IEC 63452
IEC 63452 is the international standard for railway cybersecurity, published in 2025, evolving the earlier CENELEC TS 50701. It applies the IEC 62443 approach across the railway lifecycle (risk assessment, zoning, security requirements and operations) for signaling, rolling stock and fixed installations.
How it works
IEC 63452 adapts IEC 62443 to the railway context. It maps cybersecurity activities onto the rail system lifecycle defined in EN 50126, from concept and risk assessment through zoning, requirement specification, implementation, integration, operation and decommissioning. It addresses how security and safety processes interact, including how to handle security-related changes to safety-certified systems.
The standard covers all railway subsystems, including signaling, rolling stock, fixed installations and telecommunications, and provides guidance on security levels, threat and risk assessment, and operational security management.
Why it matters for security
IEC 63452 gives rail operators and suppliers a single, international reference for what good cybersecurity practice looks like across the asset lifecycle. Regulators and tenders increasingly reference it, so demonstrating alignment through continuous risk assessment, zoning validation and operational monitoring is becoming a procurement and compliance expectation.
Related solution
Supporting compliance with TS 50701 / IEC 63452
Lifecycle security: understanding system behavior, identifying deviations and maintaining traceability.
See the solution →

