Dailyhunt Logo
  • Light mode
    Follow system
    Dark mode
    • Play Story
    • App Story
India Proposes Mandatory Cybersecurity Rules For Connected And Autonomous Vehicles From October 2026

India Proposes Mandatory Cybersecurity Rules For Connected And Autonomous Vehicles From October 2026

Swarajya 1 week ago

The Ministry of Road Transport and Highways has proposed mandatory cybersecurity and software update management requirements for connected and autonomous vehicles through new amendments to the Central Motor Vehicles Rules, 1989.

Implementation will begin in October 2026 for new vehicle models equipped with Level 3 or higher automated driving systems, with existing models required to comply from April 2027.

The draft notification introduces Rules 125-T and 125-U, which will require manufacturers to comply with India's AIS-189 cybersecurity standard and establish a Cyber Security Management System.

The rules will apply to passenger vehicles, goods vehicles, tractors equipped with at least one Electronic Control Unit, and vehicles featuring Level 3 or higher automated driving capabilities.

Manufacturers will be required to establish a Cyber Security Management System designed to identify, assess and manage cybersecurity risks throughout a vehicle's lifecycle.

The proposed regulations bring India closer to the United Nations regulatory framework that already mandates Cyber Security Management System certification for vehicle type approval in markets such as the European Union, Japan and South Korea, where cybersecurity compliance has become a mandatory prerequisite for vehicle certification.

Industry estimates suggest meeting the new requirements could add Rs 10,000-15,000 to the cost of highly-connected vehicles through investments in secure electronics, software validation and long-term cybersecurity support.

The implementation will follow a risk-based phased approach beyond the initial October 2026 deadline.

Vehicles capable of receiving over-the-air software updates will follow, with compliance deadlines extending to April 2028 for new models and October 2028 for existing models.

All other vehicles with software update capability must comply from October 2029.

The ministry has invited public comments on the draft notification for 30 days before finalising the regulations.

The new rules are expected to strengthen cybersecurity protection and improve data safety for vehicle owners.

The next generation of vehicles will have to be built with cybersecurity at their core rather than treating it as another software feature.

Dailyhunt
Disclaimer: This content has not been generated, created or edited by Dailyhunt. Publisher: Swarajya