News

Automotive Suppliers Face Stricter Cybersecurity Assessments

Cybersecurity is becoming a key part of supplier evaluations in the automotive industry. Vehicle manufacturers now check how suppliers protect data and systems alongside quality, cost, and delivery.

Neha Dvivedi · 2026 оны есдүгээр сарын 13

Cybersecurity is becoming an important part of doing business in India's automotive supply chain. Auto component manufacturers face greater scrutiny from vehicle manufacturers as companies assess security risks linked to suppliers, service providers, and digital systems.

As a result, this change is creating a growing need for manufacturers to understand their cybersecurity gaps and prepare documented evidence before customer assessments begin.

New Automotive Cybersecurity Rules Put Supply Chains Under Focus

India is developing stronger cybersecurity requirements for connected and software-driven vehicles. AIS-189 addresses Cyber Security Management Systems, while AIS-190 addresses Software Update Management Systems. These standards were drafted by the Automotive Industry Standards Committee under ARAI.

These standards are linked to the wider automotive cybersecurity framework based on UNECE Regulations R155 and R156 and ISO/SAE 21434.

The Ministry of Road Transport and Highways has also been working on regulatory provisions related to vehicle cybersecurity and software updates. However, suppliers should check the latest government notifications before planning around proposed implementation dates.

The impact does not stop with vehicle manufacturers. Automotive cybersecurity also involves the wider supply chain. Vehicle manufacturers need to understand cybersecurity risks linked to suppliers and other organisations that support vehicle development and production.

Cybersecurity Becomes a Key Focus for Automotive Suppliers

The automotive industry is also paying closer attention to cybersecurity as digital systems become more central to manufacturing and vehicle development.

At industry events, automotive leaders have highlighted the need for stronger cybersecurity capabilities and better backup plans. The growing use of connected systems means that a cyber incident can affect more than data. It can also interrupt business operations and production.

The Automotive Component Manufacturers Association of India represents manufacturers across different levels of the automotive supply chain. Its membership also includes Tier 2 suppliers that provide components and sub-assemblies to Tier 1 companies.

Recent Cyberattacks Highlight Risks for Automotive Supply Chains

Recent cyber incidents show how quickly an attack can disrupt business operations.

The Jaguar Land Rover cyberattack in 2025 caused major disruption to the company's operations. The incident showed how a cyberattack can create significant business costs when it affects manufacturing systems and supply chains.

The company reported GBP 196 million of exceptional costs and a GBP 485 million loss for the quarter; the Cyber Monitoring Centre put the wider cost to the UK economy at GBP 1.9 billion.

Cybersecurity risks can also involve sensitive business information. Engineering drawings, product designs, customer information and supplier data can become valuable targets for attackers.

For automotive manufacturers, the concern is therefore not limited to preventing unauthorised access. Companies also need to consider how quickly they can detect an incident, protect critical information and continue operations.

What New Cybersecurity Checks Are Automotive Suppliers Facing?

Customer cybersecurity assessments can cover many parts of an organisation's security system.

These assessments may examine access control, user permissions, system logs, configuration management, physical security, business continuity, data privacy and incident response. Some assessments can also include questions about cloud services and the use of artificial intelligence.

The assessment process may require suppliers to provide documents and other evidence to support their answers. This means a cybersecurity policy alone may not be enough. Suppliers may need to show that their policies are implemented and that employees follow the required processes.

This is where a structured management system can make a practical difference. A manufacturer can use a defined system to identify risks, assign responsibilities, maintain records and review its controls regularly.

How Do Customer Cybersecurity Checks Align With Indian Compliance Requirements?

Automotive suppliers also have to consider cybersecurity obligations that apply under Indian law.

The CERT-In Directions issued in April 2022 require covered organisations to report specified cyber incidents within the prescribed timeline. They also require organisations to securely maintain ICT system logs for a rolling period of 180 days.

These requirements can become important when suppliers prepare for customer cybersecurity assessments.

For example, a customer may ask a supplier how it manages security logs or responds to cyber incidents. The supplier may already have related obligations under the applicable Indian cybersecurity framework.

How Can ISO/IEC 27001 Help Suppliers Strengthen Information Security?

ISO/IEC 27001 provides a structured framework for establishing an Information Security Management System.

The standard helps organisations identify information security risks and establish controls to protect important information. It also encourages organisations to review and improve their security processes over time.

For automotive suppliers, an ISO/IEC 27001-based system can support preparation for customer assessments by bringing policies, risk assessments, controls and evidence into one organised framework.

However, ISO/IEC 27001 certification does not automatically satisfy every customer requirement. Each vehicle manufacturer can have its own assessment criteria and contractual expectations.

How Can Auto Suppliers Prepare for Cybersecurity Assessments?

Manufacturers can begin with a cybersecurity gap assessment. The first step is to identify the information and systems that are important to the business. The organisation can then review who has access to these systems and whether appropriate controls are in place.

Manufacturers should also review their incident response plans and backup arrangements. Regular testing can help organisations understand whether they can recover critical operations after a cyber incident.

Suppliers should maintain clear records of their policies, risk assessments, training activities, access reviews, security incidents and corrective actions.

Indian Legal and Compliance Requirements for Automotive Suppliers

Automotive suppliers face more than contractual assessment requirements. They also have statutory duties that apply to them independently. The Digital Personal Data Protection Act, 2023, also known as the DPDP Act, applies to employee and customer personal data. The CERT-In Directions of April 2022 establish incident reporting timelines and log retention requirements. Section 43A of the Information Technology Act, 2000 and the associated rules on reasonable security practices remain in force and expressly recognise ISO/IEC 27001 as a benchmark.

Our reference guide to the control families and scoring explains the requirements covered under each control area. The statutory obligations guide explains what Indian law requires from suppliers in their own right. MSCi works with automotive component manufacturers on gap assessment and readiness.

How Can Auto Suppliers Prepare for Cybersecurity Assessments?

Automotive cybersecurity requirements are becoming more detailed as manufacturers rely more heavily on connected systems and digital supply chains.

For suppliers, preparing only when a customer sends an assessment can create unnecessary pressure. A planned readiness programme can help organisations identify gaps earlier and address them in an organised way.

MSCi supports automotive component manufacturers with ISO consultancy, gap assessments and readiness support. The consultancy helps organisations understand applicable requirements, strengthen their management systems and prepare for assessment and certification.

Manufacturers can also use the free readiness checklist to get an initial view of areas that may require attention before an assessment. 

See how this looks as a working system

Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO/IEC 27001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.

Ask us about this

Tell us what is being asked of you and by whom.

What are you looking for?

We reply within one working day. Your details stay with our consultants.

More reading

All articles