Key Details
The reply covers the identified vulnerability, immediate mitigation measures and the evolving regulatory framework for EV cybersecurity.
Key Area | Main Update |
|---|---|
Cybersecurity vulnerability | CERT-In identified Bluetooth security weaknesses in BMS used in some low-cost e-rickshaws, potentially enabling unauthorised battery shutdowns. |
Immediate response | Vulnerable mobile applications were reported to MeitY for removal, while advisories were issued to industry bodies and testing agencies. |
Battery safety | Existing battery safety remains governed under AIS 156, with electric powertrain safety covered by AIS 038 Rev. 2. |
Cybersecurity regulation | Draft cybersecurity approval requirements based on AIS 189 and AIS 190 have been notified for L, M and N category vehicles. |
Vehicle certification | Prototype testing and Type Approval certification continue to be mandatory under Rule 126 of the CMVR, 1989. |
CERT-In Identifies Vulnerability in E-Rickshaw Battery Systems
Replying to a Lok Sabha question on 21 July 2026, the Ministry of Heavy Industries stated that CERT-In had identified a cybersecurity vulnerability affecting the Bluetooth-enabled Battery Management Systems (BMS) used in certain low-cost electric three-wheelers.
According to the Government, weak or absent authentication credentials could allow unauthorised users to connect through publicly available mobile applications, potentially modifying battery settings or interrupting battery discharge.
To mitigate the risk, CERT-In reported the identified applications to MeitY for removal from app stores, while the Ministry of Heavy Industries issued advisories to industry associations and testing agencies.
Vehicle Safety Is Expanding to Include Cybersecurity
The Lok Sabha reply indicates that India's electric vehicle safety framework is evolving beyond battery and powertrain safety to address cybersecurity risks associated with increasingly connected vehicles.
While AIS 156 and AIS 038 Rev. 2 continue to govern battery and powertrain safety, the Government has proposed dedicated cybersecurity approval requirements through draft rules based on AIS 189 and AIS 190. Manufacturers must also continue to obtain Type Approval certification under Rule 126 of the Central Motor Vehicles Rules, 1989, before vehicles enter the market.
What Is a Battery Management System (BMS)?
A Battery Management System (BMS) is the electronic system that monitors and controls the operation of an electric vehicle's battery. It manages functions such as charging, discharging, temperature and battery health, making it critical to both vehicle performance and safety.
Policy Relevance
Connected Vehicle Security: The incident highlights the growing need to secure software-enabled vehicle components, particularly Battery Management Systems, against unauthorised access.
Regulatory Evolution: Draft standards based on AIS 189 and AIS 190 indicate a shift towards incorporating cybersecurity into vehicle approval frameworks.
Secure-by-Design Manufacturing: Manufacturers and component suppliers will need to integrate stronger authentication and cybersecurity controls into connected vehicle systems.
Integrated EV Safety: India's regulatory framework is expanding from battery safety to encompass both the physical and digital security of electric vehicles.
Consumer Confidence: Strengthening cybersecurity standards can improve the safety, reliability and public trust needed to support wider EV adoption.
Relevant Question for Policy Stakeholders: As electric vehicles become increasingly software-defined, how should cybersecurity assurance be incorporated into vehicle certification and post-market safety oversight?
Follow the Full News Here: Lok Sabha Q&A: CYBERSECURITY VULNERABILITIES IN E-RICKSHAW BMS AND ROLE OF CERTIFICATION AGENCIES

