NEW DELHI — In a major move to protect connected vehicles from digital vulnerabilities, the Ministry of Road Transport and Highways (MoRTH) has proposed a strict new legal framework. The law makes cybersecurity and software update management mandatory for all technologically advanced vehicles operating on Indian roads.
The legislative push addresses the growing threat of malware, unauthorized remote access, and cyberattacks targeting software-heavy automotive systems as vehicles become smarter and increasingly reliant on code.
Phased Implementation Timeline
The ministry has outlined a multi-phase rollout to give automakers adequate transition time to implement Cybersecurity Management Systems (CSMS).
| Phase & Compliance Group | Effective Date | Target Vehicles |
| Phase 1 (New Models) | October 2026 | New vehicle models featuring Level-3 automation and above. |
| Phase 1 (Existing Models) | April 2027 | Existing automotive models currently in production with Level-3 automation. |
| Phase 2 | April – October 2028 | Vehicles equipped to receive Over-the-Air (OTA) software updates. |
| Phase 3 | October 2029 | All remaining vehicles built with any software update capabilities. |
Target Vehicles and Tech Scope
The upcoming regulations explicitly target any passenger vehicle, commercial vehicle, or tractor that houses at least one Electronic Control Unit (ECU) paired with Level-3 or higher autonomous driving functionality.
Elite luxury models currently retailing in India—such as the Mercedes-Benz S-Class, Audi A8, and BMW 7 Series—fall directly under the initial October 2026 enforcement window due to their advanced driving automation.
The Focus on Over-the-Air (OTA) Risks
Modern vehicles frequently update their software, firmware, and navigational systems via Wi-Fi or cellular networks, much like a smartphone. While OTA updates eliminate the need for owners to physically visit a dealership for software patches, they present a significant digital attack surface for hackers.
Government officials emphasized that auto manufacturers must heavily fortify their underlying source code, with a specific focus on Battery Management Systems (BMS). Because the BMS monitors the health, temperature, and power distribution of electric and hybrid battery packs, a compromised system poses severe physical safety hazards alongside data privacy risks.

