Most of the coverage you have read about these rules is about passenger cars. Your buses and rail cars sit outside it. That is the first thing worth knowing, and the second is that a different federal restriction has already been binding on your rolling stock procurement since 2021.
This piece sorts out which rule reaches which part of your fleet, what the Department of Commerce actually prohibits, what the Connected Vehicle Security Act would change, and where a transit agency's real exposure sits right now. If you are signing procurement documents, certifying grant compliance, or answering a board question about foreign technology on your vehicles, the distinction between these two regimes is the difference between a clean audit and a finding.
What does connected vehicle cybersecurity mean for a transit fleet?
Every revenue vehicle you operate is now a networked endpoint. Connected vehicle systems on a modern bus include CAD and AVL, fare collection, automatic passenger counters, transit signal priority, onboard video, and telematics all move vehicle data across a wireless link you do not own. Add depot charging management and the attack surface grows again.

That exposure is operational technology, not office IT, which is why it does not show up cleanly on an enterprise risk register. A compromise of vehicle operating systems does not leak spreadsheets. Once software reaches the vehicle network and acts on a physical system, it affects headways, doors, and dispatch, which is the kind of threat to the national security the government now cites when it restricts a technology class. We have written about that split in our guide to IT/OT convergence across industrial environments, and transit is one of the places where the physical consequence arrives fastest.
The federal response has been to attack the problem at procurement rather than at the firewall. Both regimes below work the same way: they decide who you may buy from, on the theory that you cannot patch your way out of a component you should never have installed.
What does the Department of Commerce rule on connected vehicles supply chains prohibit?
The Bureau of Industry and Security published its final rule, Securing the Information and Communications Technology and Services Supply Chain: Connected Vehicles, in January 2025, and it took effect that March. It bans transactions involving vehicle connectivity systems hardware and covered software designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia.

The authority is Executive Order 13873, which lets the Department of Commerce restrict transactions involving information and communications technology on three grounds: undue or unacceptable risk of sabotage to information and communications technology and services in the United States, undue risk of catastrophic effects on the security or resiliency of United States critical infrastructure or the digital economy, and any transaction otherwise posing an unacceptable risk to the national security of the United States or the security and safety of U.S. persons. Those tests are the vocabulary the agency reaches for whenever it argues a class of communications technology or services is adverse to the national security. Its published reasoning regarding the ICTS supply chain treats the vehicle sector as one node in a larger problem, and the definition of a covered entity was drawn broadly so BIS could address identified risks to national security elsewhere without rebuilding the argument. Protecting national security from ICTS transactions nobody can inspect at the border means making importers inspect them first, and violations carry civil and criminal penalties under the International Emergency Economic Powers Act.
BIS defines its object of regulation as an automotive vehicle that integrates onboard networked hardware with automotive software systems to communicate, by dedicated short range communication, cellular, satellite, or other wireless link, with any network or device outside the vehicle. That definition reaches technologies integral to connected vehicles rather than cars in general, so a component matters only if it touches the capabilities of connected vehicles that depend on it.
Two technology sets are covered. Vehicle connectivity systems means the hardware and software that let a vehicle talk to the world: telematics control units, cellular modems, satellite and Bluetooth and Wi-Fi modules, the GNSS receiver. The second is automated driving system software. Note the asymmetry. For ADS, only the software is covered. For VCS, both hardware and software are, which is why connected vehicle hardware carries the longer runway.
Does the rule cover buses and rail cars?
Not yet. The rule reaches passenger cars under 10,001 pounds. Commercial trucks and buses were left out because BIS called that supply chain too complex to fold into the same rulemaking, and the agency committed to a separate proposed rule for the sector. Your forty-foot bus is out of scope today.
Your non-revenue fleet is a different story. Supervisor vehicles, paratransit vans, inspection trucks, and pool cars under the weight threshold are ordinary passenger vehicles, and the rule reaches them exactly as it reaches a retail buyer. Certain connected vehicles in your yard are covered right now. Most agencies I have talked to had not separated the two lists.
Treat the commercial vehicle rulemaking as scheduled rather than hypothetical. When it lands, the transit fleet moves from exempt to in-scope, and the sourcing decisions on a bus order placed this year will still be on the road in 2040.
What already restricts your rolling stock procurement?
Section 7613 of the FY2020 National Defense Authorization Act added 49 U.S.C. § 5323(u), which prohibits using Federal Transit Administration funds to procure rolling stock from any manufacturer owned or controlled by, a subsidiary of, or otherwise related legally or financially to a corporation based in a covered country. FTA's guidance on the Section 7613 restrictions is the authoritative read, and in some circumstances the limitation reaches local funds too.
Notice what that rule tests. It asks who owns the manufacturer. The connected vehicle rule asks where the hardware or software was designed and developed, which is a different question about a different layer of the supply chains feeding your vehicles. A manufacturer can pass the ownership test and still ship a telematics unit whose firmware came from a covered jurisdiction.
If you are used to clearing rolling stock on the § 5323(u) certification alone, that is the gap. One regime governs your funding eligibility. The other governs whether a connected vehicle that is imported into the country may be sold at all.
What does subject to the jurisdiction or direction of a foreign adversary mean in practice?
The test is not whether a supplier is a Chinese company. A person is covered if headquartered, incorporated, or principally doing business in the PRC or Russia, or otherwise owned by, controlled by, or subject to the jurisdiction or direction of one of those governments. A European Tier 1 with a design center in Shanghai writing firmware for a fleet telematics unit puts covered software into your vehicle without tripping any ownership screen.
Equity alone does not always trigger a filing, because BIS carved out situations where the only foreign interest is non-controlling ownership. That carve-out is narrower than it sounds and does not relieve anyone of the diligence needed to know it applies.
Which means the questionnaire most agencies send is aimed at the wrong target. Country of assembly tells you where a box was closed, not where the code was written. Most supply chain risk management programs we inherit answer the first question and quietly assume it settles the second.
How does the Connected Vehicle Security Act of 2026 change things?
The Connected Vehicle Security Act of 2026 (S. 4429), introduced in April by Senators Bernie Moreno and Elissa Slotkin, cleared the Senate Commerce Committee on a bipartisan voice vote in July. An identical House bill from Representatives John Moolenaar and Debbie Dingell is moving separately. It would prohibit the importation, manufacture, sale, and resale of vehicles and related hardware and software tied to foreign adversaries, and it names four rather than two: China, Russia, Iran, and North Korea.
Three things matter for a transit agency. The adversary list widens, which affects component sourcing paths outside the obvious two. The bill reaches ownership stakes through a threshold that could sweep in manufacturers carrying significant covered investment via joint ventures, a structure common in the bus market. And it directs a Department of Commerce regulatory review in 2030 on whether coverage should continue, change, or expand.
The mechanism is the real story. A regulation can be rewritten by the next administration. A statute cannot, not without another act of Congress. The bill still needs a floor vote and passage through three House committees, so nothing is law. Planning on the assumption that the current position softens is a poor bet.
Who files a Declaration of Conformity, and could that be you?
Two categories file: VCS hardware importers and connected vehicle manufacturers. The filing goes to the Office of Information and Communications Technology and Services at least 60 days before you import VCS hardware, before you import completed connected vehicles that incorporate covered software, and before the first sale of connected vehicles in the United States. BIS posts current forms on its Declarations of Conformity page.

A transit authority is almost never the filer. You are the downstream buyer, which sounds like relief and is not. Your vendors' certifications become your evidence, and a certification you never collected is a certification you cannot produce when a grant monitor asks. Contract for it.
What the declarant certifies is worth understanding, because it tells you what to demand. They attest that the item was not designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia, and that they conducted due diligence and hold the records. The notice of proposed rulemaking would have required a software bill of materials with every filing. BIS dropped that and imposed ten-year recordkeeping instead, so the evidence exists somewhere. Your leverage to see it is contractual, and it expires the moment you sign.
Why is this a civic trust problem, not just a paperwork problem?
Transit runs on public consent. Riders accept fare cards, cameras, and location tracking because they assume the data stays inside the agency. The risk regulators keep naming is aggregate access across a fleet, plus manipulation of connected vehicle functions at the vehicle level rather than the app level. Cybersecurity and privacy stop being separate problems here. Cybersecurity concerns about remote access and privacy concerns about rider location run through the same uplink, because the channel that leaks a position is the channel that accepts a command.
Where completed connected vehicles are used matters as much as what they contain. A fleet moving daily past a federal building, a port, or a substation is a different cybersecurity risk than the same vehicles in a low-density suburb, and an existing connected vehicle already in service cannot be recalled out of the problem. BIS concluded that adversary access here is an unacceptable risk to U.S. persons and infrastructure, and the unacceptable risks to national security it described are the argument behind treating this as critical infrastructure policy rather than consumer product safety.
Your vehicles also feed the rest of the civic stack. Signal priority, tolling, and charging networks all take input from connected vehicle technologies, which puts this inside the smart cities threat model and the broader picture in our IoT and smart infrastructure guide. A compromise reaching critical vehicle systems does not stay inside the bus. The full civic framing sits in our pillar guide, Smart City Cybersecurity: The Civic Trust Imperative for 2026 Mayors.
How do you inventory connected vehicle technologies across a mixed fleet?
Build the list by vehicle class, not by asset tag. Separate revenue rolling stock from light-duty support vehicles, because they fall under different regimes today. Then inventory the connected components inside each class and trace each one to a design and development location rather than a shipping origin. A software bill of materials is the practical instrument on the software side, and NIST's supply chain risk management guidance, particularly SP 800-161 Rev. 1, is the free reference to build against.

Expect it to stall at tier two. Your bus OEM knows its own footprint. It often does not know, or will not say, where its telematics supplier's firmware team sits. That is a contract problem before it is a technology problem, and it gets solved with flowdown clauses, audit rights, and ownership change notifications. A third party risk management program built on annual questionnaires will not produce evidence a federal grant monitor accepts.
Older systems are the hard cases. Legacy vehicle OS and CAD/AVL code with undocumented dependencies is where covered software hides, and untangling it is a code modernization effort rather than a records exercise. Supply is tightening too: S&P Global's 2026 light vehicle production forecast has been cut repeatedly this year, with automakers pulling production forward to hedge parts shortages. Global passenger vehicle production narrows at the same moment your approved supplier list does, and supply chain disruptions from a late compliance finding will not be absorbed quietly.
What should a transit authority do before the 2027 deadline?
Split the fleet list this quarter. Light-duty vehicles under 10,001 pounds are in scope for the covered software prohibition at model year 2027, and you should know today which ones you plan to buy. Rolling stock stays on the § 5323(u) track until the commercial vehicle rule lands, which is a limit written to protect the security and safety of United States persons rather than to police your grant paperwork.
Write the diligence into the next solicitation rather than the next audit. Cybersecurity best practices in the automotive industry now have to reach vehicle procurement, with supplier provenance checked at design selection, because that is the last point where switching costs nothing. Ask for the Declaration of Conformity, the supporting records, and notice of any ownership change during the contract term.
And name an owner. The national security risks driving these rules are not the risks your SOC is staffed to see. Nobody watching network traffic will notice that a directly connected module in next year's paratransit order was designed in a covered jurisdiction. This belongs to procurement, legal, and engineering together. If nobody owns it by name, it is not owned, and the certification you signed does not update itself when a supplier gets acquired.
Get a straight read on your fleet exposure
Our Civic Cyber Readiness 1-Pager walks a transit leadership team through the fleet split, the procurement language, and the questions to put to your OEM before the next order. VisioneerIT's cybersecurity consulting practice was built inside federal supply chain compliance, and the same assessor's eye we bring to CMMC and NIST 800-171 work for contractors transfers directly to ICTS diligence. See our transportation practice for how this fits the wider modernization picture, and read the parent pillar, Smart City Cybersecurity: The Civic Trust Imperative for 2026 Mayors, for the civic trust case your board will ask about.
Key things to remember
- The Commerce connected vehicle rule covers passenger vehicles under 10,001 pounds. Your buses and rail cars are outside it today, and a separate commercial vehicle rulemaking has been promised.
- Your light-duty non-revenue fleet is already in scope. Connected vehicles incorporating covered software must comply at model year 2027, while connected vehicles that incorporate VCS hardware have until model year 2030.
- Section 7613 of the FY2020 NDAA, at § 5323(u), already limits FTA funding for rolling stock from manufacturers owned or controlled by corporations based in covered countries. That test is about ownership, not component design origin.
- The two regimes ask different questions. Passing one does not clear you under the other, and connected vehicles containing compliant-on-paper hardware can still carry covered firmware.
- The Connected Vehicle Security Act cleared Senate Commerce in July and would put the ban into statute while widening the adversary list to four countries. It still needs a floor vote and House passage.
- You are almost never the declarant. Your vendors are, so contract for their Declaration of Conformity and supporting records before you sign, not after a grant monitor asks.
- Tier two is where the exercise stalls. Flowdown clauses, audit rights, and ownership change notices do more than another annual questionnaire.

