Resources

Global Rail Cybersecurity Regulations

Which cybersecurity laws apply to your fleet, and where? We track 70 jurisdictions: the handful with genuinely rail-specific rules, and the critical-infrastructure laws that apply to rail operators everywhere else. That includes the Middle East, Japan, Latin America and Africa, regions most compliance maps leave blank. Click a country for details.

An introduction to the rules affecting rail. This map is for general information. Check the linked official sources and seek advice for your organisation before relying on an entry; the content is still under review.
70jurisdictions tracked
180regulations & frameworks
6with rail-specific rules
2026-09-10country guides added
Explore by country

Rail cyber security country guides

Explore the key frameworks, applicability questions and practical steps for these 13 countries. Official sources checked 10 September 2026.

EU member states must follow EU-level rules in addition to national law: NIS2, the CER Directive and the Cyber Resilience Act. .

Browse

All jurisdictions

Compliance requirements keep changing. Your security architecture should not have to change with them.

RazorSecure products support compliance work for NIS2, TS 50701, IEC 62443 and the TSA Security Directives, while we track the IEC PT 63452 project.

Talk compliance with an expert How we support compliance