The clock has started ticking for India’s automotive industry, and for buyers of its next generation of connected vehicles.
From software-rich vehicles such as the Tata Harrier EV, Mahindra XEV 9e, BE 6, Tata Curvv.ev and Hyundai Creta Electric to connected buses, trucks and smart tractors, the next generation of vehicles will have to be built with cybersecurity at their core rather than treating it as another software feature.
Industry estimates suggest meeting the new requirements could add ₹10,000-15,000 to the cost of highly-connected vehicles through investments in secure electronics, software validation and long-term cybersecurity support.
In return, buyers stand to gain stronger protection against cyber threats, safer over-the-air (OTA) software updates, better protection of vehicle data and faster software fixes throughout a vehicle’s life, while automakers and component suppliers will have to redesign everything from electronic architecture to software development and long-term lifecycle support.
Driving this shift is a draft notification issued by the Ministry of Road Transport and Highways (MoRTH) on June 22, proposing the insertion of Rules 125-T and 125-U into the Central Motor Vehicles Rules, 1989.
The proposal would make compliance with AIS-189 for Cyber Security Management Systems (CSMS) and AIS-190 for Software Update Management Systems (SUMS) mandatory for vehicle type approval, with implementation beginning on October 1, 2026, for new Level 3 automated vehicles before expanding in phases to connected passenger vehicles, commercial vehicles, tractors and construction equipment through October 2029, aligning India with cybersecurity regulations already in force across the European Union, Japan and South Korea.
Source link







