Who needs to consider these requirements?
A supplier delivering to a government railway or public-sector programme should obtain the customer's applicable security instructions, procurement conditions and reporting arrangements. National strategy helps explain the policy context, but the specific controls and evidence required for a project need to be established with the operator and responsible authorities.
Key regulations and frameworks
Government critical ICT infrastructure protection
Government requirements — establish operator and project scope
Egypt's State Information Service describes Prime Ministerial Decision 994 of 2017 as requiring government bodies and public business-sector companies to implement the Supreme Cybersecurity Council's decisions and recommendations for their critical ICT infrastructure. For a railway project, establish which decisions and implementing instructions apply to the customer. A high-level public summary is not a substitute for the project's applicable requirements.
Official source: Government critical ICT infrastructure protection
National Cybersecurity Strategy 2023–2027
National strategy — not a standalone rail control specification
EG-CERT publishes Egypt's National Cybersecurity Strategy for 2023–2027. It is a policy reference for national preparedness and infrastructure protection, rather than an equipment acceptance checklist. Use it alongside the operator's binding instructions and contract requirements, with a clearly agreed route for escalating cybersecurity incidents to the appropriate teams.
Practical steps for rail teams
Use these engineering and project-planning actions to prepare evidence for the requirements that apply to your organisation.
- Obtain a written security requirements baseline from the operator, identifying the authority, contract clause or instruction behind each requirement and who accepts the evidence.
- Agree ownership of network configurations, maintenance credentials and backups at handover. Include local support teams and any overseas suppliers in the responsibility matrix.
- Exercise the incident escalation route with operations staff. Check how the team can retain useful evidence, limit remote access and restore service when connectivity or supplier support is unavailable.
Using this guide
This is an introduction to selected frameworks, not a complete legal assessment. Applicability depends on your organisation, systems and contracts. Check the linked official texts and obtain advice for your project before relying on a requirement or deadline.
