Regulation (EU) 2026/1184



What is Regulation (EU) 2026/1184?

Regulation (EU) 2026/1184 of 20 May 2026 on the use of railway infrastructure capacity in the single European railway area, establishes a harmonised legal framework governing the management of railway infrastructure capacity within the Single European Railway Area. Its principal objective is to enhance the efficiency and coordination of railway operations by introducing common rules for capacity planning, capacity allocation, traffic management, disruption management, crisis management, and performance management across the European Union.

The Regulation addresses the increasing complexity of railway operations in a highly interconnected cross border transport environment. It establishes mechanisms designed to improve cooperation among infrastructure managers, railway undertakings, and other operational stakeholders.

This is an important crisis management regulation, primarily structured as a framework for the management of operational consequences. The repeated references to crisis (75 occurrences) and the limited use of the term risk (4 times) suggest that the Regulation assumes the existence of risk management processes, and focuses on ensuring the resilience of railway operations during periods of disruption.


In Recital 11 we read:

Transport infrastructure is the backbone of the economy and society as a whole. Some railway infrastructure is critical to ensuring the good functioning of vital societal functions and has a strategic significance for national security. In certain cases, granting capacity rights to an applicant could compromise public security or public order in the Union, including at Member State level, for example where a railway undertaking intends to transport dangerous goods or weapons having illegally entered the Union on the railway infrastructure of a Member State.

In order to guarantee smooth, safe and secure rail transport traffic and to ensure the protection of their railway infrastructure, Member States should be allowed to require infrastructure managers to refuse to grant, or to withdraw, capacity rights to an applicant where the access to their railway infrastructure presents a risk for public order or public security, including to national security and defence.

Any such decision should be duly justified and strictly necessary and proportionate to the objective pursued, taking also into account the impacts of that decision on competition and on the continuity of the supply chains, in particular for the supply of critical inputs, and where the requested capacity right constitutes a multi-network capacity right.

When assessing the risk for public security or public order, the Member State concerned should be able to take into account, among other factors, the fact that the applicant is subject to restrictive measures adopted by the Union and the reasons for adopting such measures, that the applicant is owned or effectively controlled by, or acts on behalf or at the direction of, a person or an entity subject to restrictive measures adopted by the Union, or that the applicant or that person or entity is engaged in illegal activities or in activities facilitating the development of a third country’s military capabilities presenting a threat to the Member State’s national security.


In Article 1.1, Subject matter and scope, we read:

This Regulation lays down the principles, rules and procedures applicable to management of railway infrastructure capacity, to traffic management, to crisis management and to performance management, for domestic and international rail services, and to the coordination between infrastructure managers and other operational stakeholders, as well as the principles, rules and procedures applicable to the implementation of digital tools to support the capacity and traffic management processes in this Regulation. It also lays down rules for a European network for coordination between infrastructure managers and with other relevant stakeholders and on the oversight of capacity and traffic management.


In Article 46, European framework for the coordination of cross-border traffic management, disruption management and crisis management, we read:

1. By 12 April 2028, the European Network of Infrastructure Managers (ENIM) shall develop and adopt a European framework for the coordination of cross-border traffic management, disruption management and crisis management in accordance with the principles referred to in Article 44, laying down common tools, methodologies and procedural arrangements for the coordination between infrastructure managers, railway undertakings and other operational stakeholders, and taking into account the work of Europe’s Rail Joint Undertaking established by Article 3(1), point (d), of Regulation (EU) 2021/2085.

Infrastructure managers shall take the utmost account of those common tools, methodologies and procedural arrangements for the coordination of cross-border traffic management, disruption management and crisis management.


According to Article 49, Crisis situations:

1. In crisis situations or in cases of imminent risk of a crisis situation occurring related to public safety, health epidemics, natural disasters or the environment that have or are expected to have a critical effect on the supply or demand of rail transport services, Member States shall be allowed to apply emergency measures that include, by way of derogation from the rules of this Regulation and from the rules related to the allocation of railway infrastructure capacity laid down in Chapter IV, Section 3 of Directive 2012/34/EU:

(a) the cancellation of capacity rights without penalty in accordance with Article 42;

(b) alternative principles, rules and procedures for capacity management;

(c) alternative procedures for traffic management;

(d) the use of alternative routes;

(e) the amendment of capacity supply plans.


We cannot find the term "cyber" in Regulation (EU) 2026/1184. Why?

The absence of the terms "cyber" and "hybrid" from Regulation (EU) 2026/1184 reflects the distribution of regulatory responsibilities within the Union legal framework. Cybersecurity and resilience obligations applicable to railway operators and railway infrastructure managers are addressed principally through other legislative instruments, most notably Directive (EU) 2022/2555 (NIS 2) and, where applicable, Directive (EU) 2022/2557 (CER).

Regulation (EU) 2026/1184 focuses on operational coordination, capacity management, disruption management, and crisis management, relying on the broader Union resilience framework to address the identification, assessment, and management of cyber (and other) security related risks.

For railways specifically, NIS 2 is highly relevant, and covers how railway entities manage cybersecurity risk.

A railway infrastructure manager or railway undertaking may simultaneously have obligations under NIS 2 Directive, CER Directive, and Regulation (EU) 2026/1184.

Before a disruption, NIS 2 plays a central role. It answers the questions:

1. What are your cybersecurity risks? 2. What controls have you implemented?
3. How do you manage vulnerabilities?
4. How do you detect incidents?
5. How do you report significant incidents?
6. How do you ensure resilience?

This is the preventive and risk-management phase.

When a disruption begins, there is overlap. A cyberattack against signalling systems, for example, may trigger NIS 2 incident-management obligations, NIS 2 reporting obligations, and operational disruption procedures under Regulation (EU) 2026/1184.

During a major crisis, both regimes remain applicable. For example, when a hostile actor compromises signalling infrastructure in several Member States, NIS 2 continues to govern incident handling, reporting, cybersecurity response, and technical remediation.

Regulation (EU) 2026/1184 governs traffic management, disruption management, crisis coordination, and operational continuity.

NIS 2 and Regulation (EU) 2026/1184 regulate different aspects of the same event. NIS 2 primarily addresses cybersecurity risk management and incident response, whereas Regulation (EU) 2026/1184 primarily addresses the operational management and coordination of railway services during disruptions and crises.


Which is the role of the Critical Entities Resilience Directive (CER)?

According to Recital 45 of Regulation (EU) 2026/1184, the Critical Entities Resilience Directive (CER) (Directive (EU) 2022/2557) lays down measures to achieve a high level of resilience for critical entities that provide essential services within the Union. Infrastructure managers within the scope of Regulation (EU) 2026/1184 are in principle also within scope of the CER Directive.

Directive (EU) 2022/2557 requires critical entities to take resilience enhancing measures. Regulation (EU) 2026/1184 also requires that infrastructure managers take resilience enhancing measures in the event of network disruption and crisis situations affecting rail traffic. Resilience measures under Regulation (EU) 2026/1184 should apply without prejudice to, and in complementarity with, Directive (EU) 2022/2557.

Infrastructure Managers must ensure that they also fulfil their obligations under the Directive (EU) 2022/2557. Where infrastructure managers have already taken measures pursuant to Regulation (EU) 2026/1184 that are relevant for resilience enhancing measures under Directive (EU) 2022/2557, they can use those measures and documents to meet the requirements of CER.

That is very significant. The legislator is attempting to avoid duplicate documentation, assessments, resilience plans, and compliance exercises.