Automotive cybersecurity forecasts disagree because the category itself is slippery, and the newest figures from Transparency Market Research do not survive a calculator. Apply the 11.9 percent annual growth the firm advertises to its $3.8B base for 2024, and 2035 arrives at roughly $13.1B rather than the $14.2B headline.
Rival research houses cannot even settle the present. Across four competing forecasts, 2025 lands anywhere between $3.87B and $7.23B.
Part of that spread is definitional. Some analysts tally an intrusion-detection module inside a gateway ECU. Others fold in the fees a consultancy charges for a compliance review, or the cost of a crypto chip in a telematics box. Redraw the boundary and the total moves with it.
Attackers make the news, but regulators move the money. Europe’s R155 and R156, the UN rules on security management and software updates, entered into force in January 2021. Mandatory compliance arrived for new vehicle types in July 2022, and it extended to every newly built vehicle from July 2024. Architectures engineered before that point often failed certification without a redesign. Porsche tied the constrained European availability of its mid-engine 718 to those requirements, ended production of the current car in the fourth quarter of 2025, and pointed to the resulting supply gaps when first-half 2025 deliveries came in soft.
The 2015 Uconnect case is the cautionary template. FCA recalled about 1.4 million vehicles from model years 2013 through 2015 fitted with 8.4-inch radios, and the remedy reached owners as USB drives in the mail. R156 exists so a fleet can be patched over the air instead.
US supply-chain restrictions now push budgets the same way, with software rules beginning in model year 2027 and hardware rules from 2030, favoring secure update plumbing over anti-hacking gadgetry.