EV BMS Cybersecurity Testing Now Mandatory in India: AIS-156 Amendment Targets Wireless Battery Vulnerabilities
In a major move to bolster electric vehicle (EV) safety, India has made cybersecurity testing mandatory for Battery Management Systems (BMS) equipped with wireless connectivity, such as Bluetooth and Bluetooth Low Energy (BLE).
The regulatory update—introduced via Amendment No. 5 to the AIS-156-2020 standards—comes in response to rising security concerns surrounding low-cost EVs and e-rickshaws, aiming to prevent unauthorized remote tampering with critical vehicle systems.
Why the New EV Battery Cybersecurity Norms Were Introduced
The Ministry of Heavy Industries and testing agencies acted following disturbing reports where unauthorized individuals used publicly available mobile apps to connect to poorly secured, Bluetooth-enabled BMS units. In some cases, rogue users were able to remotely cut battery discharge, alter settings, or abruptly power off moving e-rickshaws.
To eliminate these vulnerabilities, the updated AIS-156 framework ensures that wireless-enabled REESS (Rechargeable Electrical Energy Storage Systems) cannot be manipulated without proper authentication and authorization.
Key Highlights of the AIS-156 BMS Cybersecurity Testing Framework
Under the newly tightened regulations, authorized testing agencies will subject EV battery management systems to rigorous evaluations:
- Unauthorized Access & Command Prevention: Labs will use generic BLE scanners, protocol analyzers, and smartphones to check if third-party apps can discover, pair with, or command the BMS.
- Critical Function Protection: Testing will verify that unauthorized users cannot view live telemetry (voltage, temperature, state of charge) or execute safety-critical commands like operating contactors, enabling/disabling charge/discharge cycles, or resetting faults.
- Resistance to Advanced Cyberattacks:
- Replay & Spoofing Tests: The BMS must reject captured legitimate commands (replay attacks) and identify fake device identities (spoofing).
- Denial of Service (DoS) / "Bluesmacking": Batteries will be flooded with malformed frames and excessive connection requests during simulated driving conditions. Even under heavy digital interference, core safety protections against overcharging, over-temperature, and short circuits must remain fully functional.
- Manufacturer Declarations: Battery manufacturers must now officially declare their wireless interface specifications, including chipsets, Bluetooth profiles, pairing methods, and accessible commands.
Impact on the EV Industry
With these strict cybersecurity testing protocols now in place, EV and battery manufacturers operating in India must ensure their products are built with robust, chip-level security hardening from the factory floor. The move is expected to significantly enhance consumer confidence, safeguard public safety, and establish India as a pioneer in holistic EV cybersecurity standards
(2).png)