top of page

IEC 63452 and Railway Cybersecurity Regulations: What Rail Organisations Need to Know for 2026–2027

Sep 2
7 min read

Cybersecurity in rail is changing quickly. Over the next couple of years, rail organisations will have several new railway cybersecurity standards and regulations to keep track of. IEC 63452 is on the way, the UK’s Cyber Security and Resilience Bill is progressing through Parliament, and parts of the EU Cyber Resilience Act will start to apply from September 2026.


Together, these developments are changing the railway cybersecurity landscape, particularly for organisations managing complex rail OT cybersecurity environments, legacy systems, long asset lifecycles and equally complex supply chains.


The good news is that preparing for IEC 63452 and changing railway cybersecurity regulations isn’t about throwing away everything you’re already doing and starting again.


A lot of the work rail organisations have already done around risk assessment, asset management, CLC/TS 50701, supplier assurance and OT security will still matter. The challenge is understanding what’s changing, when it’s changing and where you may need to adapt.


So, let’s break it down, shall we?


What Is IEC 63452 and How Does It Affect Railway Cybersecurity Regulations?

IEC 63452 is an upcoming international cybersecurity standard specifically for the railway industry. Its official title is Railway Applications – Cybersecurity, and it builds on existing rail cybersecurity work while drawing on principles from the IEC 62443 series used across industrial automation and control systems.

As of August 2026, it hasn't been published yet. If you've been working with CLC/TS 50701, IEC 63452 is one you'll want on your radar.


The current indicative timeline points towards September 2026, although that date could still move. That's why we wouldn't recommend treating September as a hard compliance deadline just yet. Your own rail timeline already marks the date as indicative and subject to change.


So, what’s actually changing?


This is where it gets more interesting. IEC 63452 isn’t simply another cyber standard to add to the compliance folder. Built upon the existing TS 50701 Railway Application Cybersecurity, this new standard provides an objective means to complete Cyber activities for Railway Systems Engineering. 


Rail systems can stay operational for decades. During that time, equipment gets upgraded, software changes, suppliers changes, new connections are introduced and legacy technology has to coexist with newer digital systems.


Cyber risk changes along with all of that. That’s why the focus on managing cybersecurity throughout the railway lifecycle matters. And this isn’t completely new territory for the UK railway. We expect cyber risks around command, control and signalling systems to be considered during specification, design, procurement and operation.


IEC 63452 gives the industry another reason to look at cybersecurity as an ongoing engineering and operational issue, rather than a security exercise carried out once and filed away. It provides a manner in whether your part of the Supply-Chain, an OEM or Operator/Infrastructure Manager to manage Railway Assets inline with the typical Engineering V-lifecycle, e.g. aligned to BS EN 50126 (find standard name). 


What to expect from the industry is that once formally approved for international use, every procurement contract, engineering change will commence to start referencing IEC 63452 and therefore users in the industry will need to be proactive in Cybersecurity in respect to Railway Systems Engineering aspects. 


EU Cyber Resilience Act(CRA) Reporting Obligation

IEC 63452 is not the only cyber development arriving around September. From 11th of September 2026, reporting obligations under the EU Cyber Resilience Act (CRA) begin to apply. 


The CRA focuses on products with digital elements placed on the EU market and introduces cybersecurity responsibilities for manufacturers.


From September 2026, manufacturers covered by the CRA must report certain actively exploited vulnerabilities and severe incidents affecting the security of their products.


The initial early warning must be submitted within 24 hours of becoming aware of the issue, followed by a fuller notification within 72 hours.


IEC 63452 and changing railway cybersecurity regulations

What is the connection between Cyber Resilience Act (CRA) with rail?

We’re glad you asked! This does not mean that every UK rail organisation suddenly falls under the CRA. The answer depends on what an organisation does, the products involved and where those products are placed on the market.


But rail has a highly international supply chain. Rolling stock, signalling technology, software, communications equipment, control systems and other digital products can be developed, manufactured and supplied across multiple countries.


That means manufacturers supplying relevant products into the EU market need to understand whether the CRA applies to them.


It also matters from a procurement perspective.


When purchasing digital products or systems, rail organisations increasingly need to understand how their suppliers approach questions such as:

  • How are vulnerabilities managed?

  • How quickly will we be told about a serious security issue?

  • How are software and firmware updates handled?

  • How long will the product receive security support?

  • What happens when a component becomes obsolete?

These questions become important in rail, where assets may remain operational for decades.


CRA 2027 Update

The wider requirements of the Cyber Resilience Act become applicable from 11th of December 2027. The CRA puts greater emphasis on cybersecurity throughout the lifecycle of products with digital elements, including how products are designed, developed, maintained and supported.


For rail, that reinforces something that should already be familiar: Cybersecurity needs to start before a system enters service.


Security requirements should be considered when equipment is being specified and procured, not once it has already been installed. That means procurement, engineering and cybersecurity teams increasingly need to work together. A technically capable product that cannot be securely maintained for the expected life of the asset can create problems years down the line.


For rail systems with long operational lifecycles, understanding the supplier’s security support, vulnerability-management process and product roadmap can therefore be just as important as understanding the technology itself.


UK Rail Cyber Regulation Update

The UK is also updating its own cybersecurity framework through the Cyber Security and Resilience (Network and Information Systems) Bill.


The Bill was introduced in November 2025 and is intended to update and expand the existing UK NIS framework. Transport is already part of the UK’s essential-services landscape, but modern rail does not operate alone.


Operators increasingly depend on software providers, cloud platforms, IT services, managed security providers, system integrators and specialist suppliers. That wider ecosystem is receiving more regulatory attention.


And what about UK rail implementation?

IEC 63452 gives us the international picture, but UK rail will also need to consider how those principles are applied in practice. This is where the upcoming RSSB 2707 standard, Integration, Implementation and Management of Operational Technology, comes in.


Currently aiming for publication around July 2027, the standard is expected to support the implementation and use of IEC 63452 within the UK rail environment, whilst aligning OT cybersecurity with the requirements and safety-management approach under ROGS.


For UK rail organisations, this is an important part of the picture. IEC 63452 will provide the wider international cybersecurity framework, whilst RSSB 2707 is expected to help translate that into a more UK-specific rail context.


The July 2027 date is still an expected release date, so organistions should continue to follow RSSB updates as the standard develops.


What does the 2026-2027 timeline look like?

When

What’s happening

Why it matters

2026

UK Cyber Security and Resilience Bill

Proposed changes to the UK NIS framework, including qualifying MSPs and greater focus on critical suppliers. 

Around September 2026*

IEC 63452

Indicative publication timeframe for the forthcoming international railway cybersecurity standard.

11th of September 2026

EU CRA reporting requirements

Reporting begins for certain actively exploited vulnerabilities and severe security incidents affecting covered products. 

2026 onwards

Cyber becomes increasingly lifecycle-focused 

Greater attention on cyber risk across design, procurement, operation, suppliers and system change. 

Around July 2027*

RSSB 2707: Integration, Implementation and Management of Operational Technology 

Expected to support the implementation of IEC 63452 within UK rail and align OT cybersecurity with the ROGS safety-management context. 

11th of December 2027

Wider EU CRA requirements 

Wider cybersecurity requirements for covered products with digital elements become applicable. 

**IEC 63452 and RSSB 2707 publication timeframes are indicative and may change. 


There is one important thing to remember when looking at this timeline: These are not all the same type of requirement.


IEC 63452 is a standard currently in development. The Cyber Security and Resilience Bill is proposed UK legislation. The Cyber Resilience Act is already EU law with defined application dates.

Understanding those differences is important when deciding what needs immediate action and what needs continued monitoring.


Cyber and safety can’t sit in separate boxes

Rail OT cybersecurity is not the same as protecting a typical office IT environment. It’s more complicated than that. Protecting information still matters. But in an operational railway environment, availability, system integrity, operational continuity and safety matter just as much. 


A cybersecurity decision that makes perfect sense in corporate IT may not be appropriate for a system that needs to remain available to support railway operations. That is why cyber risk needs input from more than just the cybersecurity team.


In practice, good rail cybersecurity increasingly requires collaboration between:

Cybersecurity, Engineering, Operations, Safety, Procurement, Supply Chain, and Leadership.


What should rail organisations do to prepare now?

There is no need to wait for every standard and regulation to be finalised before doing anything.

A lot of the preparation comes back to good OT cybersecurity fundamentals: stay informed. Keep track of IEC 63452 as it moves towards publication and understand how the final requirements may affect your organisation. 


Getting ready for IEC 63452 and what comes next

There is a lot happening in rail cybersecurity over the next couple of years. IEC 63452, the Cyber Resilience Act and changes to UK cyber regulation all have different scopes and timelines, but they point in a similar direction.


Cybersecurity is becoming more closely connected to how railway systems are designed, purchased, operated, maintained and supported throughout their lifecycle.

For organisations managing complex IT and OT environments, working out where to start can be the difficult part.


That is where we can help.


At Complete Cyber, we work across IT and OT cybersecurity, including complex railway environments. So we understand how challenging it can be to keep up with evolving standards, regulations and cyber risks.

We’ve worked across the rail industry for the past 12 years, supporting SMEs, large enterprises and major rail and infrastructure projects, including HS2. With 30+ years of combined cybersecurity experience, our team understands the challenges that come with protecting complex environments, from legacy OT and long asset lifecycles to supply-chain risk and changing compliance requirements.


We can help you understand your current cyber posture, identify where gaps may exist and work out what upcoming standards and regulatory changes, including IEC 63452, could mean for your organisation.

Not sure where to start? Book a meeting with our experts and let’s get you ready for what’s next!



bottom of page