Skip to main content
AutoSec Innovation

India connected vehicle security

AIS-230 V2V and C-V2X Cybersecurity for Indian Automotive Programmes

Support Indian OEM, Tier-1, and OBU supplier programmes preparing for MoRTH’s draft Vehicle-to-Vehicle framework under AIS-230. We turn C-V2X cybersecurity and communication-security expectations into requirements, architecture decisions, and testable evidence ahead of India’s phased 2027 and 2028 fitment timeline.
Connected vehicles exchanging V2V / C-V2X safety messages for AIS-230-oriented automotive cybersecurity

At a glance

  • Concept
  • Architecture
  • Development
  • Verification
Standards referenced
AIS-230ISO/SAE 21434UNECE R155C-V2X / ITS 5.9 GHzCMVR (draft V2V)
Core deliverables
  • India V2V/C-V2X security scope and OBU item definition
  • Threat analysis and risk treatment decisions for V2X interfaces
  • Cybersecurity goals and technical requirements for AIS-230-oriented readiness
  • Verification and test planning for OBU and message-security controls

The problem we are asked to solve

  • V2V and C-V2X work in India is treated as a radio or ITS feature, with AIS-230 cybersecurity left until late.
  • OBU trust boundaries, message authenticity, and CMVR-facing evidence ownership are unclear across Indian and global suppliers.
  • Teams cannot yet map draft AIS-230 security provisions and 5.9 GHz C-V2X constraints to concrete requirements and tests.
  • Programme plans do not yet absorb MoRTH’s proposed October 2027 and October 2028 V2V milestones for categories L, M, and N.

What changes as a result

  • Clear security scope for India-bound V2V/C-V2X items and OBU interfaces
  • Threat analysis covering communication security and AIS-230 safety use cases
  • Requirements and verification plans aligned to AIS-230-oriented readiness
  • A defensible roadmap for India’s phased V2V implementation timeline

Scope of work

What the engagement covers

Scope is agreed per programme. These are the activities we most often deliver for this service.

  • AIS-230 India and MoRTH V2V draft security requirements interpretation
  • C-V2X On-Board Unit item definition and trust-boundary analysis
  • Threat analysis for V2V interfaces and safety-relevant message flows on Indian roads
  • Communication-security and message-authenticity considerations for 5.9 GHz ITS
  • Cybersecurity concept and technical requirements for C-V2X stacks
  • Architecture and interface review across vehicle and OBU suppliers serving India
  • Verification and penetration-testing planning for C-V2X implementations
  • Programme readiness review against the 2027/2028 India fitment timeline
  • Supplier alignment on evidence for Indian OEM and Tier-1 programmes
  • Coordination with ISO/SAE 21434 and UNECE R155 cybersecurity obligations

Engagement methodology

How we work

A predictable sequence, adapted to your process and release gates rather than replacing them.

  1. 01

    Establish V2X context

    Agree the OBU and V2V item boundary, interfaces, safety use cases in scope, and which draft AIS-230 provisions the programme must prepare for.

  2. 02

    Analyse V2X threats

    Run or review threat analysis for communication paths, message authenticity, positioning integrity, and misuse scenarios that affect road-safety applications.

  3. 03

    Specify security requirements

    Derive cybersecurity goals and technical requirements for the C-V2X stack, then review architecture and supplier interfaces against them.

  4. 04

    Plan verification

    Define the evidence each requirement needs—including radio, security, and application-level checks—and who produces it across OEM and suppliers.

  5. 05

    Review readiness

    Assess programme readiness against the phased 2027/2028 timeline and close gaps before they become late assessment findings.

Deliverables

Every engagement ends with artefacts your organisation owns and can defend in review.

  • India V2V/C-V2X security scope and OBU item definition
  • Threat analysis and risk treatment decisions for V2X interfaces
  • Cybersecurity goals and technical requirements for AIS-230-oriented readiness
  • Verification and test planning for OBU and message-security controls
  • Supplier interface and evidence checklist for Indian programmes
  • Readiness roadmap against MoRTH’s phased 2027–2028 timeline

Relevant standards

We help organisations interpret and implement these requirements. We do not certify or approve organisations.

  • AIS-230
  • ISO/SAE 21434
  • UNECE R155
  • C-V2X / ITS 5.9 GHz
  • CMVR (draft V2V)

Typical use cases

  • Indian OEM C-V2X On-Board Unit programme preparing for AIS-230-oriented compliance
  • Tier-1 V2V stack security concept and TARA for Emergency Brake Alert and related use cases
  • Supplier review of communication-security evidence for vehicles sold in India
  • Gap assessment against India’s October 2027 and October 2028 V2V milestones
  • Aligning India V2V security work with existing ISO/SAE 21434 and R155 programmes

Evidence

Case studies covering V2V / C-V2X Security work are being prepared for publication. Automotive security engagements are normally confidential, so we discuss comparable scope, method, and deliverables directly rather than publishing unverifiable claims.

Questions

Frequently asked

What is AIS-230 in the Indian V2V context?
AIS-230 is the Automotive Industry Standard referenced by MoRTH for factory-installed V2V / C-V2X On-Board Units on Indian roads. The PIB summary of the draft framework describes minimum technical, functional, performance, environmental, and cybersecurity requirements, including communication-security provisions and safety use cases such as Emergency Brake Alert and Forward Collision Warning.
Is AIS-230 already a final mandatory rule in India?
The Ministry of Road Transport and Highways has issued a draft notification proposing phased V2V implementation under AIS-230, with consultation still part of the process. Final Central Motor Vehicles Rules text may change. We help Indian OEM and supplier programmes prepare against the published draft direction without overstating what is already binding.
What are the proposed India V2V timelines for 2027 and 2028?
Per the PIB summary, vehicles in categories L, M, and N manufactured on or after 1 October 2027 must comply with AIS-230 where V2V systems are fitted. From 1 October 2028, those categories are proposed to require V2V systems conforming to AIS-230. We build readiness roadmaps around those milestones.
Do you support Indian OEMs and Tier-1 suppliers only?
The service is framed for India-market V2V / AIS-230 readiness, including programmes delivered from India, Germany, or mixed supply chains. The same engineering methods—item definition, TARA, communication security, and verification—also support alignment with ISO/SAE 21434 and UNECE R155.
Can you test a C-V2X stack for the Indian market as well as write requirements?
Yes. We define verification needs as part of the engagement and can extend into penetration testing and security validation of OBU and interface implementations through our related automotive penetration testing services.
Which frequency band does the India V2V draft reference?
The PIB release cites the 5.875 GHz to 5.925 GHz band for V2V and other Intelligent Transportation System applications, with a Department of Telecommunications licensing exemption referenced via G.S.R. 466(E). Security work must still treat message authenticity, integrity, and misuse independently of spectrum allocation.

Discuss Your Cybersecurity Program

Tell us where the programme is today and we will outline a realistic next step.