Skip to main content

India Drafts Mandatory Cybersecurity, Software-Update Rules for Connected and Autonomous Vehicles

Draft MoRTH rules make cybersecurity (AIS-189) and software-update management (AIS-190) mandatory for M, N, T and other vehicle categories, aligning India with EU, Japan and South Korea norms through a phased rollout starting October 2026.

Shahkar AbidiBy Shahkar Abidi calendar 27 Jun 2026 Views icon1851 Views Share - Share to Facebook Share to Twitter Share to LinkedIn Share to Whatsapp
India Drafts Mandatory Cybersecurity, Software-Update Rules for Connected and Autonomous Vehicles

The Ministry of Road Transport and Highways has published draft rules that would, for the first time, make cybersecurity and software-update management legal requirements for certain categories of motor vehicles, moving the country toward a regulatory standard already in force across the European Union, Japan and South Korea.

The notification proposes inserting two new provisions—Rules 125-T and 125-U—into the Central Motor Vehicles Rules, 1989. The draft is open for public comment for 30 days before the government finalizes it.

What the rules require:

Rule 125-T covers cybersecurity. Any vehicle in categories M, N or T (passenger vehicles, goods vehicles and tractors) equipped with at least one electronic control unit, and category L7 vehicles with Level 3 automation or higher, will have to comply with AIS-189, India's domestic cybersecurity standard, and maintain what regulators call a Cyber Security Management System, a structured process for identifying and managing security risks across a vehicle's lifecycle.

Rule 125-U covers software updates. It applies to a broader set of categories—M, N, T, A and C—and requires compliance with AIS-190, which governs how software updates are delivered and tracked through a Software Update Management System.

Both standards will remain in effect only until the Bureau of Indian Standards issues its own formal specifications, at which point those will take over.

Catching up to a global baseline:

The move brings India in line with the United Nations framework, which already requires CSMS and SUMS certification for vehicle type approval in the EU, Japan and South Korea. Those markets have treated cybersecurity as a type-approval condition—not an optional feature—for several years.

A phased rollout that prioritizes risk:

Rather than applying uniformly, the rules will be phased in based on risk exposure. Vehicles with Level 3 automation and above face the earliest deadlines—October 2026 for new models and April 2027 for existing ones. Vehicles capable of over-the-air updates follow, with deadlines extending to April 2028 and October 2028. Every other vehicle with any form of software-update capability, whether OTA or not, falls under an October 2029 deadline.
 

RELATED ARTICLES

Uno Minda Launches Compact 4-Channel Amplifier

auther Arunima Pal calendar29 Sep 2026

The new amplifier delivers up to 150W per channel and can be installed in space-constrained areas such as under the seat...

Rapidise to Quadruple Manesar Manufacturing Capacity with Rs 200 Crore Investment

auther Arunima Pal calendar29 Sep 2026

Rapidise’s new 120,000 sq ft Manesar facility will add SMT and automated manufacturing capacity for high-volume electron...

Cummins India Launches REDEFINE 2026 Case Study Competition

auther Arunima Pal calendar29 Sep 2026

Cummins India’s ninth REDEFINE edition will see students from 11 B-schools tackle growth opportunities across industrial...