Editor's Note: This article is based on reporting originally published by auto.economictimes.indiatimes.com. All key details have been cross-referenced and verified for accuracy. View Original Source ↗

India's Automotive Cybersecurity Push: A Looming Challenge for OEMs

The Ministry of Road Transport and Highways (MoRTH) has proposed a phased rollout of automotive cybersecurity norms, under AIS-189, to enhance the security quotient of automobiles made in India. The norms aim to align with global best practices on vehicle cybersecurity and software lifecycle management.

The Proposed Regulations

According to the draft notification, the regulations will apply across vehicle categories M (passenger vehicles), N (goods carriers), T (trailers), and agricultural and construction machinery categories. Vehicles equipped with at least one electronic control unit (ECU) and compliant with AIS-189 will be required to implement cybersecurity and software update management systems.

Phased Implementation Roadmap

The implementation roadmap begins with Level 3 and above automated vehicles, for which compliance will become mandatory from October 1, 2026 for new models and April 1, 2027 for existing models. The mandate will be expanded to all OTA-enabled vehicles by October 1, 2029.

Audit & Contradictions

While the proposed regulations aim to enhance vehicle cybersecurity, there are concerns about the enforcement and auditing of these norms. The article mentions that the standard will require automakers to ensure cybersecurity governance, risk assessment, monitoring, and secure updates across a vehicle's lifecycle, but does not provide specific details on how this will be enforced or audited.

Future Outlook

The phased rollout of automotive cybersecurity norms in India is expected to have significant implications for OEMs, particularly those operating in the autonomous and connected vehicle space. As the industry adapts to these new regulations, we can expect to see a greater emphasis on cybersecurity and software update management in vehicle design and development.

Global Implications

India's push for automotive cybersecurity norms is not an isolated incident. Globally, regulators are increasingly focusing on vehicle cybersecurity, with many countries implementing or proposing similar regulations. OEMs will need to navigate these changing regulatory landscapes to ensure compliance and maintain consumer trust.