Standards & compliance

From Framework To Fitted Fleet

Regulators and tenders define what is required. We translate the frameworks (IEC 62443, TS 50701 and its successor IEC 63452, NIS2, TSA) into products on trains and evidence in audits.

The key fact

At SL2 And Above, Monitoring Stops Being Optional

Under an IEC 62443-3-2 / TS 50701 risk assessment, most modern rolling stock zones land at Security Level 2 or above. At SL2+, intrusion detection and continuous monitoring become required controls, not optional extras.

That is exactly the gap our products close: Delta for detection, Security Gateway for zone enforcement, DMG for controlled access, Echo for asset visibility.

What we provide at audit time

Framework-aligned reporting from Dashboard: alert history, baseline changes, access records and asset configuration state. Evidence your assessor can use, not screenshots.

Framework map

The Standards That Matter In Rail

CLC/TS 50701The rail-specific cyber security specification: zones, conduits and lifecycle requirements for rolling stock. Our reference architectures are TS 50701-aligned for new build and retrofit.
IEC PT 63452The IEC project team is developing a proposed international cyber security standard for railways, informed by CLC/TS 50701. We track the project's development while supporting the current specification.
IEC 62443Zones & conduits (-3-2), system requirements (-3-3) and component requirements (-4-2). Our products provide the detection, enforcement and access controls SL2+ zones require.
EN 50155The rolling stock electronics environment standard. Security Gateway ships as an EN 50155 compliant appliance; Delta also deploys as software on EN 50155-certified hardware you already carry, including Westermo switches.
EU NIS / NIS2Essential-service risk management and incident reporting. We have supported operator NIS compliance since the first directive; detection, evidence and reporting are the operational core of it.
TSA Security DirectivesUS surface transportation requirements for network segmentation, monitoring and incident response capability. Security Gateway, Delta and our managed monitoring cover them.
EU Cyber Resilience ActProduct security obligations for suppliers: secure development, vulnerability handling and update capability. See our responsible disclosure policy and signed-update lifecycle.
UK NCSC CAF · NIST CSF · AS 7770National frameworks we map to for UK, US and Australian operators. Same products, different paperwork, and we've done the paperwork before.
Product mapping

Which Product Answers Which Requirement

Segmentation & zone enforcementSecurity Gateway: IEC 62443-3-2 zones & conduits, TS 50701 architecture, TSA segmentation requirements.
Intrusion detection & monitoringDelta: the SL2+ detection requirement, NIS2 detection & reporting, TSA monitoring expectations.
Access control & maintenance integrityDigital Maintenance Gateway: MFA, audited access and code-signed software distribution from a wayside repository, synchronised to the train with software validation.
Asset inventory & configurationEcho: the asset visibility every framework starts with; configuration drift evidence.
Evidence, reporting & responseDashboard + optional managed monitoring: audit-ready records and analyst review where contracted.

Need the detailed control-by-control matrix for a tender response? Ask us. We maintain mappings for TS 50701, IEC 62443-3-3/-4-2 and TSA directives.

Management systems

Independently Audited

Our management systems are independently audited and certified to ISO 9001, ISO 14001 and ISO 27001.

From framework to fitted fleet

Talk to our engineering team

Bring your programme requirements, fleet architecture and risk assessment, including any penetration-test findings. We help train builders meet their operators’ specifications and help operators plan security improvements to existing fleets.

Request a demo Explore products