Cybersecurity rules could raise connected vehicle costs in India

India’s proposed automotive cybersecurity regulations could increase the cost of highly connected vehicles by around Rs 10,000–15,000 as manufacturers prepare to meet stricter requirements for vehicle cybersecurity and software updates.

The Ministry of Road Transport and Highways (MoRTH) has proposed amendments to the Central Motor Vehicles Rules, 1989, through draft rules that would make compliance with AIS-189 for Cyber Security Management Systems (CSMS) and AIS-190 for Software Update Management Systems (SUMS) mandatory for vehicle type approval.

The proposed framework is expected to cover a growing range of connected and software-driven vehicles, including electric passenger cars, commercial vehicles, buses, trucks, tractors and construction equipment. Implementation is proposed to begin with new Level 3 automated vehicles from October 2026 and expand in phases through October 2029.

For vehicle buyers, the additional cost could translate into stronger protection against cyber threats, more secure over-the-air software updates, improved vehicle data protection and faster security fixes throughout the vehicle’s lifecycle.

The regulations could also significantly influence how vehicles are designed and developed. Automakers and component suppliers may need to incorporate cybersecurity into electronic architecture, software development, testing, certification and long-term support rather than treating it as an add-on feature.

Software updates are expected to become an increasingly important part of vehicle ownership. Connected vehicles could receive numerous updates over their lifespan to improve battery performance, enhance driver assistance systems, fix software issues and strengthen security. Under the proposed framework, such updates would need to be authenticated, properly recorded and designed to fail safely in the event of an issue.

The proposed regulations are also expected to create opportunities for semiconductor companies, embedded software developers, cybersecurity firms, engineering service providers and automotive testing agencies as software becomes increasingly central to the automotive value chain.

Although the immediate deadline applies to new Level 3 automated vehicles, manufacturers developing models for future launches may need to begin integrating cybersecurity measures much earlier. With vehicle development typically taking 18 to 30 months, electronic architecture, software systems and semiconductor choices are often finalised well before a vehicle reaches the market.

The additional spending is likely to increase development costs, with investments expected across secure electronics, software engineering, cybersecurity testing, certification and lifecycle support. However, the eventual impact on vehicle prices will depend on how much of these costs manufacturers absorb amid competition in the market.

Send news announcements/press releases to:
jeevika@thefoundermedia.in

Leave a Reply

Your email address will not be published. Required fields are marked *