# Contract Upgradability (EVM)
Source: https://docs.chain.link/ccip/evm/concepts/upgradability
Last Updated: 2025-05-19

> For the complete documentation index, see [llms.txt](/llms.txt).

Chainlink Cross-Chain Interoperability Protocol (CCIP) is designed to evolve in response to new feature requests, security considerations, and the need to support additional blockchains over time. This requires an upgrade process that preserves CCIP's security while allowing iterative improvements.

**Note**: The Router contract's code is intentionally immutable, which preserves reliability, stability, and developer predictability over time. The Router remains the primary user entry point on both source and destination blockchains. Its owner can still update the OnRamp and OffRamp addresses registered for each chain.

## What Can Be Upgraded

Upgradability in CCIP primarily refers to two categories of changes:

1. **Onchain Configuration**
   - Many CCIP contracts expose public setter functions that adjust operational parameters.
   - Setters change these parameters without redeploying the contract, which helps keep CCIP secure and reliable over time.

2. **Redeploying Contracts and Redirecting References**
   - Once a smart contract is deployed, its code cannot be modified. If a new contract version (e.g., OnRamp, OffRamp, or token pool) is required, a new contract can be deployed and every existing reference updated to point to its address.
   - For example, an OffRamp address might be updated in the Router or a local mapping so that new inbound messages go through the upgraded contract.
   - With this approach, older versions remain stable while new versions are phased in.

## Implementation Process

All configuration changes to CCIP-owned contracts must pass through a Role-Based Access Control Timelock (RBACTimelock) contract. Token pools are owned by token issuers, who configure them directly.

1. **Proposals**
   - All proposals originate from a ManyChainMultiSig (MCMS), which requires multiple independent signers to sign off.
   - Signers are selected from multiple Chainlink node operators with a multi-year track record of securing billions in value within the Chainlink Network, as well as from Chainlink Labs.
   - Signers are also spread across multiple geographic locations worldwide and may be rotated periodically to help mitigate risks as they arise, such as geographic concentration.
   - A proposal can succeed through two paths:
     - **Timelocked review:** Node operators securing CCIP can veto a proposal within a defined review period. If no veto occurs, the update proceeds.
     - **Explicit approval:** A quorum of independent signers (including node operators) endorses the proposal, which allows for urgent or time-sensitive fixes.

2. **Review and Veto Window**
   - During the timelock review period, CCIP node operators can inspect the onchain proposal (e.g., one that adjusts a rate limit) and veto it if it appears incorrect. A veto stops the proposal from being executed.

3. **Execution**
   - Once the timelock period ends with no veto, the proposal becomes executable.
   - Any party can call the timelock contract to finalize the proposal (e.g., via a [timelock-worker](https://github.com/smartcontractkit/timelock-worker) script).
   - The timelock then calls the target CCIP contracts with the specified changes.

4. **Public Verifiability**
   - Information about the MCMS, including the timelock configuration, signer set, and pending proposals, is visible onchain.
   - For example, you can view the Ethereum mainnet MCMS on [Etherscan](https://etherscan.io/address/0xE53289F32c8E690b7173aA33affE9B6B0CB0012F#readContract).
   - Anyone can use onchain data to track pending proposals and node operator vetoes, and to monitor the final execution status.

## Additional Resources

- **[CCIP Owner Contracts - GitHub](https://github.com/smartcontractkit/ccip-owner-contracts)**: Further documentation and source code for the ManyChainMultiSig, timelock, and other related contracts.
- **[Etherscan: MCMS on Ethereum Mainnet](https://etherscan.io/address/0xE53289F32c8E690b7173aA33affE9B6B0CB0012F#readContract)**: Shows the current configuration, pending proposals, and signer addresses on Ethereum.
- **[Timelock Worker Repo](https://github.com/smartcontractkit/timelock-worker)**: Demonstrates how to automate final execution for proposals that have cleared the timelock period.

> **CAUTION: Disclaimer**
>
> Chainlink CCIP is an interoperability messaging protocol. Chainlink does not hold or transfer any assets. The
> performance and behaviour of applications using Chainlink CCIP may depend on coding, engineering, configuration, and
> other technical implementation choices made by developers, token issuers, Cross-Chain Verifiers, and other
> participants. Users remain responsible for evaluating, configuring, testing, deploying, operating, and maintaining
> their own applications and integrations, including assessing any applicable operational, security, technical, and
> legal or regulatory risks. Please review the [Chainlink Terms of Service](https://chain.link/terms) which provides
> important information and disclosures. By using Chainlink CCIP, you expressly acknowledge and agree to accept these
> terms. Cross-Chain Verifiers (CCVs) may be operated by third parties. The security, availability, governance, and
> operational profile of a CCV varies depending on the verifier selected. Users are solely responsible for evaluating
> any CCVs used in connection with their applications or integrations and determining whether they are appropriate for
> their intended use case. This code represents an example of using a Chainlink product or service. It is provided "AS
> IS" and "AS AVAILABLE" without warranties of any kind, has not been audited, and may omit checks or error handling.
> Each party intending to use this reference implementation must perform its own audits, security and code review, and
> testing before any production deployment and ensure the operation and performance of such code matches expectations.
> Neither Chainlink Labs, the Chainlink Foundation, nor Chainlink node operators are responsible for outcomes due to
> errors in this example or how it is deployed or operated. Use of the Chainlink Network is subject to the Chainlink
> Foundation Terms of Service, which provides important information and disclosures. By using this code, you acknowledge
> and agree to these terms.