News
Automotive Vendor Cybersecurity Assessments Move from Advisory to Scored: What Indian Suppliers Are Now Being Measured On
Vehicle manufacturers in India now score suppliers on cybersecurity against weighted checklists, with corrective action deadlines. What is being measured.
Neha Dvivedi · 13 September 2026
Automotive supplier cybersecurity requirements in India have become a measured condition of supply for auto component manufacturers. Vehicle manufacturers are assessing vendors against structured, weighted checklists, issuing scores, and setting deadlines for corrective action. Information security now sits alongside quality, cost and delivery as a commercial qualification criterion.
The regulatory driver
AIS-189, the Indian automotive standard for Cyber Security Management Systems, applies to new vehicle types from October 2027 and to all vehicle types from October 2028, on a timetable that is still being given force through draft rules. Its companion AIS-190 covers Software Update Management Systems. Both were drafted by the Automotive Industry Standards Committee under ARAI and are modelled on UNECE Regulations R155 and R156 and on ISO/SAE 21434. The Ministry of Road Transport and Highways has moved to bind compliance through proposed Rules 125-T and 125-U of the Central Motor Vehicles Rules, tying cybersecurity and software update management to vehicle type approval.
The rules are in draft and the dates attached to them are not final. Check the current position on the Ministry of Road Transport and Highways site before planning against them.
The provision that reaches the supply chain is less widely discussed. AIS-189 requires the vehicle manufacturer to manage cybersecurity dependencies on suppliers, service providers and sub-organisations, with bilateral Cybersecurity Interface Agreements allocating responsibility. A manufacturer cannot demonstrate an approved management system without evidence of control over its supply chain. The obligation passes down the tiers by design.
The industry signal
The message was put to the component industry at the 66th Annual Session of the Automotive Component Manufacturers Association of India, held in New Delhi on 2 September 2026 under the theme Beyond Resilience. Hisashi Takeuchi, Managing Director and Chief Executive Officer of Maruti Suzuki India, told delegates that as the industry embraces greater digitalisation, cybersecurity becomes equally important, and that organisations must stay ahead of increasingly sophisticated attackers. He added that the possibility of an incident cannot be ruled out, and that manufacturers need a robust contingency plan enabling operations to resume in the shortest possible time.
Reporting of the session noted particular emphasis on cybersecurity capability and backup planning among Tier 2 and Tier 3 suppliers. ACMA represents more than 830 component manufacturers in an industry that recorded a turnover of approximately Rs 7.6 lakh crore in FY26.
Why now
- Jaguar Land Rover, September 2025. A cyberattack halted production in the United Kingdom and Slovakia for about five weeks. The company reported GBP 196 million of exceptional costs and a GBP 485 million loss for the quarter; the Cyber Monitoring Centre put the wider cost to the UK economy at GBP 1.9 billion.
- Tata Electronics, June 2026. An extortion group published a dataset reported at more than 630 GB, said to contain component design documentation associated with global manufacturers.
- Bajaj Auto, 23 June 2026. A ransomware attack affected corporate IT infrastructure and an engineering subsidiary. The incident was reported to CERT-In under the Information Technology Act, 2000.
A production stoppage and an intellectual property leak reaching a manufacturer through its supply chain are the two outcomes that change procurement policy.
What suppliers are being asked for
Vendor assessment instruments now in circulation are substantially more detailed than the security questionnaires suppliers encountered previously. They run to well over a hundred individual checkpoints across governance, access control, logging, configuration management, physical security, business continuity, data privacy and the use of artificial intelligence.
Three characteristics matter. Checkpoints are weighted and separated into mandatory and desirable categories, so gaps do not cost equally. A vendor’s self-assessment is recorded separately from the assessor’s validated score, meaning self-declaration is tested rather than accepted. And assessment is followed by a defined corrective action cycle, with submission dates for an improvement plan and for supporting evidence typically falling within weeks of the report.
The statutory dimension
The assessment obligation is contractual, but suppliers carry parallel statutory duties in their own right. The Digital Personal Data Protection Act, 2023, the DPDP Act, applies to employee and customer personal data. The CERT-In Directions of April 2022 set incident reporting timelines and log retention requirements. Section 43A of the Information Technology Act, 2000 and the associated rules on reasonable security practices remain in force and expressly recognise ISO/IEC 27001 as a benchmark.
The controls satisfying a customer assessment and those satisfying Indian law overlap substantially. Suppliers addressing both together will spend less than those treating them as separate programmes.
Our reference guide to the control families and scoring sets out what each area asks for, and the statutory obligations guide covers what Indian law requires of a supplier in its own right. MSCi works with automotive component manufacturers on gap assessment and readiness. MSCi is a consulting organisation: we prepare organisations for assessment and certification, we do not issue certificates, and we are not an approved or empanelled assessor for any manufacturer. The free readiness checklist gives an indicative position in about fifteen minutes.
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO/IEC 27001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- Automotive OEM Vendor Cybersecurity Assessment: Control Families, Scoring and Standards Mapping
What an automotive vendor cybersecurity assessment covers, how it is scored, the evidence it asks for, and how each control family maps to ISO standards.
13 September 2026
- Inside an Automotive OEM Vendor Cybersecurity Assessment: The 19 Control Families and What They Actually Ask For
The nineteen control families in an automotive vendor cybersecurity assessment, where the structure came from, and why good controls still score zero.
13 September 2026
- Why Auto Component Suppliers Score Poorly on OEM Cybersecurity Assessments, and the Nine Documents That Close Most of the Gap
Scored assessments award marks for documented evidence, not for practice. That is why secure suppliers score badly, and nine documents close most of the gap.
13 September 2026
