Crisam Logo
  • CRISAM®
    CRISAM®
    • What is CRISAM®?
    • Method
    • Content
    • Customers
    • Continuing education
    • Webinars
    • Events
  • Areas of application
    Areas of application
    • Information Security Management
    • Integrated Risk Management
    • ESG
    • CRISAM.AI
    • CRISAM® AI Risk Intelligence
    • CRISAM® AI Risk Assistance
    • DORA
    • Data protection management
    • Internal Control System & Audit Management
    • Compliance Management
    • Business Continuity Management
    • Tax Compliance Management System
    • CRISAM® Compliance powered by Deloitte
    • Global Internal Audit Standards
    • Project Risk Management
    • Legal register
    • Approvals & Disclosures Workflow Software
    • Conflicts of Interest Software
    • CRISAM® Legal Hold Software
  • Industries
    Industries
    • Automobile
    • Energy
    • Manufacturing
    • Finance
    • Trade
    • Real estate & construction industry
    • Health
    • Broadcasting & Telecommunications
    • Technology
    • Transportation & Logistics
  • More
    More
    • Download Center
    • CRISAM® Academy
    • Webinars
    • News
    • Jobs
    • CRISAM® Partner
    • Trustcenter
    • Contact
  • en
    • de
Request
  • Sprache
    • en-gb
    • de
  • CRISAM®
    • What is CRISAM®?
    • Method
    • Content
    • Customers
    • Continuing education
    • Webinars
    • Events
  • Areas of application
    • Information Security Management
    • Integrated Risk Management
    • ESG
    • CRISAM.AI
    • CRISAM® AI Risk Intelligence
    • CRISAM® AI Risk Assistance
    • DORA
    • Data protection management
    • Internal Control System & Audit Management
    • Compliance Management
    • Business Continuity Management
    • Tax Compliance Management System
    • CRISAM® Compliance powered by Deloitte
    • Global Internal Audit Standards
    • Project Risk Management
    • Legal register
    • Approvals & Disclosures Workflow Software
    • Conflicts of Interest Software
    • CRISAM® Legal Hold Software
  • Industries
    • Automobile
    • Energy
    • Manufacturing
    • Finance
    • Trade
    • Real estate & construction industry
    • Health
    • Broadcasting & Telecommunications
    • Technology
    • Transportation & Logistics
  • More
    • Download Center
    • CRISAM® Academy
    • Webinars
    • News
    • Jobs
    • CRISAM® Partner
    • Trustcenter
    • Contact
  • Request

New Compliance Support for Cybersecurity in the Swiss Railway Sector

CySec-Rail Now Integrated into
CRISAM® Multi-Compliance

Hamburg, August 2026 – With the integration of the “Railway Cybersecurity” Directive (RL CySec-Rail), CRISAM® is expanding its multi-compliance support for operators of critical infrastructure. Railway companies can now assess the regulatory requirements of the Swiss Federal Office of Transport in a structured manner, map them to existing security standards, and document their implementation in a transparent and traceable way.

RL CySec-Rail has been in force since 1 July 2024. It specifies the requirements for information security management systems in the Swiss railway sector and also serves as a basis for the supervisory activities of the Federal Office of Transport. It applies to railway infrastructure managers and railway undertakings. Its scope covers the processes, information systems, and data networks in use – from traditional IT and Operational Technology to ICT systems in railway vehicles.

Seven ISMS Requirements and 29 Basic Measures

At the heart of the directive is a risk-based information security management system. The seven overarching minimum requirements cover:

  • Information security strategy
  • Roles and responsibilities
  • Policies and organisation
  • Regular reviews and audits
  • Continuous improvement
  • Documentation
  • Risk assessment and risk treatment

These requirements are complemented by 29 organisational and technical controls. They address areas including asset and supplier management, information security in projects, cloud usage, security monitoring, incident management, business continuity, access management, vulnerability management, and network segmentation.

Particular attention is given to requirements for Operational Technology and railway vehicles. In these areas, security measures must be closely aligned with safety management. This reflects the specific operating conditions of the railway sector: high availability requirements, long system life cycles, limited opportunities for updates, and the close relationship between cybersecurity and functional safety.

Assess Once, Demonstrate Compliance Multiple Times

RL CySec-Rail draws on a range of established standards and regulatory frameworks. These include, in particular, ISO/IEC 27001 and ISO/IEC 27002, the NIST Cybersecurity Framework 2.0, CLC/TS 50701, IEC 62443, and Commission Delegated Regulation (EU) 2018/762.

This is exactly where CRISAM® Multi-Compliance comes into play: requirements from different frameworks that address the same underlying topics are linked with one another. Existing assessments, controls, measures, and evidence can therefore also be used to demonstrate compliance with CySec-Rail requirements. This reduces duplicate work and allows existing ISMS structures to be reused consistently.

Instead of managing regulatory requirements in separate lists and documents, organisations gain a consistent view of compliance, risks, and implementation measures. Responsibilities, deviations, and required actions remain transparent and can be evaluated in a way that is tailored to the relevant target groups.

CySec

Audit-Ready for Management and Regulatory Oversight

With CRISAM®, the level of compliance with RL CySec-Rail can be systematically assessed. Deviations can be evaluated, measures assigned, and their implementation tracked. The corresponding evidence is centrally available for internal audits, management reporting, and regulatory reviews.

The binding implementation timeline required by the directive can also be managed transparently. This turns regulatory requirements into a traceable improvement process – from the initial gap analysis and risk treatment through to regular reviews of effectiveness.

Implement CySec-Rail Efficiently with CRISAM®

By integrating RL CySec-Rail into CRISAM® Multi-Compliance, we support railway companies in efficiently incorporating regulatory requirements into their existing information security and risk management processes.

Would you like to find out how your existing assessments and evidence can be used for CySec-Rail? Talk to our team. We will be happy to show you how to make your current implementation status transparent, leverage synergies with existing standards, and prepare for audits in a structured manner.

CySec

Let’s Stay in Touch

CySec-Rail can be implemented efficiently when requirements, risks, measures, and evidence are not managed in isolation, but as part of an integrated information security management system.

Would you like to integrate CySec-Rail into your existing ISMS in a structured way?

Explore our ISMS-module and discover how CRISAM® helps you manage requirements centrally, leverage synergies with existing standards, and prepare for audits in a structured manner.

Crisam - Andreas und Tim
Chart Diagramm

Entdecken Sie auch unsere CRISAM® / AWADO
Vor-Ort-Schulung!

Die CRISAM® / AWADO Vor-Ort-Schulung im GenoHotel Baunatal bietet praxisnahes Know-how zum Aufbau und Betrieb eines ISMS oder IRM – vermittelt von Experten aus der Praxis. Die Plätze sind begrenzt – sichern Sie sich jetzt Ihren Platz und bringen Sie Ihr Risikomanagement auf das nächste Level.

Hier registrieren

 

No risk - let's just stay in touch!

Telefonsymbol in grün für Kontaktaufnahme.
Phone

+43 732 601 216-0

Umschlag-Icon in grün, das den Versand von E-Mails symbolisiert.
E-Mail

office@crisam.net

Papierflieger in grün, der die Versandoption für E-Mails symbolisiert.
Newsletter

Register now

CRISAM GRC Software
Darstellung eines Trends im Risikomanagement

CALPANA business consulting GmbH

Blumauerstr. 45-47

4020 Linz, Austria

+43 732 601 216-0 sales@crisam.net

CALPANA business consulting Deutschland GmbH

Paul-Dessau-Str. 1

22761 Hamburg, Germany

+49 (40) 35 98 29 21 sales@crisam.net

CALPANA business consulting GmbH

Blumauerstr. 45-47

4020 Linz, Austria

+43 732 601 216-0 sales@crisam.net

CALPANA business consulting Deutschland GmbH

Paul-Dessau-Str. 1

22761 Hamburg, Germany

+49 (40) 35 98 29 21 sales@crisam.net
CRISAM®
  • What is CRISAM?
  • CRISAM® Method
  • CRISAM® Content
  • Customers
  • Continuing education
  • Webinars
  • Events
  • CRISAM® Academy
Operational area
  • Integrated Risk Management
  • Information Security Management
  • CRISAM.AI
  • CRISAM® AI Risk Intelligence
  • CRISAM® AI Risk Assistance
  • ESG
  • Data protection management
  • Internal Control System & Audit Management
  • Compliance Management
  • Business Continuity Management
  • Tax Compliance Management System
  • CRISAM® Compliance powered by Deloitte
  • Global Internal Audit Standards
  • Project Risk Management
  • Legal register
  • Approvals & Disclosures Workflow Software
  • Conflicts of Interest Software
  • CRISAM® Legal Hold Software
Industries
  • Automobile
  • Energy
  • Manufacturing
  • Finance
  • Health
  • Trade
  • Real estate & construction industry
  • Broadcasting & Telecommunications
  • Technology
  • Transportation & Logistics
More
  • Download Center
  • CRISAM® Academy
  • Webinars
  • CRISAM® Partner
  • Jobs
  • News
  • Trustcenter
  • Contact

© 2026 CALPANA business consulting GmbH. All rights reserved.

  • Imprint
  • Privacy
  • Trustcenter
linkedin
xing