Skip to content
MotorBeast
  • BMW
  • Geely
  • Mercedes
  • Stellantis
  • Tata
  • Volkswagen

Modern car repair is no longer just about fixing the fault; it is about getting the manufacturer’s permission to finish the job.

Across the UK aftermarket, a growing number of repairs now depend on secure gateways, SFD unlocks, cloud-based programming, online coding, certificates, tokens and factory portal access. A garage can fit the part, identify the fault and still be blocked from completing the work because the vehicle will not accept the repair without a live authorisation session or approved software path. That is the real shift in modern vehicle repair: the physical job may happen in the workshop, but the final authority increasingly sits with the manufacturer.

Key point

Repair has become permission-based. On many newer vehicles, replacing the hardware is no longer enough. The workshop must also gain access to coding, adaptation, calibration or security-controlled setup functions before the car will properly recognise the repair.

UK trade bodies have been warning for years that independent garages were being squeezed out of a level playing field. The Independent Garage Association says the UK’s route into the SERMI framework followed a 17-year campaign to secure proper access to security-related repair and maintenance information, underlining how long this battle has been running in the background of the aftermarket through the official UK SERMI rollout. That alone tells you this is not a niche complaint from a few specialists. It is a structural change in how cars are repaired.

What makes the issue so serious is that modern vehicles increasingly split the repair process into two parts. The first part is still traditional workshop work: diagnosis, removal, fitting, testing and verification. The second part is digital permission: coding the module, running the adaptation, unlocking the protected function, pairing the system or completing the calibration. If that second part is withheld, the garage can do the physical labour and still be unable to return a properly repaired car to the customer.

How the workshop lost control of the final stage of the repair

The old diagnostic model was far simpler. Plug in, read the codes, confirm the fault, replace the failed part, clear the memory and road-test the vehicle. That world has been eroded by a new one in which deeper functions sit behind manufacturer-controlled systems. Advanced diagnostics are increasingly tied to online accounts, active subscriptions, approved interfaces and security-checked workflows. One of the clearest summaries of that change came in a UK trade analysis which described diagnostics as a pay-to-play environment, with workshops now juggling subscriptions, remote programming dependencies and online permissions across multiple brands as the trade itself has openly acknowledged.

That matters because many normal-looking repairs are no longer normal in the background. A steering rack, angle sensor, battery, ADAS radar, camera, gateway, immobiliser component or control module may all need some combination of coding, relearn, calibration or configuration after the part is physically installed. In older terms, the part was the repair. In modern terms, the part is often only the start of the repair.

The legal fight has started to catch up with that practical reality. A detailed legal review of the EU’s latest delegated regulation says Europe is finally trying to define where legitimate cybersecurity ends and unlawful restriction begins, especially when access to OBD and repair information is made harder by manufacturer-imposed registration, server connections or approval barriers under Delegated Regulation (EU) 2026/699. That is the bigger context: this is no longer just a workshop gripe. It has become a regulatory issue.

What Is a Secure Gateway in a Modern Car?

Right to Repair for Cars in the UK Explained

Volkswagen Group made the problem impossible to ignore

If one manufacturer group has become the public face of this issue, it is Volkswagen Group. VAG’s SFD system, short for Schutz Fahrzeug Diagnose, restricts functions such as coding, adaptations and parameter changes unless the technician has the right authorisation to unlock those protected modules. A UK diagnostics supplier’s explanation of SFD and SFD2 lays out the basic model clearly: the workshop can often read data and faults, but deeper functions are blocked unless the system is authenticated and released by the backend through VAG’s SFD protection model.

The significance of that cannot be overstated. SFD is not just a technical wrinkle on a few rare vehicles. It is one of the clearest demonstrations that vehicle repair can be divided into open and closed layers. The open layer lets you inspect and observe. The closed layer controls whether you are allowed to alter, match, code or complete. Once that idea became normal on a large manufacturer group’s vehicles, the rest of the industry had a template.

That is why VAG matters in this conversation even beyond its own brands. It normalised the idea that the car can physically be in your workshop while the real control sits somewhere else. That is the business model change at the heart of the secure-gateway era.

Internal link opportunity: VAG SFD and SFD2 Explained for UK Garages
Suggested slug: /vag-sfd-sfd2-explained-uk-garages/

Mercedes-Benz moved down the same road

Mercedes-Benz is another clear example of how protected access now affects ordinary workshop work. The strongest UK trade evidence is not abstract. In a report on problems submitted to UK AFCAR, one garage described a Mercedes A-Class radar issue where diagnosis pointed to the control unit, but the replacement could not be completed because it required a Mercedes OEM and C5 SCN login, which is exactly the sort of barrier independents say turns straightforward technical competence into a dealer-controlled process according to the evidence gathered by UK AFCAR.

That example matters because it shows the real-world shape of the problem. The issue is not that the garage failed to identify the fault. The issue is that the workshop could reach the diagnosis and still be digitally fenced out of the final stage. That is what turns a repair restriction into a market-control issue. Customers do not care which login page blocked the job; they care that the car now needs dealer-style access to complete work that a competent independent already understands.

Mercedes is not alone in that behaviour, but it is one of the brands that makes the problem easy to explain. When a repair cannot be finalised without a protected OEM login, repair independence has already been weakened.

Internal link opportunity: Mercedes SCN Coding and Secure Access Explained
Suggested slug: /mercedes-scn-coding-secure-access-explained/

BMW uses different language, but the same control logic

BMW is sometimes discussed differently because it does not always appear in aftermarket marketing under the same SGW or SFD labels used elsewhere. That should not be mistaken for openness. BMW’s repair ecosystem is firmly part of the same wider shift towards online software, portal-based access and manufacturer-controlled service functions. BMW’s own Aftersales Online System is explicitly positioned as the route for independent workshops carrying out repair and maintenance work on BMW Group vehicles, which shows how access is increasingly channelled through the manufacturer’s digital environment rather than left as a straightforward local workshop function via BMW’s official AOS platform.

That matters because BMW is often the type of brand where a simple-looking job stops being simple once software acceptance enters the picture. Steering-related components, sensors, modules and other electronically managed parts may be physically replaced without difficulty but still require the right follow-up routine before the car will accept them properly. The part may fit. The system may not. That is the modern distinction.

It also explains why so many independents feel the job has changed beneath their feet. They are not being beaten by the mechanical complexity alone. They are increasingly being forced into a manufacturer-run digital corridor in order to finish work that used to be completed at workshop level.

Internal link opportunity: BMW Online Coding, ISTA and Independent Garage Access
Suggested slug: /bmw-online-coding-ista-independent-garage-access/

Stellantis, FCA and the secure-gateway template

Stellantis deserves separate attention because the FCA side of the business helped normalise secure-gateway restriction long before many people outside the trade had heard the term. The basic model was simple and effective: leave broad visibility in place, but put critical actions behind an authorised path. Once that model proved workable, it showed the rest of the industry how access control could be expanded without openly saying independent repair was being shut out.

The brand spread involved is one reason this matters so much. A major European diagnostics supplier now sells a security-gateway package covering VAG brands, FCA-origin brands, Renault and Dacia, while explicitly listing manufacturers such as Chrysler, Dodge, Jeep, Alfa Romeo, Fiat, Lancia and Maserati inside that managed-access environment through its own aftermarket SGW coverage. Once access control becomes a product line in its own right, the direction of travel is obvious.

The important point is not that every brand uses exactly the same architecture. It is that the underlying commercial logic is shared. Repair functions that were once part of ordinary workshop capability are gradually being converted into approved services, restricted routines or authenticated transactions.

This is now much bigger than BMW, Mercedes and VAG

One of the easiest mistakes to make is to treat this as a three-brand story. It is not. The manufacturers and brand groups tied to secure access, security-related functions, portal-based repair pathways or wider controlled access models now stretch far beyond the headline German names. Even the official UK SERMI rollout makes that obvious, because the committed list includes brands such as Ford, Jaguar, Land Rover, Nissan, Peugeot, Toyota, Vauxhall, Volvo and a long run of Stellantis marques alongside Mercedes-Benz as reported when SERMI officially went live in the UK.

That list should be read carefully. It does not mean every one of those brands behaves in exactly the same way, or that every workshop problem is caused by the same technical gate. Some issues involve secure gateways. Some involve security-related authorisation. Some involve service records, coding rights, OEM software access or protected programming routines. But from the independent workshop’s point of view, those are variations on the same theme: more of the repair chain is now managed by the vehicle manufacturer.

  • The workshop still does the labour.
  • The workshop still buys the tooling.
  • The workshop still carries the customer relationship.
  • But the manufacturer increasingly controls whether the final digital step can happen.

Why this gets expensive fast

If an independent garage must maintain active subscriptions, secure-gateway access, identity verification, approved interfaces, remote-programming support and stable internet just to complete ordinary repairs, those costs will show up somewhere. They reappear as higher labour charges, diagnostic fees, outsourced programming costs, delays and more work pushed back to dealer networks.

Why Secure Gateways Make Car Repairs More Expensive

Toyota is different, but not innocent

Toyota should not be lazily treated as a pure right-to-repair hero. It is part of the wider access-controlled world, and it appears on the UK SERMI commitment list. Even so, it does not currently stand out in the same way as VAG, Mercedes or FCA-origin secure-gateway systems in the aftermarket evidence reviewed here. Toyota’s model still appears more closely tied to subscription-based technical access and Techstream-led OEM pathways than to being one of the most visible symbols of the SGW/SFD unlock economy.

A good example is the European Toyota technical portal itself, which states that some services are available only with paid subscription. That is still a control model, but it is a different kind of control from the increasingly obvious secure-gateway marketplace surrounding some rival groups through Toyota-Tech Europe. The distinction matters. Toyota has not stayed completely open, but it has not become one of the clearest faces of this particular repair nightmare either.

There is an irony here that says a lot. When Toyota hardware overlaps with BMW-derived systems, the access story can become much more BMW-like. That is a useful reminder that this problem is less about brand mythology and more about the software architecture hiding underneath the badge.

SERMI helps, but it does not restore the old workshop world

SERMI matters because it creates a legitimate framework for approved independents to access security-related information and functions that were previously much harder to reach. That is an important correction. But it is not a time machine. It does not take the trade back to the era when a skilled independent could simply plug in and get on with the work on commercially reasonable terms. It is better understood as a controlled route through an already controlled system.

That is why the argument does not end with “security is necessary”. Security may be necessary. The real question is whether the security model is proportionate, non-discriminatory and compatible with genuine competition in repair. Once ordinary workshop capability is converted into a paid, approved, online service layer, the line between cybersecurity and market control becomes very thin indeed.

The bottom line

Manufacturers will keep defending these systems as protection against tampering and cyber threats, and some of that argument is obviously legitimate. Modern cars do need stronger digital protection than old ones. The problem is what happens when that logic expands beyond real security needs and starts swallowing normal repair functions. At that point, the customer loses choice, the independent loses ground and the dealer-aligned digital ecosystem wins by default.

So yes, BMW, Mercedes-Benz and Volkswagen Group are central to this story. But the broader truth is bigger than any one badge. The industry is moving towards a model in which repair is no longer just a workshop capability but a licensed digital privilege. That is the real issue, and it is already shaping how much UK motorists pay, where they can take their cars and whether independent garages are allowed to compete on fair terms.

Verdict

Secure gateways are no longer a future problem. They are already changing who can complete modern repairs, how long those repairs take and how much they cost. The more manufacturers push coding, calibration and acceptance routines behind controlled online systems, the less independent repair operates like a real open market.


Sources

  • Independent Garage Association – SERMI Goes Live in the UK
  • Autotechnician – The evolution of automotive diagnostics
  • Noerr – Delegated Regulation and secure gateways
  • Thinkcar UK – VAG SFD Unlock
  • Aftermarketonline – UK AFCAR findings on restricted access
  • BMW Group – Aftersales Online System
  • LAUNCH Europe – Security Gateway coverage
  • Fleet News – UK independents can now access essential vehicle data
  • Toyota-Tech Europe
  • About Us
  • Affiliate Disclosure
  • Contact Us
  • Privacy Policy
  • Testing
  • Accessibility

© 2026 MotorBeast Motorbeast.Org

Scroll to top
  • BMW
  • Geely
  • Mercedes
  • Stellantis
  • Tata
  • Volkswagen
Search