AIS-189/190 Compliance (India)

India now has its own automotive cybersecurity mandate. AIS-189/190 brings CSMS requirements to vehicles sold in India, and AIS-190 adds software-update security, effective for new vehicle types from October 2026 and all vehicle types from April 2027. We help India OEMs and suppliers get ready in time.

India's Automotive Cybersecurity Mandate

AIS-189/190 is India's automotive cybersecurity standard, aligned with UN R155/R156. It requires any OEM selling vehicles in India to operate an approved Cybersecurity Management System (CSMS). AIS-190 extends that to software-update security (SUMS), mirroring UN R156.

If you're already preparing for UN R155/R156, a lot of the groundwork carries over. But Indian approval may be its own separate, mandatory step for the domestic market. It may not be granted automatically just because you've met R155/R156 elsewhere.

What AIS-189/190 and AIS-190 Require

Because AIS-189/190 lines up with UN R155/R156, an OEM with a global programme can reuse much of its CSMS. But the documentation and approval for India have to stand on their own.

AIS-189/190: CSMS (Cybersecurity Management System)

A documented CSMS covering the vehicle's whole lifecycle. A TARA for each vehicle type sold in India. Risk treatment, plus monitoring after the vehicle is in production.

AIS-190: SUMS (Software Update Management System)

A system for secure, validated software and OTA updates. Integrity and traceability for every update package.

How We Support India OEMs and Suppliers

India-specific knowledge, global experience

Most of AIS-189/190 overlaps with UN R155/R156, and we work across both. So we can tell you which of your existing evidence carries straight over, what has to be built specifically for the Indian process, and how an assessor here will expect to see it presented.

AIS-189/190 gap report

We measure your current processes and documentation against every AIS-189 and AIS-190 clause, then hand you a prioritised gap report that sets out exactly what is missing and which gaps to close first.

Vehicle-type TARA

We run the Threat Analysis and Risk Assessment for each vehicle type you sell in India, identifying the threats that genuinely apply, rating them, and recording the risk treatment the regulation expects to see.

CSMS/SUMS evidence

We build the documented evidence your Cybersecurity and Software Update Management Systems need, covering the vehicle's whole lifecycle, from the design decisions through to monitoring once it is in production.

Approval-readiness pack

We pull the TARA, the risk treatment, the update-integrity records and the monitoring evidence into a single pack, organised the way an assessor will expect to review it when your approval is assessed.

Common Questions

It's India's automotive cybersecurity standard. It requires OEMs to operate an approved CSMS for vehicles sold in India, and it's aligned with UN R155/R156.
Software-update security: a Software Update Management System (SUMS) for validated, traceable updates, aligned with UN R156.
Not automatically. A lot of the CSMS work carries over, but Indian approval is separate, so you may still need AIS-specific documentation and sign-off.
Download the AIS-189/190 checklist to see what's required, then book a gap assessment to map where you stand against it.

Get AIS-189/190 Ready for the Indian Market

Download the AIS-189/190 checklist to see exactly what's required, then book a gap assessment for a prioritised path to compliance.