New Cybersecurity Rules for Software Defined Vehicles
Discover how India's proposed cybersecurity rules for software-defined vehicles will improve connected car security, secure OTA updates, and reshape the future of automotive cybersecurity.

Not long ago, the biggest concern for car owners was engine failure or a flat tire. Today, it could be a cyberattack.
Modern vehicles are no longer just machines, they're connected computers on wheels. From over-the-air (OTA) software updates and AI-powered driver assistance to cloud connectivity and smartphone integration, today's vehicles rely on millions of lines of code. While this digital transformation has made driving safer and more convenient, it has also opened the door to an entirely new category of threats.
Recognizing this shift, the Indian government has proposed mandatory cybersecurity and software update regulations for software-defined and connected vehicles. The move marks one of India's biggest steps toward securing the future of intelligent mobility.
Why Cars Are Becoming Prime Cyber Targets
Software-defined vehicles (SDVs) operate much like smartphones. Features can be added, bugs can be fixed, and performance can improve through software updates without visiting a service center.
But every connected feature also becomes a potential attack surface.
Cybercriminals can target:
Vehicle control systems
Infotainment platforms
GPS and navigation services
Bluetooth and Wi-Fi connections
Mobile companion apps
Cloud-based vehicle management systems
A successful breach could go beyond stealing personal information. In extreme cases, attackers could interfere with vehicle functions, disable safety features, manipulate software updates, or compromise entire fleets.
As vehicles become increasingly autonomous and connected, cybersecurity becomes a road safety issue—not just an IT problem.
What Is India Proposing?
The Ministry of Road Transport and Highways (MoRTH) has proposed introducing two new regulations under the Central Motor Vehicles Rules:
Rule 125-T – Mandatory Vehicle Cybersecurity Management System (AIS-189)
Rule 125-U – Mandatory Software Update Management System (AIS-190)
Together, these standards require manufacturers to build cybersecurity into the vehicle lifecycle instead of treating it as an afterthought. They also establish structured processes for secure software updates and vulnerability management.
A Phased Rollout
Rather than enforcing compliance across all vehicles immediately, the government plans a phased implementation.
The rollout begins with highly automated vehicles (Level 3 and above) before expanding to OTA-enabled vehicles and eventually covering most vehicles capable of receiving software updates by 2029. This phased strategy gives manufacturers time to redesign systems while aligning India with automotive cybersecurity practices already adopted in markets such as the European Union, Japan, and South Korea.
Why This Matters More Than Ever
The automotive industry is experiencing one of its biggest technological shifts.
Cars are now connected to:
Mobile applications
Cloud services
Digital payment systems
Smart city infrastructure
Charging networks
Vehicle-to-vehicle communication
Every new connection improves the customer experience—but also creates another opportunity for attackers.
A compromised software update or vulnerable connected service can impact thousands of vehicles simultaneously. We've already seen similar large-scale attacks affect software supply chains across multiple industries. The automotive sector cannot afford to wait until a major incident occurs.
India's proposal reflects a growing understanding that cybersecurity must be embedded into vehicle design from day one.
What This Means for Automotive Manufacturers
The proposed regulations aren't just about passing compliance checks.
Manufacturers will need to rethink how they:
Design secure software architectures
Identify and manage cyber risks throughout the vehicle lifecycle
Validate every software update before deployment
Monitor vulnerabilities after vehicles reach customers
Respond quickly to emerging threats
Cybersecurity will become an ongoing engineering responsibility rather than a one-time certification exercise.
For automotive suppliers, software vendors, and OEMs, this also means closer collaboration between engineering, cybersecurity, quality assurance, and compliance teams.
Benefits for Consumers
For everyday drivers, these regulations may remain invisible—but their impact will be significant.
They can expect:
Safer software updates
Better protection against cyberattacks
More reliable connected features
Reduced risk of malicious vehicle manipulation
Greater confidence in smart vehicle technologies
As consumers increasingly adopt electric, connected, and autonomous vehicles, trust will become as important as horsepower.
The Bigger Picture
India's automotive industry is rapidly evolving into a software-first ecosystem.
Vehicles are becoming platforms that receive continuous improvements throughout their lifetime. That future depends on secure software, trusted updates, and resilient digital infrastructure.
The government's proposed cybersecurity framework is more than another compliance requirement, it signals a fundamental shift in how vehicle safety is defined.
Tomorrow's safest cars won't just have stronger brakes or better airbags.
They'll also have stronger cybersecurity.
Secure the Road Ahead with Evvo Technology
As vehicles become smarter, cybersecurity needs to keep pace. At Evvo Technology, we help businesses stay ahead with practical cybersecurity solutions that strengthen digital infrastructure, reduce risk, and support compliance, so innovation never comes at the cost of security.
Let's build a safer, smarter future together.
From smart vehicles to smart hospitals, every connected system is a potential target. Read our next blog, What Happens When a Hospital Gets Hit by Ransomware?, to see how cyberattacks can disrupt critical services and what organizations can do to stay protected.


