Software Standards for Railways is a hot topic. According to a survey published by Fortune Business Insights, the Railway Signalling System market is predicted to grow at a CAGR of 5.2 per cent to USD 11273.2 million by 2027. And another estimate suggests that the demand for rolling stock applications is expected to reach USD 52.92 billion by 2027, with a CAGR of 10.4% over the forecast period. With the increasing level of adoption of embedded software, IoT, AI, and Industry 4.0 in railway applications, safety and security are becoming a concern. One of the finest strategies to address these issues is standards-driven design and development.
This blog discusses software standards for railways – safety standards such as EN 50128 and EN 50657, and cybersecurity standards including CLC/TS 50701:2021, IEC 62443, and AS 7770.
EN 50128 is perhaps the best known software standards for railways. It was derived from IEC 61508 (Functional Safety of E/E/PE electronic safety-related systems) and was prepared by the technical committee CENELEC TC 9X for railways. EN 50128 focuses on methods to provide software (including application programming, operating system, support tools, and firmware) for railway applications to meet the demand for safety integrity. It details the following software requirements aimed at railway control and protection applications.
These requirements are mapped against five software integrity levels (0-4), where SIL 0 is least critical and SIL 4 is most critical. The higher the risk resulting from software failure, the higher the software safety integrity level.
EN 50657 is similar in nature to EN 50128. EN 50128 is focused on software for railway control and protection systems, and the EN 50657 standard fulfils a similar role the development of software for use in rolling stock applications.
This standard specifies the process and technical requirements for developing software for programmable electronic systems for rolling stock applications. It applies exclusively to software and the interaction between software and the system of which it is part. Its content includes:

In the rail and GTS industry, the evolution from closed, wired isolated networks to open, interconnected networks has led to a new generation of threats. EN 50128 and the EN 5012x series only deal with cybersecurity indirectly (when such threats have implications for safety), and they provide no specific guidance on how to address them. For that reason, many GTS and rail projects have specified adherence to the IEC 62443 standard.
IEC 62443 is a series of standards for Cyber Security of Industrial Automation & Control Systems (IACS). IEC 62443-4-1 focuses on secure product development lifecycle requirements. It defines general principles, maturity model, security management lifecycle requirements, secure by design, secure implementation, security verification & validation testing, management of security-related issues, security update management, security guidelines, and more, along with rational and supplement guidance.
June 2021 saw the publication of CLC/TS 50701, “Railway applications – Cybersecurity” which defines requirements and recommendations for cybersecurity within the railway sector. CLC/TS 50701 aims to ensure that bad actors cannot compromise the RAMS characteristics of railway systems. The security models, the concepts, and the risk assessment process it describes are based on or derived from IEC 62443 series standards (above), adapted to a rail-specific context. CLC/TS 50701 covers several key topics, the most relevant here being cybersecurity during a railway application life cycle.
CLC/TS 50701 is applicable to both safety and non-safety-related systems, and accommodates the use of industrial COTS products compliant with the ISA/IEC 62443 series of standards. It provides guidance & specifications on how cybersecurity can be managed in the context of EN 5012x lifecycle processes. Its content includes:
Indian Railways has defined RDSO/SPN/144/2014 for Safety & Reliability Requirement of Electronic Signaling Equipment by RDSO where Clause 7.0 defines Software Requirements. Additionally, ELRS/SPEC/SI/0015 defines Reliability of Electronics used in Rolling Stock Application where Clause 8.0 defines Software Requirements.
AS7770 is an Australian RISSB Standard, which defines Rail Cybersecurity requirements for rail transport operators (RTOs) to manage cyber security risk on the Australian railway network, where Clause 3 protects Rail Control Systems.
Although not a standard, the Railway Cybersecurity report (November 2020) from the European Union Agency for Cybersecurity (ENISA) is also worthy of note. It covers cybersecurity challenges, measures (Governance, Ecosystem, Defence, and Resilience), and cybersecurity in ERTMS (The European Railway Traffic Management System). ERTMS (Train Control System + Global System for Mobile Communications – Railways) deals with signalling and speed control.
Reference:
Email: info@ldra.com
EMEA: +44 (0)151 649 9300
USA: +1 (855) 855 5372
INDIA: +91 80 4080 8707