For decades, vehicle safety has been measured by airbags, crash structures and braking distances. But as modern vehicles evolve into software-defined machines, a new threat has emerged—cybersecurity. Today's connected cars exchange data with smartphones, cloud platforms, charging infrastructure and even other vehicles. They receive over-the-air (OTA) software updates, support remote unlocking, AI-powered voice assistants and connected diagnostics. In this new reality, protecting a vehicle is no longer just about preventing collisions—it's about preventing cyberattacks.
India's proposed amendments to the Central Motor Vehicles Rules (CMVR) recognise this shift. Through the introduction of Rule 125-T and Rule 125-U, the government proposes making compliance with AIS-189 (Cyber Security Management System) and AIS-190 (Software Update Management System) mandatory for specified vehicle categories. In simple terms, cybersecurity will no longer be a value-added feature—it will become a legal requirement for vehicle approval.
The burden falls where it should—on manufacturers
One of the most progressive aspects of the draft regulations is that they place accountability squarely on the vehicle manufacturer rather than the customer.
OEMs will be required to demonstrate that cybersecurity has been engineered into every stage of the vehicle lifecycle—from design and production to software updates and post-sale monitoring. Before a vehicle reaches the showroom, manufacturers must establish a certified Cyber Security Management System (CSMS), conduct structured Threat Analysis and Risk Assessments (TARA), implement secure electronic architectures, continuously monitor emerging threats and maintain the capability to respond rapidly when vulnerabilities are discovered.
Software updates will also undergo far greater scrutiny. Every OTA update must be authenticated, validated for integrity, assessed for safety implications and remain fully traceable throughout the vehicle's lifetime. That means software can finally be treated with the same rigour as mechanical safety systems.
For Indian OEMs, this represents a cultural shift. Cybersecurity is no longer an IT function—it becomes a boardroom responsibility.
Cybersecurity doesn't stop at the factory gate
Perhaps the most important takeaway from the draft is that cybersecurity cannot be outsourced.
While legal liability rests with manufacturers, compliance depends on an entire ecosystem of Tier-1 suppliers, software vendors, semiconductor manufacturers, battery suppliers, telematics providers and testing agencies. Every connected component now contributes to the vehicle's cybersecurity posture.
OEMs must ensure suppliers follow recognised engineering practices, validate third-party software and manage risks introduced through open-source libraries and connected services. This mirrors global automotive cybersecurity standards and recognises a simple truth: a vehicle is only as secure as its weakest supplier.
For India's rapidly growing EV ecosystem, where numerous startups and component manufacturers are entering the market, this supply-chain discipline may prove even more valuable than the regulations themselves.
Drivers have responsibilities too
The regulations do not penalise owners who ignore software updates or install aftermarket accessories. Yet the effectiveness of the framework depends heavily on responsible user behaviour.
Ignoring security updates leaves known vulnerabilities unpatched. Installing unofficial ECU tunes or firmware can bypass cryptographic protections and even prevent legitimate security patches from being installed. Cheap Bluetooth-enabled accessories, uncertified OBD-II devices or poorly secured battery management systems may introduce entirely new attack surfaces.
Modern vehicle ownership increasingly resembles smartphone ownership. Just as users routinely update their phones, protect online accounts and avoid installing unknown applications, connected vehicles demand similar digital hygiene. Strong authentication, authorised software, secure companion apps and responsible servicing are becoming part of everyday vehicle maintenance.
Recent incidents show why regulation matters
The timing of these regulations is no coincidence.
Recent cybersecurity incidents involving Jaguar Land Rover's global operations, repeated customer data breaches affecting Hyundai India and Zoomcar, and the BAT-BMS vulnerability that allowed pranksters to remotely immobilise electric rickshaws demonstrate that automotive cyber risks are no longer theoretical.
Perhaps the BAT-BMS incident was the strongest wake-up call. It wasn't a sophisticated nation-state cyberattack. It exploited unsecured Bluetooth settings and default credentials, allowing vehicles to be disabled using freely available mobile applications. While premium passenger vehicles remained largely unaffected due to stronger security architectures, the episode exposed significant vulnerabilities across lower-cost mobility platforms and aftermarket components.
It also highlighted an important reality: banning vulnerable mobile applications addresses only the symptom. The real solution lies in secure-by-design engineering, authenticated communications and lifecycle cybersecurity governance—the very principles embedded within AIS-189 and AIS-190.
More than compliance
When viewed narrowly, these regulations introduce another layer of certification, but if viewed strategically, they represent something much bigger.
Connected vehicles are rapidly becoming extensions of our digital lives. They know where we live, where we work, what are our points of interest, what’s our driving style and behaviour, how we drive and increasingly control critical vehicle functions through software. Consumer confidence in this connected future depends entirely on trust.
India's proposed cybersecurity framework is therefore not merely about satisfying regulators. Responsibility now extends beyond manufacturing reliable vehicles to ensuring continuous cyber resilience throughout the vehicle's operational life. It is about creating confidence in connected mobility, protecting consumers from evolving digital threats and ensuring Indian manufacturers remain globally competitive as international cybersecurity regulations become the norm.
Manufacturers must lead through certified governance, suppliers must deliver secure components, technology partners must support trusted software ecosystems, and vehicle owners must adopt responsible digital practices.
The message is clear. Automotive safety is no longer defined solely by crash tests and crumple zones. In the connected era, a secure line of software code may be just as important as a strong chassis. India's automotive industry has successfully embraced emissions regulations, advanced safety standards and electrification. Cybersecurity for mobility is the next frontier—and one that cannot arrive soon enough.