Who needs to consider these requirements?
Railway undertakings and infrastructure managers should assess the Railways Ordinance and the CySec-Rail directive, including any applicable exemption process. Suppliers, maintenance providers and rolling-stock owners need clearly agreed security responsibilities and evidence for their customers. Separately check whether the organisation falls within the Information Security Act's reporting scope and whether a Cybersecurity Ordinance exception applies.
Key regulations and frameworks
FOT railway cybersecurity directive (CySec-Rail)
Rail-specific supervisory directive — version 1.1 effective 1 July 2024
The directive sets out minimum requirements for an information security management system and addresses IT and operational technology, including systems on vehicles. It provides a basis for FOT supervision under the railway framework. Rail teams should coordinate cyber-risk management with safety management, document the systems and responsibilities included, and justify the measures selected for their operational risks. The directive also explains how alternative approaches can meet the underlying requirements.
Official source: FOT railway cybersecurity directive (CySec-Rail)
Information Security Act: critical-infrastructure cyberattack reporting
Reporting duty — effective from 1 April 2025
Covered operators, including transport companies subject to the scope rules, must report qualifying cyberattacks to the NCSC within 24 hours of discovery. After the initial submission they have 14 days to complete the report. Reportable cases include attacks threatening critical-infrastructure functioning, information manipulation or leakage, and blackmail. The Cybersecurity Ordinance specifies exceptions, so neither every supplier nor every technical fault automatically triggers this duty.
Official source: Information Security Act: critical-infrastructure cyberattack reporting
Practical steps for rail teams
Use these engineering and project-planning actions to prepare evidence for the requirements that apply to your organisation.
- Map CySec-Rail information-security responsibilities to the railway's safety-management arrangements. Make ownership clear for systems shared between operators, infrastructure managers and maintenance contractors.
- Maintain an operational asset and connection inventory covering onboard, trackside and depot environments. Record remote-access arrangements, supported software versions and compensating controls for long-lived equipment.
- Rehearse a 24-hour reporting decision using the Swiss criteria. Name authorised reporters and arrange supplier escalation early enough to preserve time for assessment and initial submission.
- Test recovery procedures against rail operating constraints, including the safe restoration of communications and maintenance access. For international fleets, keep Swiss and neighbouring-country reporting routes separately documented.
Using this guide
This is an introduction to selected frameworks, not a complete legal assessment. Applicability depends on your organisation, systems and contracts. Check the linked official texts and obtain advice for your project before relying on a requirement or deadline.
