New Compliance Support for Cybersecurity in the Swiss Railway Sector
Hamburg, August 2026 – With the integration of the “Railway Cybersecurity” Directive (RL CySec-Rail), CRISAM® is expanding its multi-compliance support for operators of critical infrastructure. Railway companies can now assess the regulatory requirements of the Swiss Federal Office of Transport in a structured manner, map them to existing security standards, and document their implementation in a transparent and traceable way.
RL CySec-Rail has been in force since 1 July 2024. It specifies the requirements for information security management systems in the Swiss railway sector and also serves as a basis for the supervisory activities of the Federal Office of Transport. It applies to railway infrastructure managers and railway undertakings. Its scope covers the processes, information systems, and data networks in use – from traditional IT and Operational Technology to ICT systems in railway vehicles.
At the heart of the directive is a risk-based information security management system. The seven overarching minimum requirements cover:
These requirements are complemented by 29 organisational and technical controls. They address areas including asset and supplier management, information security in projects, cloud usage, security monitoring, incident management, business continuity, access management, vulnerability management, and network segmentation.
Particular attention is given to requirements for Operational Technology and railway vehicles. In these areas, security measures must be closely aligned with safety management. This reflects the specific operating conditions of the railway sector: high availability requirements, long system life cycles, limited opportunities for updates, and the close relationship between cybersecurity and functional safety.
RL CySec-Rail draws on a range of established standards and regulatory frameworks. These include, in particular, ISO/IEC 27001 and ISO/IEC 27002, the NIST Cybersecurity Framework 2.0, CLC/TS 50701, IEC 62443, and Commission Delegated Regulation (EU) 2018/762.
This is exactly where CRISAM® Multi-Compliance comes into play: requirements from different frameworks that address the same underlying topics are linked with one another. Existing assessments, controls, measures, and evidence can therefore also be used to demonstrate compliance with CySec-Rail requirements. This reduces duplicate work and allows existing ISMS structures to be reused consistently.
Instead of managing regulatory requirements in separate lists and documents, organisations gain a consistent view of compliance, risks, and implementation measures. Responsibilities, deviations, and required actions remain transparent and can be evaluated in a way that is tailored to the relevant target groups.
With CRISAM®, the level of compliance with RL CySec-Rail can be systematically assessed. Deviations can be evaluated, measures assigned, and their implementation tracked. The corresponding evidence is centrally available for internal audits, management reporting, and regulatory reviews.
The binding implementation timeline required by the directive can also be managed transparently. This turns regulatory requirements into a traceable improvement process – from the initial gap analysis and risk treatment through to regular reviews of effectiveness.
By integrating RL CySec-Rail into CRISAM® Multi-Compliance, we support railway companies in efficiently incorporating regulatory requirements into their existing information security and risk management processes.
Would you like to find out how your existing assessments and evidence can be used for CySec-Rail? Talk to our team. We will be happy to show you how to make your current implementation status transparent, leverage synergies with existing standards, and prepare for audits in a structured manner.
CySec-Rail can be implemented efficiently when requirements, risks, measures, and evidence are not managed in isolation, but as part of an integrated information security management system.
Would you like to integrate CySec-Rail into your existing ISMS in a structured way?
Explore our ISMS-module and discover how CRISAM® helps you manage requirements centrally, leverage synergies with existing standards, and prepare for audits in a structured manner.
You are currently viewing a placeholder content from Facebook. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from reCAPTCHA to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Hubspot Embedded Content. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from HubSpot. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Hubspot Meetings. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Instagram. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from X. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More Information