#

Connected Vehicle Supply Chains Enter a New Era of Regulatory Risk

By Manuel Nau, Editorial Director at IoT Business News.

New US restrictions on connected vehicle technologies are forcing automakers to examine not only where components are manufactured, but also who designed their hardware, wrote their software and controls the companies behind them.

For years, automotive supply-chain risk was largely measured in terms of cost, availability, quality and delivery time. The rapid growth of connected vehicles has added cybersecurity and data protection to that list. Regulation is now introducing another dimension: the national origin and ownership of the technology embedded in a vehicle.

This shift is becoming tangible in the United States. A rule finalized by the US Department of Commerce targets certain vehicle connectivity system—or VCS—hardware and software, as well as automated driving system software, linked to China or Russia. The software-related restrictions apply from model year 2027, while the hardware restrictions take effect from model year 2030, or January 1, 2029 for components without a model year. The rule entered into force on March 17, 2025 (US Bureau of Industry and Security).

Connectivity Components Are Becoming Regulated Assets

The rules do not amount to a blanket prohibition on every electronic component manufactured in China. They apply to defined categories of connected vehicle technology supplied by entities owned by, controlled by or subject to the jurisdiction or direction of China or Russia.

That distinction matters. Compliance cannot necessarily be determined by looking only at the country printed on a component or its shipping documents. Automakers may need visibility into corporate ownership, software development, engineering control and the origin of individual functions within a connectivity system.

The scope covers technologies that allow vehicles to communicate externally, including certain cellular, satellite, Wi-Fi and Bluetooth systems. It also covers software used by automated driving systems. These components occupy a particularly sensitive position because they can transmit vehicle data, receive remote instructions and, in some architectures, provide a potential path toward other in-vehicle systems.

The immediate deadlines concern the US market, but the operational consequences are global. Automakers rarely design completely separate electronic architectures for every country. A restriction in one major market can therefore influence purchasing decisions, platform designs and supplier relationships across an entire vehicle program.

Recent reporting suggests that this adjustment is already underway. US automakers and suppliers are examining alternatives to Chinese-designed connectivity hardware as the regulatory deadlines approach. The transition is creating demand for new suppliers, but it is also exposing the difficulty of replacing components already integrated into long vehicle development cycles (Reuters).

Replacing the Hardware Is Only the Visible Part

At first sight, compliance might appear to be a component substitution exercise: identify a restricted telematics control unit or wireless module and replace it with an approved alternative. In practice, the physical hardware is only one layer of the dependency.

A modern automotive connectivity system typically combines cellular hardware, embedded firmware, operating system components, security functions, eSIM technology, cloud services and operator integrations. Responsibility for those elements can be distributed across several direct and indirect suppliers.

Changing one part of that stack may affect:

Antenna performance, power consumption and thermal behavior
Modem firmware and radio frequency certification
Emergency calling and safety-related services
eSIM provisioning and mobile network compatibility
Cybersecurity testing and over-the-air update processes
Data formats, cloud integrations and vehicle diagnostics
Type approval and market-specific homologation

A technically comparable module is therefore not always a drop-in replacement. Even when its mechanical and electrical interfaces match, differences in firmware, radio behavior or security architecture can require engineering changes and renewed validation.

Long automotive development cycles make the timing particularly challenging. Model year 2027 vehicles may have been designed several years before the software prohibition becomes applicable. Suppliers must be qualified, systems tested and manufacturing capacity secured well before a vehicle enters production.

The rule also makes software provenance more important. A component could be assembled outside China while still containing covered software developed by a Chinese entity. Conversely, a supplier may use globally distributed engineering teams, licensed code and third-party libraries. Establishing origin at the required level may consequently involve more than obtaining a conventional country-of-origin certificate.

Software bills of materials can help identify embedded dependencies, but they do not resolve every question. Companies also need reliable information about intellectual property ownership, development control, update infrastructure and subcontractors. This turns compliance into a continuing governance process rather than a one-time supplier declaration.

The automotive industry already has frameworks for managing cybersecurity across the supply chain. NHTSA guidance, for example, stresses that vehicle manufacturers should establish clear cybersecurity expectations for suppliers and verify their implementation. Regulatory origin requirements add another layer to those existing security and lifecycle obligations (NHTSA Cybersecurity Best Practices).

The Implications Extend Beyond Connected Cars

Connected vehicles are an early and highly visible example of a broader regulatory trend. Governments increasingly view networked products not simply as commercial equipment, but as components of national digital infrastructure.

Similar questions could arise wherever connected devices collect sensitive information or interact with essential services: energy networks, industrial facilities, healthcare systems, ports, telecommunications infrastructure and public safety equipment.

The automotive rule does not automatically apply to these industries. Nevertheless, it provides a model for how future regulation could be structured. Instead of restricting only finished products or specific companies, authorities can target particular hardware and software functions, corporate relationships and supply-chain dependencies.

For IoT manufacturers, this changes the meaning of supply-chain resilience. Maintaining a second supplier is no longer sufficient if both alternatives rely on the same restricted modem design, firmware provider or cloud dependency. Genuine resilience may require diversity at several levels of the technology stack.

It also creates a difficult commercial balance. Chinese vendors have built strong positions in cellular modules and other IoT hardware partly through competitive pricing, broad product portfolios and large-scale manufacturing. Replacing them may increase costs or reduce short-term availability. Moving too quickly to a new supplier can introduce its own reliability and capacity risks.

Companies selling connected products internationally may eventually need architectures that accommodate different regulatory environments. Modular hardware, portable connectivity software, separable cloud services and better-documented interfaces could make regional substitutions easier. However, greater modularity can also increase development complexity and testing requirements.

The most important lesson is that regulatory exposure can remain hidden until late in a product lifecycle. A manufacturer may know its direct suppliers while having limited visibility into the firmware libraries, connectivity platforms and upstream technology providers on which those suppliers depend.

Connected vehicle regulation is therefore not simply another episode in the trade dispute between the United States and China. It signals a more structural change in IoT governance: the origin and control of connected technology are becoming product requirements.

For automakers and other IoT manufacturers, supply-chain mapping will increasingly need to extend beyond factories and shipping routes. It must reach into software repositories, corporate ownership structures, remote update systems and cloud architectures. In this new environment, knowing what a connected product does is no longer enough. Companies must also be able to demonstrate who ultimately controls the technologies that make it connected.

The post Connected Vehicle Supply Chains Enter a New Era of Regulatory Risk appeared first on IoT Business News.

Generated by Feedzy