NHTSA Publishes Final Cybersecurity Best Practices
Time 2 Minute Read

On September 9, 2022, the National Highway Traffic Safety Administration (NHTSA) announced its publication of final Cybersecurity Best Practices for the Safety of Modern Vehicles (the “2022 Best Practices”). The 2022 Best Practices reflect the agency’s final, non-binding vehicle cybersecurity guidance following its release of draft guidance in January 2021. The 2022 Best Practices also is an update to NHTSA’s first cybersecurity best practices document, which was issued in 2016

The 2022 Best Practices describe steps manufacturers can take to improve vehicle cybersecurity in light of emerging risks, taking into account both technological developments as well as other voluntary industry information security standards. These include:

  • creating a system of governance for identifying and preventing cybersecurity risks, including creating processes and procedures to report and eradicate security incidents;
  • implementing risk assessments in the design, manufacturing, and selling of vehicles;
  • proactively auditing processes and procedures to ensure effectiveness;
  • limiting access to vehicle computing resources and design diagnostics to identify and eliminate potential unauthorized access; and
  • promoting collaboration between the industry and staying updated on new innovations and trends/standards in the market, such as the National Institute for Standards and Technology (“NIST”) cybersecurity standards.

The 2022 Best Practices remind vehicle manufacturers to make vehicle cybersecurity a priority as vehicles become more technologically advanced, and to stay informed regarding the best practices to prevent unreasonable, foreseeable cybersecurity risks.

You May Also Be Interested In

Time 4 Minute Read

On January 27, 2026, the Centre for Information Policy Leadership hosted a fireside chat with California Privacy Protection Agency General Counsel Phil Laird in honor of Data Privacy Day.

Time 2 Minute Read

On January 8, 2026, the California Privacy Protection Agency announced enforcement activity against Rickenbacher Data LLC d/b/a Datamasters and S&P Global Inc. for failing to register as data brokers in California.

Time 2 Minute Read

On December 17, 2025, the California Privacy Protection Agency announced the release of its Enforcement Advisory No. 2025-01, reminding data brokers of their obligations under California’s Delete Act.

Time 2 Minute Read

On December 16, 2025, the Federal Trade Commission announced an enforcement action against Illusory Systems Inc., a Utah-based company doing business as Nomad, following a major data breach in which hackers stole $186 million from consumers.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page