CarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Notification
  • Autonomous Driving
  • Automotive Ethernet
  • BMS
  • ECU
  • EV
  • ISO/SAE 21434
  • Infotainment
  • OTA Updates
  • OBD-II
  • Pwn2Own
  • RCE
  • SDVs
  • TCU
  • UNECE R155
Cybersecurity

St. Paul pulls plate reader cameras after data reached immigration agents

Policy & Compliance

China freezes vehicle software to end patch-later OTA era

Policy & Compliance

NRMA and Lexus Australia push Canberra toward car data law

Policy & Compliance

Quebec report declares car data consent fundamentally broken

Font ResizerAa
CarThreatCarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Sign In Sign In
Follow US
© 2026 Carthreat.com. All right reserved.
Cybersecurity

India Mandates AIS-189 Cybersecurity Norms for Connected Vehicles by 2029

CarThreat Staff
Last updated: June 30, 2026 3:07 am
By
ctadmin
2 Min Read
SHARE

Phased Regulatory Roadmap

The Ministry of Road Transport and Highways (MoRTH) has released a draft notification proposing mandatory cybersecurity and software update management systems under the AIS-189 standard. The amendment to the Central Motor Vehicles Rules, 1989 introduces two key provisions: Rule 125-T for Cyber Security and Cyber Security Management Systems (CSMS), and Rule 125-U for Software Updates and Software Update Management Systems (SUMS). These requirements apply to passenger vehicles (M category), goods carriers (N category), trailers (T category), and for software updates, also cover agricultural and construction machinery.

Contents
Phased Regulatory RoadmapImpact on Automotive Cybersecurity Ecosystem

The compliance timeline unfolds in multiple phases. Level 3 and above automated vehicles must comply by October 1, 2026 for new models and April 1, 2027 for existing models. OTA-enabled vehicles with OTA-capable ECUs (excluding infotainment and tracking devices) face an April 1, 2028 deadline for new models and October 1, 2028 for existing models. By October 1, 2029, all OTA-enabled vehicles and those supporting software updates without OTA capability must comply, along with vehicles lacking any software update or OTA functionality.

Impact on Automotive Cybersecurity Ecosystem

AIS-189 aligns India’s framework with global standards for vehicle cybersecurity and software lifecycle management, targeting the growing connected vehicle and software-defined vehicle landscape. The standard mandates automakers to establish structured cybersecurity governance, risk assessment processes, incident monitoring, and secure software update mechanisms throughout a vehicle’s lifecycle. This regulatory push forces OEMs, tier-1 suppliers, and software developers to integrate cybersecurity from design through end-of-life, covering ECUs, OTA update channels, and fleet management systems. MoRTH has opened a 30-day public comment period after gazette publication before finalizing the rules, accelerating India’s transition from voluntary cybersecurity measures to mandatory compliance for connected and autonomous vehicles.

Source: ETAuto

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
TAGGED:AIS-189Connected VehiclesCSMSIndiaOTA SecuritySUMS
Share This Article
Facebook Email Copy Link

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

You Might Also Like

Cybersecurity

Ethernet flood via OBD port stalls cars and blacks out displays

By
ctadmin
August 6, 2026
Car NewsCybersecurity

Critical buffer overflow in EV charging protocol puts vehicles at risk

By
ctadmin
July 18, 2026
Cybersecurity

Thieves jam fleet trackers as European van thefts spike

By
ctadmin
August 19, 2026
Cybersecurity

Stealthy camera delay attack fools self-driving object detection

By
ctadmin
August 12, 2026
Cybersecurity

Repeated patterns hijack depth readings of car stereo cameras

By
ctadmin
August 13, 2026
Cybersecurity

Patch mechanism updates embedded ECUs without dual-bank flash

By
ctadmin
August 13, 2026

CarThreat

Intelligence for the EV and automotive security market
  • News
  • Features
  • Spotlight
  • Events
  • About Carthreat
  • Our Mission
  • Services
  • Contact Us
  • OBD-II
  • Automotive Ethernet
  • TCU
  • Infotainment Systems
  • SDVs
  • BMS
  • ECU Security
  • CAN Bus
  • OTA Updates
  • Vulnerabilities
  • Relay Attacks
  • RCE
  • Threat Intelligence
  • Cybersecurity
  • Digital Keys
  • Bluetooth Security
  • ISO/SAE 21434
  • UNECE R155
  • Regulations
  • Data Privacy
  • EVs
  • Autonomous Driving
  • Pwn2Own Automotive

© 2026 Carthreat.com. All right reserved.  Privacy Policy | Legal

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?