HomePolicies & Regulations ›MoRTH Mandates Cybersecurity Testing for Wireless-Enabled EV BMS

MoRTH Mandates Cybersecurity Testing for Wireless-Enabled EV BMS

The Ministry of Road Transport and Highways has introduced new cybersecurity requirements for wireless-enabled BMS in electric two- and three-wheelers, mandating seven security assessments to protect critical battery functions from unauthorised access, cyberattacks and remote manipulation.

September 09, 2026. By Mrinmoy Dey

The Ministry of Road Transport and Highways (MoRTH) has prescribed new cybersecurity requirements for Battery Management Systems (BMS) used in L-category electric vehicles, including electric two- and three-wheelers, to protect battery systems against unauthorised access, malicious intervention and remote manipulation.
 
The new requirements apply to BMS equipped with Bluetooth Classic, Bluetooth Low Energy (BLE) or other wireless interfaces, whether accessed directly or through an OEM companion mobile application.
 
The cybersecurity provisions cover critical BMS functions, including access to live battery telemetry such as voltage, current, temperature and State of Charge (SoC), as well as safety-related controls such as actuating relays and contactors, enabling or disabling charging and discharging pathways, and overriding cell balancing. They also cover modification of protection thresholds, fault resets and over-the-air (OTA) firmware operations.
 
For type approval, manufacturers are required to submit the Rechargeable Electrical Energy Storage System (REESS) BMS in its default, as-delivered configuration for testing. The amendment specifies seven mandatory cybersecurity assessments covering discoverability, pairing and authentication, unauthorised connections and command injection, replay attacks, spoofing and man-in-the-middle (MITM) attacks, denial-of-service (DoS) attacks and protocol or firmware fuzzing.
 
The testing will verify that BMS units do not expose sensitive identifying information, accept unauthenticated connections or rely on easily bypassed default credentials. Testing will also assess whether third-party applications can execute safety-critical commands, whether captured command frames can be replayed, and whether rogue devices can impersonate genuine BMS units.
 
In addition, systems will be subjected to wireless flooding and malformed data inputs to ensure that core protections against overcharging, over-discharging, short circuits and thermal events remain operational.
 
Under the amended standard, a BMS will fail the cybersecurity compliance assessment if it executes a safety-critical command from an unauthenticated source or loses core protective functions during cyber-stress testing.
 
The provisions establish a formal cybersecurity baseline for wireless-enabled EV battery systems and are expected to strengthen protection against emerging digital vulnerabilities as connected battery technologies become increasingly common in India's electric two- and three-wheeler segment.
Please share! Email Buffer Digg Facebook Google LinkedIn Pinterest Reddit Twitter
If you want to cooperate with us and would like to reuse some of our content,
please contact: contact@energetica-india.net.
 
 
Next events
 
 
Last interviews
 
Follow us