Glossary
The concepts behind the documents — SIL, RAMS, TSI, the assessment bodies and more.
SIL — Safety Integrity Level
A Safety Integrity Level is a discrete grade — SIL 0 to SIL 4 — expressing how demanding the safety requirements on a function or system are, and therefore how rigorous its development and assessment must be. In the railway context the grades come from the CENELEC chain: EN 50126 defines the RAMS process in which safety requirements are allocated, EN 50129 applies them to electronic signalling systems, and EN 50716 prescribes, for each software SIL, which lifecycle activities, techniques and independence of roles are required. SIL 4 marks the most critical functions — interlocking logic, ETCS movement authority handling — where a dangerous failure could directly cause a catastrophic accident; SIL 0 covers functions with no safety impact beyond basic quality. A SIL attaches to a specific function against a quantified tolerable hazard rate, not to a product in general: 'a SIL 4 platform' is marketing shorthand for 'a platform assessed as capable of hosting SIL 4 functions'. Allocation happens during risk analysis (EN 50126-2, and SUBSET-091 for ETCS), and the resulting evidence is presented in the safety case that an independent assessor reviews.
RAMS — Reliability, Availability, Maintainability, Safety
RAMS bundles the four system qualities — reliability, availability, maintainability and safety — that EN 50126 turns into a single engineering lifecycle for railway applications. The standard structures a project into lifecycle phases from concept through design, operation and decommissioning; at each phase, RAMS requirements are specified, apportioned to subsystems, and later demonstrated with evidence. The point of treating the four together is that they trade against each other: a design choice that raises availability (say, redundancy) changes failure modes that safety analysis must cover, and maintenance concepts drive both availability and the exposure of staff to hazards. In EU practice the RAMS process is the backbone under nearly every conformity demonstration: TSIs and the Common Safety Method for risk assessment assume hazard identification and safety-requirement allocation of exactly the kind EN 50126-2 describes, and supplier safety cases under EN 50129 present the results. 'Doing RAMS' on a project concretely means maintaining hazard logs, reliability predictions and apportionments, demonstration plans, and the traceability that lets an independent assessor confirm every requirement ended somewhere it can be verified.
TSI — Technical Specification for Interoperability
A TSI is binding EU law — adopted as a Commission regulation under the Interoperability Directive (EU) 2016/797 — that translates the directive's essential requirements into concrete technical requirements for one subsystem of the rail system: infrastructure, energy, rolling stock, control-command and signalling, operation, telematics, noise, accessibility, or tunnel safety. Unlike an EN standard, a TSI is not optional for its scope: placing a subsystem in service in the EU requires an EC verification procedure in which a Notified Body assesses conformity with the applicable TSIs. TSIs cite EN standards and other specifications as means of compliance — sometimes making a specific document mandatory, as the CCS TSI's Annex A does for the ETCS subsets. Where a TSI intentionally leaves a topic unregulated (an 'open point') or grants a member state a deviation (a 'specific case'), notified national rules fill the gap. The nine TSIs were substantially revised as a package in 2023, and ERA publishes application guides explaining their shared mechanics.
NoBo / DeBo / AsBo — the three assessment bodies
EU rail conformity assessment runs through three kinds of independent body, and mixing them up is one of the sector's classic confusions. A Notified Body (NoBo) assesses conformity with TSIs: it runs the EC verification of a subsystem or interoperability constituent and issues the certificates the authorisation file is built on. A Designated Body (DeBo) does the equivalent job for notified national rules — the requirements that still exist where TSIs leave open points or specific cases, or for legacy compatibility. An Assessment Body (AsBo) is different in kind: under the Common Safety Method for risk evaluation (CSM-RA), it independently assesses whether a proposer's risk-management process was properly applied for a significant change — it audits the risk assessment itself, not conformity with a document. One project routinely involves all three: the NoBo certifies TSI conformity of the new signalling, the DeBo covers the national-rule remainder, and the AsBo signs the safety-assessment report the safety authority relies on. All three must be accredited or recognised, and their reports feed ERA's one-stop shop for authorisations.
ETCS baseline
An ETCS baseline is a consistent, frozen set of the specifications that define the European Train Control System — chiefly the System Requirements Specification SUBSET-026 plus its companion interface and test subsets — released together so that trackside and on-board built to the same baseline are guaranteed to interoperate. Baseline 3 exists in two maintained states: Maintenance Release 1 (SRS 3.4.0) and Release 2 (SRS 3.6.0), the version most in-service fleets run today. Baseline 4 (SRS 4.0.0), mandated by the 2023 CCS TSI's Annex A, brings in FRMCS readiness, ATO over ETCS and other Game-Changer functions. Compatibility across baselines is managed through system-version negotiation: a Baseline 4 trackside can announce older system versions so legacy vehicles keep running, which is why 'which baseline?' is the first question in any ETCS procurement or retrofit conversation. The binding version numbers per document live in Annex A Table A 2 of the CCS TSI — reproduced on each subset's page in this library.
Specific case
A specific case is a provision written into a TSI that allows a member state, network or defined class of situations to deviate from the TSI's general requirement — permanently ('P' cases) or temporarily ('T' cases) while migration completes. Specific cases exist because Europe's railways were built to different gauges, electrification systems, clearance profiles and operating rules, and the TSIs regulate the transition to a common target rather than pretending the differences away: the Iberian 1668 mm gauge, the Nordic loading gauge, or particular platform heights all survive as specific cases. For anyone applying a TSI the practical consequence is that the general requirement is not the whole story — the specific-case annex must be checked for each member state in scope, and where a specific case applies, the requirement it modifies is typically covered by notified national rules assessed by a Designated Body rather than a Notified Body. ERA's application guides list the specific cases per TSI and per state.
Open point
An open point is a topic a TSI explicitly declares it does not yet regulate — the drafters either lacked consensus, mature technology or sufficient data when the TSI was adopted. Unlike a specific case (a deliberate national deviation from a regulated requirement), an open point is a hole in the harmonised layer itself: for that topic there simply is no EU-level technical requirement yet. The gap does not mean 'anything goes' — it is filled by notified national rules, which member states must register in ERA's Reference Document Database, and conformity with them is assessed by a Designated Body rather than a Notified Body. Each TSI revision aims to close open points as harmonised solutions mature, which is why comparing a TSI's open-point annex across editions is a quick way to read the direction of regulatory travel. For project planning, open points are risk items: they mean per-country engineering variance in an otherwise harmonised procurement, and their closure in a future TSI revision can change requirements mid-programme.
Harmonised standard
A harmonised standard is a European standard (EN) developed by CEN/CENELEC under a Commission standardisation request whose reference the Commission has published in the Official Journal in support of a piece of EU law — for rail, the Interoperability Directive (EU) 2016/797. Publication triggers the presumption of conformity: applying the cited standard is presumed to satisfy the essential requirements the citation covers, which reverses the burden of proof in conformity assessment and is why suppliers care intensely about the OJ list. Three practical subtleties follow. First, the presumption attaches to the exact edition cited — EN 45545-2 is cited in its 2013+A1 edition, so building to the newer 2020 edition means demonstrating equivalence rather than presuming it. Second, an EN standard that is not cited is simply voluntary — excellent engineering practice, but carrying no legal presumption. Third, citations move: EN 50128 and EN 50657 were delisted when EN 50716 was cited in 2025. Each standard's page in this library shows its current OJ-cited editions.
SMS — Safety Management System
A Safety Management System is the documented organisation, procedures and accountabilities through which a railway undertaking or infrastructure manager controls the risks of its operation — the corporate machinery that turns safety from individual diligence into a managed process. The Railway Safety Directive (EU) 2016/798 makes an SMS a legal precondition: a railway undertaking obtains its single safety certificate, and an infrastructure manager its safety authorisation, by demonstrating the SMS meets the requirements spelled out in Regulation (EU) 2018/762 — risk management integrated with CSM-RA for changes, competence management, occurrence reporting and learning, emergency preparedness, safety culture and continuous improvement. After certification, the Common Safety Method for monitoring (CSM-MON) obliges the organisation to check that its risk controls actually work in operation, closing the loop supervision by the national safety authority then audits. The SMS is also where interfaces are governed: contractors, ECMs and station operators all connect to the certificate-holder's risk controls through it.
ECM — Entity in Charge of Maintenance
Every vehicle registered in the EU must have an Entity in Charge of Maintenance assigned in the vehicle register — the organisation that answers for the vehicle being maintained in a safe state of running. The ECM system exists because wagons and increasingly locomotives circulate far from their keeper across many operators: someone specific must own the maintenance file, the maintenance programme, and the fleet-wide feedback loop regardless of where the vehicle runs. Regulation (EU) 2019/779 defines the certification scheme: an ECM's management system covers four functions — management, maintenance development, fleet maintenance management, and maintenance delivery — and certification is mandatory for freight-wagon ECMs, with the same framework applied more widely. The ECM appears in the European Vehicle Register entry for each vehicle, and its certificates in ERADIS. In wagon practice the ECM system interlocks with the GCU, the contractual framework under which wagons are exchanged between keepers and railway undertakings.
One-stop shop (OSS)
The one-stop shop is ERA's single application portal for the EU-level authorisations created by the Fourth Railway Package: vehicle (type) authorisations, single safety certificates, and ERTMS trackside approvals. Instead of applying separately in each member state, an applicant files once through the OSS; ERA acts as the authorising entity when the area of use covers more than one member state (the national safety authority can still handle single-state cases), coordinating the assessment with the NSAs concerned. The applicant chooses the authorising entity for single-state cases — one of the package's practical flexibility points. The OSS is also where pre-engagement happens: applicants can ask for a view on their approach before formally applying, which for complex first-of-class projects is often the difference between a smooth file and a contested one. Regulation (EU) 2018/545 details the vehicle-authorisation process stages and decision timelines; Regulation (EU) 2018/763 does the same for safety certificates.
Interoperability constituent (IC)
An interoperability constituent is a component or assembly the TSIs single out as safety- or interoperability-critical enough to be certified on its own, before it is ever installed in a subsystem: a wheel, a rail fastening, a pantograph head, a balise, a driver's desk ETCS DMI. The manufacturer obtains an EC declaration of conformity for the IC from a Notified Body against the requirements of the relevant TSI — often by applying the harmonised EN standards the TSI cites — and subsystem-level EC verification then builds on those component certificates instead of re-assessing everything from scratch. The mechanism is what lets a wagon builder buy certified wheelsets on the open market, or a signalling integrator source Eurobalises from any certified vendor, and it is the legal backbone of component-level competition in the EU rail supply market. Each TSI's annexes list which constituents it defines and which assessment modules (design examination, production quality system, and so on) may be used.

