Cybersecurity standards and supply chain management for rail
Rail networks are a part of critical infrastructure and must be protected against cyberthreats. That’s why we are committed to setting the benchmark for cybersecurity leadership with trained personnel, secure products and solutions, as well as certified security processes over the product lifecycle. Mature processes and supply chain management are key to our cybersecurity approach.

Rail networks are a part of critical infrastructure and must be protected against cyberthreats. That’s why we are committed to setting the benchmark for cybersecurity leadership with trained personnel, secure products and solutions, as well as certified security processes over the product lifecycle. Mature processes and supply chain management are key to our cybersecurity approach.
Our approach to cybersecurity
Leading the market in security compliance
We are one of the most certified railway vendors worldwide. Our certification scheme covers both processes and selected products, continuously expanding to meet emerging regulatory requirements. Certificates are issued by leading institutes such as TÜV Süd and DNV.
Our process system is based on organizational maturity and risk management, with comprehensive risk assessment and treatment capabilities. We adhere to ISO 27001 controls for IT systems with all headquarters maintaining certified information security management systems. For operational technology we are industry leaders in IEC 62443 certifications. Our comprehensive security program spans the entire lifecycle—from products and solutions to integration, maintenance and support services.
We ensure compliance with key cybersecurity standards and regulations such as IEC 62443, CRA, and NIS 2 through secure-by-default measures and optional enhanced protections.
Our certifications

Information Security Management System (ISMS)
Achieving the ISO27001 certification signifies that an organization has established and maintains a robust Information Security Management System (ISMS). This internationally recognized standard demonstrates a systematic and rigorous approach to managing sensitive company and customer information. Ultimately, it builds trust with stakeholders by proving a commitment to protecting data confidentiality, integrity, and availability.

Security program for rolling stock blueprint
Our rolling stock cybersecurity framework includes a comprehensive lifecycle risk assessment and management strategy. The IEC 62443-2-4 certification, known as the security program, validates the security of our integration process, covering the entire system lifecycle and all risk management aspects.
Technical validation for our blueprint architecture is provided by the IEC 62443-3-3 certification, which confirms the security capabilities of our rolling stock. This architecture separates train operator and train control networks, while also including other measures to protect train access.

Secure products
Key products like the CoreShield DCU are part of our IEC 62443 4-2 certification and compliance strategy. The CoreShield DCU is a passive network terminal for one-directional data transfer. It blocks any attempts to send data through the DCU into the critical network and protects the network from the outside. The CoreShield DCU is IEC 62443-4-1 and IEC 62443-4-2 certified.

Train IT Security Gateway
The Train IT Security Gateway is a firewall with an application layer gateway and intrusion detection capabilities to securely separate onboard networks. It is developed by Siemens Mobility Rolling Stock and has been certified by TÜV SÜD according to IEC 62443-4-1 & 4-2 since 2021.

Secure research and development process in rolling stock
A secure research and development process is used within Siemens Mobility Rolling Stock to develop secure onboard components and IT/OT systems (e.g., the Train IT Security Gateway). It has been certified by TÜV SÜD according to IEC 62443-4-1 since 2021.

Secure product development lifecycle process for rail infrastructure
We follow an established and IEC 62443 4-1-certified Secure Development Process for development and lifecycle management across all major development sites globally.
Ensuring the integrity of the supply chain
When vetting a supplier, Siemens Mobility assigns each supplier a criticality level: low, medium or high. This criticality level also decides how their cybersecurity capabilities are verified:
- Low criticality suppliers must declare their compliance with baseline requirements, e.g. by accepting terms and conditions
- Medium criticality suppliers must complete a self-assessment questionnaire
- High criticality suppliers must provide evidence that they meet the requirements
Used in the assessment of suppliers are lists of controls, lists of supplies and scope of delivery as well as documents from independent, accredited certifying bodies such as checklists and certifications.
How we assess the cybersecurity levels of our suppliers
There are three different levels of assessment and validating the cybersecurity capabilities of a supplier. All of these might be used in the process of selecting and working with a supplier.

1. Generic cyber capability assessment
Generic assessments can take the form of certification, self-assessments by the supplier through questionnaires, for example the Security Supplier Questionnaire, or visits or remote assessments by Siemens Mobility.

2. Contractual agreements
The adherence to cybersecurity criteria shall be fixed in contract terms, depending on the requirements of the Siemens Mobility customer, regulatory needs and internal baseline or comprehensive clauses. These contracts can also define a target profile, and the measures a supplier will need to take to reach the necessary level of cybersecurity capabilities.

3. Measurements of cybersecurity capabilities achieved
Suppliers are tested on whether they have achieved the agreed-upon cyber capabilities with a range of measures including security tests as well as documentation and/or demonstration of their technical capabilities.
Additional elements of supply chain management
Open source is another way we practice supply chain integration. In combination with Software Bill of Materials (SBOM), open source greatly enhances transparency and enable a faster decision making on vulnerability handling.
At Siemens Mobility, we require SBOMs – a list that describes the make-up of software components – from suppliers. SBOMs allow for a faster risk assessment and improve incident and vulnerability handling. Thanks to an SBOM exchange mechanism, all relevant parties receive the information they need in the respective contractual framework.

Collaborating with Siemens
Want to work with Siemens Mobility?
Learn more about the cybersecurity guidelines and requirements for our business partners.

Conditions of Purchase
Our Conditions of Purchase outline the rights of Siemens, supplier duties as well as warranty questions and timeframes for orders and acceptance.

Cybersecurity standards and certificates at Siemens AG
For industrial facilities, cybersecurity is key to protect important assets and data. Siemens offers both built-in protection for their products and solutions as well as cybersecurity services for your industry.

