News

MoRTH Proposes Mandatory Cybersecurity Framework for Connected and Autonomous Vehicles

The Ministry of Road Transport and Highways (MoRTH) has proposed amendments to the Central Motor Vehicles Rules, 1989, to introduce mandatory cybersecurity and software update management requirements for connected and technologically advanced vehicles. The initiative aims to strengthen vehicle security in response to the increasing cyber risks associated with software-driven and connected automobiles.

Introduced through a draft notification under Section 110 of the Motor Vehicles Act, 1988, the proposed framework adds Rules 125-T and 125-U to the Central Motor Vehicles Rules, 1989. Rule 125-T requires manufacturers to establish a Cyber Security Management System (CSMS) in accordance with India’s AIS-189 cybersecurity standard, while Rule 125-U mandates a Software Update Management System (SUMS) under the corresponding AIS-190 standard. The regulations are intended to ensure that cybersecurity risks are identified, assessed and managed throughout a vehicle’s lifecycle.

Key Regulatory Proposals

  1. Mandatory Cyber Security Management System (CSMS): Manufacturers will be required to establish a CSMS to manage cybersecurity risks throughout the lifecycle of connected and automated vehicles.
  2. Phased Implementation: Compliance will commence from October 2026 for new vehicle models equipped with Level 3 or higher automated driving systems, while existing models will be required to comply from April 2027. Vehicles capable of receiving over-the-air (OTA) software updates will be brought under the framework in subsequent phases through 2028, followed by all remaining software-enabled vehicles by October 2029.

The proposed rules will apply to passenger vehicles, goods vehicles, tractors equipped with at least one Electronic Control Unit (ECU), and vehicles incorporating Level 3 or higher automated driving capabilities.

The proposed framework is intended to align India’s automotive cybersecurity regime with international practices adopted in jurisdictions such as the European Union, Japan and South Korea, where cybersecurity compliance forms part of vehicle certification requirements.

The regulations are expected to require investments in secure electronics, software validation and long-term cybersecurity support, while enhancing vehicle safety and protecting consumers against evolving cyber threats as vehicles become increasingly software-driven.