Who needs to consider these requirements?
For a fleet deployment, establish who owns the essential service, who controls the onboard network and who maintains it. A supplier may need to provide evidence under its customer's contract even where it is not itself an operator of essential services. Record those responsibilities before selecting controls or agreeing acceptance criteria.
Key regulations and frameworks
Network and Information Systems Regulations 2018
Law — applies to in-scope essential services
The NIS Regulations provide the existing security and incident-reporting framework for operators of essential services. Transport is an included sector, with the Department for Transport acting as the competent authority for rail. Applicability depends on the statutory criteria and designation; supplying a railway does not automatically make every company a regulated operator.
Official source: Network and Information Systems Regulations 2018
DfT rail and rolling stock procurement guidance
Guidance — check procurement and contract requirements
DfT's rail cyber security guidance sets out good practice for railway systems. Its 2026 rolling stock procurement guidance brings cyber security into procurement specifications. Use these documents to structure requirements for new trains and their support arrangements; guidance and an obligation incorporated into a tender or contract should be identified separately.
Official source: DfT rail and rolling stock procurement guidance
Cyber Security and Resilience Bill
Proposed legislation — monitor Parliament
The Bill would reform the NIS framework. Parliament's record checked for this guide shows a House of Lords bill, including an amended text dated 7 September 2026. Proposed changes should inform preparation, but should not be presented as obligations already brought into force.
Practical steps for rail teams
Use these engineering and project-planning actions to prepare evidence for the requirements that apply to your organisation.
- Create a responsibility matrix covering the operator, rolling stock owner, maintainer and remote-access suppliers; attach the relevant NIS or contract requirement to each owner.
- Specify the evidence needed at train acceptance: network boundaries, allowed connections, support access, security monitoring and a process for handling vulnerabilities over the fleet's life.
- Exercise a disruption scenario with operations and engineering. Identify who can isolate affected equipment, preserve evidence and make the operator's regulatory notifications.
Using this guide
This is an introduction to selected frameworks, not a complete legal assessment. Applicability depends on your organisation, systems and contracts. Check the linked official texts and obtain advice for your project before relying on a requirement or deadline.
