CarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Notification
  • Autonomous Driving
  • Automotive Ethernet
  • BMS
  • ECU
  • EV
  • ISO/SAE 21434
  • Infotainment
  • OTA Updates
  • OBD-II
  • Pwn2Own
  • RCE
  • SDVs
  • TCU
  • UNECE R155
Cybersecurity

St. Paul pulls plate reader cameras after data reached immigration agents

Policy & Compliance

China freezes vehicle software to end patch-later OTA era

Policy & Compliance

NRMA and Lexus Australia push Canberra toward car data law

Policy & Compliance

Quebec report declares car data consent fundamentally broken

Font ResizerAa
CarThreatCarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Sign In Sign In
Follow US
© 2026 Carthreat.com. All right reserved.
Cybersecurity

India Mandates AIS-189 Cybersecurity Norms for Connected Vehicles by 2029

CarThreat Staff
Last updated: June 30, 2026 3:07 am
By
ctadmin
2 Min Read
SHARE

Phased Regulatory Roadmap

The Ministry of Road Transport and Highways (MoRTH) has released a draft notification proposing mandatory cybersecurity and software update management systems under the AIS-189 standard. The amendment to the Central Motor Vehicles Rules, 1989 introduces two key provisions: Rule 125-T for Cyber Security and Cyber Security Management Systems (CSMS), and Rule 125-U for Software Updates and Software Update Management Systems (SUMS). These requirements apply to passenger vehicles (M category), goods carriers (N category), trailers (T category), and for software updates, also cover agricultural and construction machinery.

Contents
Phased Regulatory RoadmapImpact on Automotive Cybersecurity Ecosystem

The compliance timeline unfolds in multiple phases. Level 3 and above automated vehicles must comply by October 1, 2026 for new models and April 1, 2027 for existing models. OTA-enabled vehicles with OTA-capable ECUs (excluding infotainment and tracking devices) face an April 1, 2028 deadline for new models and October 1, 2028 for existing models. By October 1, 2029, all OTA-enabled vehicles and those supporting software updates without OTA capability must comply, along with vehicles lacking any software update or OTA functionality.

Impact on Automotive Cybersecurity Ecosystem

AIS-189 aligns India’s framework with global standards for vehicle cybersecurity and software lifecycle management, targeting the growing connected vehicle and software-defined vehicle landscape. The standard mandates automakers to establish structured cybersecurity governance, risk assessment processes, incident monitoring, and secure software update mechanisms throughout a vehicle’s lifecycle. This regulatory push forces OEMs, tier-1 suppliers, and software developers to integrate cybersecurity from design through end-of-life, covering ECUs, OTA update channels, and fleet management systems. MoRTH has opened a 30-day public comment period after gazette publication before finalizing the rules, accelerating India’s transition from voluntary cybersecurity measures to mandatory compliance for connected and autonomous vehicles.

Source: ETAuto

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
TAGGED:AIS-189Connected VehiclesCSMSIndiaOTA SecuritySUMS
Share This Article
Facebook Email Copy Link

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

You Might Also Like

Cybersecurity

Microchip Adds FOTA and Key Management ICs to Meet Automotive Cyber Regulations

By
ctadmin
June 19, 2026
iBoy Netflix film scene depicting remote car hacking
Cybersecurity

From Screen to Street: How a Netflix Film Exposes Real Car Hacking Risks

By
ctadmin
May 25, 2026
Cybersecurity

Stellantis and Microsoft Expand Partnership to Tackle Automotive AI Security

By
ctadmin
May 22, 2026
Cybersecurity

US Bans Polestar EV Sales Under National Security Connected Vehicle Rule

By
ctadmin
July 1, 2026
Policy & Compliance

Quebec report declares car data consent fundamentally broken

By
ctadmin
August 23, 2026
Cybersecurity

NHTSA tells self-driving car makers to stop blocking ambulances

By
ctadmin
July 12, 2026

CarThreat

Intelligence for the EV and automotive security market
  • News
  • Features
  • Spotlight
  • Events
  • About Carthreat
  • Our Mission
  • Services
  • Contact Us
  • OBD-II
  • Automotive Ethernet
  • TCU
  • Infotainment Systems
  • SDVs
  • BMS
  • ECU Security
  • CAN Bus
  • Threat Intelligence
  • Cybersecurity
  • Digital Keys
  • Bluetooth Security
  • OTA Updates
  • Vulnerabilities
  • Relay Attacks
  • RCE
  • Data Privacy
  • EVs
  • Autonomous Driving
  • Pwn2Own Automotive
  • ISO/SAE 21434
  • UNECE R155
  • Regulations

© 2026 Carthreat.com. All right reserved.  Privacy Policy | Legal

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?