Who needs to consider these requirements?
A transit agency, freight railroad and equipment manufacturer should not assume they share the same regulatory scope. For an international supplier, the operator's directive and approved implementation approach are the starting point for contract evidence. Confirm the current revision directly with the operator or TSA; a public copy of an older directive is not a reliable substitute.
Key regulations and frameworks
TSA rail cybersecurity directives
Mandatory for the operators within directive scope
The Federal Transit Administration distinguishes TSA security directives for higher-risk operators from an information circular for other surface transportation operators. Its overview describes measures including cybersecurity coordination, incident reporting, response planning and vulnerability assessment. These requirements should be checked against the operator's current directive, including any renewed or superseding version.
Cybersecurity risk management rulemaking
Rulemaking — verify final rule and effective dates
TSA announced a proposed rule in November 2024 covering cybersecurity risk management for specified pipeline and surface transportation operators. That announcement is a proposal, not proof that a final rule has taken effect. Continue to use the applicable security directive and check TSA's current rulemaking record before adopting a new compliance deadline.
Practical steps for rail teams
Use these engineering and project-planning actions to prepare evidence for the requirements that apply to your organisation.
- Maintain a controlled register of the operator's applicable TSA directives, revisions, implementation plans and accountable contacts. Check renewal dates with the operator.
- Trace connections between enterprise IT and operational systems. Test the intended restrictions on vendor access and identify how monitoring distinguishes expected maintenance from suspicious activity.
- Run a joint exercise with the cybersecurity coordinator and rail operations team. Preserve a timeline, identify reporting responsibilities and test recovery without assuming every network can be patched immediately.
Using this guide
This is an introduction to selected frameworks, not a complete legal assessment. Applicability depends on your organisation, systems and contracts. Check the linked official texts and obtain advice for your project before relying on a requirement or deadline.
