Who needs to consider these requirements?
A new metro or mainline programme should establish the operator's NCA obligations early enough to shape procurement. Separate the corporate technology environment from the operational systems that control or support railway services. Suppliers need clear requirements for the equipment, remote connections and support services they deliver into those environments.
Key regulations and frameworks
Essential Cybersecurity Controls — ECC 2:2024
Mandatory controls for organisations within scope
NCA's ECC 2:2024 establishes national baseline controls. Its scope includes government organisations and private-sector entities that own, operate or host critical national infrastructure. The organisation should determine its scope and applicable controls, maintain implementation evidence and consider the relevant complementary NCA frameworks. Do not assume an equipment supplier and its regulated customer have the same direct obligations.
Official source: Essential Cybersecurity Controls — ECC 2:2024
Operational Technology Cybersecurity Controls — OTCC 1:2022
OT controls — assess facility and system scope
NCA publishes additional controls for operational technology in critical industrial facilities. For rail, determine with the operator which operational environments and facility categories are covered. Apply the OT-specific requirements alongside the relevant baseline, rather than treating enterprise IT controls as a complete answer for signalling, control and other operational systems.
Official source: Operational Technology Cybersecurity Controls — OTCC 1:2022
Practical steps for rail teams
Use these engineering and project-planning actions to prepare evidence for the requirements that apply to your organisation.
- Request the operator's applicable NCA control set and system boundaries before tender acceptance. Allocate an evidence owner for each requirement passed to the supplier.
- Document all operational support connections, including vendor maintenance paths. Agree how access is authorised, limited, monitored and revoked when a support engagement ends.
- Plan acceptance tests and operational handover together. Record configuration baselines, backup responsibilities and how security changes will be assessed against service and safety constraints.
Using this guide
This is an introduction to selected frameworks, not a complete legal assessment. Applicability depends on your organisation, systems and contracts. Check the linked official texts and obtain advice for your project before relying on a requirement or deadline.
