6 Crucial Auto Cybersecurity Rules to Guard New Vehicles

Harshvardhan Jain
The proposed framework follows incidents where unsecured Bluetooth battery apps allowed attackers to stop moving e-rickshaws remotely. By Harshvardhan Jain.

Quick Take

  • India is drafting auto cybersecurity rules for all new vehicles, ready in about six months, officials told ET.
  • The push follows viral cases of hackers stopping moving e-rickshaws through unsecured Bluetooth battery apps.
  • New rules will cover data collection by connected cars, with roadworthy nods only for safe models.

India is building strict auto cybersecurity rules that will apply to every new vehicle sold in the country, with the framework set to be ready in about six months, officials told The Economic Times. The government is also in talks over data collection by new-age connected vehicles.

The move follows a wave of incidents where attackers tampered with e-rickshaw batteries through mobile apps. Officials said the proposed framework will stress hacking-proof compliance for all new vehicles. The Ministry of Electronics and Information Technology (MeitY) had earlier ordered the removal of unsafe Battery Management System apps from app stores on 3 July 2026, per an official government release.

StartupFeed Insight

The real signal here is not the e-rickshaw fix, it is data. The Centre is examining whether carmakers store and use commuter and driver location data, which drags every connected-car maker into DPDP compliance early. That is a bigger cost line than a Bluetooth patch. Tata Motors, Mahindra, Ola Electric, and importers of low-cost Chinese EVs should read the fine print now, because retrofitting security into shipped fleets is far costlier than building it in. Expect a near-final draft rule with public comments closing before December 2026, ahead of the first mandatory compliance dates in 2027. By Harshvardhan Jain.

What do the new auto cybersecurity rules cover?

The new auto cybersecurity rules will make hacking-proof ability a condition for selling any new vehicle in India. Officials said the framework will be ready in roughly six months and will cover both locally made and fully imported models.

The rules target connected features where drive data is collected, processed, and used to send commands back to the vehicle. StartupFeed learns the government is examining the safety of over-the-air (OTA) updates, the same channel that pushes remote software fixes but can also open a door for attackers if left unsecured.

Deal Breakdown: Key Facts

Metric Detail Notes
Framework readiness About 6 months Officials cited by ET
Scope All new vehicles Includes fully imported EVs
Core standards AIS-189, AIS-190 Cybersecurity and software updates
First trigger App removal, 3 July 2026 MeitY order
ADAS projection 90% of new cars by 2030 NITI Aayog assessment
Data angle Commuter, driver location Under DPDP Rules, 2025

The most striking part is the data question. The government wants to know if carmakers store and process the location and travel patterns of commuters and drivers, and whether that data is safeguarded.

About the Framework

The proposed framework is led by MeitY with inputs from the Ministry of Heavy Industries and the Ministry of Road Transport and Highways (MoRTH). It builds on India’s existing cyber defence bodies, including the Indian Computer Emergency Response Team (CERT-In) under the IT Act, 2000. The aim is one coordinated rulebook for connected and autonomous vehicles, tied to roadworthy certification for new models.

Why did e-rickshaw hacking trigger this move?

E-rickshaw hacking exposed a glaring gap in low-cost EVs. Certain Bluetooth-enabled Battery Management System apps, many tied to imported Chinese batteries, ran with default or no passwords, letting strangers connect and cut power to a moving vehicle.

CERT-In received reports that attackers could abruptly switch off a running e-rickshaw. Viral prank videos showed content creators stranding drivers and passengers mid-route, and Delhi Police arrested a suspect on charges of tech-based extortion.

“The software security vulnerability will be plugged,” a senior official told The Economic Times.

For a driver who rents a tirri for roughly Rs 400 to Rs 500 a day, one remote shutdown can wipe out a full day of earnings. That real-world harm, not a lab test, pushed the Centre to act fast and widen the fix to every new vehicle.

The Standards and Timeline

India’s vehicle cybersecurity standard is AIS-189, and software updates fall under AIS-190. MoRTH issued a draft notification in June 2026 proposing two new provisions, Rule 125-T and Rule 125-U, in the Central Motor Vehicles Rules, 1989, as reported by Autocar India.

The rules follow a phased rollout by risk. Vehicles with Level 3 or higher automated driving must comply first, from October 2026 for new models and April 2027 for existing ones. These standards apply until the Bureau of Indian Standards (BIS) notifies its own specifications.

What does this mean for EV owners?

For EV owners, the auto cybersecurity rules promise safer connected cars but may raise prices. Adding secure hardware and software lifts costs, and older e-rickshaws on plain lead-acid batteries stay safe because they lack wireless links.

Vehicle type Cyber risk Compliance load
Low-cost e-rickshaw (Bluetooth BMS) High Heavy retrofit
Premium EV (encrypted software) Low Mostly ready
Legacy lead-acid e-rickshaw Minimal Largely exempt

What sets this framework apart is its reach. Unlike a one-off app ban, it ties cybersecurity to the roadworthy certificate itself, so no compliant certificate means no sale.

What’s Next

The government is expected to firm up the draft rules and close public comments before the first mandatory compliance dates arrive in 2027. Watch for how the Centre defines data-storage duties for carmakers under the Digital Personal Data Protection (DPDP) Rules, 2025. Will low-cost EV makers absorb the added security cost, or pass it on to buyers?

Frequently Asked Questions

What are India’s new auto cybersecurity rules?
+

India’s new auto cybersecurity rules are a compliance framework requiring all new vehicles to be hacking-proof before sale. Officials told The Economic Times the framework will be ready in about six months and will cover both locally made and fully imported models, tied to roadworthy certification.

Why did e-rickshaw battery hacking happen?
+

E-rickshaw battery hacking happened because some Bluetooth Battery Management System apps used default or no passwords. This let strangers connect to imported low-cost batteries and cut power to moving vehicles. CERT-In received reports of these attacks, and the government ordered the apps removed on 3 July 2026.

Which vehicles do the auto cybersecurity rules cover?
+

The auto cybersecurity rules cover all new vehicles, including fully imported EVs. MoRTH’s draft applies to passenger vehicles, goods vehicles, and tractors with at least one electronic control unit, plus quadricycles with Level 3 or higher automation. Standards AIS-189 and AIS-190 govern cybersecurity and software updates.

Are old e-rickshaws affected by these rules?
+

Older e-rickshaws running on lead-acid batteries are largely safe because they lack wireless connectivity, so attackers cannot connect remotely. Premium EVs using encrypted, proprietary software are also low-risk. The security gap mainly affects low-cost models with unsecured Bluetooth Battery Management Systems.

How does vehicle data collection fit the new framework?
+

The government is examining whether connected vehicles store and use commuter and driver location data. New-age cars share location and process travel information. Officials are checking if carmakers handle this data in line with the Digital Personal Data Protection Rules, 2025, making data safety part of the wider framework.

Disclaimer: This article is for informational purposes only and does not constitute investment advice. StartupFeed and its authors are not SEBI-registered investment advisors. The analysis above is based on publicly available information and should not be the sole basis for any investment decision. Please consult a SEBI-registered financial advisor before making investment decisions.

Have a tip? Write to us at editorial@startupfeed.in.

Don’t Miss Startup News That Matters

Join thousands of readers getting daily startup stories, funding alerts, and industry insights.

Newsletter Form

Free forever. No spam.