Overview
Purpose
To provide a structured framework for developing, deploying and maintaining railway software with an appropriate level of software integrity. The standard aims to control systematic software errors through defined engineering processes, responsibilities, verification, validation, testing and assurance activities.
Scope
Applies to software for programmable electronic systems used in railway control-command and signalling applications and onboard rolling-stock applications. It covers application software, operating systems, support tools, firmware, application data and certain pre-existing software. It primarily applies to new developments and major modifications, with specific provisions for maintenance and minor changes.
Important exclusion: It is not intended for fixed electric traction power supply or conventional station power/control applications such as office or shop power supplies
Engineering Overview & Illustrations
Supporting engineering explanation, diagrams and visual references for understanding and applying this railway standard.
What is EN 50716 Standard?
EN 50716 is a framework that provides guidelines for managing the life cycle of systems. It is no longer necessary to divide up the software development specifications into a standard for signalling installations and one for vehicles. The standard can also be applied to software with basic integrity (formerly SIL0). The restriction in 1.3 stating that the standard is not applicable to non-safety-related software has been deleted.

EN 50716 Software Development Lifecycle
EN 50716:2023 establishes a structured approach for developing and maintaining software used in railway control-command and signalling systems and onboard rolling-stock applications. The diagram above provides a simplified view of how software progresses through the development lifecycle while maintaining appropriate levels of verification, validation, traceability and assurance.

A major development from EN 50128 is that EN 50716 creates a single, harmonised railway software framework. EN 50128 was primarily focused on software for railway control and protection systems, while onboard rolling-stock software was addressed separately by EN 50657. EN 50716 brings these areas together, replacing both EN 50128 and EN 50657 and reducing differences between the two approaches.
Software Integrity Levels
EN 50716 applies different levels of engineering and assurance rigour depending on the software integrity required for the railway application. The higher the potential consequences of a software failure, the more rigorous the development, verification, validation and independence requirements become.
As illustrated belowthe framework progresses from Basic Integrity through SIL 1, SIL 2, SIL 3 and SIL 4. Higher integrity levels require increasingly robust development techniques, stronger verification and testing, greater traceability, more comprehensive evidence and increased independence between development and assessment activities.
In simple terms:
Higher safety consequence → Higher integrity requirement → Greater development and assurance rigour.

Watch on Railbays TV
Related Standards
EN 50126 series – RAMS lifecycle
EN 50129 – Safety-related electronic systems for signalling
EN 50159 – Safety-related communication
EN 50155 – Electronic equipment on rolling stock
EN 50657 – Predecessor standard for onboard rolling-stock software
EN 50128 – Predecessor standard for railway control/protection software
Reference / Further Reading
iTeh – EN 50716:2023 Standard Overview
Typical Railway Applications
Electronic interlocking; ETCS; CBTC; ATP; ATO; onboard train control and protection; signalling control systems; rolling-stock control software; application data/configuration; operating systems and firmware supporting applicable railway systems.
Key Topics
Software integrity levels; software lifecycle; software requirements; architecture and design; component design; implementation and testing; software integration; overall software testing; final validation; verification; application data; software deployment; maintenance; change control; configuration management; support tools; pre-existing software; staff competence; independence of roles; documentation and software assurance
Who Uses This Standard?
Railway software engineers; signalling engineers; rolling-stock engineers; systems engineers; RAMS and safety engineers; software architects and developers; V&V engineers; software testers; safety assessors; system integrators; railway suppliers; operators; infrastructure managers; consultants and certification/assessment organisations.
Obtain the Official Standard
RailBays provides an independent engineering overview for reference and educational purposes. For complete normative requirements, always refer to the official current edition issued by the relevant standards organisation or authorised distributor.
View Official Standard ↗