Cybersecurity standards and supply chain management for rail

Rail networks are a part of critical infrastructure and must be protected against cyberthreats. That’s why we are committed to setting the benchmark for cybersecurity leadership with trained personnel, secure products and solutions, as well as certified security processes over the product lifecycle. Mature processes and supply chain management are key to our cybersecurity approach.

mobility-cybersecurity-standards-keyvisual

Rail networks are a part of critical infrastructure and must be protected against cyberthreats. That’s why we are committed to setting the benchmark for cybersecurity leadership with trained personnel, secure products and solutions, as well as certified security processes over the product lifecycle. Mature processes and supply chain management are key to our cybersecurity approach.

Our approach to cybersecurity

We take a systematic approach to IT and OT security. The first pillar is the security of the system itself. We classify our products and processes according to risk, and implement procedures and security measures appropriate for the risk level. The second pillar is a secure supply chain. A Siemens Mobility supplier must prove their cybersecurity capability, and security requirements are embedded in our contracts with them. In case of incidents like a security breach or responsible disclosure, managed transparency is practiced through structured public or confidential reporting and controlled data access.

Leading the market in security compliance

We are one of the most certified railway vendors worldwide. Our certification scheme covers both processes and selected products, continuously expanding to meet emerging regulatory requirements. Certificates are issued by leading institutes such as TÜV Süd and DNV. 

Our process system is based on organizational maturity and risk management, with comprehensive risk assessment and treatment capabilities. We adhere to ISO 27001 controls for IT systems with all headquarters maintaining certified information security management systems. For operational technology we are industry leaders in IEC 62443 certifications. Our comprehensive security program spans the entire lifecycle—from products and solutions to integration,  maintenance and support services.

We ensure compliance with key cybersecurity standards and regulations such as IEC 62443, CRA, and NIS 2 through secure-by-default measures and optional enhanced protections.

Our certifications

smo-certificate-tuv

Information Security Management System (ISMS)

Achieving the ISO27001 certification signifies that an organization has established and maintains a robust Information Security Management System (ISMS). This internationally recognized standard demonstrates a systematic and rigorous approach to managing sensitive company and customer information. Ultimately, it builds trust with stakeholders by proving a commitment to protecting data confidentiality, integrity, and availability.

smo-tuv-integration-service-provider-logo-

Security program for rolling stock blueprint

Our rolling stock cybersecurity framework includes a comprehensive lifecycle risk assessment and management strategy. The IEC 62443-2-4 certification, known as the security program, validates the security of our integration process, covering the entire system lifecycle and all risk management aspects.

Technical validation for our blueprint architecture is provided by the IEC 62443-3-3 certification, which confirms the security capabilities of our rolling stock. This architecture separates train operator and train control networks, while also including other measures to protect train access.

smo-tuv-iacs-component

Secure products

Key products like the CoreShield DCU are part of our IEC 62443 4-2 certification and compliance strategy. The CoreShield DCU is a passive network terminal for one-directional data transfer. It blocks any attempts to send data through the DCU into the critical network and protects the network from the outside. The CoreShield DCU is IEC 62443-4-1 and IEC 62443-4-2 certified.

smo-tuv-iacs-component

Train IT Security Gateway

The Train IT Security Gateway is a firewall with an application layer gateway and intrusion detection capabilities to securely separate onboard networks. It is developed by Siemens Mobility Rolling Stock and has been certified by TÜV SÜD according to IEC 62443-4-1 & 4-2 since 2021.

smo-tuv-secure-product-logo

Secure research and development process in rolling stock

A secure research and development process is used within Siemens Mobility Rolling Stock to develop secure onboard components and IT/OT systems (e.g., the Train IT Security Gateway). It has been certified by TÜV SÜD according to IEC 62443-4-1 since 2021.

smo-tuv-secure-product-logo

Secure product development lifecycle process for rail infrastructure

We follow an established and IEC 62443 4-1-certified Secure Development Process for development and lifecycle management across all major development sites globally.

Ensuring the integrity of the supply chain

When vetting a supplier, Siemens Mobility assigns each supplier a criticality level: low, medium or high. This criticality level also decides how their cybersecurity capabilities are verified:

  • Low criticality suppliers must declare their compliance with baseline requirements, e.g. by accepting terms and conditions
  • Medium criticality suppliers must complete a self-assessment questionnaire
  • High criticality suppliers must provide evidence that they meet the requirements

Used in the assessment of suppliers are lists of controls, lists of supplies and scope of delivery as well as documents from independent, accredited certifying bodies such as checklists and certifications.

How we assess the cybersecurity levels of our suppliers

There are three different levels of assessment and validating the cybersecurity capabilities of a supplier. All of these might be used in the process of selecting and working with a supplier.

icon-notebook-screen

1. Generic cyber capability assessment

Generic assessments can take the form of certification, self-assessments by the supplier through questionnaires, for example the Security Supplier Questionnaire, or visits or remote assessments by Siemens Mobility.

icon-contract

2. Contractual agreements

The adherence to cybersecurity criteria shall be fixed in contract terms, depending on the requirements of the Siemens Mobility customer, regulatory needs and internal baseline or comprehensive clauses. These contracts can also define a target profile, and the measures a supplier will need to take to reach the necessary level of cybersecurity capabilities.

icon-shield

3. Measurements of cybersecurity capabilities achieved

Suppliers are tested on whether they have achieved the agreed-upon cyber capabilities with a range of measures including security tests as well as documentation and/or demonstration of their technical capabilities.

Additional elements of supply chain management

Open source is another way we practice supply chain integration. In combination with Software Bill of Materials (SBOM), open source greatly enhances transparency and enable a faster decision making on vulnerability handling.

At Siemens Mobility, we require SBOMs – a list that describes the make-up of software components – from suppliers. SBOMs allow for a faster risk assessment and improve incident and vulnerability handling. Thanks to an SBOM exchange mechanism, all relevant parties receive the information they need in the respective contractual framework.