In May 2026, the International Automotive Task Force (IATF) formally notified all accredited bodies in India that the transition window for IATF 16949:2024 closes on 30 November 2026. For engineering and auto-component suppliers—especially Tier-1 and Tier-2 manufacturers serving OEMs—this marks a hard deadline.
Non-compliance means loss of current certifications and immediate removal from approved-supplier lists. The new standard tightens cybersecurity, risk management, and supply-chain resilience requirements.
Market signals
IATF 16949:2024 introduces mandatory controls on IT security and data protection for connected automotive systems. Suppliers must now evidence encryption, access logs, and incident-response protocols as part of audit scope.
The updated standard requires mapped tier-2 and tier-3 supplier networks, business-continuity plans, and geopolitical risk assessments. Indian component makers must now document upstream vendor resilience alongside downstream OEM expectations.
Accreditation bodies have limited audit capacity. Early movers applying before August 2026 face shorter wait times; late filers may face queue delays extending past the November deadline, forcing temporary loss of certified status.
Under IATF and AIAG rules, Indian auto suppliers currently holding IATF 16949:2016 certificates must complete full re-audit and receive new credentials by 30 November 2026. After this date, 16949:2016 certificates are null; OEMs will suspend POs and supply contracts. Vinayakam Consultants assists manufacturers in gap-analysis audits, documentation updates (especially cybersecurity and risk registers), and coordination with NABL-accredited certification bodies to meet the transition timeline without supply disruption.
Your action checklist
- Engage an NABL-accredited IATF auditor by 15 July 2026 to schedule re-certification audit before November deadline.
- Conduct internal gap assessment against IATF 16949:2024 clauses 8.4 (cybersecurity) and 8.5 (supply-chain resilience); document control framework.
- Map and risk-rate all sub-tier suppliers; prepare evidence of business-continuity plans and geopolitical exposure to meet new audit criteria.
- Notify key OEM customers (Honda, Maruti, Hyundai, TATA, etc.) of your transition timeline; confirm their acceptance of new certificate version before re-audit.
Frequently asked questions
The deadline is 30 November 2026. All IATF 16949:2016 certificates become null after this date, and non-compliant suppliers risk removal from OEM approved-supplier lists.
The standard introduces mandatory cybersecurity controls, supply-chain resilience audits with tier-2/3 vendor mapping, and business-continuity planning. Suppliers must evidence encryption, access logs, and incident-response protocols.
Your current certification becomes invalid, OEMs will suspend purchase orders, and you'll be delisted from approved-supplier lists, risking supply-chain exit.