IEC 62425:2025
(Main)Railway applications - Communication, signalling and processing systems - Safety related electronic systems for signalling
Railway applications - Communication, signalling and processing systems - Safety related electronic systems for signalling
IEC 62425:2025 is applicable to safety-related electronic systems (including subsystems and equipment) for railway signalling applications. This document applies to generic systems (i.e. generic products or systems defining a class of applications), as well as to systems for specific applications. The scope of this document, and its relationship with other IEC and CENELEC standards, are shown in Figure 1. This document is applicable only to the functional safety of systems. It does not deal with other aspects of safety such as the occupational health and safety of personnel. While functional safety of systems clearly can have an impact on the safety of personnel, there are other aspects of system design which can also affect occupational health and safety and which are not covered by this document. Cybersecurity aspects of functional safety are addressed only to a limited extent. This document applies to all the phases of the life cycle of a safety-related electronic system, focusing in particular on phases 5 (architecture and apportionment of system requirements) to 10 (system acceptance) as defined in IEC 62278-1: -
Requirements for systems which are not related to safety are outside the scope of this document. This document is not applicable to existing systems, subsystems or equipment which had already been accepted prior to the development of this document. However, so far as reasonably practicable, it is applicable to modifications and extensions to existing systems, subsystems and equipment. This document is primarily applicable to systems, subsystems or equipment which have been specifically designed and manufactured for railway signalling applications. It is also applicable, so far as reasonably practicable, to general-purpose or industrial equipment (e.g. power supplies, display screens or other commercial off the shelf items), which is procured for use as part of a safety-related electronic system. This document is aimed at railway duty holders, railway suppliers, and assessors as well as at safety authorities, although it does not define an approval process to be applied by the safety authorities. This second edition cancels and replaces the first edition published in 2007. This edition constitutes a technical revision.
This edition includes the following significant technical changes with respect to the previous edition:
a) a better alignment with the life cycle phases defined in IEC 62278-1 has been made;
b) Clause 5 describes the requirements that apply to the development of safety-related electronic systems (until phase 9 of the life cycle);
c) Clause 8 focuses on the requirements for safety acceptance and approval of safety-related electronic systems and subsequent phases;
d) requirements and guidance have been added in Clause 6 on the following topics:
- reuse of pre-existing systems,
- safety-related tools,
- impact of cybersecurity threats on functional safety,
- specific application safety cases;
e) requirements for the structure and content of the safety case are now defined in a dedicated Clause 7;
f) Annex A has been updated for the specification and allocation of safety integrity requirements;
g) the content of former Annex D has been merged with Annex B, and the content has been changed from informative to normative;
h) the status of Annex E has been changed from informative to normative;
i) an Annex F has been added as an informative annex on User Programmable Integrated Circuits.
A more detailed comparison of changes between IEC 62425:2007 and this document can be found in Annex G.
Applications ferroviaires - Systèmes de signalisation, de télécommunication et de traitement - Systèmes électroniques de sécurité pour la signalisation
IEC 62425:2025 Cette édition inclut les modifications techniques majeures suivantes par rapport à l'édition précédente:
a) le document a été aligné sur les phases du cycle de vie définies dans l'IEC 62278-1 ;
b) l'Article 5 décrit les exigences relatives au développement de systèmes électroniques relatifs à la sécurité (jusqu'à la phase 9 du cycle de vie) ;
c) l'Article 8 traite des exigences relatives à l'acceptation et à l'approbation de la sécurité des systèmes électroniques relatifs à la sécurité, ainsi que des phases suivantes du cycle de vie ;
d) des exigences et des recommandations ont été ajoutées à l'Article 6 concernant les sujets suivants :
1) réutilisation de systèmes préexistants ;
2) outils relatifs à la sécurité ;
3) impact des menaces de cybersécurité sur la sécurité fonctionnelle ;
4) dossiers de sécurité pour applications spécifiques ;
e) les exigences relatives à la structure et au contenu du dossier de sécurité sont désormais définies dans un Article 7 dédié ;
f) l'Annexe A a été mise à jour en ce qui concerne la spécification et l'allocation des exigences d'intégrité de la sécurité ;
g) le contenu de l'ancienne Annexe D a été fusionné avec celui de l'Annexe B, et l'annexe est passée du statut informatif à normatif ;
h) l'Annexe E est passée du statut informatif à normatif ;
i) une Annexe F informative a été ajoutée pour couvrir les circuits intégrés programmables par l'utilisateur.
L'Annexe G compare en détail les modifications entre l'IEC 62425:2007 et le présent document.
Le présent document s'applique aux systèmes électroniques relatifs à la sécurité (en incluant les sous-systèmes et les équipements) utilisés dans les applications de signalisation ferroviaire.
Le présent document s'applique aux systèmes génériques (c'est-à-dire aux produits ou systèmes génériques qui définissent une classe d'applications), ainsi qu'aux systèmes destinés à des applications spécifiques.
La Figure 1 représente le domaine d'application du présent document, ainsi que ses relations avec les autres normes de l'IEC et du CENELEC.
Le présent document est applicable uniquement à la sécurité fonctionnelle des systèmes. Il ne traite pas d'autres aspects de la sécurité tels que la santé des travailleurs et la sécurité du personnel. Si la sécurité fonctionnelle des systèmes peut avoir un impact sur la sécurité du personnel, la santé et la sécurité des travailleurs peuvent également être affectées par d'autres aspects de la conception du système qui ne sont pas couverts par le présent document. Les aspects de cybersécurité de la sécurité fonctionnelle ne sont couverts que dans une certaine mesure.
Le présent document s'applique à toutes les phases du cycle de vie d'un système électronique relatif à la sécurité, et en particulier aux phases 5 (architecture et allocation des exigences du système) à 10 (acceptation du système) définies dans l'IEC 62278-1:—.
Les exigences applicables aux systèmes non relatifs à la sécurité ne relèvent pas du domaine d'application du présent document.
Le présent document n'est pas applicable aux systèmes, sous-systèmes ou équipements existants (c'est-à-dire ceux qui ont déjà été acceptés avant le développement du présent document). Toutefois, autant que cela est raisonnablement possible, le présent document s'applique aux modifications et extensions des systèmes, sous-systèmes et équipements existants.
Le présent document s'applique essentiellement aux systèmes, sous-systèmes ou équipements qui ont été spécialement conçus et fabriqués dans les applications de signalisation ferroviaire. Le présent document s'applique également, autant que cela est raisonnablement possible, aux équipements généraux ou industriels (par exemple, alimentations, écrans d'affichage ou autres articles disponibles dans le commerce) qui sont utilisés comme partie d'un système électronique relatif à la sécurité.
Le présent document s'adresse aux responsables d'exploitation ferroviaire, aux fournisseurs de matér
General Information
Relations
Standards Content (Sample)
IEC 62425 ®
Edition 2.0 2025-05
COMMENTED VERSION
INTERNATIONAL
STANDARD
Railway applications – Communication, signalling and processing systems –
Safety related electronic systems for signalling
ICS 45.060.01 ISBN 978-2-8327-0420-2
All rights reserved. Unless otherwise specified, no part of this publication may be reproduced or utilized in any form or
by any means, electronic or mechanical, including photocopying and microfilm, without permission in writing from either
IEC or IEC's member National Committee in the country of the requester. If you have any questions about IEC copyright
or have an enquiry about obtaining additional rights to this publication, please contact the address below or your local
IEC member National Committee for further information.
IEC Secretariat Tel.: +41 22 919 02 11
3, rue de Varembé info@iec.ch
CH-1211 Geneva 20 www.iec.ch
Switzerland
About the IEC
The International Electrotechnical Commission (IEC) is the leading global organization that prepares and publishes
International Standards for all electrical, electronic and related technologies.
About IEC publications
The technical content of IEC publications is kept under constant review by the IEC. Please make sure that you have the
latest edition, a corrigendum or an amendment might have been published.
IEC publications search - IEC Products & Services Portal - products.iec.ch
webstore.iec.ch/advsearchform Discover our powerful search engine and read freely all the
The advanced search enables to find IEC publications by a publications previews, graphical symbols and the glossary.
variety of criteria (reference number, text, technical With a subscription you will always have access to up to date
committee, …). It also gives information on projects, content tailored to your needs.
replaced and withdrawn publications.
Electropedia - www.electropedia.org
The world's leading online dictionary on electrotechnology,
IEC Just Published - webstore.iec.ch/justpublished
Stay up to date on all new IEC publications. Just Published containing more than 22 500 terminological entries in English
details all new publications released. Available online and and French, with equivalent terms in 25 additional languages.
once a month by email. Also known as the International Electrotechnical Vocabulary
(IEV) online.
IEC Customer Service Centre - webstore.iec.ch/csc
If you wish to give us your feedback on this publication or
need further assistance, please contact the Customer
Service Centre: sales@iec.ch.
– 2 – IEC 62425:2025 CMV © IEC 2025
CONTENTS
FOREWORD . 6
INTRODUCTION . 9
1 Scope . 10
2 Normative references . 11
3 Terms, definitions and abbreviated terms . 12
3.1 Terms and definitions . 12
3.2 Abbreviated terms . 22
4 Overall framework of this document . 23
5 Requirements for developing safety-related electronic systems . 25
5.1 General . 25
5.2 The quality management process . 25
5.3 The safety management process. 27
5.3.1 General . 27
5.3.2 Guideline for structuring documentation . 27
5.3.3 Safety life cycle . 28
5.3.4 Safety organization . 28
5.3.5 Safety plan . 30
5.3.6 Hazard log . 31
5.3.7 Safety requirements specification . 31
5.3.8 System design for safety . 31
5.3.9 Safety operation and maintenance plan . 32
5.3.10 Safety verification . 32
5.3.11 Safety validation . 33
5.3.12 Safety qualification tests . 34
5.3.13 Management of safety-related application conditions . 35
5.3.14 Safety justification . 36
5.3.15 Independent safety assessment . 37
6 Requirements for elements following different life cycles . 37
6.1 General . 37
6.2 Use of pre-existing items . 38
6.2.1 General . 38
6.2.2 Requirements for use of complete pre-existing systems . 39
6.2.3 Requirements for use of pre-existing equipment . 39
6.3 Safety-related tools for electronic systems . 40
6.4 Physical security and cybersecurity. 41
7 The safety case: structure and content . 42
7.1 The safety case structure . 42
7.2 The technical safety report . 44
7.3 Generic and specific safety cases . 53
7.4 Provisions for the specific application safety case . 53
7.5 Dependencies between safety cases . 54
8 System safety acceptance and subsequent phases . 55
8.1 System safety acceptance process . 55
8.2 Operation, maintenance and performance monitoring . 59
8.3 Modification and retrofit . 59
8.4 Decommissioning and disposal . 59
Annex A (normative) Safety integrity levels . 60
A.1 General . 60
A.2 Safety requirements . 60
A.3 Safety integrity . 61
A.4 Determination of safety integrity requirements . 61
A.4.1 General . 61
A.4.2 Risk assessment . 63
A.4.3 Hazard control . 65
A.4.4 Identification and treatment of new hazards arising from design . 71
A.5 Allocation of SILs . 72
A.5.1 General aspects . 72
A.5.2 Relationship between SIL and associated TFFR . 73
Annex B (normative) Management of faults for safety-related functions . 75
B.1 General . 75
B.2 General concepts . 75
B.2.1 Detection and negation times . 75
B.2.2 Composition of two independent items . 76
B.3 Effects of faults . 77
B.3.1 Effects of single faults . 77
B.3.2 Independence of items. 79
B.3.3 Detection of single faults . 84
B.3.4 Action following detection (retention of safe state) . 87
B.3.5 Effects of multiple faults . 88
B.3.6 Defence against systematic faults . 91
Annex C (normative) Identification of hardware component failure modes . 92
C.1 General . 92
C.2 General procedure . 92
C.3 Procedure for integrated circuits . 92
C.4 Procedure for components with inherent physical properties . 93
C.5 General provisions concerning component failure modes . 93
Annex D (informative) Example of THR/TFFR/FR apportionment and SIL allocation. 111
Annex E (normative) Techniques and measures for the avoidance of systematic faults
and the control of random and systematic faults . 113
E.1 General . 113
E.2 Tables of techniques and measures . 115
Annex F (informative) Guidance on User Programmable Integrated Circuits. 123
F.1 General . 123
F.1.1 Purpose . 123
F.1.2 Terminology and context . 123
F.2 UPIC life cycle . 124
F.2.1 General . 124
F.2.2 Organization, roles, responsibilities and personnel competencies . 126
F.2.3 UPIC Requirements . 126
F.2.4 UPIC Architecture and Design . 127
F.2.5 Logic Component Design . 128
F.2.6 Logic Component Coding . 128
F.2.7 Logic Component Verification . 128
F.2.8 UPIC Physical Implementation . 128
– 4 – IEC 62425:2025 CMV © IEC 2025
F.2.9 UPIC Integration . 128
F.2.10 UPIC Validation . 128
F.2.11 Requirements for use of pre-existing logic components . 128
F.3 Detailed technical requirements for UPIC . 128
F.3.1 Guidance on safety architecture . 128
F.3.2 Protection against random faults – architectural principles . 129
F.3.3 Protection against systematic faults – techniques and measures . 129
Annex G (informative) Changes in this document compared to IEC 62425:2007. 138
Bibliography .
...








Questions, Comments and Discussion
Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.