SIS-licensed ISO clauses and controls·an add-on inside the AI clients and agents you already use
    Sector · Rail

    Rail & signalling

    Railway cybersecurity anchored on the CLC/TS 50701 clause map and the EN 50126/50129 safety-case spine — cited at clause and article level.

    Ansvar is a gateway for the AI assistant your team already uses — Claude, Microsoft Copilot, any MCP client. Connect it, and every answer below comes back cited to the provision or marked unresolved.

    TS 50701railway cyber clause map
    EN 5012xRAMS & safety-case spine
    Freethe EU regulations, every tier

    CLC/TS 50701 — the railway application of IEC 62443 — is surfaced as a clause map with Ansvar cross-references, never the reproduced standard: the railway asset and zone model, zones & conduits, the initial and detailed risk assessments, security-level targets and the cybersecurity case. It sits on the EN 50126/50129 RAMS and signalling safety-case spine, bridges into the shared IEC 62443 industrial-cyber mapping, and is grounded in the railway rows of the live ENISA transport threat landscape. NIS2 lands on rail operators as essential entities; run the rail TARA or a NIS2 gap analysis over signalling, rolling stock and trackside estates.

    what we cover

    The law and standards we ground on

    Standard

    Control mapping: CLC/TS 50701 railway cybersecurity

    railway zone model, zones & conduits, SL targets, the cybersecurity case — clause map + Ansvar cross-refs, not the standard text

    Standard

    Control mapping: EN 50126 RAMS · EN 50129 signalling safety case

    the safety-case spine the cyber clause map layers on — not the standard text

    Standard

    Control mapping: IEC 62443 industrial cyber

    the 50701 ↔ 62443 bridge, shared with the Industrial / OT lane — not the standard text

    Guidance

    ENISA transport threat landscape — railway

    served full text (CC-BY-4.0) — rail threat actors, incidents and scenarios, cited per item

    Regulation

    Horizontal: NIS2 (Dir (EU) 2022/2555) · CER (EU) 2022/2557

    rail as an essential / critical-entity sector, article level

    what you can do

    Workflows that turn it into evidence

    Rail TARA

    threat analysis & risk assessment off the rail TARA workflow, following the CLC/TS 50701 initial + detailed risk-assessment shape — an available analysis, not a CSM-RA determination or an assessment-body verdict

    STRIDE threat model

    over signalling / CCS, rolling stock, TMS and trackside OT, grounded in the 50701 zone model

    NIS2 gap analysis

    Directive (EU) 2022/2555 Art. 21 for rail essential entities

    IEC 62443 zone & conduit gap analysis

    the shared 62443 clause map applied to the railway zone model

    Document review, paragraph-cited

    cybersecurity cases, risk assessments and signalling documentation

    STRIDE threat-model workflows run on every plan against a system you describe — 1 run a month on Free, 2 on Solo, 5 on Premium, which also adds the LINDDUN and TARA families, the rendered reports, and case law inside the run. Document-grounded workflows run on Team and Company. Every tier runs the same corpora as cited research inside your own AI client.

    Questions buyers ask first

    Do you serve the CLC/TS 50701 or EN 50126/50129 text?
    Not by default — railway standards are surfaced as clause maps with Ansvar-authored cross-references, addressable against your licensed copy. IEC 63452, the emerging international successor to TS 50701, is catalogued by status and scope only. Through the SIS-licensed standards module, any ISO, EN or SS standard SIS publishes can be licensed in and served cited verbatim inside your workflows; see /standards.
    Do you cover the EU rail directives, CSM-RA or the TSIs?
    Not yet as served text. The Rail Interoperability Directive (EU) 2016/797, the Rail Safety Directive (EU) 2016/798, CSM-RA (Reg (EU) 402/2013) and the CCS TSI are on the ingestion roadmap, and the clause map already cross-references them by CELEX so the mapping is ready. What is served today at article level is the horizontal stack — NIS2 and CER. We will not imply coverage we cannot ground.
    How is this different from the Industrial / OT page?
    Industrial / OT takes the plant operator's view — IEC 62443 zones, conduits and live ICS advisories. This lane is railway-specific: CLC/TS 50701's railway zone model and cybersecurity case, layered on the EN 50126/50129 signalling safety case. The IEC 62443 mapping is shared between both.

    Run it against your own systems

    Connect the AI client you already use and ask your first cited question — Free, Solo, Premium and Team are self-serve.

    Building rail compliance? It works today — we take on a few design partners per sector to tune it to your team.