From Framework To Fitted Fleet
Regulators and tenders define what is required. We translate the frameworks (IEC 62443, TS 50701 and its successor IEC 63452, NIS2, TSA) into products on trains and evidence in audits.
At SL2 And Above, Monitoring Stops Being Optional
Under an IEC 62443-3-2 / TS 50701 risk assessment, most modern rolling stock zones land at Security Level 2 or above. At SL2+, intrusion detection and continuous monitoring become required controls, not optional extras.
That is exactly the gap our products close: Delta for detection, Security Gateway for zone enforcement, DMG for controlled access, Echo for asset visibility.
What we provide at audit time
Framework-aligned reporting from Dashboard: alert history, baseline changes, access records and asset configuration state. Evidence your assessor can use, not screenshots.
The Standards That Matter In Rail
| CLC/TS 50701 | The rail-specific cyber security specification: zones, conduits and lifecycle requirements for rolling stock. Our reference architectures are TS 50701-aligned for new build and retrofit. |
|---|---|
| IEC PT 63452 | The IEC project team is developing a proposed international cyber security standard for railways, informed by CLC/TS 50701. We track the project's development while supporting the current specification. |
| IEC 62443 | Zones & conduits (-3-2), system requirements (-3-3) and component requirements (-4-2). Our products provide the detection, enforcement and access controls SL2+ zones require. |
| EN 50155 | The rolling stock electronics environment standard. Security Gateway ships as an EN 50155 compliant appliance; Delta also deploys as software on EN 50155-certified hardware you already carry, including Westermo switches. |
| EU NIS / NIS2 | Essential-service risk management and incident reporting. We have supported operator NIS compliance since the first directive; detection, evidence and reporting are the operational core of it. |
| TSA Security Directives | US surface transportation requirements for network segmentation, monitoring and incident response capability. Security Gateway, Delta and our managed monitoring cover them. |
| EU Cyber Resilience Act | Product security obligations for suppliers: secure development, vulnerability handling and update capability. See our responsible disclosure policy and signed-update lifecycle. |
| UK NCSC CAF · NIST CSF · AS 7770 | National frameworks we map to for UK, US and Australian operators. Same products, different paperwork, and we've done the paperwork before. |
Which Product Answers Which Requirement
| Segmentation & zone enforcement | Security Gateway: IEC 62443-3-2 zones & conduits, TS 50701 architecture, TSA segmentation requirements. |
|---|---|
| Intrusion detection & monitoring | Delta: the SL2+ detection requirement, NIS2 detection & reporting, TSA monitoring expectations. |
| Access control & maintenance integrity | Digital Maintenance Gateway: MFA, audited access and code-signed software distribution from a wayside repository, synchronised to the train with software validation. |
| Asset inventory & configuration | Echo: the asset visibility every framework starts with; configuration drift evidence. |
| Evidence, reporting & response | Dashboard + optional managed monitoring: audit-ready records and analyst review where contracted. |
Need the detailed control-by-control matrix for a tender response? Ask us. We maintain mappings for TS 50701, IEC 62443-3-3/-4-2 and TSA directives.
Independently Audited
Our management systems are independently audited and certified to ISO 9001, ISO 14001 and ISO 27001.

