Skip to content

    EN 50128 vs EN 50716: what actually changed

    For two decades, "developed to EN 50128" was shorthand for trustworthy railway software. That era is formally over: EN 50716, published in 2023, replaced both EN 50128 (software for control-command and protection systems) and EN 50657 (software on board rolling stock). Understanding the transition matters for every supplier with a certified development organisation and every project whose contracts still name the old standard.

    One standard instead of two

    The split between EN 50128 and EN 50657 was always an artefact of scope, not of engineering: EN 50657 was adapted from EN 50128 so that on-board, non-signalling software (train control and management, HVAC, passenger information) had a home of its own. EN 50716 reunifies the two into a single set of requirements for railway software wherever it runs. The engineering core survives intact — software Safety Integrity Levels from SIL 0 to SIL 4, the V-model lifecycle with defined phases and documentation, the techniques-and-measures tables graded by SIL, and the independence requirements between roles (designer, verifier, validator, assessor). A team fluent in EN 50128 will recognise almost everything.

    What changed in substance

    Beyond the merge itself, EN 50716 modernises the framework at its edges: clarified requirements around tool qualification and pre-existing software, better alignment with the current EN 50126 RAMS lifecycle and EN 50129 safety-case structure, and requirements written to serve both the signalling and rolling-stock context that formerly diverged between the two predecessor documents. The philosophical shift is consolidation: one vocabulary and one set of tables for the whole railway software estate, which simplifies multi-domain suppliers' quality systems.

    The legal switch already happened

    The detail many teams miss: the Official Journal citation moved. Under the Interoperability Directive, presumption of conformity attaches to standards whose references are published in the OJ — and the 2025 update of the harmonised-standards list cited EN 50716:2023 while EN 50128 and EN 50657 were delisted. In this library's terms, EN 50716 is now the harmonised entry; the predecessors are voluntary legacy documents. New EC verifications should therefore be built on EN 50716, while running projects assess whether their certification basis, contracts and safety-case claims need a managed transition. Existing certificates against EN 50128 do not evaporate — but their value in new conformity arguments now has to be argued rather than presumed.

    Practical checklist

    For a supplier: map your quality-management and competence framework onto EN 50716's roles and tables (expect high reuse); plan re-certification of generic products at the natural next revision; align tool-qualification evidence. For a project: name EN 50716 in new contracts; for in-flight work, agree explicitly with the assessor and NoBo which edition governs, and document the decision in the safety case. For both: the SIL allocation logic upstream in EN 50126-2 is untouched — this transition is about the software layer, not the risk analysis above it.