EN 50701 places significant weight on supply chain security and lifecycle management, reflecting the reality that signaling and rolling stock assets often run for decades. Here is how to translate that into concrete supplier conversations.
Ask about vulnerability disclosure
Does the supplier have a documented process for receiving, triaging, and disclosing vulnerabilities in their products, and what is their typical response timeline?
Ask about long-term support commitments
Given multi-decade asset lifecycles, what is the supplier's commitment to security support, and what happens when a product reaches end of vendor support -- what compensating guidance do they provide?
Ask how safety and security assurance are reconciled
Can the supplier demonstrate that a proposed security control or update has been evaluated against the product's safety case (RAMS), not just its cybersecurity profile in isolation?
Ask for zone and conduit documentation
Does the supplier provide documentation of the security zones and conduits their system participates in, compatible with your own EN 50701 / IEC 62443-aligned architecture?
Ask about update authentication
How does the supplier cryptographically verify firmware and software updates, protecting against a compromised update becoming a supply chain attack vector?