EN 50126 explained: the RAMS lifecycle for railways

Who this is for: RAMS engineers, safety assessors and project managers who need a working mental model of EN 50126 before opening their licensed copy — what it governs, how the 2017 revision is structured, and where it sits relative to EN 50128 and EN 50129. This is reference material, not a substitute for the standard itself, which you must read in full from a licensed source.

What EN 50126 is (and what it isn't)

EN 50126 is the CENELEC standard that defines the RAMS process — Reliability, Availability, Maintainability and Safety — across the whole lifecycle of a railway system, from concept to decommissioning. It is the process framework that tells you when to do risk analysis, what to produce at each stage, and how RAM and safety activities fit together. Its international twin is IEC 62278.

Crucially, EN 50126 is a process standard, not a design standard. It does not tell you how to build a brake, size a cable or write a line of code. It tells you how to specify, apportion, demonstrate and manage RAMS requirements so that the finished system is acceptably safe and available, and — just as important — so that you can demonstrate that to an assessor. If your project is failing its safety assessment, the cause is very often a broken EN 50126 process (missing traceability, late hazard analysis) rather than a bad design decision.

The current edition is EN 50126:2017, published in two parts, which superseded the single-part EN 50126:1999. A first amendment, EN 50126-1:2017/A1, was published in 2024. A further revision of the EN 5012x family is anticipated later this decade, so always confirm the edition and amendment status of the copy you are working from.

EN 50126-1 vs EN 50126-2 (generic process vs safety approach)

The 2017 revision split the standard into two parts with distinct jobs:

In practice, Part 1 is what your process and audit trail are measured against; Part 2 is what you reach for when you need to justify how you did the safety work.

Where it sits relative to EN 50128 and EN 50129

Think of EN 50126 as the umbrella. Underneath it, two companion standards go deep on specific technologies:

EN 50126 sets the process and the RAMS targets; EN 50128/50716 and EN 50129 tell you how to meet the safety-integrity obligations for software and signalling hardware respectively.

The RAMS lifecycle phases

The headline change in the 2017 revision was a restructured lifecycle. The 1999 edition described fourteen phases; the 2017 edition consolidates the work into twelve phases, arranged as a V. The left (top-down) branch is the refining, development side — from concept down to manufacture. The right (bottom-up) branch is integration, validation, acceptance and operation of the assembled system. The point of the V is that each verification and validation activity on the right maps back to a specification activity on the left.

The twelve phases of EN 50126-1:2017, in order:

# Phase What it broadly produces
1ConceptScope, purpose, initial RAMS context
2System definition and operational contextSystem boundary, operating and maintenance conditions, the RAMS plan
3Risk analysis and evaluationHazard identification, risk assessment, hazard log established
4Specification of system requirementsRAMS requirements specification
5Architecture and apportionment of system requirementsRAMS targets apportioned down to subsystems/components
6Design and implementationDesign meeting apportioned RAMS requirements; RAM predictions, FMEA
7ManufactureProduction under controlled conditions
8IntegrationAssembly and integration of subsystems
9System validationDemonstration that the system meets its RAMS requirements
10System acceptanceFormal acceptance against agreed criteria
11Operation, maintenance and performance monitoringIn-service RAMS performance, FRACAS, hazard log maintained
12DecommissioningManaged disposal, residual risk handling

(This is a paraphrased structural summary. The normative phase objectives, inputs, requirements and deliverables are set out in the standard itself — consult your licensed copy for the exact wording and clause references.)

A few things worth internalising:

RAMS vs safety — how the four attributes relate

RAMS bundles four attributes, but they are not managed identically:

They are managed together because they trade off against each other (a design that improves availability can introduce a hazard, and vice versa) and because they share the same lifecycle, hazard log and evidence trail. But they are assessed differently: RAM against performance targets, safety against risk-acceptance criteria and the safety case. Conflating the two — for example, treating a safety requirement as merely a reliability target — is a classic source of assessment findings.

A practical way to keep them straight: a RAM failure costs you money and reputation (a delayed or cancelled service), whereas a safety failure costs you the risk-acceptance argument. Both matter, but the burden of proof differs. RAM targets can be demonstrated statistically and, to a degree, corrected in service through the FRACAS loop. Safety, by contrast, has to be argued to an acceptance principle before the system enters service — you cannot "run it and see". This is why EN 50126 front-loads hazard identification (phase 3) and insists the hazard log is opened early and maintained throughout: the safety argument is cumulative, and gaps discovered late are expensive or impossible to close retrospectively.

How EN 50126 connects to EN 50128 and EN 50129

The three standards form the classic railway "V". EN 50126 owns the top of the V — the system-level RAMS process, the targets and the apportionment. As you descend into specific technologies:

The SILs apportioned under the EN 50126 process become the input that drives the rigour demanded by EN 50128/50716 and EN 50129. Get the apportionment wrong at the top and you either over-engineer (expensive) or under-engineer (unsafe, and it will not pass assessment) at the bottom.

Guides on EN 50128 SIL levels and the EN 50129 safety case are coming next.

Common pitfalls when applying EN 50126

Patterns that repeatedly cost projects time in assessment:

Frequently asked questions

Is EN 50126 mandatory?
The standard itself is voluntary, but it is very commonly invoked contractually and is the recognised means of demonstrating RAMS management in European rail. It also underpins the safety demonstration expected under the interoperability and safety frameworks. In practice, on most mainline projects it is effectively mandatory because your client, your assessor and your TSI conformity route all expect it.
How does EN 50126 map to the CSM-RA?
They are complementary, not the same thing. The Common Safety Method for Risk Assessment (Regulation (EU) 402/2013) is the legal framework for assessing significant changes to the railway system. EN 50126 is the engineering process for delivering and demonstrating RAMS. A well-run EN 50126 hazard-management process produces much of the evidence an AsBo needs under the CSM-RA — see NoBo vs DeBo vs AsBo for who assesses what.
What changed in the 2017 revision?
The 1999 single-part standard became two parts (generic process in Part 1, safety approach in Part 2), the lifecycle was restructured from fourteen phases to twelve, and the treatment of hazard management and SIL allocation was clarified. A 2024 amendment (A1) to Part 1 followed. Always check the exact edition and amendment your project cites.
Does it apply to urban/metro systems?
EN 50126 is written for railway applications generally and the RAMS process is routinely applied to metro, light rail and tram projects. However, urban systems often sit outside the mainline TSI regime and under different national and local safety frameworks, so the process travels well even where the regulatory obligations differ.

Sources

ERA Standards is an independent product and is not affiliated with the European Union Agency for Railways. This guide is general information, not certification advice.