Oct. 18, 2022TSA Security Directive, rail
Designated passenger and freight railroads
Performance-based. Network segmentation so OT can keep running safely if IT is compromised, access control for critical cyber systems, continuous monitoring and detection, and timely patching. Operators also have to assess how well the measures work. [2,4]
March 7, 2023TSA emergency amendment, aviation
Certain TSA-regulated airport and aircraft operators
The same outcomes as rail: segmentation between IT and OT, access control, continuous monitoring and detection, patching of critical cyber systems, and proactive assessment of those measures. [3]
Proposed Nov. 7, 2024TSA proposed rule, surface
Pipelines, freight rail, passenger rail, and rail transit
Enhancing Surface Cyber Risk Management would turn the surface directives into a standing rule, with a Cybersecurity Operational Implementation Plan and an annual Cybersecurity Assessment Plan. The comment period closed Feb. 5, 2025. Until a final rule takes effect, the security directives set the requirements. [5,6]
49 CFR 236 Subpart IFRA Positive Train Control
Railroads required to run PTC
PTC is a safety system that can stop a train. The federal rules cover the safety plans and the systems behind it, so any security work on PTC starts with the people who own the safety case. [7]
Recommended practicesAPTA control and communications security
Rail transit
APTA's SS-CCS series defines a security zone architecture for rail transit and how to protect the most critical zones. RP-006-23 adds an OT cybersecurity maturity framework. [8,9]
2019 onwardICAO and EASA
International aviation
ICAO's Aviation Cybersecurity Strategy (2019) and Cybersecurity Action Plan. In Europe, Part-IS: Delegated Regulation (EU) 2022/1645, which covers aerodrome operators, applied from Oct. 16, 2025, and Implementing Regulation (EU) 2023/203 from Feb. 22, 2026. [11,12,13]
SeriesISA/IEC 62443
Industrial automation and control systems
Zones and conduits, security levels, and requirements for asset owners, integrators, and suppliers. Good language for BHS, APM, and fuel system contracts. [15]
FrameworksNIST CSF 2.0 and CISA CPGs
Voluntary, any sector
The NIST CSF gives the program and board reporting a structure. CISA's Cross-Sector Cybersecurity Performance Goals are the baseline CISA points transportation owners to. [16,17,1]