Railway Applications — Cybersecurity
Issuing body: CENELEC · Version: CLC/TS 50701:2023 · Published: 2023-08-31
Link verified July 21, 2026
Scope
Technical specification applying the IEC 62443 industrial-cybersecurity framework to railways: zones and conduits, risk assessment, security levels and lifecycle security requirements covering signalling, fixed installations and rolling stock. It is the primary European reference used by infrastructure managers, operators and suppliers to specify and assess cybersecurity of rail systems.
CLC/TS 50701 is CENELEC's technical specification applying the IEC 62443 industrial cybersecurity framework specifically to the railway domain, structuring a railway system into security zones and conduits and requiring risk assessment, defined security levels and lifecycle security requirements to be applied across signalling systems, fixed installations and rolling stock. It provides railway-specific guidance on adapting IEC 62443's generic industrial-automation security concepts -- such as zone segmentation and security level targets -- to the particular architecture of railway control-command, telecommunications and traction systems. Infrastructure managers, railway operators and suppliers use it as the primary European reference for specifying cybersecurity requirements in new procurements and for assessing the cybersecurity posture of existing rail systems, an area of growing regulatory and operational attention as railway systems become more networked and software-dependent. The current 2023 edition superseded the original 2021 edition, which was withdrawn on 21 August 2023 following the update. As a technical specification rather than a full European Standard, it does not yet carry the same harmonisation status as an EN, but is nonetheless the sector's de-facto cybersecurity reference pending further standardisation.

