacturer may be required to collect and store the VIN and unique diagnostic-tool identifier. Where access changes the vehicle, records may include executed diagnostic jobs, service identifiers, sub-functions, parameters and UTC timestamps.
For qualifying reprogramming operations, the vehicle manufacturer may require a richer record: network topology inspection, the initial vehicle state including ECU hardware and software versions, results of module interactions and routines, and a post-repair vehicle health check. The official text gives examples including pairing an original or manufacturer-authorized replacement part and reprogramming a module with OEM vehicle and programming software according to manufacturer instructions.
This is not permission to collect unlimited customer data. The regulation expressly preserves obligations under EU data-protection and privacy law. A workshop needs a defined purpose, controlled access, retention rules and a way to respond when an authorized party requests evidence.

Credentials may be specific and short-lived
When the stated conditions are met, the vehicle manufacturer must provide the diagnostic-tool manufacturer with sufficient credentials for the required OBD access. Credentials may be VIN-specific. The regulation sets a general minimum validity of 30 days, but where access involves a vehicle change the manufacturer may limit validity to 24 hours.
For a workshop, the lesson is not to promise a same-minute programming start merely because the cable fits. Confirm the account, vehicle, operator and operation before booking the bay. A credential window should be treated as part of job planning, alongside stable power, OEM subscription access and the correct VCI.
Why December 23, 2026 matters
The annex introduces phased availability requirements. From December 23, 2026, vehicle manufacturers must make specified software or information available to independent diagnostic-tool manufacturers for vehicle types whose type-approval certificate was first granted after September 1, 2020. The rule lists options related to manufacturer-specific applications, validated interfaces and information needed for compatible solutions.
Other deadlines differ by operation and vehicle history. For example, the regulation sets dates for sharing information needed to implement interfaces between vehicle-manufacturer and diagnostic-tool systems, with separate timing for software-update-dependent operations, other operations and certain earlier type approvals. A shop should not reduce those provisions to a single claim that “all vehicles open on December 23.” Tool suppliers still have to implement, validate and support their routes.
The J2534, DoIP and CAN FD guide helps separate interface standards from network technology. Regulation 2026/699 also mentions validation routes for independently developed VCIs using standards such as ISO 22900-2, SAE J2534-1/-2 or TMC RP1210B, but a standards label alone does not prove OEM approval for a particular job.
A preparation plan for an independent workshop
- Classify your role. Decide whether the business acts only as a repairer, distributes diagnostic tools, develops interfaces or provides remote programming. Obligations and evidence differ.
- Inventory secure-access work. List OEM portals, gateway services, pass-thru tools, remote-service providers and ECU programmers currently used. Record the exact legal entity that owns each account.
- Ask suppliers specific questions. Which manufacturers and operations are supported? Who obtains the credential? Is access VIN-specific? What happens when the credential expires? Which records can the shop export?
- Assign individual operators. Avoid shared passwords. Keep employment and authorization records current, remove access promptly when staff leave and use multi-factor authentication where provided.
- Standardize the job file. Keep customer authorization, vehicle identity, requested repair, OEM procedure version, tool ID, pre-scan, software identifiers, timestamps, programming result and post-repair health check as applicable.
- Review data protection. Define why VIN, technician identity and diagnostic records are stored, who can see them and how long they are retained. Obtain professional advice for your jurisdiction.
- Create a stop rule. If the credential source, vehicle authorization, tool compatibility or repair purpose is unclear, do not improvise a bypass. Escalate to the OEM route or qualified provider.
What this means for ECU programmers such as KT200II
Bench, boot and ECU-memory tools solve a different technical problem from secure OEM vehicle access. A programmer may support reading or writing a specific ECU family outside the vehicle, while Regulation 2026/699 addresses access to vehicle OBD information and the conditions surrounding diagnostic tools and operators. One capability does not automatically replace the other.
The ECU programmer fundamentals guide explains that distinction. Before accepting a job, identify whether the customer needs generic diagnosis, OEM software installation, authorized part pairing, configuration or ECU memory work. Then select the lawful tool and source for that operation.
This regulation does not authorize emissions defeat, odometer manipulation, immobilizer bypass or unauthorized software changes. Nor does it guarantee that a non-OEM programmer will receive secure OBD credentials. Use legitimate repair objectives and follow the controlling OEM and legal process.
Frequently asked questions
Is Regulation 2026/699 already in force?
Yes. It entered into force on June 23, 2026, twenty days after publication on June 3. Some specific availability and information-sharing duties have later dates.
Does every independent workshop need ISO 27001?
The cited provision allows requirements concerning the diagnostic tool and its manufacturer, including TISAX or ISO 27001 conditions. It does not impose a blanket ISO 27001 duty on every repair shop.
Will every secure gateway open on December 23, 2026?
No. That date applies to specified software or information obligations under defined conditions. OEM implementation, tool validation, vehicle type and operation still determine actual access.
Can credentials be tied to one vehicle?
Yes. The regulation allows VIN-specific credentials. For operations that change the vehicle, credential validity may be limited to 24 hours.
What records should a programming shop keep?
Depending on the operation, keep authorization, VIN, operator and tool identity, timestamps, original ECU state, routines performed, software result and post-repair health check. Apply lawful retention and access controls.
Does this regulation replace OEM programming instructions?
No. It governs access conditions. The current OEM procedure, approved software, compatible interface, stable power and post-programming checks remain necessary for the individual vehicle.
Prepare the process before the credential request arrives
Regulation 2026/699 does not turn secure access into a free-for-all, and it does not remove the independent aftermarket from the equation. It creates a more detailed path built around proportional security, tool validation, operator authorization and traceable work.
Use the months before the phased deadlines to question suppliers, separate access types and standardize job records. This article is an operational summary, not legal advice; confirm the authentic EUR-Lex text and obtain professional guidance where the regulation affects your business model.