1 month ago
India to Mandate Cybersecurity for Vehicles by 2026
India is making new rules to keep cars and trucks safe from hackers.
The rules say that cars with special computer parts must have security systems and ways to get updates over the internet.
The rules start for cars that can drive themselves a bit in 2026, and later for cars that can get updates from the cloud.
The government also wants to add rules for electric two- and three-wheelers after some battery hacks.
The goal is to make all new cars in India hard to hack and safer for drivers.
MoRTH proposes new cybersecurity rules for passenger, goods, and trailer vehicles.
Rules 125‑T (Cyber Security) and 125‑U (Software Updates) apply to vehicles with at least one ECU and Level 3 automation.
Compliance begins October 1, 2026 for new Level 3+ vehicles, with later phases for OTA‑enabled vehicles in 2028 and 2029.
Draft also considers extending rules to electric two‑ and three‑wheelers after e‑rickshaw battery hack incidents.
The framework aims to make all new vehicles hacking‑proof and improve safety of future ADAS‑equipped cars.
- Who
- Ministry of Road Transport and Highways (MoRTH) and the Indian government
- What
- Draft notification to mandate cybersecurity and software update management for vehicles
- Where
- India
- When
- Draft dated June 22, 2024; compliance dates from 2026 to 2029
- Why
- To enhance vehicle safety and prevent hacking, especially with advanced driver assistance systems
Key facts
- Regulation Date
- June 22, 2024
- Vehicle Categories
- M, N, T (passenger, goods, trailers)
- Compliance Start for Level 3+
- October 1, 2026 (new models)
- Compliance for OTA-enabled vehicles
- April 1, 2028 (new models)
- Scope Expansion
- Electric two- and three-wheelers considered
Quotes
government official
official from India's Ministry of Road Transport and Highways
“evaluating the interventions required”
thestatesman.com






