Under the proposed amendments to India's motor vehicle regulations, vehicle manufacturers will be required to demonstrate that their vehicles meet defined cybersecurity standards before they can be sold. 

The automotive industry is rapidly embracing connected and software-defined vehicles, making Automotive Cybersecurity as critical as traditional safety features like airbags and braking systems. Modern vehicles communicate with cloud platforms, smartphones, charging infrastructure, and intelligent transport networks while supporting Over-the-Air (OTA) updates, remote management, and AI-powered features. Although these innovations enhance convenience and performance, they also increase cyber risks. Securing today's vehicles means protecting drivers, passengers, data, and critical vehicle systems from evolving cyber threats. 

India's proposed amendments to the Central Motor Vehicles Rules (CMVR) introduce Rule 125-T and Rule 125-U, making compliance with AIS-189 (Cyber Security Management System) and AIS-190 (Software Update Management System) mandatory for specified vehicle categories. Automotive cybersecurity will become a legal requirement, not just an optional feature. 

Why Automakers Can No Longer Treat Cybersecurity as an Afterthought  

A key strength of India's proposed automotive cybersecurity regulations is that they place responsibility firmly on Original Equipment Manufacturers (OEMs) rather than vehicle owners. Manufacturers must embed cybersecurity throughout the vehicle lifecycle by implementing a certified Cyber Security Management System (CSMS), performing Threat Analysis and Risk Assessments (TARA), securing electronic architectures, monitoring emerging cyber threats, and ensuring rapid vulnerability response before and after vehicles enter the market. 

India's proposed rules require OTA software updates to be authenticated, validated for integrity, assessed for safety, and fully traceable throughout a vehicle's lifetime. This elevates software security to the level of mechanical safety and makes cybersecurity governance a core responsibility for OEM leadership and boards. 

A Connected Vehicle Is Never 'Finished'—Neither Is Its Cybersecurity 

The draft regulations reinforce that automotive cybersecurity is a shared responsibility across the entire supply chain. While OEMs remain legally accountable, compliance requires collaboration with software developers, Tier-1 suppliers, semiconductor manufacturers, battery suppliers, telematics providers, and testing organisations to secure every connected vehicle component. 

Under India's proposed automotive cybersecurity framework, OEMs must ensure that suppliers follow recognised cybersecurity engineering practices, validate all third-party software, and effectively manage risks arising from open-source libraries and connected services. This aligns with global Automotive Cybersecurity standards and reinforces a critical principle: a connected vehicle's security is only as strong as its weakest supplier. For India's rapidly expanding Electric Vehicle (EV) industry, where new manufacturers and component suppliers continue to emerge, strengthening supply chain cybersecurity will be essential for maintaining compliance, reducing cyber risks, and building long-term consumer trust. 

Compliance Is Just the Beginning: The Real Future of Automotive Cybersecurity 

These proposed regulations are far more than an additional certification process—they lay the foundation for the future of Automotive Cybersecurity. Today's connected vehicles function as digital platforms, continuously processing information about drivers, journeys, driving habits, and vehicle performance while software controls increasingly critical systems. Protecting this ecosystem is essential for maintaining consumer confidence, strengthening vehicle cybersecurity, and ensuring public trust in India's rapidly evolving connected and autonomous mobility landscape. 

India's proposed regulations are about far more than meeting automotive cybersecurity compliance requirements. They acknowledge that connected vehicles have evolved into intelligent digital platforms that process sensitive personal information, including driving behaviour, travel patterns, locations, and user preferences. At the same time, software now controls many essential vehicle functions, making cybersecurity a critical component of both safety and reliability. As vehicles become increasingly connected through cloud services, Over-the-Air (OTA) updates, and digital ecosystems, maintaining consumer trust will require strong vehicle cybersecurity, secure software management, and continuous protection against evolving cyber threats.