Resources

Global Rail Cybersecurity Regulations

Which cybersecurity laws apply to your fleet, and where? We track 70 jurisdictions: the handful with genuinely rail-specific rules, and the critical-infrastructure laws that apply to rail operators everywhere else. That includes the Middle East, Japan, Latin America and Africa, regions most compliance maps leave blank. Click a country for details.

An introduction to the rules affecting rail. This map is for general information. Check the linked official sources and seek advice for your organisation before relying on an entry; the content is still under review.
70jurisdictions tracked
189regulations & frameworks
6with rail-specific rules
2026-09-18latest content update
Explore by country

Rail cyber security country guides

Explore the key frameworks, applicability questions and practical steps for these 16 countries. Source review dates are shown in each guide.

EU member states must follow EU-level rules in addition to national law: NIS2, the CER Directive and the Cyber Resilience Act. .

Browse

All jurisdictions

Compliance requirements keep changing. Your security architecture should not have to change with them.

RazorSecure products support compliance work for NIS2, TS 50701, IEC 62443 and the TSA Security Directives, while we track the IEC PT 63452 project.

Talk compliance with an expert How we support compliance