India plans new cybersecurity rules for vehicles; rollout to begin in October

A draft notification issued on June 22, said the proposed regulations will apply to vehicle categories M (passenger vehicles), N (goods carriers), and T (trailers).

Ai generated representational image
2 min read  |  Published: 27 Jun 2026

New Delhi: The Government of India has proposed the phased rollout of cybersecurity and cybersecurity management systems to enhance the safety of automobiles manufactured in the country.

The Ministry of Road Transport and Highways (MoRTH), in a draft notification issued on June 22, said the proposed regulations will apply to vehicle categories M (passenger vehicles), N (goods carriers), and T (trailers).

Under the draft proposal, motor vehicles in categories M, N, and T fitted with at least one Electronic Control Unit (ECU), as well as L7 vehicles with Level 3 automation, as referred to in the standard, will be required to meet cybersecurity and Cybersecurity Management System (CSMS) requirements under AIS-189.

AIS-189 aligns India's regulatory framework with globally accepted practices on vehicle cybersecurity and software lifecycle management.

According to the draft notification, compliance with cybersecurity and CSMS requirements will become mandatory for vehicles with Level 3 automation and above from October 1, 2026, for new models, and April 1, 2027, for existing models.

For over-the-air (OTA)-enabled vehicles, compliance will be mandatory for all new and existing models from October 1, 2029.

The ministry has invited comments and objections from stakeholders within 30 days.

To advertise here,contact us