đ From Complexity to Clarity: A Common Path Toward Cybersecurity in Rail
In a previous post, we introduced the System Pillar:Â and the work of the Transversal CCS Domain –Â now itâs time to spotlight another essential building block: the Cybersecurity Domain.
As a horizontal domain within Lot 2 of the System Pillar, the Cybersecurity Domain plays a foundational and increasingly strategic role in shaping a safer, more harmonised European railway system.
đ Why is this important?
The Cybersecurity team is responsible for defining central security requirements and ensuring alignment with European regulations and international standards. This includes:
- A general cybersecurity architecture
- Risk and threat assessments
- System-specific requirements
- Integration with shared services
Even though companies can develop secure systems independently, shared specifications create a common framework that simplifies compliance and reduces duplication. That means faster, more efficient, and more cost-effective implementation for everyone in the rail ecosystem.
â Whatâs the goal?
To deliver secure, cost-efficient rail products and systems that are fully aligned with EU regulations (such as NIS2, CRA, etc.). The System Pillar documents provide the technical and regulatory foundation to achieve this â offering clear, harmonised guidance for suppliers, integrators, and operators.
By defining shared cybersecurity requirements and how to implement them consistently, these documents help:
- Ensure sector-wide compliance
- Simplify implementation for all stakeholders
- Support interoperability across borders and suppliers
- Reduce duplication, saving time, cost, and effort
đ˘ Big news: the Cybersecurity Specification v1.0 has just been published by the System Pillarâs Cybersecurity Domain!
This marks a major milestone, combining the latest regulatory requirements (NIS2, CSA, RED, CRA) with globally recognized standards (ISO 27001, IEC 62443, EN TS 50701, IEC PT 63452).
đ§Š Along with the main specification, some supporting documents were published:
- -Regulatory Requirement tracing (tracing to 8 EU regulations/directives and international standards)
- Â Product Documentation Template (to fulfil EU CRA Annex VII, IEC 62443-4-1 SG1 to SG8, IEC 62443-2-4, EN TS 50701 and IEC PT 63452).
- Â Glossary and References
- Â Supporting documents for a reference system in accordance with CEN TS 50701 and IEC PT 63452
- Â Support for essential functions
- Â System description
- Â Initial Risk Assessment
- Â Threat Catalog
đ Whatâs next?
The Cybersecurity Domain is already:
- Developing training materials to support implementation
- Performing security gap analyses across the entire EU rail standardisation landscape
đ Cybersecurity, when done right, isnât a barrier â itâs an enabler.
The System Pillar helps bring clarity and structure to a complex landscape â guiding the sector toward secure, compliant, and future-ready railway systems.
For more information visit the ERJU Website