SERMI AND HIGH POWER
June 1, 2026

SERMI AND HIGH POWER

A new system was launched in Europe to access vehicle manufacturer operated websites that host repair information for their own models. It is called ‘SERMI’, and that is Security-related Repair Maintenance Information.

The process for approval is similar to security service/locksmiths, which requires verification as well as approval for both the business and the people working in the business. It is a new, additional gateway to get hold of information.

Within Europe there are appointed ‘agents’ who deal with the registration, verification and approval. In the UK that is the Independent Garage association (‘IGA’) who operate under the Retail Motor Industry Federation (known as ‘RMI’ not to be confused with the South African RMI.

The problem

For some time there has been little protection from criminal activity via the diagnostics socket (‘OBDII’/‘EOBD’) where nefarious individuals can do the same things as a legitimate repairer normally to hide pre-existing damage or to mis-represent the milage covered. Indeed, just ‘making the lights go out’ on the instrument panel has long been a major reputational problem for vehicle manufacturers, insurers, warranty companies and… the people who pay for the whole show… the public.

Every time new, better, security processes were introduced, they were vehicle manufacturer specific and quirky. This meant unless a shop used vehicle manufacturer approved diagnostic tools, they could find accessing the vehicle data system would involve moving the wreck or recently completed repaired vehicle back and forth to a local manufacturer approved repair shop. Time consuming, expensive and, let’s face it, not always successful.

The root cause was and is not all vehicle repair outlets are as capable as a collision repairer, and since their entire activity is not routine maintenance, the components and systems requiring software access are beyond what most maintenance outlets come across. The competence block is seriously frustrating and expensive.

The proposed solution

Enter SERMI. This has been more than 20 years in the making. It places the collision repairer, upon signing up, with the ability to access repair information direct from the vehicle manufacturer website, along with software access. It does not change the way the vehicle manufacturer websites work.

So, that means: Payment of annual fees for SERMI membership for the business. The approval is valid for five years and includes two independent audits.

Payment of annual fees for SERMI registered employees of the same business. The employee will undergo a security clearance check for criminal activities, which depending on the approval authority is valid for some years. The employee can only access information in connection with their employer’s business.

The approved business must sign and return a declaration the company pursues ‘legitimate business activities’.

From the IGA: In accordance with the SERMI Standard, this means that the business does not offer services which would ‘negatively impact the emissions performance of a vehicle’. This includes: Deactivating or removing pollution control devices or emission control systems, or degrading their performance or concealing their malfunction

Installing defeat devices (any element of design which senses temperature, vehicle speed, engine speed (RPM), transmission gear, manifold vacuum or any other parameter for the purpose of activating, modulating, delaying or deactivating the operation of any part of the emission control system, that reduces the effectiveness of the emission control system under conditions which may reasonably be expected to be encountered in normal vehicle operation and use).

Installing defeat strategies (an emission control strategy that reduces the effectiveness of the emission controls under ambient or engine operating conditions encountered either during normal vehicle operation or outside the type-approval test procedures).

Deactivating, removing or tampering with devices for the monitoring of the consumption of fuel or electric energy, or tampering with odometer readings.

The SERMI process requires the following information and is kept for up to five years:

  • Vehicle registration number
  • Vehicle make and model
  • Recorded vehicle mileage
  • The reason for the repair
  • A customer signature (owner and/or the person presenting the vehicle).

The reality: Fees are still due to access vehicle manufacturer websites, along with specific application processes.

Vehicle manufacturer software updates are available, via the paid access to their websites.

Use of third-party diagnostics such as Target, Bosch, Texa et al is possible – they must agree to SERMI as well.

Access to such information is a vital service and source of profitable business for collision repairers, but this has to be weighed in light of the operational on-cost.

Why should we care?

There are several aspects. In Europe right to access vehicle repair information by independent automotive aftermarket businesses in exchange for fees was made law under ‘sister’ legislation related to Euro 5 emission regulations. This was met with qualified joy by the vehicle manufacturers, who would rather purge as many independents from the ‘value chain’ as possible – even if they do not have the capacity or in some cases the capability to offer this service. There have been many attempts to subvert this law, which was adopted by the UK when it left the European Union.

SERMI opens up the debate once more. In the short term some vehicle manufacturers use the following logic: While originally the ‘diagnostics port’ was deigned to access the powertrain emission control system, with the correct type of equipment and expertise it can access the entire data system of a vehicle.

Thus, the port should be ‘locked’ to apart from those who are approved to access it (see SERMI).

This means everything from system resets to software updates – many, many vehicles do not have over air software update capability right now – is in effect locked.

Anyone accessing this who is not SERMI registered is thus some sort of potential criminal. 

It’s only the beginning

The initiation of SERMI on 1st April 2026 has initiated the wider aftermarket to become involved in security clearance to access information, quite often for the very first time. In the short term some vehicle manufacturers are stuffing everything they can behind the SERMI front, which subverts       ‘Euro 5’ access rights, and mayhem is underway. Could changing the oil be a ‘security’ matter?

There is the clash between an automotive business model built on selling bits, often specifically ‘unique’ (non-standardised), and the electronics business more interested in selling vapourware (converging on a few major standards).

That’s the direction of travel. The answer is not very clear, except the make/model/body shape specific parts are narrowing due to ruinous manufacturing costs due to unsustainable market conditions undermining return on investment let alone profit. The question is – what will come out the other side? Clue: high volume models like Toyota Corolla et al are in the past …

Meanwhile, removal or refitting many parts on the vehicle are not security related. So, why should some vehicle manufacturers claim this is the case in order to shape the automotive aftermarket as they see fit?

This reflects on the misbehaviour of some vehicle manufacturers in regard to SERMI – short-term protectionism, which won’t work, that will kill their business in the medium term. The European Commission, European Union and the European Parliament are once more asleep at the wheel, which could result in a powerful tool to combat crime – in this case SERMI – damage legitimate collision repair businesses and accelerate the rate of total losses. What’s needed is a relationship between systems that should be protected by SERMI, and systems that do not require such protection – right now, that debate has not started.

The last thing anyone needs is to accelerate the rate of total loss.

By Andrew Marsh