ok.com
Browse
Log in / Register

India’s auto cybersecurity rules coming: framework in 6 months to target connected vehicles

OKer_e3zt8wr
07/28/2026, 04:24:49 PM
auto cybersecurity rules

New Delhi, July 20, 2025 – India has launched development of a mandatory cybersecurity compliance framework covering all new vehicles sold in the country, with a target completion of six months, according to government officials. The move follows recent incidents where e-rickshaw batteries were tampered with via mobile apps, raising alarms about broader vulnerabilities in connected and semi-autonomous vehicles.

“We are evaluating the interventions required,” a senior official told ET, emphasizing that the proposed safeguards will require hacking-proof compliance for every new car, SUV, and two-wheeler entering the Indian market. The framework will scrutinize features that collect, process, and use driving data to issue commands to the vehicle—such as remote diagnostics, telematics, and over-the-air (OTA) updates.

What the New Rules Will Cover

The upcoming framework is expected to address three main areas: hardware-level cybersecurity, software integrity, and data privacy. The government is specifically examining how drive data is stored and transmitted, and whether automakers are complying with India’s Digital Personal Data Protection Rules (DPDP) 2025. Officials noted that many connected vehicles share location data over the internet and process vast amounts of surrounding environment information, which could be exploited if not properly secured.

Second, the possibility of enhancing cybersecurity for existing connected vehicles through OTA updates is also being studied. This would allow manufacturers to patch vulnerabilities without requiring owners to visit service centers—a critical capability given that millions of already-sold cars may lack adequate protection.

Broader Context: ADAS and Semi-Autonomous Risks

The push for stricter rules comes as India’s passenger vehicle market accelerates adoption of Advanced Driver Assistance Systems (ADAS). Niti Aayog, India’s premier policy think tank, has projected that by 2030, 90% of all passenger vehicles sold in India will be ADAS-enabled—featuring lane departure warning, adaptive cruise control, and automatic emergency braking. These systems rely heavily on sensors, cameras, and internet connectivity, creating new attack surfaces.

Recent concerns about possible sabotage of semi-autonomous vehicles in India have prompted the government to act. While the mobile apps used to hack e-rickshaw batteries have been banned, officials worry that similar exploits could target vehicles with automatic parking, braking, and lane assist functions. A second official noted that the government is also examining whether automakers are storing and utilizing commuter and driver data in compliance with the DPDP framework.

Global Implications for Automakers

Although focused on India, the new rules will have ripple effects on global automakers that sell vehicles there, including Toyota, Hyundai, Maruti Suzuki, and Tesla. Many of these companies already comply with cybersecurity regulations in the European Union (UN Regulation No. 155) and China, but India’s requirements may differ in scope and timelines. Foreign manufacturers will need to ensure their vehicles meet India’s specific hacking-proof standards and data localization mandates.

Industry experts expect India’s framework to borrow from international best practices while adding unique provisions for local conditions, such as public charging infrastructure and two-wheelers. The six-month timeline is aggressive, but officials say the urgency stems from rising incidents of cyberattacks on vehicle systems globally.

What’s Next

The government is currently in the consultation phase with automakers, technology partners, and cybersecurity firms. The final framework will likely include mandatory third-party audits, incident reporting obligations, and penalties for non-compliance. Once published, new models will need to obtain certification before hitting the showroom floor, with existing models given a grace period for OTA upgrades.

“This is not just about protecting individual cars—it’s about safeguarding India’s entire transportation ecosystem as it becomes more connected and autonomous,” the official added.


Editor’s note: This article was originally published on July 20, 2025, summarizing the latest developments from Indian government sources.

Cookie
Cookie Settings
Our Apps
Download
Download on the
APP Store
Download
Get it on
Google Play
© 2025 Servanan International Pte. Ltd.