Railway Applications — Requirements for software development
Issuing body: CENELEC · Version: EN 50716:2023 · Published: 2023-11-30
Link verified July 21, 2026
Scope
Single European standard for the development of railway software, consolidating and superseding both EN 50128 (trackside control and protection software) and EN 50657 (on-board software). It defines software safety integrity levels SIL 0-4, lifecycle phases, verification and validation activities, documentation and organisational independence requirements, and is the normative software reference of EN 50129-based safety cases.
EN 50716 is the single, consolidated European standard for railway software development, merging and superseding both EN 50128 (previously covering trackside control and protection software) and EN 50657 (previously covering on-board rolling stock software) into one common set of requirements applicable regardless of where in the railway system the software runs. It defines software safety integrity levels from SIL 0 to SIL 4, the lifecycle phases a software development project must follow, the verification and validation activities required at each level, and the documentation and organisational independence requirements that must be demonstrated in the resulting safety case. As the current normative software reference underpinning EN 50129-based signalling safety cases, it is applied by signalling suppliers, rolling stock manufacturers and independent safety assessors developing or assessing any safety-related railway software, whether for trackside interlockings or on-board train control systems. Its consolidation of two previously separate standards reflects the railway sector's move toward common software assurance practices across signalling and rolling stock domains. The current edition in force is EN 50716:2023.

