Modern connectivity does not remove the end-to-end assurance problem
The European Union Agency for Railways has published its opinion and supporting specifications for FRMCS Version 2, reflecting the migration of railway communications toward 5G-based services. The capability brings major operational benefits, but it also expands the set of telecom components and service relationships on which railway applications depend.
The critical distinction is between transport and authority. A mobile network can provide authenticated connectivity, quality of service and operational monitoring, but the railway application still needs its own controls to determine whether a message is authentic, current and acceptable for the safety or operational context.
Treating network membership as proof of application trust would recreate the same implicit-trust problem seen elsewhere in OT, only at a much larger and more dynamic scale.
The trust boundary should remain end to end between railway applications even when safety-relevant traffic crosses a mobile network operated as external transport.
Can the railway application remain safe if the communications transport is degraded or untrusted?
Railway zoning still matters when the bearer changes
ENISA railway guidance highlights risk management, legacy systems, supply-chain dependencies and the practical use of zones and conduits. FRMCS should be integrated into that architecture as a conduit with defined security assumptions, not as a reason to flatten them.
This means separating telecom-service health from railway-message validity. Loss of coverage, routing anomalies or compromised telecom credentials should not directly determine a safety outcome without application-level checks and safe degraded behaviour.
The engineering test is therefore simple to state: if the mobile carrier or a FRMCS component is degraded, malicious or simply wrong, can the railway system reject unsafe authority and transition predictably without losing the evidence needed to understand what happened?
- Document which properties are provided by telecom versus application layers.
- Protect message freshness and integrity independently of network membership.
- Define degraded operation for loss or corruption of service.
- Segment FRMCS interfaces into explicit railway zones and conduits.
- Exercise compromise and outage scenarios with telecom suppliers.
Sources & further reading
- GOVERNMENT RECORDERA · Opinion on FRMCS Version 2 specifications↗
- STANDARD / GUIDANCEENISA · Railway Cybersecurity Good Practices↗
- STANDARD / GUIDANCEENISA · Zoning and Conduits for Railways↗
- STANDARD / GUIDANCEUNE · CLC/TS 50701:2023, Railway applications — Cybersecurity↗
- STANDARD / GUIDANCENEN · EN 50159:2026, safety-related communication in transmission systems↗
