Blog

NIS2 for Rail: Onboard and Trackside IoT Security

Written by IXT | 14. aug. 2026, 11:22:45

This article maps NIS2 Article 21(2) technical measures to the connectivity layer of a rail deployment. It covers the IP-connected onboard and trackside estate carried over public cellular: condition monitoring, diagnostic gateways, CCTV, passenger systems, trackside sensors, and remote maintenance access.

 

It does not cover GSM-R or the ETCS radio path. Those run under the ERTMS specifications and the relevant TSI, on dedicated railway spectrum and infrastructure, and they are a separate assurance problem. It does not claim that any product makes an operator NIS2-compliant. Most of the directive sits outside the network, but it is a support to help you on the way.

 

Each measure below is split three ways: what it requires, where the connectivity layer contributes, and what stays with the operator.

 

 

 

The compliance question rail operators are asking

Article 21(2) reads as though every asset is a managed endpoint. In an IT estate that holds up. Someone installs an agent, patches the operating system, and pulls telemetry back to a security operations centre. The measure and the mechanism line up.

 

An axle counter has no operating system. A brake sensor has no room for an agent. A CCTV recorder specified in 2011 has firmware its supplier stopped touching years ago. The measures still apply, but the mechanism everyone assumes behind them does not exist on these devices.

 

So the question is not whether Article 21(2) applies to onboard and trackside systems. It is which layer answers each measure once the device itself answers nothing.

 

Who is in scope

The NIS2 Directive lists transport in Annex I. Within transport, rail is named, and two entity types are identified: infrastructure managers within the meaning of Article 3(2) of Directive 2012/34/EU, and railway undertakings within the meaning of Article 3(1) of the same directive, including operators of service facilities.

 

Annex I entities above the large-enterprise thresholds fall in the essential entity tier, which carries proactive supervision. Medium-sized entities in the same sectors are important entities, supervised after an incident. Confirm which tier applies to you before scoping anything, because it changes what a national authority does with your evidence.

 

 

Why rail is harder than a fixed OT site

A substation or a factory has one network boundary, one set of physical access controls, and one maintenance regime. Rail has none of those properties.

 

The asset moves. A vehicle changes cell constantly, and changes mobile operator as it crosses borders and coverage gaps. Any control anchored to a static IP address or a fixed network location breaks on the first handover.

 

The device population is fixed for decades. Rolling stock service lives run far longer than the threat model the onboard devices were specified against. Firmware updates depend on a supplier who has moved on to the next platform.

 

Ownership is split. On one vehicle the traction supplier, the door supplier, the CCTV integrator, the passenger Wi-Fi provider and the depot maintainer each need to reach their own subsystem. Nobody owns the whole thing.

 

The devices run nothing. See what is Zero Trust for headless IoT devices.

 

 

Article 21(2)(a): risk analysis and information system security policies

What it requires. Policies on risk analysis and on the security of network and information systems.

 

Where the connectivity layer contributes. What the connectivity layer evidences against this measure is narrower than the clause: containment, so a security event in one part of the network does not reach the rest. A private APN through SecureNet removes the public internet from the path between vehicle and back office, with private IP addressing and direct routing into the operator's data centre or cloud. That is isolation. Inside the APN the fleet is still flat. Policy-based segmentation between individual devices contains a compromise to one camera on one vehicle and stops lateral movement to the next unit or into the depot network.

 

What stays yours. The risk assessment, the policy itself, the segmentation policy design, the threat model per subsystem, and segmentation of the back office systems the vehicles connect to.

 

 

Article 21(2)(b): incident handling

What it requires. Incident handling, against reporting obligations that begin with an early warning within 24 hours of becoming aware of a significant incident.

 

Where the connectivity layer contributes. Detection starts with knowing what normal traffic looks like. Real-time traffic mapping across every IXT-connected device shows which devices reach which destinations, and flags a deviation when a CCTV recorder starts talking to something it has never contacted. Article 23 gives you 24 hours for an early warning. A connectivity portal running a 24-48 hour data delay tells you nothing inside that window.

 

What stays yours. The incident response plan, the decision on what counts as significant, the reporting workflow to your national authority, and the people who run it at 3am.

 

Article 21(2)(d): supply chain security

What it requires. Security in the relationships with direct suppliers and service providers, including the access those suppliers hold.

 

Where the connectivity layer contributes. The default answer in rail is a VPN per supplier into the depot network or into an onboard gateway. That grants network reach far beyond the subsystem in question, and multiple supplier VPNs produce address conflicts. Privileged Remote Access replaces it with a browser session against one device, time-limited to an agreed maintenance window, recorded in full, and co-viewable by your own engineer. No client on the device, no routable path into the wider network. The mechanics are in how to grant OT vendor access without VPNs.

 

What stays yours. Supplier governance, contractual security obligations, the approval process for maintenance windows, and the decision about which supplier reaches what.

 

 

Article 21(2)(i) and (j): human resources security, access control, asset management and authentication

What it requires. Human resources security policies, access control policies and asset management, and where appropriate multi-factor or continuous authentication.

 

Where the connectivity layer contributes. Identity starts at the SIM. The network authenticates the subscriber identity before the device sends a packet. A Zero Trust layer in the network and cloud then checks each session against policy instead of trusting traffic because it arrived inside the APN. Each device receives least privileged access to the one application it needs. Asset management follows from the same place: a live inventory of every IXT SIM by vehicle, status, usage and country.

 

What stays yours. Human resources security, the access control policy, the identity lifecycle for engineers and depot staff, the asset register that maps SIM to vehicle to subsystem, and the decision on which systems justify stronger authentication.

 

 

Article 21(2)(f): assessing whether the measures work

What it requires. Policies to assess the effectiveness of the cybersecurity risk management measures, rather than measures that exist on paper.

 

Where the connectivity layer contributes. An audit trail of every device, every user and every third-party maintainer that reached a vehicle subsystem, with the actions taken in the session. Session recording turns a supplier's assurance about a maintenance visit into evidence an auditor reads.

 

What stays yours. Retention policy, the audit programme that reviews the evidence, and the internal reporting that closes findings.

 

 

Private APN, VPN and Zero Trust on a rail fleet

 

Requirement Private APN alone VPN over cellular Zero Trust in the network and cloud
Traffic off the public internet Yes No, encrypted across public infrastructure Yes, with private networking underneath
Works on a device that runs no client Yes No Yes
Restricts a device to one application No, flat network inside the APN No, broad network reach Yes, least privileged access
Contains a compromise to one vehicle No No Yes, policy-based segmentation
Shows what each device talks to No No Yes, for every IXT-connected device
Supplier access to one subsystem No No Yes, browser-based, time-limited, recorded
Session-level audit trail No Partial, gateway logs only Yes, session recording

 

 

What this architecture does not do

It does not write your risk documentation. It does not train depot staff. It does not patch onboard firmware or manage the devices. It does not replace a SIEM, a SOC or an incident response function. It does not extend to GSM-R, the ETCS radio path or anything under the ERTMS assurance regime. It certifies nothing.

 

IXT Zero Trust addresses NIS2 Article 21(2) technical controls at the connectivity layer. Everything else in the directive stays with the operator. The full mapping across NIS2 and the Cyber Resilience Act is in IXT Zero Trust and EU compliance.

 

 

 

Frequently asked questions

Is rail in scope for NIS2?

Yes. Transport sits in Annex I of the NIS2 Directive. Rail is named within it, covering infrastructure managers under Article 3(2) of Directive 2012/34/EU and railway undertakings under Article 3(1), including operators of service facilities, where size thresholds are met.

 

 

Does NIS2 apply to rolling stock or only to fixed infrastructure?

Both. Infrastructure managers and railway undertakings are listed separately, so an operator running services on someone else's track is in scope on its own account.

 

 

Does this replace GSM-R or ETCS security?

No. GSM-R and the ETCS radio path run under the ERTMS specifications and the relevant TSI, on dedicated railway infrastructure. The estate covered here is the IP-connected onboard and trackside devices carried over public cellular.

 

 

Does IXT Zero Trust make a railway undertaking NIS2-compliant?

No. It addresses the Article 21(2) technical controls at the connectivity layer. Risk documentation, incident response planning, staff training, human resources security, supplier governance and vulnerability handling stay with the operator.

 

 

How do you give a rolling stock supplier access to one train without a VPN?

The supplier opens a browser session brokered by the Zero Trust Exchange against a single device. The session is time-limited, recorded, and co-viewable. No client is installed on the device, and the supplier gets no routable path to anything else.

 

 

Where is enforcement applied, on the SIM or in the network?

In the network and cloud. The SIM identifies the device. Policy is keyed to that identity and enforced in the network and cloud, not on the SIM and not on the device.

 

 

Is this mapping usable in a tender response?

Check it against your own legal and compliance team's reading of the transposed national legislation in your jurisdiction first. The mapping describes technical controls, not a compliance opinion.

 

Where to start

List every IP-connected device on one vehicle class and one trackside route, then mark which of the Article 21(2) measures above your current connectivity answers. Most rail operators find access control and segmentation have nothing behind them, because the private APN was treated as the security layer when it is only the isolation layer.

 

Ask us how the Article 21(2) technical controls map to your fleet. Book a demo at ixt.io.