



Notification Center


Frauscher Marketing
04 Aug 2026 | 7 min read
Railway systems are becoming more connected every year, and with that connectivity comes a shared responsibility for cyber security across the entire supply chain. To understand what this shift means in practice, we sat down with Florian Einböck, Head of Portfolio Strategy at Frauscher Sensor Technology. Following Frauscher's recent certification to IEC 62443-4-1:2018 for its Secure Development Lifecycle, issued by TÜV Süd on 7 May 2026, Florian shares his thoughts on what the railway industry will face going forward, also in light of the EU Cyber Resilience Act, and how suppliers, such as Frauscher, approach cyber security today.

Railway networks are moving toward distributed system architectures, open network communication and real-time data exchange between operational technology and IT environments. These changes bring real efficiency gains, but they also widen the number of points that need to be protected. It's no longer enough for one party in the supply chain to take responsibility. Manufacturers need to build protection into products from the earliest design stages, integrators need to carry that protection through into the finished installation, and operators need organisational measures like access control and patch management to keep systems secure over their lifetime.
This shift is also reflected in regulation. The EU Cyber Resilience Act, which entered into force in December 2024, introduces mandatory cyber security requirements for products with digital elements placed on the EU market. Reporting obligations for actively exploited vulnerabilities apply from 11 September 2026, while the remaining core obligations—including essential security requirements, technical documentation and CE marking—apply from 11 December 2027. Railway-specific standards such as IEC 62443 and its derivation TS 50701 translate these requirements into concrete measures suited to safety-critical environments.
Digital signalling with IP-based control of field elements is a key driver for increasing capacity at a lower total cost of ownership, and for higher availability through predictive maintenance. We have been developing our portfolio in this direction for years, and cyber security has to be a reliable, built-in part of these new architectures from the outset.

Frauscher's focus on cyber security grew as the company extended its portfolio beyond field elements into software- and network-based solutions, including Frauscher Insights and Frauscher Connect. Secure network communication has always been a central consideration, and the broader focus on cyber security intensified in step with developments across the railway industry and beyond. Today, Frauscher has built up comprehensive in-house expertise, supported by a dedicated Product Security & Network Team responsible for cyber security measures across the full product lifecycle, including vulnerability management and penetration testing.
IEC 62443-4-1 confirms that our development process addresses cyber security at every stage, not just at the end. It looks at three core principles: security by design, so relevant security factors are considered and documented from the outset; security by default, meaning products are delivered with secure configurations and settings; and security in implementation, which covers the testing and documentation needed to operate a system securely.


Vulnerabilities identified in released products are handled by Frauscher's Product Security Incident Response Team (PSIRT), which publishes corresponding security advisories on the Frauscher PSIRT page on our website. External researchers can also report findings directly to the PSIRT, reinforcing a transparent and collaborative approach to security disclosure.
An important part of this work is applying current expectations to existing products as well as new ones. The Frauscher Advanced Counter FAdC®, for example, was originally developed before security-by-design principles became standard practice, but it can still be brought up to current cyber security expectations without redesigning its safety-critical core.
Clearly, involving themselves in according working groups and organisations, such as VDB and CENELEC. At Frauscher, we see ourselves as an active part of the cyber security community within railways, not just a company responding to new regulation. The exchange with players from various areas feeds directly back into how we develop our products. New solutions are built to be cyber secure by design from the outset, and that thinking now extends across our whole portfolio.
This reflects a broader positioning: Frauscher aims to be a partner ready to engage with customers, integrators and industry bodies on the cyber security challenges that digitalisation brings to the railway sector, rather than simply meeting minimum requirements as they arise.
As the EU Cyber Resilience Act's remaining obligations approach in December 2027, Frauscher continues to strengthen its cyber security foundations across the full product lifecycle. With IEC 62443-4-1 certification in place and ongoing networking in industry standards bodies, Frauscher is positioned to support customers through a regulatory landscape that is still taking shape—while keeping safety and security at the core of every new development.

Share this post
Get in touch with our team!
Interested in how Frauscher's Secure Development Lifecycle can support your project's cyber security requirements?
The Association of the European Rail Supply Industry (UNIFE) has published an expert guidance on the implementation of the Cyber Resilience Act in mainline and urban railways. The document explains the impacts and boundaries between the CRA and its compliance with the legal framework for railway vehicle authorisation. The unife-guide can be found here.
Additionally, the German Railway Industry Association (VDB) has published a comprehensive guideline, which will soon be available in English.

Share this post
Get in touch with our team!
Interested in how Frauscher's Secure Development Lifecycle can support your project's cyber security requirements?