Skip to main content
AutoSec Innovation

Regulations

India AIS-230 V2V Draft Explained: C-V2X Cybersecurity for MoRTH’s 2027–2028 Timeline

MoRTH’s draft V2V framework puts factory-installed C-V2X On-Board Units on a phased path for Indian vehicle categories L, M, and N. AIS-230 also brings cybersecurity and communication-security requirements that Indian OEM and Tier-1 programmes must treat as engineering work—not only radio compliance.

· AutoSec Engineering Team · 4 min read

Practitioner guidance on automotive cybersecurity topics

On 3 August 2026, the Press Information Bureau published a Ministry of Road Transport and Highways release describing a draft notification to amend the Central Motor Vehicles Rules, 1989 for the phased introduction of Vehicle-to-Vehicle communication systems in India. The technical foundation named in that release is AIS-230, covering factory-installed On-Board Units that use Cellular Vehicle-to-Everything technology in the 5.875 GHz to 5.925 GHz Intelligent Transportation System band.

For cybersecurity teams supporting Indian OEM, Tier-1, and OBU programmes, the important point is not only that V2V is coming to Indian roads. It is that the draft framework already treats cybersecurity and communication security as part of the minimum technical package for systems that exchange safety-relevant vehicle state in real time.

MoRTH draft V2V timeline for India: 2027 and 2028

According to the PIB summary of the draft Central Motor Vehicles Rules notification, vehicles in categories L, M, and N manufactured on or after 1 October 2027 must comply with AIS-230 where they are fitted with V2V communication systems. From 1 October 2028, those Indian vehicle categories are proposed to require V2V systems conforming to AIS-230. The phased approach is intended to give manufacturers, importers, and other stakeholders time to prepare.

  • India from 1 October 2027: AIS-230 compliance where V2V systems are fitted on categories L, M, and N
  • India from 1 October 2028: V2V systems conforming to AIS-230 proposed as a fitment requirement for categories L, M, and N
  • India spectrum context: 5.875–5.925 GHz ITS / C-V2X band, with DoT licensing exemption referenced via G.S.R. 466(E) dated 10 June 2026

Draft status matters for Indian programme planning. Consultation comments were still open when the release was published, and final CMVR wording can change. Programmes should prepare against the published MoRTH direction without treating every draft clause as already locked law.

Why Vehicle-to-Vehicle communication changes cybersecurity in India

V2V lets nearby vehicles exchange speed, position, direction, acceleration, and related state so drivers or vehicle systems can receive advance warnings beyond the line of sight of onboard sensors. The PIB release cites safety-critical situations such as sudden braking, forward-collision risk, unsafe lane changes, and approaching emergency vehicles—use cases that matter on congested and mixed Indian traffic conditions as much as on controlled test tracks.

That is a different trust model from a closed ECU talking only to the rest of the vehicle. Messages arrive from other road users. False, delayed, spoofed, or replayed information can degrade the very safety use cases the system is meant to support. For Indian connected-vehicle programmes, cybersecurity and communication security are therefore part of the safety argument, not an optional IT overlay.

What AIS-230 covers for C-V2X On-Board Units in India

The PIB release states that AIS-230 specifies minimum technical, functional, performance, environmental, and security requirements for V2V systems installed in vehicles operating on Indian roads. The standard covers factory-installed On-Board Units using C-V2X in the 5.9 GHz ITS band. Principal requirement areas named in the release include radio performance, receiver behaviour, GNSS and positioning, electrical supply, electromagnetic compatibility, cybersecurity and communication-security provisions, and performance requirements for road-safety applications.

  • Emergency Brake Alert
  • Forward Collision Warning
  • Wrong-way Driving
  • Emergency Vehicle Alert

Those AIS-230 safety use cases are useful planning anchors for Indian OEM validation plans. Each one depends on timely, trustworthy messages. A programme that only proves RF conformity for the Indian 5.9 GHz allocation and never shows how authenticity, integrity, availability, and misuse cases were treated will struggle later when assessors, customers, or internal quality gates ask for the security argument.

Implications for Indian OEMs, Tier-1s, and OBU suppliers

The engineering work looks familiar to teams already operating under ISO/SAE 21434 and UNECE R155 for export or global platforms, but the India V2V item boundary is easy to get wrong. An On-Board Unit is not only a modem. It sits at the junction of radio, positioning, vehicle interfaces, security controls, and applications that may trigger warnings or escalate into ADAS-related behaviour on vehicles sold in India.

  1. Define the India-bound V2X item and trust boundaries early, including supplier interfaces and CMVR-facing evidence ownership.
  2. Extend TARA to cover communication-security threats and safety-relevant message misuse for Indian operating conditions, not only conventional ECU attack paths.
  3. Turn AIS-230 cybersecurity and communication-security expectations into requirements that architecture and suppliers can implement.
  4. Plan verification that covers security controls as well as radio and application performance for C-V2X stacks.
  5. Build a readiness plan against MoRTH’s 2027 and 2028 milestones so security work is not left to the last gate.

How AutoSec helps with AIS-230 V2V cybersecurity in India

AutoSec Innovation supports Indian and international OEM and Tier-1 teams preparing V2V and C-V2X programmes for AIS-230-oriented security readiness. That includes OBU item definition, threat analysis for V2X interfaces, communication-security requirements, architecture review, verification planning, and a phased readiness roadmap for the India timeline. See our India-focused V2V / C-V2X Security service at /services/v2v-cv2x-security.

We interpret the published MoRTH and PIB material as engineering input. We do not claim authorship of AIS-230, Task Force membership, or Government of India endorsement. Final regulatory text remains with the competent authorities after consultation.

Written by

AutoSec Engineering Team

Automotive cybersecurity engineering

Engineers working on vehicle cybersecurity concepts, requirements, embedded implementation, and verification across OEM and supplier programmes.

More from this author

Discuss this with a specialist

If this applies to a programme you are working on, we are happy to talk it through.

Book a Consultation