India's V2X framework — consultation to draft mandate in ninety-five days.
Between 30 April and 3 August 2026, India moved from having no V2X policy to having a proposed national fitment mandate covering every category of road vehicle including motorcycles. Three instruments, from three different arms of government, at three different levels of the stack. This page is what each one actually says.
Dated 30 April 2026. Announced by Press Release No. 57/2026.
Issued on a DoT reference letter of 1 December 2025. Correct citation matters here, because the paper is widely miscited: it is Consultation Paper No. 08/2026, Regulatory Framework for Vehicle-to-Everything (V2X) Communication. The commonly seen “CP 30/04/2026” is the PDF filename date, not the paper number.
Comments were originally due 28 May 2026 with counter-comments on 11 June. Both were extended by Press Release No. 64/2026 — comments to 4 June 2026 and counter-comments to 18 June 2026, and TRAI's consultation page records 4 June 2026 as the closing date. The consultation drew 33 comments and 6 counter-comments, the counter-comments filed between 19 and 22 June 2026. TRAI's Recommendations had not been issued as of mid-August 2026 — the only recommendation TRAI published in 2026 up to that point was on IMT spectrum auction, dated 24 February 2026.
Structure: five chapters — Introduction; V2X Technologies and Global Perspective; Service Authorisation Framework and Spectrum Assignment; Spectrum Charges and Other Financial Conditions; and Issues for Consultation, beginning at page 132.
Spectrum. 5875–5925 MHz (50 MHz), split as 5875–5905 MHz (30 MHz) for initial deployment and 5905–5925 MHz (20 MHz) held in reserve for future ITS. The MoRTH ITS Task Force recommended the full range at a maximum 4 W EIRP (36 dBm) for both on-board and roadside units. One secondary source recasts the split as “30 MHz for V2V, 20 MHz for V2I”; that is a misreading, and the initial-deployment / reserve framing is the correct one. The spectrum picture →
Technology. C-V2X, covering 3GPP LTE-V2X and 5G NR-V2X. DSRC is rejected on the basis that it has not been meaningfully adopted or deployed domestically and that C-V2X is the harmonised international choice.
Authorisation model.
- On-board units — licence-exempt under defined technical conditions. Individually licensing millions of units is impractical.
- Roadside units — authorisation required, with eligibility restricted, per MoRTH correspondence, to “Central or State Governments or any other agencies authorized by them.” In practice: state governments, NHAI, city bodies. Private entities considered only for non-safety applications.
- Administrative assignment with minimal charges rather than auction, on the reasoning that most countries have avoided aggressive auction-based pricing for ITS given the public-safety linkage — while noting that under-pricing invites inefficient deployment.
Cybersecurity. This is the paper's most substantive section and the one Indian vendors should read most carefully. It addresses spoofing, replay, Sybil attacks, message tampering, denial of service and physical RSU compromise; identifies that continuous broadcast of position, speed and heading enables persistent surveillance and behavioural profiling, and that India lacks a V2X-specific privacy framework; and compares the US SCMS, EU CCMS and Chinese C-SCMS models.
Its structural finding is the important one. India's existing digital-trust infrastructure, under the IT Act and the CCA-licensed certifying authorities, recognises only ITU-T X.509 certificates. Global V2X standards use IEEE 1609.2 and ETSI ITS formats. That is a genuine incompatibility with the Indian PKI regime. The Task Force recommendation quoted in the paper is a harmonised approach based on ETSI TS 102 941, with either a separate dedicated national ITS root CA, or a coexistence framework in which the national X.509 root CA countersigns ITS certificates. Our view on the architecture →
The paper assigns certification of on-board and roadside radio equipment to TEC, DoT as the competent authority for verification of emission-limit compliance.
The verbatim numbered Issues for Consultation in Chapter V could not be retrieved — the PDF truncated on every fetch — so no question numbers are quoted on this site.
G.S.R. 466(E), dated 10 June 2026.
Notifying the Use of On Board Unit for Cellular Vehicle-to-Everything Communication in the 5.9 GHz Band (Exemption from Licensing Requirements) Rules, 2026, under the Indian Telegraph Act 1885 and the Indian Wireless Telegraphy Act 1933.
| Parameter | Value |
|---|---|
| Band exempted | 5875–5905 MHz (30 MHz) |
| Maximum power spectral density | 23 dBm/MHz |
| Maximum in-band EIRP | 33 dBm |
| Out-of-band emissions | −30 dBm/MHz |
| Basis | Non-interference, non-protection, non-exclusive |
| Scope | On-Board Units only. Roadside units are not covered. |
| Still required | Equipment type approval through the DoT portal |
The exemption removes the spectrum licence, not the equipment approval. This is a real and significant enabler — an OBU manufacturer no longer needs a spectrum authorisation to ship — and it is narrower than press coverage sometimes suggests.
Draft notification published 3 August 2026, amending the Central Motor Vehicles Rules, 1989.
Thirty-day comment window, closing early September 2026. Note that G.S.R. 466(E) belongs to DoT, not MoRTH — the two are frequently conflated in trade coverage. No G.S.R. number is published here for the MoRTH instrument, because its own number is not available in any accessible source; the date, content and timelines are corroborated by PIB and multiple outlets. Note also a band discrepancy worth stating precisely: PIB and MoRTH describe the band as 5.875–5.925 GHz, while the DoT exemption rules cover only 5875–5905 MHz. Designation and licence exemption are different things at different widths.
Scope: categories L, M and N — two- and three-wheelers including sub-100cc scooters; passenger cars and buses; goods vehicles.
| Date | Requirement |
|---|---|
| 1 October 2027 | Vehicles of categories L, M and N manufactured on or after this date that are fitted with a V2V system must comply with AIS-230 |
| 1 October 2028 | All newly manufactured L, M and N vehicles must carry an AIS-230-compliant, factory-installed on-board unit |
AIS-230 specifies minimum technical, functional, performance, environmental and security requirements for factory-installed C-V2X on-board units: radio performance and frequency stability, output power, receiver sensitivity, GNSS positioning, electromagnetic compatibility, and mandatory PKI-based cybersecurity provisions. It was considered by the CMVR Technical Standing Committee at its 56th meeting on 7 May 2026.
Technology: C-V2X, dual-mode — PC5 sidelink for infrastructure-independent V2V, Uu for network-assisted features — explicitly designed so that LTE-V2X Release 14/15 can be upgraded to 5G NR-V2X Release 16+ without hardware replacement. Band 5875–5925 MHz. What that upgrade path actually requires →
Four safety applications, phased: Emergency Brake Alert, Forward Collision Warning, Wrong-Way Driving Alert, Emergency Vehicle Alert. Vehicles must continuously broadcast speed, position, acceleration and direction. The V2V application set →
Why this is globally significant. If finalised, it is the first national V2V fitment mandate anywhere to cover two-wheelers — and in India, close to half of all road deaths are two-wheeler riders, per MoRTH's Road Accidents in India series. India's annual road death toll is measured in the high hundreds of thousands of crashes and around 170,000–180,000 fatalities on the most recently published editions of that series. No single-year total is quoted here: the current-year figures circulating in trade coverage could not be matched to a published MoRTH edition.
Why it is fragile. Trade coverage cites a per-unit cost estimate of ₹5,000–7,000 (roughly US$60 to US$85). India sells roughly nineteen to twenty million two-wheelers a year, many at price points where that is a material fraction of the vehicle. And no Indian two-wheeler manufacturer has a publicly announced V2X programme. This will be the most contested element of the consultation, and it is the reason a domestic hardware supply base matters commercially rather than merely patriotically. The AmbiOBU programme →
TEC 31318 — read this carefully.
- TEC 31318:2021, Release 1.0 (August 2021) — Code of Practice for Securing Consumer IoT. Five headline mandates: no universal default passwords, a vulnerability disclosure mechanism, secure OTA updates with consumer notification, hardware-backed credential storage, and secure boot with signed firmware.
- Superseded by TEC 31318:2025, Release 2.0, dated 26 November 2025, aligned to ETSI EN 303 645 V3.1.3 (September 2024), with 13 guidelines rather than five: no universal default passwords; vulnerability disclosure; software updates with lifecycle disclosure; secure key storage; encrypted communications; minimised attack surface; secure boot; personal data protection; resilience; telemetry monitoring; user data deletion; simple installation; input validation.
- Scope, verbatim: “This Code of Practice applies to consumer IoT products that are connected to the internet and/or home network and associated services.” Be precise about what this does and does not say: the document carries no exclusion clause, and automotive is not named either way. It simply is not a connected-vehicle standard, and its illustrative categories are domestic and personal devices.
The practical consequence: TEC 31318 is a real, current and useful standard for IoT devices and for the wider Indian IoT market. It is not a V2X security standard and this site does not present it as one. Indian V2X security requirements will come through AIS-230, through whatever TEC publishes as a V2X-specific Essential Requirement, and through the PKI framework TRAI's recommendations propose.
MTCTE. Now operating under the Telecommunications (Framework to Notify Standards, Conformity Assessment and Certification) Rules, 2025, with the operative procedure in TEC 93009:2024, Amended MTCTE Procedure v3.0. The core rule: no notified telecom equipment may be sold or deployed in any telecommunication network without a valid Certificate of Conformity Assessment. Security requirements flow through ITSAR documents and the NCCS. On the evidence available, V2X equipment does not currently appear in the MTCTE notified equipment list — but the TRAI consultation designates TEC as the competent certification authority for OBU and RSU radio compliance, and G.S.R. 466(E) preserves mandatory equipment type approval, so on-board units will require TEC and WPC approval regardless. Expect a future MTCTE phase notification or a dedicated TEC Essential Requirement for C-V2X equipment.
The automotive side. AIS standards are issued through the ARAI-run CMVR-TSC and AISC process and enforced through CMVR type approval by ARAI, ICAT, GARC and CIRT. AIS-140 — vehicle location tracking, emergency button, and for public service vehicles camera surveillance — remains the incumbent connected-vehicle standard for commercial and public service vehicles. AIS-230 is the new V2X OBU standard. Bharat NCAP, in force since 1 October 2023, is a consumer rating programme rather than a V2X instrument, but is the obvious vehicle for incentivising early voluntary fitment ahead of 2028.
Seven institutions, and a domestic technology base that is thinner than it looks.
MoRTH — ITS policy; the ITS Task Force constituted October 2024. DoT / WPC — spectrum. TEC — equipment certification. MeitY / CCA — the PKI framework under the IT Act 2000, and the X.509 licensing regime that creates the V2X certificate-format problem. C-DOT and C-DAC — the likely implementing R&D bodies for a national ITS root CA, though no formal designation has been made. CERT-In — incident reporting. NABL-accredited labs — testing capacity, which does not yet exist for V2X in India and will need to be built. The test-capacity gap →
Domestic technology base. Maruti Suzuki with IIT Hyderabad, which conducted India's first V2X research demonstration on 11 May 2022 with five prototype vehicles covering ambulance alert, wrong-way driver alert, pedestrian alert, motorcycle alert and road condition alert — with the explicit caveat in the IIT-H release that “this research project has no connection to the company's product planning.” L&T Technology Services joined that collaboration in June 2024. Mahindra uses Qualcomm's Snapdragon Digital Chassis in the BE 6 and XEV 9e; the Qualcomm announcement does not mention C-V2X, and Mahindra is not described here as shipping it.
As of the TRAI consultation in April 2026, India had effectively zero operational V2X roadside units, and no domestic OBU or RSU manufacturer.
Each of them still open, and each of them shapes whether the framework works.
1 · Whether roadside operation needs its own authorisation.
It does. A dedicated authorisation instrument gives regulatory clarity that a general permission cannot, and it lets conditions be attached to something that is genuinely infrastructure. Sensible conditions: demonstrated technical capability to deploy and operate roadside infrastructure; financial capacity commensurate with scale; organisational capacity for cybersecurity including certificate lifecycle management and incident response; and compliance with published equipment standards. A ten-year initial validity renewable in five-year periods, conditional on demonstrated compliance, is a reasonable shape.
2 · Which generation of C-V2X to specify.
NR-C-V2X as the primary standard, with LTE-C-V2X permitted as a transitional path. Specifying only LTE risks locking national infrastructure to an earlier generation for its entire service life — roadside units installed in 2028 will still be there in 2043. A workable sequence: NR-C-V2X for new infrastructure after a defined effective date roughly eighteen months from framework publication; LTE-C-V2X permitted for a five-year transition; dual-mode LTE and NR capability required in roadside units deployed after the effective date.
3 · What conformity testing should actually cover.
Roadside and on-board units are active endpoints in a public-safety cryptographic trust chain, which puts them in a different category from ordinary telecom equipment. Test scope should cover RF conformance against the band parameters and out-of-band emission limits; EMI and EMC; protocol conformance to the mandated ITS stack; and a cybersecurity baseline covering certificate lifecycle management, secure boot, authenticated firmware update and hardware-backed key storage. Key non-extractability should be a pass-or-fail criterion, not a recommendation — it is the one property whose absence invalidates everything else in the certificate. Why →
4 · What the PKI framework looks like.
This is the single most consequential decision in the whole framework, and the one where a wrong answer is least recoverable. Without it, every other technical investment is exposed. Our view on the architecture is set out in full on the trust models page: a parallel hierarchy rather than a sub-CA of the existing national root; multiple approved root CAs under one published certificate policy; a national trust list; enrolment and authorisation authorities separated by construction; and a misbehaviour authority in a separate organisation. Publish the certificate policy before the first roadside tender.
5 · How safety spectrum should be charged for.
V2X safety messaging is public-welfare infrastructure rather than a commercial service, and charging for it as though it were commercial spectrum will suppress exactly the deployment the framework is trying to create. Nominal or waived charges for safety applications, with commercial services on the same infrastructure treated separately, is the arrangement that matches the public-interest case.
6 · Whether domestic capability in security-critical components is a policy objective.
If it is, authorisation conditions and testing requirements are the instruments that express it, and they have to be written early enough that a domestic supply base can form before the deadline rather than after it.
Three further things worth building into the framework: a system-level interoperability testing programme covering roadside and on-board units together, complementary to component-level conformity testing; phased deployment obligations beginning with defined national highway corridors rather than a uniform national requirement; and a liability framework for safety-critical message failures arising from equipment malfunction, revocation latency or deliberate message injection — because that question will be asked for the first time in a courtroom if it is not answered in a rulebook.
Where this fits.
SCMS vs CCMS
The four trust models, and the shape we think India should adopt.
Spectrum
The designation and the licence exemption, side by side with six other jurisdictions.
AmbiOBU
The domestic on-board unit development platform, and what it needs to reach production.
AmbiRSU
Roadside hardware, and the authorisation question around who may operate it.
The OEM landscape
Who ships V2X today — and the empty row for Indian two-wheeler manufacturers.
Test and certification
The accredited-laboratory gap that has to close before the 2028 deadline.
Last reviewed: 17 August 2026. TRAI's recommendations were pending and the MoRTH consultation was open at that date.
Preparing for AIS-230?
The security requirements are the long-lead item — secure-element selection, applet architecture, provisioning-line design and EA/AA integration cannot be retrofitted in the last quarter before a type-approval submission. Talk to us early.
Questions this page answers.
Is V2X mandatory in India?
Not yet. On 3 August 2026 MoRTH published a draft amendment to the Central Motor Vehicles Rules proposing that all newly manufactured L, M and N category vehicles carry an AIS-230-compliant C-V2X on-board unit from 1 October 2028, with an earlier 1 October 2027 date applying to vehicles voluntarily fitted with such a system. The draft was open for comment for thirty days from publication. Nothing is mandatory until the notification is finalised.
What is AIS-230?
The Automotive Industry Standard for factory-installed C-V2X on-board units in India, specifying minimum technical, functional, performance, environmental and security requirements — including radio performance, output power, receiver sensitivity, GNSS positioning, EMC and mandatory PKI-based cybersecurity. It was considered by the CMVR Technical Standing Committee on 7 May 2026.
What frequency will V2X use in India?
TRAI has proposed 5875–5925 MHz, with 5875–5905 MHz for initial deployment and 5905–5925 MHz reserved for future ITS. As of G.S.R. 466(E) of 10 June 2026, the 5875–5905 MHz portion is already exempt from licensing for on-board units.
Do I need a licence for a V2X on-board unit in India?
No spectrum licence, following G.S.R. 466(E), provided the unit operates within 5875–5905 MHz at a maximum power spectral density of 23 dBm/MHz and maximum EIRP of 33 dBm, on a non-interference, non-protection, non-exclusive basis. Equipment type approval through the DoT portal is still required.
Does TEC 31318 apply to V2X equipment?
Not as written. TEC 31318:2025 Release 2.0, which superseded the 2021 release in November 2025, scopes itself to consumer IoT products connected to the internet or a home network and their associated services. It contains no exclusion clause, but connected vehicles are not among the product categories it addresses. It remains a relevant and current standard for IoT devices. V2X security requirements in India will come through AIS-230 and through whatever TEC publishes specifically for V2X equipment.
Who can operate a roadside unit in India?
Not finally settled. The TRAI consultation, following MoRTH correspondence, indicates authorisation restricted to central and state governments and their authorised agencies, with private entities considered only for non-safety applications. TRAI's recommendations were still pending as of mid-August 2026.
When will TRAI issue its recommendations?
No date has been announced. The consultation closed on 4 June 2026 and the recommendations were still pending as of mid-August 2026.