" " indicates required fields
Following our last Q&A session covering the basics of the Securing the Information and Communications Technology and Services Supply Chain: Connected Vehicles rule (download a complimentary 1-pager executive overview), in this article, we’ll cover the implications of the new DoC rule for OEMs and suppliers.

The US Department of Commerce (DoC) has enacted Biden’s proposed ban on Chinese and Russian vehicle software as of January 2025 in a continued effort to tighten security in global supply chains.
The new restrictions on prohibited software will take effect for model year 2027 vehicles, while the ban on hardware from China will begin with model year 2030 vehicles.
This groundbreaking rule, officially called Securing the Information and Communications Technology and Services Supply Chain: Connected Vehicles (DoC 791D Rule), directly impacts the future of connected vehicles, starting with private vehicles, connected motorcycles, and RVs up to 10,000 pounds. Having significant implications for carmakers (OEMs), suppliers, and the entire automotive ecosystem, requiring the submission of annual Declarations of Conformity to demonstrate compliance with the prohibitions.
The rule, which takes effect 60 days after its publication (today, March 17th, 2025), is part of a more significant effort to protect critical national infrastructure and reduce cybersecurity risks within the global automotive supply chain.
The move is driven by rising concerns over the security risks connected vehicle systems pose. As the number of connected vehicles in the US is projected to exceed 180 million by 2028, representing 70.9% of all licensed drivers, the need for secure software and hardware is paramount. According to the China Passenger Car Association, in 2023, the total number of passenger cars exported from China to the US was 74,800 units, accounting for only 1.4 percent of total exports.
Cybersecurity vulnerabilities in connected vehicle systems could expose drivers and infrastructure to severe risks, including data breaches, remote hacking, and unauthorized access to critical vehicle functions. Therefore, the rule prohibits importing and selling vehicles containing VCS or ADAS software that is subject to the jurisdiction or control of the PRC or Russia, aiming to reduce risks in the connected vehicle supply chain.
The US Department of Commerce’s Bureau of Industry and Security (BIS) clarified that all hardware and software integrated into the Vehicle Connectivity System (VCS) must meet the final rule. The new rule extends EO 13873’s “Securing the Information and Communications Technology and Services Supply Chain” and aims to reduce the risks associated with untrusted software sources in vehicles. National Security Advisor Jake Sullivan emphasized the importance of protecting American infrastructure by preventing foreign-controlled software from entering the connected vehicle ecosystem.
Failure to comply with the final rule may result in civil penalties of up to $368,136 per violation under IEEPA, while criminal violations can carry fines of up to $1,000,000.
These challenges will require OEMs, partners, suppliers, and product security teams to evaluate alternative options. However, certain best practices that all parties can uphold to comply with the new Department of Commerce regulations are also available.
Compliance with this new rule goes beyond simple documentation – it requires a strategic approach to supply chain security, proactive monitoring, and thorough due diligence. Here are the key steps OEMs and suppliers can take to meet the DoC’s final rule:
The new prohibitions outlined in the DoC’s final rule necessitate a proactive approach to ensuring compliance with the regulations surrounding connected vehicle software and hardware. Starting with Model Year 2027, all connected vehicle manufacturers will be impacted by these software restrictions, making it crucial to act now. With EVSec, you can automate the compliance process and streamline your efforts to meet these new requirements.
Schedule a demo to learn how C2A Security can help prepare you for the DoC’s new rule.
Dynamic threat modeling and risk assessment aligned with global regulations
LLM-agnostic generative AI layer powering automation across every module
Aggregated threat feed contextualized against your actual products
Generate, manage, and triage all BOMs and vulnerabilities across the lifecycle
Quantitative optimization of mitigation strategy and security control allocation
Configurable dashboards and reports across every EVSec data layer
Extract software composition and risk from firmware and binaries without source code
Optimized anomaly detection for Ethernet and CAN, plus ECU runtime protection
Quantify and manage cybersecurity risk for products operating in the field
Enrich SOC events with deep product and architecture context
Context-driven test and validation with intelligent fuzzing, integrated into CI/CD
AI-powered static analysis integrated into CI/CD with reduced false positives
Foundational layer: cyber model, workspaces, and integration backbone to DevOps toolchain
Out-of-the-box and customizable workflows for regulatory and security processes
Centralized compliance management with evidence generated from live data