Standards status. EN 50159:2026 is published and defines the interface to applicable cybersecurity standards where unauthorised access to the transmission system is relevant. Projects should still verify the national adoption and contractual baseline before rebaselining an existing safety case.

Modern connectivity does not remove the end-to-end assurance problem

The European Union Agency for Railways has published its opinion and supporting specifications for FRMCS Version 2, reflecting the migration of railway communications toward 5G-based services. The capability brings major operational benefits, but it also expands the set of telecom components and service relationships on which railway applications depend.

The critical distinction is between transport and authority. A mobile network can provide authenticated connectivity, quality of service and operational monitoring, but the railway application still needs its own controls to determine whether a message is authentic, current and acceptable for the safety or operational context.

Treating network membership as proof of application trust would recreate the same implicit-trust problem seen elsewhere in OT, only at a much larger and more dynamic scale.

What this diagram shows

The trust boundary should remain end to end between railway applications even when safety-relevant traffic crosses a mobile network operated as external transport.

Trust and authority pathFRMCS Should Treat the Mobile Network as Transport, Not as Trust
Trust pressure / decision point Governed state or evidence domain
Authority and evidence flow
Evidence domainRailway applicationSafety/operational logic defines authority
Evidence domainFRMCS interfaceRail-specific interface carries protected information
Trust pressure5G / transportMobile network provides transport service
Evidence domainRemote endpointAnother trusted railway function receives the message
Decision gate

Can the railway application remain safe if the communications transport is degraded or untrusted?

YESThe decision can rely on bounded, auditable trust.
NOThe residual authority or evidence gap remains material.
How to read this: the dark node marks the point where trust can be lost or authority can expand. Arrows represent control, evidence or dependency relationships, not necessarily direct network links.

Railway zoning still matters when the bearer changes

ENISA railway guidance highlights risk management, legacy systems, supply-chain dependencies and the practical use of zones and conduits. FRMCS should be integrated into that architecture as a conduit with defined security assumptions, not as a reason to flatten them.

This means separating telecom-service health from railway-message validity. Loss of coverage, routing anomalies or compromised telecom credentials should not directly determine a safety outcome without application-level checks and safe degraded behaviour.

The engineering test is therefore simple to state: if the mobile carrier or a FRMCS component is degraded, malicious or simply wrong, can the railway system reject unsafe authority and transition predictably without losing the evidence needed to understand what happened?

A communications service can be highly available and well managed while still remaining outside the railway application trust boundary.
The decision
Keep trust end to end at the railway application layer and treat FRMCS as a governed communications conduit.
Operational checks
  • Document which properties are provided by telecom versus application layers.
  • Protect message freshness and integrity independently of network membership.
  • Define degraded operation for loss or corruption of service.
  • Segment FRMCS interfaces into explicit railway zones and conduits.
  • Exercise compromise and outage scenarios with telecom suppliers.
Related episodeListen to the podcast versionLinkedInJoin the discussion
Source record

Sources & further reading

5 cited sourcesHow we source →
← All analysisCompanion episode →