AIS-189 clause 5.3.1: why being on the Rule 126 list isn't enough
The clause that separates a named test agency from one that actually holds cybersecurity competence
Two different questions
There are two questions hiding behind "who assesses my CSMS in India", and they are routinely confused. The first is procedural: which agency is named to receive a prototype for test. The second is substantive: does that agency actually hold the cybersecurity competence to assess a management system against AIS-189. AIS-189 clause 5.3.1 is the clause that keeps these two questions apart — and knowing the difference changes how a programme is planned.
Being listed under Rule 126 of the Central Motor Vehicles Rules answers only the first question. Clause 5.3.1 answers the second, and it does so by placing a requirement on the assessor rather than the manufacturer.
What clause 5.3.1 actually says
In plain terms, clause 5.3.1 requires that the agency assessing a cyber security management system holds automotive cybersecurity and risk-assessment competence of its own. The competence is not delegated, assumed, or inherited from a Rule 126 listing — it has to sit with the agency doing the assessment.
That phrasing matters because a CSMS assessment is not a bench test with a pass/fail readout. AIS-189 is aligned to UN R155, and R155 asks an approval authority to judge whether an organisation's processes — governance, risk management, supplier flow-down, monitoring, incident response — are real and are followed across the vehicle lifecycle. Judging that requires someone who can read a threat analysis and risk assessment (TARA), follow an attack path, and tell whether the risk treatment is defensible. That is a competence, not a checklist.
Why Rule 126 listing is not cybersecurity scope
Rule 126 of the CMVR, 1989, names the institutions to which a vehicle prototype may be submitted for test. The list is about type-approval standing across the whole vehicle — emissions, safety, construction — and it grew over time. CIRT (the Central Institute of Road Transport, Pune, under MoRTH) was added to that list by G.S.R. 276(E) dated 10 April 2007.
But being named in Rule 126 confers the standing to test a prototype; it does not, by itself, confer cybersecurity scope. A body can be a long-established, respected test agency and still need to build automotive cybersecurity capability separately. That is precisely the gap clause 5.3.1 closes: it says the agency must hold the cybersecurity and risk-assessment competence itself before it can assess a CSMS. Naming and competence are two different gates.
| Aspect | Rule 126 listing | AIS-189 clause 5.3.1 |
|---|---|---|
| What it establishes | Standing to receive a prototype for test | Competence to assess a CSMS |
| Instrument | CMVR, 1989 (CIRT added by G.S.R. 276(E), 10 Apr 2007) | AIS-189 |
| Question answered | Which agency may test | Whether that agency can judge cybersecurity |
| Scope | Whole-vehicle type approval | Automotive cybersecurity + risk assessment |
| Confers the other? | No — listing is not cyber scope | No — competence is assessed on its own terms |
What this means for an OEM
The practical consequence is that you cannot treat cybersecurity assessment as an administrative extension of the type-approval you already do. Two things follow.
First, the assessor's competence is part of the value of the certificate. A Certificate of Compliance for a CSMS under R155 is valid three years; the same weight attaches to the Indian assessment. A certificate signed by an agency that genuinely holds the competence in clause 5.3.1 is worth more than one issued by rote, because it will survive scrutiny in an export market and in a later incident review.
Second, the manufacturer's own evidence has to be strong enough to withstand a competent reading. If you have written a process but cannot show the records proving it ran on a real programme, a competent assessor will find the gap — that is the classic failure mode, covered in our note on what evidence a UN R155 audit actually opens. Clause 5.3.1 raises the floor on both sides of the table.
Where the work happens
Because the competence has to sit with the assessing agency, the sensible way to prepare is alongside that agency rather than in isolation from it. This is a structural point, not a marketing one: the closer the manufacturer's CSMS work runs to the body that will assess it, the fewer surprises there are at assessment. The competence requirement is exactly what makes an early, shared reading of the evidence valuable.
In India that body is identifiable, not hypothetical: CIRT — a Testing & Certification agency notified under CMVR Rule 124 and Rule 126, and a type-approval authority for AIS-189 and AIS-190 — holds the assessment scope this clause demands. So the clause resolves cleanly for a homologation manager: the venue clears the competence bar, and the open work is the manufacturer's own evidence. How that venue fits the wider CMVR route is set out in Rule 124, Rule 126 and CIRT.
That is also why the Rule 126 question and the clause 5.3.1 question should be answered together at the start of a programme, not sequentially. Our companion piece on Rule 126 and who can type-approve your vehicle works through the listing side; this one works through the competence side. For the standard as a whole, see AIS-189 explained.
A last point on honesty. AIS-189 and AIS-190 enforcement in India is proposed in MoRTH draft G.S.R. 503(E) (17 June 2026) — phased from October 2026 — but not yet finalised in the gazette. Clause 5.3.1 is in the published standard regardless of when enforcement lands, so the competence question is live now — it is one of the few parts of the Indian regime you can plan against with certainty.
The AutoSifu view
AutoSifu works one route: compliance, solutioning, and CoC/VTA support, with the approval body in the room. Clause 5.3.1 is the reason that matters — a CSMS is only worth the competence that reads it, so we prepare the evidence alongside CIRT rather than hand a dossier over a wall. That keeps the assessment defensible and the certificate meaningful in the markets an OEM actually ships to.
Questions
- What does AIS-189 clause 5.3.1 require?
- Clause 5.3.1 of AIS-189 requires that the agency assessing a cyber security management system holds automotive cybersecurity and risk-assessment competence of its own. It is a competence requirement placed on the assessor, not on the manufacturer. Meeting it means the agency can demonstrably read a TARA, judge risk treatment, and test the evidence behind a CSMS — not merely receive a dossier.
- Can any Rule 126 agency assess a CSMS?
- No. Rule 126 of the CMVR names the institutions to which a vehicle prototype may be submitted for test, but that listing is about type-approval standing, not cybersecurity scope. AIS-189 clause 5.3.1 handles competence separately, so an agency needs to demonstrate cybersecurity and risk-assessment capability in addition to being named in Rule 126.
- Why does competence matter for the assessor?
- A CSMS assessment is only as good as the person reading it. Without genuine automotive cybersecurity competence, an assessor cannot distinguish a process that is written down from one that was actually run on a programme, nor judge whether a TARA is defensible. Clause 5.3.1 exists so that the certificate means something.
