Skip to main content

Regulation Update

AIS 189: Cybersecurity Requirements for the Indian Market

India’s automotive cybersecurity standard follows the structure established by UNECE R155. Global platform teams should understand where it aligns and where local process obligations differ.

Article details

Category
Regulation Update
Published
Reading time
6 min read
Author
AutoSec Academy · Compliance Practice

AIS 189 sets out cybersecurity requirements for vehicles in the Indian market, following the management-system structure that UNECE R155 established internationally. For manufacturers already building toward R155, the conceptual work transfers; the process and submission obligations are what require local attention.

What transfers from an existing CSMS

  • Risk identification, assessment and treatment processes
  • Supplier assurance and interface responsibilities
  • Monitoring, incident response and field capability
  • The underlying engineering evidence produced to ISO/SAE 21434

Practical preparation

Map your existing CSMS artefacts against the AIS clause structure before engaging a testing agency. Most global manufacturers find they hold the substance and lack the presentation — evidence organised for one authority rarely reads cleanly to another.

Applicability, vehicle categories and timelines are set through the Indian regulatory process and revised periodically. Confirm the current position with ARAI and the CMVR technical standing committee rather than relying on a secondary summary.

Back to the Knowledge Center

Stay current

Get the Next One in Your Inbox

Regulatory updates and lab research, sent when there is something worth saying.

Threat intelligence, straight to your inbox

Regulatory updates, lab research and new program announcements. No noise.

What should we send you?

Go Deeper Than an Article

The programs behind this analysis put you on real ECU hardware, with practitioners who do this work for a living.