Country guide

Rail cyber security regulations in the United Kingdom

UK rail cyber security combines obligations for designated essential services with railway-specific guidance and procurement requirements. Start with the operator's legal status and the service being protected: a train operator, infrastructure manager and equipment supplier can have different responsibilities on the same project.

Initial source review ; procurement guidance and Bill status checked .

Who needs to consider these requirements?

For a fleet deployment, establish who owns the essential service, who controls the onboard network and who maintains it. A supplier may need to provide evidence under its customer's contract even where it is not itself an operator of essential services. Record those responsibilities before selecting controls or agreeing acceptance criteria.

Key regulations and frameworks

Network and Information Systems Regulations 2018

Law — applies to in-scope essential services

The NIS Regulations provide the existing security and incident-reporting framework for operators of essential services. Transport is an included sector, with the Department for Transport acting as the competent authority for rail. Applicability depends on the statutory criteria and designation; supplying a railway does not automatically make every company a regulated operator.

Official source: Network and Information Systems Regulations 2018

DfT passenger rolling stock procurement: cyber-security

Procurement guidance — published 26 March 2026

DfT's March 2026 guidance addresses passenger rolling stock procurements in Great Britain, including heavy rail, light rail, metro, open-access services and trams. It covers contracting-authority preparation and supplier evidence across the asset lifecycle. The guidance calls for tenders to distinguish mandatory requirements, supplier proposals and collaborative commitments. It addresses risk assessment, assurance gates, penetration testing, security monitoring, recovery and secure maintenance. It is not legislation: the agreed tender and contract establish the project's requirements, alongside applicable law.

Official source: DfT passenger rolling stock procurement: cyber-security

Source checked .

RSSB Key Train Requirements (KTR) v8

Industry procurement guidance — new and refurbished trains

RSSB describes KTR as support for procurers, specifiers, manufacturers and system suppliers preparing specifications for new and refurbished trains. It captures experience and good practice beyond requirements already covered by standards. RSSB's current public page identifies version 8, including a requirements applicability matrix and expanded cyber-security coverage. Review the relevant KTR requirements alongside the DfT guidance, record the selected edition and make applicability explicit in the tender. KTR is a procurement resource, not a standalone Act or blanket legal mandate.

Official source: RSSB Key Train Requirements (KTR) v8

Source checked .

Cyber Security and Resilience Bill

Proposed legislation — monitor Parliament

The Bill would reform the NIS framework. Parliament's record checked for this guide shows a House of Lords bill, including an amended text dated 7 September 2026. Proposed changes should inform preparation, but should not be presented as obligations already brought into force.

Official source: Cyber Security and Resilience Bill

Source checked .

Practical steps for rail teams

Use these engineering and project-planning actions to prepare evidence for the requirements that apply to your organisation.

  1. Create a responsibility matrix covering the operator, rolling stock owner, maintainer and remote-access suppliers; attach the relevant NIS or contract requirement to each owner.
  2. Before tender, record the KTR edition and applicable requirements. Give bidders a traceable requirements-and-evidence schedule rather than relying solely on a general instruction to comply with standards.
  3. Use the DfT guidance to agree cyber assurance gates, penetration-test scope, monitoring responsibilities and recovery expectations. Specify supplier dependency records, secure-maintenance arrangements and the evidence needed throughout service life.
  4. Specify the evidence needed at train acceptance: network boundaries, allowed connections, support access, security monitoring and a process for handling vulnerabilities over the fleet's life.
  5. Exercise a disruption scenario with operations and engineering. Identify who can isolate affected equipment, preserve evidence and make the operator's regulatory notifications.

Using this guide

This is an introduction to selected frameworks, not a complete legal assessment. Applicability depends on your organisation, systems and contracts. Check the linked official texts and obtain advice for your project before relying on a requirement or deadline.