Country guide

Rail cyber security regulations in the United States

US rail cyber security requirements are shaped by Transportation Security Administration directives for specified operators. Higher-risk passenger and freight rail operators can face mandatory requirements that differ from the recommendations issued more widely to transit agencies. The first question is which directive, revision and applicability notice the operator has actually received.

Official sources checked

Who needs to consider these requirements?

A transit agency, freight railroad and equipment manufacturer should not assume they share the same regulatory scope. For an international supplier, the operator's directive and approved implementation approach are the starting point for contract evidence. Confirm the current revision directly with the operator or TSA; a public copy of an older directive is not a reliable substitute.

Key regulations and frameworks

TSA rail cybersecurity directives

Mandatory for the operators within directive scope

The Federal Transit Administration distinguishes TSA security directives for higher-risk operators from an information circular for other surface transportation operators. Its overview describes measures including cybersecurity coordination, incident reporting, response planning and vulnerability assessment. These requirements should be checked against the operator's current directive, including any renewed or superseding version.

Official source: TSA rail cybersecurity directives

Cybersecurity risk management rulemaking

Rulemaking — verify final rule and effective dates

TSA announced a proposed rule in November 2024 covering cybersecurity risk management for specified pipeline and surface transportation operators. That announcement is a proposal, not proof that a final rule has taken effect. Continue to use the applicable security directive and check TSA's current rulemaking record before adopting a new compliance deadline.

Official source: Cybersecurity risk management rulemaking

Practical steps for rail teams

Use these engineering and project-planning actions to prepare evidence for the requirements that apply to your organisation.

  1. Maintain a controlled register of the operator's applicable TSA directives, revisions, implementation plans and accountable contacts. Check renewal dates with the operator.
  2. Trace connections between enterprise IT and operational systems. Test the intended restrictions on vendor access and identify how monitoring distinguishes expected maintenance from suspicious activity.
  3. Run a joint exercise with the cybersecurity coordinator and rail operations team. Preserve a timeline, identify reporting responsibilities and test recovery without assuming every network can be patched immediately.

Using this guide

This is an introduction to selected frameworks, not a complete legal assessment. Applicability depends on your organisation, systems and contracts. Check the linked official texts and obtain advice for your project before relying on a requirement or deadline.