CIRT, ARAI, ICAT: how an Indian type approval actually gets assessed

The submission-to-certificate workflow no one documents — and where cybersecurity fits into it

7 Aug 20264 min readAutoSifu

The workflow, in outline

Indian vehicle type approval is well established but rarely written down end to end. In outline: a manufacturer submits a vehicle prototype to a test agency named in Rule 126 of the Central Motor Vehicles Rules; the agency tests the prototype against the applicable standards; on success it certifies conformity, and production conformity is then maintained. The standards themselves are the AIS (Automotive Industry Standard) series, published by ARAI for the AISC under the CMVR-TSC.

Cybersecurity — AIS-189 for the CSMS, AIS-190 for the SUMS — enters this picture as an assessment that runs alongside the whole-vehicle process, not as one more bench test inside it. Understanding where it fits is the point of this note.

Who the agencies are

Three names come up most often, and it helps to be precise about what each does.

Agency Location Role
ARAI Pune Rule 126 test agency; also the standards body publishing the AIS series for the AISC
CIRT Pune Rule 126 test agency (Central Institute of Road Transport, under MoRTH since 1967; added to Rule 126 by G.S.R. 276(E), 10 Apr 2007)
ICAT Manesar Rule 126 test agency

All three can receive a prototype for type approval. ARAI carries a second hat as the body that publishes the AIS standards, including AIS-189 and AIS-190. CIRT — the Central Institute of Road Transport — is a Testing & Certification agency notified under CMVR Rule 124 and Rule 126, has functioned under MoRTH since 1967 (added to Rule 126 by G.S.R. 276(E) dated 10 April 2007), and is a type-approval authority for AIS-189 and AIS-190; of the principal agencies it is the one that sits directly under MoRTH. ICAT is a further named agency in the same framework. The common thread is the CMVR notification: it is what gives an agency standing to test a prototype, and — with the AIS-189 competence bar — to assess the cybersecurity file.

Submission to certificate

The whole-vehicle flow is straightforward to describe:

  1. The manufacturer prepares a prototype and the supporting documentation for the applicable standards.
  2. It submits to a Rule 126 agency.
  3. The agency tests against the standards and reviews the documentation.
  4. On success, conformity is certified; conformity of production is then maintained over the model's life.

This is a physical, test-led process. It suits standards where the thing being checked is the vehicle in front of the assessor.

Where cybersecurity is different

A CSMS assessment does not fit that mould, and this is the part that trips programmes up. Under AIS-189 — aligned to UN R155 — the assessor is not testing a prototype. They are judging whether a management system is real and followed: governance, risk management, supplier flow-down, monitoring and incident response across development, production and post-production. Under R155 the Certificate of Compliance for the CSMS is valid three years and sits beside the per-vehicle-type approval. AIS-190 does the equivalent for the SUMS, centred on RxSWIN and update integrity.

Two consequences follow. First, what the assessor opens is a dossier of process descriptions and records proving those processes ran on a real programme — not a single measurement. That evidence question is covered in what a UN R155 audit actually opens. Second, the assessment demands cybersecurity competence in the assessor. A CMVR notification gives an agency standing to test; AIS-189 clause 5.3.1 additionally requires the assessing agency to hold automotive cybersecurity and risk-assessment competence of its own. CIRT holds both — notified under CMVR Rule 124 and Rule 126, and a type-approval authority for AIS-189 and AIS-190 — so for the cybersecurity file the venue is settled. We work through that combination in Rule 124, Rule 126 and CIRT.

So the cybersecurity assessment is best pictured as a parallel track: the whole-vehicle type approval runs its test-led course, while the CSMS/SUMS assessment runs a document-and-records course beside it, feeding the same overall approval. They meet at the approval, not in the test cell.

How to plan against it

The planning implication is that you prepare the cybersecurity evidence to a different rhythm than a bench test. A physical test you can schedule late; an evidence pack that has to show a process ran over a programme's life cannot be assembled at the end. This is why cybersecurity readiness is sequenced early — see our AIS-189/190 readiness checklist — and why the sensible move is to run the preparation close to the assessing agency rather than in isolation from it.

A note on dates: AIS-189/190 enforcement in India is proposed in MoRTH draft G.S.R. 503(E) (17 June 2026) — phased from October 2026 — but not yet finalised in the gazette. The type-approval framework and the agencies are in place today; because the dates are still draft, plan on capability rather than on a single headline date.

The AutoSifu view

AutoSifu works one route: compliance, solutioning, and CoC/VTA support, with the approval body in the room. Because the CSMS/SUMS assessment is a records track running beside the whole-vehicle approval, we prepare that evidence with CIRT from the start — so when the type approval comes together, the cybersecurity dossier is already legible to the people assessing it. That is the difference between an assessment that flows and one that stalls at the last gate.

Questions

How does vehicle type approval work in India?
A manufacturer submits a vehicle prototype to one of the test agencies named in Rule 126 of the CMVR, which tests it against the applicable standards and, on success, issues certification. The framework sits under the CMVR, 1989, and the standards are the AIS series published by ARAI for the AISC under the CMVR-TSC. Cybersecurity assessment under AIS-189/190 runs alongside this whole-vehicle process rather than replacing it.
What is the role of CIRT, ARAI and ICAT?
All three are test agencies named under Rule 126 of the CMVR that can receive a prototype for type approval. ARAI (Pune) also acts as the standards body that publishes the AIS series for the AISC. CIRT (the Central Institute of Road Transport, Pune, under MoRTH since 1967) was added to Rule 126 by G.S.R. 276(E) dated 10 April 2007. ICAT is another named agency in the same framework.
Where does the CSMS assessment fit?
The CSMS assessment under AIS-189 (and the SUMS assessment under AIS-190) sits alongside the vehicle type approval, not inside the bench-test flow. It judges whether the management system is real and followed across the lifecycle, which requires an assessor holding cybersecurity competence — a separate matter from being named in Rule 126. The output supports the type approval rather than being a single physical test.

09 — Start here

Bring us the file you are least sure about.

Most conversations start with a gap assessment, or a type approval submission that is closer than it feels. Either is a good place to begin.

Direct

Jaipur · registered office

Plot No. 8, ABS Plaza, Chanakya PuriJagatpura, Jaipur – 302017, RajasthanAUTOSIFU Pvt Ltd · India

Required