Resources
Global Rail Cybersecurity Regulations
Which cybersecurity laws apply to your fleet, and where? We track 70 jurisdictions: the handful with genuinely rail-specific rules, and the critical-infrastructure laws that apply to rail operators everywhere else. That includes the Middle East, Japan, Latin America and Africa, regions most compliance maps leave blank. Click a country for details.
An introduction to the rules affecting rail.
This map is for general information. Check the linked official sources and seek advice for your organisation before relying on an entry; the content is still under review.
70jurisdictions tracked
189regulations & frameworks
6with rail-specific rules
2026-09-18latest content update
Explore by country
Rail cyber security country guides
Explore the key frameworks, applicability questions and practical steps for these 16 countries. Source review dates are shown in each guide.
EU member states must follow EU-level rules in addition to national law: NIS2, the CER Directive and the Cyber Resilience Act. .
Browse
