The era of software-defined transportation has officially arrived in India, bringing a massive shift in how vehicle safety is regulated. As cars and electric vehicles (EVs) morph into "smartphones on wheels," they rely heavily on millions of lines of code to control everything from braking to battery temperature. However, this massive digital leap has opened a dangerous backdoor for cybercriminals, transforming automotive hijacking and remote vehicle disabling from science fiction into an immediate real-world threat.

In a decisive move to protect public infrastructure and consumers, the Union Government has initiated a sweeping regulatory crackdown on vehicle cybersecurity vulnerabilities. The Ministry of Road Transport and Highways (MoRTH) issued a landmark draft notification amending the Central Motor Vehicles Rules (CMVR), 1989. The new amendments introduce Rule 125-T and Rule 125-U, making rigorous Cybersecurity Management Systems (CSMS) and Software Update Management Systems (SUMS) mandatory for vehicles operating on Indian roads.

This regulatory action follows dangerous real-world exploits. In early July 2026, investigations revealed that low-cost electric two-wheelers and three-wheelers (e-rickshaws) were being unexpectedly shut down while in motion. Malicious actors used unauthenticated Bluetooth applications to turn off the "Discharge" function of EV battery packs from up to 15 meters away. By introducing a phased rollout of strict compliance standards, the government is signaling that digital resilience is no longer an optional luxury—it is a core legal requirement for roadworthiness.

Quick Facts: India's Automotive Cyber Crackdown

Regulatory Aspect

Details and Compliance Timelines

Lead Ministries

Ministry of Road Transport & Highways (MoRTH), Ministry of Heavy Industries (MHI), Ministry of Electronics & IT (MeitY)

New CMVR Provisions

Rule 125-T (Cybersecurity Management) and Rule 125-U (Software Update Management)

Technical Standards

AIS-189 (for CSMS) and AIS-190 (for SUMS) until Bureau of Indian Standards (BIS) issues final norms

Phase 1: Automated Cars

October 1, 2026 (New Level-3 models) | April 1, 2027 (Existing Level-3 models)

Phase 2: Connected/OTA Vehicles

April 1, 2028 (New OTA models) | October 1, 2028 (Existing OTA models)

Phase 3: Full Universal Mandate

October 1, 2029 (All vehicles with any software or update capability)

Key Enforcement Action

Central ban on malicious battery apps (BAT-BMS, SMART BMS, Lossigy, Epoch Li-ion)

What Happened: The Bluetooth Exploit that Sparked the Crackdown

The trigger for this aggressive government intervention was a severe security flaw discovered in the battery packs of budget electric two- and three-wheelers. Rogue users discovered they could download legitimate smartphone utilities—primarily BAT-BMS, developed by Shenzhen Grenergy Technology, alongside others like SMART BMS, Lossigy, and Epoch Li-ion—and abuse them to hijack nearby vehicles.

[Malicious Smartphone App] --(Unauthenticated Bluetooth Link: 10-15m)--> [Vulnerable EV Battery BMS] --> [Discharge Failsafe Triggered] --> [Instant Power Cutoff to Motor]


Because many low-cost lithium battery packs were deployed with factory-default Bluetooth settings, weak passwords, or entirely without user authentication, anyone standing within a 10-to-15-meter radius could wirelessly connect to a moving vehicle's Battery Management System (BMS). With a single tap on the app, pranksters or extortionists could remotely disable the battery's "Discharge" function. This instantly cut power to the motor, freezing the vehicle in the middle of active traffic and presenting an extreme risk of multi-vehicle pileups and fatal road accidents.

Recognizing the immediate danger, MeitY ordered Google and Apple to pull the offending apps from their respective app stores. However, the Ministry of Heavy Industries (MHI) quickly noted that removing the apps merely treated the symptom. The underlying vulnerability—flawed, insecure coding within the vehicle hardware itself—remained out on the streets.

Background: Why Modern EVs are Highly Vulnerable

To understand why an electric vehicle is more vulnerable to a cyberattack than a traditional petrol or diesel car, it helps to examine its architecture. Modern passenger vehicles operate on over 200 million lines of software code. Advanced autonomous vehicles are expected to require closer to one billion lines.

Electric vehicles are completely dependent on software to manage their powertrain. The Battery Management System (BMS) acts as the brain of an EV battery pack, constantly tracking voltage, cell health, and temperature to prevent catastrophic fires or thermal runaway (uncontrolled self-heating).

The Security Blindspot in Current Safety Standards

While India previously upgraded its EV battery safety protocols using the rigorous AIS-156 and AIS-038 (Revision 2) standards, these rules focused almost exclusively on structural, thermal, and electrical safety. They mandated water-ingress protection and cell-level tracking, but they did not enforce specific digital data security or wireless communication defenses. Cheap components flooding the market relied on basic, open Bluetooth protocols, making them easy targets for anyone with a smartphone.

Detailed Explanation: Understanding AIS-189 and AIS-190

To fix these structural gaps, India's new regulations officially transition automotive cybersecurity from a voluntary checklist into a strict legal requirement. Manufacturers must re-engineer their software systems to comply with two Automotive Industry Standards (AIS):

1. AIS-189: Cybersecurity Management System (CSMS)

Modelled closely after the global United Nations regulatory framework (UNECE R155), AIS-189 forces automobile original equipment manufacturers (OEMs) to establish a secure engineering architecture across a vehicle's entire lifecycle. Under this standard, carmakers must:

  • Implement enterprise-wide cybersecurity governance and risk assessment models.

  • Monitor vehicles in real-time for active digital threats and maintain a swift incident response team.

  • Deploy secure cryptographic keys so that commands sent to critical systems (like the engine or brakes) can never be forged by external devices.

2. AIS-190: Software Update Management System (SUMS)

Modelled after UNECE R156, this standard regulates how manufacturers deliver patches and new features. Because Over-The-Air (OTA) updates send code wirelessly via cellular networks or Wi-Fi, an attacker could theoretically compromise an OEM's cloud server to send malicious firmware to thousands of vehicles simultaneously. AIS-190 prevents this by mandating:

  • Highly secure, encrypted OTA transmission channels.

  • Strict validation mechanisms to verify the integrity of software updates before the vehicle executes them.

  • Complete software version traceability across all Electronic Control Units (ECUs) for up to 10 years.

Timeline of Events: The Phased Implementation Roadmap

MoRTH has structured the implementation in phases based on a vehicle's overall complexity and vulnerability to remote attacks, giving the local automotive ecosystem time to adapt.

Phase 1 Kickoff: Automated Passenger Cars

October 1, 2026

Cybersecurity and CSMS compliance becomes mandatory for all newly launched vehicle models equipped with Level 3 or higher automated driving functions (e.g., luxury segments like the Mercedes-Benz S-Class, BMW 7 Series, and Audi A8).

Phase 1 Extension: Existing Autonomous Models

April 1, 2027

The mandate extends to existing vehicle models with Level 3 automation that are already actively sold in the commercial market.

Phase 2 Kickoff: Connected & OTA-Enabled Vehicles

April 1, 2028

Regulations expand to cover all new models equipped with Over-The-Air (OTA) software update capabilities, targeting core operational ECUs while excluding isolated infotainment or tracking units.

Phase 2 Extension: Existing OTA Models

October 1, 2028

All existing OTA-enabled vehicle models on sale must fully conform to secure update protocols and register verified software logging systems.

Phase 3 Final Deadline: Universal Software Enforcements

October 1, 2029

The final expansion. The mandate applies to all vehicles featuring any software update mechanism (including traditional physical updates performed via wired diagnostic tools at dealerships), as well as all remaining OTA-capable platforms.

Economic & Industrial Impact

This regulatory shift will reshape the economics of India's automotive sector, introducing both substantial compliance costs and massive opportunities for specialized software vendors.

  • Surge in Specialized Engineering Spend: Industry analysts project a 25% increase in automotive cybersecurity spending by 2027. Building a compliant, end-to-end CSMS takes an average of 30 months, requiring carmakers to invest heavily in secure communication architectures.

  • Boom for Indian Deep-Tech Firms: The transition from general IT security to complex automotive engineering (focused on specialized architectures like Automotive Ethernet and Vehicle-to-Everything communication) creates an exclusive market for Tier-1 software suppliers. Local firms with deep domain expertise, such as KPIT Technologies, are positioned to see a major wave of institutional demand as global and domestic OEMs look for compliance partners.

  • Consolidation of Low-Cost EV Players: Small-scale assemblers who rely on importing cheap, unbranded components will face structural challenges. Upgrading to microprocessors with cell-level protections and encrypted firmware requires substantial research and development budgets. This will likely push the market toward trusted, capital-rich manufacturers.

Expert Analysis: The Challenges Ahead

While the regulations are a vital step forward, implementing them presents major practical challenges for the automotive ecosystem:

"The regulatory landscape for Indian automotive companies is undergoing a massive shift. With modern vehicles essentially acting as software platforms, cybersecurity is transitioning from an optional feature into a core requirement for roadworthiness. Companies that fail to adapt face delayed vehicle approvals, vehicle impoundment, and direct legal liability."

The biggest engineering bottleneck involves securing legacy fleets. Vehicles that have already been sold cannot easily be recalled to swap out their microcontrollers. While removing malicious apps from app stores helps stall immediate bad actors, tech-savvy users can still sideload applications onto smartphones to bypass store bans. Automakers must develop creative aftermarket solutions, such as physical firmware flashing during routine dealer service visits, to secure vulnerable battery communication ports.

Key Highlights: Major Takeaways

  • The Trigger: Rogue smartphone apps were found wirelessly disabling the battery systems of moving e-rickshaws from 15 meters away, forcing emergency intervention.

  • New Legal Rules: MoRTH has introduced Rules 125-T and 125-U under the CMVR, requiring all advanced vehicles to feature certified cyber-defense systems.

  • Global Alignment: By adopting AIS-189 and AIS-190, India aligns its domestic auto laws with strict European Union, Japanese, and South Korean safety standards.

  • Phased Deadlines: Strict enforcement begins in October 2026 for autonomous vehicles, expanding to all connected and software-driven vehicles by October 2029.

  • BMS Secure Coding: Carmakers must eliminate factory-default passwords and secure the code controlling electric vehicle Battery Management Systems.

Why This News Matters

For the everyday commuter, this is a critical consumer protection victory. As mass transit and private travel rely more heavily on digital systems, a cyberattack on a vehicle is a direct physical threat to passengers. These rules ensure that buying an EV does not expose you to digital hijacking or random remote shutdowns on the highway.

Nationally, this policy secures India's critical transport infrastructure. As the world's third-largest automobile market, selling over 26 million vehicles annually, a widespread cyberattack on connected networks could paralyze major city logistics. By building a reliable digital ecosystem, India protects its economic interests and positions itself as a trustworthy global export hub for safe, software-defined electric vehicles.

Easy Explanation (For Beginners)

Think of an old-school car as a mechanical typewriter—it runs entirely on gears, cables, and levers. If someone wants to break it, they have to physically open the hood. A modern Electric Vehicle (EV), however, is like a smartphone on wheels. It uses computers called ECUs to control the brakes, steering, and battery.

Just like your smartphone needs security updates to keep hackers from stealing your data, a smart car needs digital defenses to keep bad actors from taking control of the vehicle.

Recently, the Indian government discovered that some cheap electric rickshaws had a security flaw. Their batteries connected to Bluetooth without asking for a password. This allowed anyone nearby with a specific smartphone app to connect to the battery and turn it off while the vehicle was moving. To fix this, the government is introducing strict new laws (AIS-189 and AIS-190). These rules force car companies to lock down their software code, use strong encryption, and make sure that wireless updates are completely secure.

Frequently Asked Questions (FAQs)

1. Can hackers actually turn off my electric scooter or car while I am riding it?

Yes, before this crackdown, certain low-cost electric two- and three-wheelers had an unauthenticated Bluetooth vulnerability. This allowed someone nearby with a specific app to connect to the battery management system and turn off the power. The new rules are designed to eliminate this flaw.

2. What are AIS-189 and AIS-190?

They are India's new automotive safety standards. AIS-189 requires car manufacturers to build a secure digital environment to protect vehicles from cyberattacks. AIS-190 ensures that any wireless or Over-The-Air (OTA) software updates sent to the vehicle are safe, encrypted, and cannot be intercepted by hackers.

3. Will these new cybersecurity rules make electric vehicles more expensive?

In the short term, yes. Automakers will need to invest more heavily in secure microchips, advanced software engineering, and third-party security audits. This could slightly increase the production costs of entry-level electric vehicles.

4. When will my regular connected car have to comply with these rules?

If your vehicle uses Over-The-Air (OTA) software updates, manufacturers must ensure compliance for new models by April 1, 2028, and for existing models by October 1, 2028. By October 2029, every single vehicle that receives any software updates must comply.

5. Why did the government ban apps like BAT-BMS and SMART BMS?

These apps were built as legitimate tools to check battery health via Bluetooth. However, because many budget battery manufacturers left their hardware open without password protection, these apps were being used to connect to random passing vehicles and shut them down maliciously.

6. Do these rules apply to petrol and diesel vehicles too?

Yes. Although electric vehicles are the primary focus due to their heavy reliance on software for power management, the rules apply to all vehicles featuring advanced automated driving (Level 3 and above) or OTA wireless updates, regardless of their fuel type.

also read : Monsoon 2026 Live Updates: States Facing Heavy Rain This Week