Onboard Wi-Fi provides internet access to rail passengers, delivered through cellular network connections aggregated and distributed inside the train via managed onboard access points.
No regulation requires it — passenger demand does. Within railway connectivity and communications, Wi-Fi is the commercially driven layer, standardised only where it touches safety.
The service depends as much on mobile coverage along the route as on the equipment inside the train.
Architecture
A train-borne Wi-Fi system consists of three functional layers. The external radio layer connects the train to mobile networks — Long-Term Evolution (LTE) and 5G on commercial spectrum from one or more operators, or dedicated onboard cellular hardware.
A routing layer manages the connection across multiple simultaneous bearers, handles handover between network cells as the train moves, and may aggregate bandwidth from different carriers through bonding.
An internal distribution layer provides 802.11 Wi-Fi coverage throughout the carriages via access points mounted in the ceiling or above the gangways, connected to the routing layer by the train’s onboard Ethernet network.
Capacity is determined by the number of concurrent mobile connections available at a given trackside location, the number of active users, and the quality of coverage along the route. On high-speed corridors with dense base stations and 5G deployment, throughput per train can reach several hundred Mbps under good conditions; on regional or rural routes, available bandwidth may be substantially lower.
Separation from safety-critical systems
Passenger Wi-Fi operates on the same physical train as the Train Control and Management System (TCMS), the ETCS radio, and other safety-critical systems, but is required to be architecturally isolated from them. EN 50159 defines the requirements for safety-related communication in transmission systems and forms the basis for network segmentation design.
IEC 63452, a dedicated cybersecurity standard for rail currently in preparation as draft prEN IEC 63452:2025, is expected to specify a security zone architecture requiring logical isolation of passenger internet traffic from operational control systems once adopted, with first publication anticipated around mid-2026.
Beyond these segmentation requirements, an operator’s choice of access point hardware, routing appliances, and subscriber management software is commercially determined and not standardised.
Regulatory and commercial context
No EU regulation mandates onboard Wi-Fi provision on passenger trains — in contrast to the minimum accessibility and safety provisions encoded in the Passenger Rights Regulation. Operators deploy it as a commercial service, with investment decisions driven by passenger expectations, competitor services, and the cost of trackside coverage.
Intercity and high-speed operators across Europe have moved to treat Wi-Fi as a standard feature; provision remains less consistent on regional and commuter services.
FRMCS is expected to improve the consistency of broadband connectivity along rail corridors as infrastructure managers deploy 5G networks for safety-critical purposes — a deployment which operators can also use for passenger services in parallel.

