Skip to content

    How European Railway Standards Fit Together

    Ask an engineer, a bid manager and a newcomer what "the standard" for something is, and you will get three different documents. That is not confusion — it reflects a genuine structure. In the EU rail sector, "standards" spans a hierarchy of binding law, technical specifications and voluntary standards, plus a further body of material that sits outside EU law altogether: UIC references, international conventions, IEC/ISO standards and national rulebooks. None of it was designed as a single system from the outset — it accreted over two decades of railway packages, each adding a layer without discarding the one beneath — which is exactly why newcomers find it opaque and experienced engineers still keep a mental map of how the pieces cite one another.

    This guide walks through that structure layer by layer, introduces the institutions that run it, and shows how it comes together for two of the system's most consequential paths — putting a vehicle into service and building a control-command and signalling installation — before explaining how this library itself is organised. Every document named below is drawn from the library's own entries, so any claim here can be checked against the source it links to.

    The three-layer system: directives, TSIs, standards

    At the top sit two EU directives that set essential requirements rather than technical detail. Directive (EU) 2016/797 establishes the conditions for interoperability of the Union rail system: the essential requirements each subsystem must meet, the mechanism for adopting Technical Specifications for Interoperability (TSIs), and the vehicle authorisation regime run through the European Union Agency for Railways (ERA). Alongside it, Directive (EU) 2016/798 sets the parallel safety framework, covered in its own section below.

    Nine TSIs translate those essential requirements into binding technical law, one per subsystem: Control-Command and Signalling, Infrastructure, Energy, Locomotives and Passenger Rolling Stock, Freight Wagons, Noise, Operation and Traffic Management, Persons with Disabilities and Reduced Mobility, and Safety in Railway Tunnels. All nine were substantially revised by the 2023 TSI package, and ERA's own General Guide for the Application of TSIs explains the common provisions — deficiencies, specific cases, non-application — that run across all of them.

    Beneath the TSIs sits a layer that is not, by itself, legally binding: harmonised European standards from CEN and CENELEC. Presumption of conformity attaches to harmonised standards whose references are published in the Official Journal under the interoperability directive; where a TSI cites a standard or specification directly, it becomes a mandatory means of compliance rather than a voluntary one. EN 50126-1, the generic RAMS lifecycle process, is a good example: whether or not a given TSI clause points to it, it is the de facto basis suppliers and assessors use to build the reliability, availability, maintainability and safety case that the TSIs and the safety directive both ultimately require.

    Who's who: the institutions and bodies

    Several kinds of actor operate this system. The European Commission adopts the TSIs and the underlying regulations. The European Union Agency for Railways, created under Regulation (EU) 2016/796, runs the one-stop shop for authorisations and certificates, approves ERTMS trackside equipment, and maintains the registers everyone else relies on: ERATV for authorised vehicle types, RINF for infrastructure and line characteristics, ERADIS for certification status, and the Reference Document Database for the notified national rules that fill the gaps TSIs leave open. CEN and CENELEC write the harmonised EN standards described above through committees of national delegations and industry experts, which is why an EN standard can take years to revise even after everyone agrees it should be — consensus has to be rebuilt across every member country. National safety authorities supervise safety within their own Member State under Directive (EU) 2016/798, and remain the first point of contact for anything a TSI leaves as a national competence. Market access and non-discriminatory network use sit on a separate track — Directive 2012/34/EU — overseen by independent regulatory bodies rather than the safety authorities. Conformity assessment then runs through three kinds of independent body: Notified Bodies assess TSI conformity, Designated Bodies assess national rules, and Assessment Bodies independently review the risk assessments carried out under the Common Safety Method for Risk Evaluation and Assessment — the process every significant technical, operational or organisational change to the railway system must go through.

    The safety pillar

    Directive (EU) 2016/798 is the safety half of the Fourth Railway Package: common safety targets and methods, safety management system (SMS) requirements, and the single safety certificate a railway undertaking needs before it can operate. Three Common Safety Methods give the framework its working machinery. CSM-RA is the risk-assessment process applied to significant changes; CSM-MON requires undertakings and infrastructure managers to monitor, after certification, that their safety processes and risk controls are actually working; and Regulation (EU) 2018/762 spells out what an SMS itself must contain, the basis national safety authorities and ERA use to assess it. The certificate that results is issued under the practical arrangements of Regulation (EU) 2018/763, through the same one-stop shop used for vehicle authorisation. Maintenance has its own certification track: Regulation (EU) 2019/779 establishes the entity-in-charge-of-maintenance (ECM) certification system. Two further pieces close the loop — Directive 2007/59/EC harmonises train driver licensing and competence, and Implementing Regulation (EU) 2020/572 standardises how national investigation bodies report accidents and incidents, so lessons learned are comparable across the Union. Taken together, this pillar is what lets a safety certificate issued in one Member State be recognised everywhere the certificate-holder wants to operate, rather than needing to be renegotiated country by country.

    The vehicle path: from directive to authorisation

    Putting a vehicle into service runs straight through several of the layers above. Directive (EU) 2016/797 sets the essential requirements; the TSI Locomotives and Passenger Rolling Stock, TSI Noise and TSI Persons with Disabilities and Reduced Mobility translate them into binding technical detail for that subsystem. Underneath sits the EN chain that gives a manufacturer something concrete to design and test against: carbody structural strength in EN 12663-1, crashworthiness in EN 15227, running-safety testing in EN 14363, fire behaviour of materials in EN 45545-2, and — for the electronics and software on board — environmental qualification in EN 50155, shock and vibration testing in IEC 61373, and software development requirements in EN 50716. Running gear has its own sub-chain beneath the same TSIs — axle design in EN 13103-1, wheel product requirements in EN 13262, and bogie frame structural requirements in EN 13749 — which manufacturers and Notified Bodies work through alongside the carbody and crash standards above. Once the technical file is complete, Regulation (EU) 2018/545 sets out the practical arrangements for the authorisation itself, run through ERA and the national safety authorities. Authorisation and registration then feed two registers: Decision 2011/665/EU governs ERATV, the register of authorised vehicle types, and Decision (EU) 2018/1614 governs the European Vehicle Register that records each individual vehicle's keeper, ECM and authorisation history.

    The CCS stack: ETCS, radio and safety software

    The control-command and signalling (CCS) subsystem has the densest specification stack in the library, because TSI CCS does not just set requirements — its Annex A incorporates dozens of ERTMS specifications by reference, making them binding law rather than voluntary standards. At the centre is ETCS: SUBSET-026 is the system requirements specification defining modes, braking curves and the core train-control logic; SUBSET-023 is the glossary every other subset relies on for consistent terminology; SUBSET-036 specifies the Eurobalise trackside-to-onboard interface; SUBSET-037 specifies EuroRadio, the safety-related protocol carried over GSM-R and, in later baselines, FRMCS; SUBSET-091 sets the quantitative safety requirements apportioned between onboard and trackside equipment; and SUBSET-119 specifies the train interface linking ETCS to braking and traction. Automatic train operation running over ETCS has its own pair of specifications: SUBSET-125 for system requirements and SUBSET-126 for the ATO onboard/trackside application layer. This specification set is not safety-assured in isolation — it sits inside the CENELEC framework of EN 50126-1 and EN 50126-2 for RAMS, EN 50129 for safety-related electronic systems, and EN 50716 for the software itself. Two open reference architectures sit alongside the mandatory stack rather than inside it: EULYNX standardises the interfaces between interlockings and trackside field elements, and OCORA does the same for the ETCS onboard computer, both aimed at breaking vendor lock-in without waiting for the next TSI revision. In practice this stack is rarely assessed piece by piece: a signalling supplier typically builds one safety case that threads the RAMS process, the SUBSET requirements it implements and the hardware and software standards behind it into a single argument a Notified Body can accept as a whole.

    Infrastructure and energy: the fixed installation

    TSI Infrastructure and TSI Energy work the same way for the fixed-installation side of the system, each backed by an ERA application guide and a chain of CEN/CENELEC standards beneath it. On the track side: EN 13674-1 specifies rail steel grades and profiles, EN 15273 defines the gauging methodology that keeps rolling stock and structures clear of one another, EN 15528 classifies lines by axle load and mass per unit length so infrastructure managers and railway undertakings can check route compatibility, and EN 1991-2 — Eurocode 1 — sets the traffic load models used in bridge design. On the electrification side: EN 50119 covers overhead contact line design, EN 50163 fixes the nominal traction supply voltages every vehicle and substation must be compatible with, and a linked trio — EN 50367, EN 50317 and EN 50318 — respectively define, measure and validate-by-simulation the dynamic interaction between pantograph and contact line. EN 50121 closes the loop with electromagnetic compatibility limits for the whole system, from rolling stock to trackside apparatus. As with the vehicle path, these standards are rarely applied in isolation: an infrastructure manager designing a new electrified line typically works through the track chain and the electrification chain in parallel, then demonstrates to a Notified Body that both meet the corresponding TSI before construction begins.

    Beyond EU law: UIC, OTIF, IEC/ISO and national rulebooks

    Not everything an engineer needs sits inside the EU interoperability framework. The International Union of Railways (UIC) publishes reference documents used across and beyond Europe: IRS 70712 is the standard rail-defect coding handbook, Code 406 defines the compression method for measuring line and node capacity, and IRS 90940 specifies the SFERA protocol for exchanging driver-advisory and ATO data with onboard devices. International conventions add another layer: RID, Appendix C to the COTIF Convention, governs the international carriage of dangerous goods by rail and is transposed into EU law rather than replaced by it. Quality management runs on ISO 22163, the IRIS scheme that is a de facto precondition for supplying rolling stock to major operators. Several CENELEC EN standards also have an IEC "twin" — the same requirements published as an international standard for markets outside the EU: IEC 62278-1 mirrors EN 50126-1, IEC 62279 mirrors EN 50128, and IEC 62425 mirrors EN 50129. And outside the EU altogether, national rulebooks remain the governing law: Germany's EBA regulatory portal, France's EPSF regulatory portal, Great Britain's RSSB standards catalogue, the United States' 49 CFR Chapter II and AREMA Manual for Railway Engineering, and Canada's Railway Safety Act each set the rules that apply once a design, or a train, crosses into their jurisdiction.

    How to use this library

    This library groups every entry above into the domain it belongs to — control-command and signalling, rolling stock, infrastructure, energy, systems and software, safety, EU legal acts, TSIs, ERA guidance, national frameworks, research and international — so starting from a subsystem is as easy as starting from a code you already know. Each entry carries an access badge (free, registration or paid) so you know before you click whether a document is an open download or sits behind a UIC shop account or a purchase, and a status badge — Active, Under Revision or Superseded — so that, for example, EN 50128 is clearly marked as superseded by EN 50716 rather than left looking current, with the successor one click away. Beyond the hard law and harmonised standards, the library also tracks the softer material that keeps the system moving: ERA's non-binding application guides for individual TSIs, data-exchange standards such as railML, the Europe's Rail Joint Undertaking programme that funds much of the next-generation work, and adjacent EU law such as rail passengers' rights that shapes the sector without being a technical specification at all. Every entry that carries a live link has been checked against its own official source, not a search result or a mirror, and is rechecked on a schedule rather than left to go stale — that verification promise is what this whole directory is built on. So whichever of the three readers at the top of this guide you are — an engineer confirming a citation, a bid manager tracing an unfamiliar designation back to its TSI, or a newcomer building a first mental map — the route through is the same: start from a domain or a code, follow the links, and let the hierarchy above do the rest of the work.