India connected vehicle security
AIS-230 V2V and C-V2X Cybersecurity for Indian Automotive Programmes

At a glance
- Concept
- Architecture
- Development
- Verification
- Standards referenced
- AIS-230ISO/SAE 21434UNECE R155C-V2X / ITS 5.9 GHzCMVR (draft V2V)
- Core deliverables
- India V2V/C-V2X security scope and OBU item definition
- Threat analysis and risk treatment decisions for V2X interfaces
- Cybersecurity goals and technical requirements for AIS-230-oriented readiness
- Verification and test planning for OBU and message-security controls
The problem we are asked to solve
- V2V and C-V2X work in India is treated as a radio or ITS feature, with AIS-230 cybersecurity left until late.
- OBU trust boundaries, message authenticity, and CMVR-facing evidence ownership are unclear across Indian and global suppliers.
- Teams cannot yet map draft AIS-230 security provisions and 5.9 GHz C-V2X constraints to concrete requirements and tests.
- Programme plans do not yet absorb MoRTH’s proposed October 2027 and October 2028 V2V milestones for categories L, M, and N.
What changes as a result
- Clear security scope for India-bound V2V/C-V2X items and OBU interfaces
- Threat analysis covering communication security and AIS-230 safety use cases
- Requirements and verification plans aligned to AIS-230-oriented readiness
- A defensible roadmap for India’s phased V2V implementation timeline
Scope of work
What the engagement covers
Scope is agreed per programme. These are the activities we most often deliver for this service.
- AIS-230 India and MoRTH V2V draft security requirements interpretation
- C-V2X On-Board Unit item definition and trust-boundary analysis
- Threat analysis for V2V interfaces and safety-relevant message flows on Indian roads
- Communication-security and message-authenticity considerations for 5.9 GHz ITS
- Cybersecurity concept and technical requirements for C-V2X stacks
- Architecture and interface review across vehicle and OBU suppliers serving India
- Verification and penetration-testing planning for C-V2X implementations
- Programme readiness review against the 2027/2028 India fitment timeline
- Supplier alignment on evidence for Indian OEM and Tier-1 programmes
- Coordination with ISO/SAE 21434 and UNECE R155 cybersecurity obligations
Engagement methodology
How we work
A predictable sequence, adapted to your process and release gates rather than replacing them.
- 01
Establish V2X context
Agree the OBU and V2V item boundary, interfaces, safety use cases in scope, and which draft AIS-230 provisions the programme must prepare for.
- 02
Analyse V2X threats
Run or review threat analysis for communication paths, message authenticity, positioning integrity, and misuse scenarios that affect road-safety applications.
- 03
Specify security requirements
Derive cybersecurity goals and technical requirements for the C-V2X stack, then review architecture and supplier interfaces against them.
- 04
Plan verification
Define the evidence each requirement needs—including radio, security, and application-level checks—and who produces it across OEM and suppliers.
- 05
Review readiness
Assess programme readiness against the phased 2027/2028 timeline and close gaps before they become late assessment findings.
Deliverables
Every engagement ends with artefacts your organisation owns and can defend in review.
- India V2V/C-V2X security scope and OBU item definition
- Threat analysis and risk treatment decisions for V2X interfaces
- Cybersecurity goals and technical requirements for AIS-230-oriented readiness
- Verification and test planning for OBU and message-security controls
- Supplier interface and evidence checklist for Indian programmes
- Readiness roadmap against MoRTH’s phased 2027–2028 timeline
Relevant standards
We help organisations interpret and implement these requirements. We do not certify or approve organisations.
- AIS-230
- ISO/SAE 21434
- UNECE R155
- C-V2X / ITS 5.9 GHz
- CMVR (draft V2V)
Typical use cases
- Indian OEM C-V2X On-Board Unit programme preparing for AIS-230-oriented compliance
- Tier-1 V2V stack security concept and TARA for Emergency Brake Alert and related use cases
- Supplier review of communication-security evidence for vehicles sold in India
- Gap assessment against India’s October 2027 and October 2028 V2V milestones
- Aligning India V2V security work with existing ISO/SAE 21434 and R155 programmes
Evidence
Case studies covering V2V / C-V2X Security work are being prepared for publication. Automotive security engagements are normally confidential, so we discuss comparable scope, method, and deliverables directly rather than publishing unverifiable claims.
Questions
Frequently asked
What is AIS-230 in the Indian V2V context?
Is AIS-230 already a final mandatory rule in India?
What are the proposed India V2V timelines for 2027 and 2028?
Do you support Indian OEMs and Tier-1 suppliers only?
Can you test a C-V2X stack for the Indian market as well as write requirements?
Which frequency band does the India V2V draft reference?
Related services
Often delivered together
Automotive Cybersecurity Engineering
Turn cybersecurity risk into traceable requirements, implementable controls, and verification-ready work products.
View serviceTARA and ISO/SAE 21434 Support
Structured threat analysis and risk assessment that produces defensible risk decisions, not spreadsheets nobody uses.
View serviceAutomotive Penetration Testing and Red Teaming
Adversary-led testing of ECUs, in-vehicle networks, wireless interfaces, applications, and supporting backends.
View serviceVSOC and Incident Response
Build the monitoring, triage, and response capability required to operate vehicle security after start of production.
View serviceEmbedded Security and AUTOSAR
Implement security controls where they run: bootloaders, cryptographic services, communication protection, and ECU hardening.
View service
Discuss Your Cybersecurity Program
Tell us where the programme is today and we will outline a realistic next step.
