When infrastructure managers talk about replacing relay interlockings with computer-based ones, the conversation usually starts with technology: which computer, who could provide it, and how to do the safety engineering. That’s the wrong starting point. The right one is a governance question: how do we make sure we can change parts ten or even twenty years from now?

A poll conducted during our 2026 February webinar on relay-to-PLC replacement at Stockholm Metro put numbers to something many infrastructure managers already sense. Asked what they recognize from their own situation, 59% of respondents said they are concerned about lock-in and oligopoly. Meanwhile, 45% are actively considering relay-to-PLC migration, and 41% already know engineering firms capable of handling PLC systems.

Read together, those three numbers describe a market that is moving but moving into terrain where the same problem could simply reappear in a different form.

The pitfall of long support agreements

Relay systems are aging out: fewer spare parts, shrinking pools of relay engineers, rising cost to keep legacy running. The pressure to modernize is real and growing across European metro and rail networks.

There is a temptation to replace a relay-based interlocking with a computer-based one from a well-established vendor, under a long-term maintenance agreement, with proprietary software and hardware. This enables you to relax and trust that your supplier will handle everything. But you have locked yourself in: if you want to add a signal or a crossover somewhere, you cannot ask the open market for bids; you need to turn to your original supplier, because the support agreement gives them a monopoly. And after a few decades, the technology might be end-of-life, forcing you to do a “big bang” replacement; and the cycle begins again.

Open Signaling is the planning discipline that interrupts that cycle.

What Open Signaling actually means in practice

The term can sound like an aspiration or a vendor pitch. It is neither. It is a culture of architectural decisions made at the beginning of a project that determines whether the system remains maintainable without lock-in over its lifetime.

Three principles underpin it

Open interfaces. Standard interfaces can be used by many. Components that communicate via standard interfaces can be replaced with entirely different brands, as long as the interface is maintained. Examples include industry automation standards such as OPC UA and MQTT, as well as rail-specific, more recent ones such as EULYNX/RaSTA. Even standard data formats such as railML help, because many tool suppliers can use railML.

Modularity. When the hardware platform and signaling logic are kept independent, it becomes possible to upgrade the logic after an infrastructure change without a full system redesign. And even better, if the hardware is divided into loosely coupled components, it becomes possible to replace one of the components without redoing the full safety argument. That requires a safety assessment of each component and a system safety argument that builds on the module properties so that if a module is replaced with one with the same properties, the system safety argument still holds.

COTS hardware (commercial off-the-shelf). That is, components that are available on the market and preferably with equivalent ones from other vendors so that you don’t become too dependent on one of them. 

The Stockholm Metro pilot: designed for replaceability from day one

We are currently working on a pilot project for the Stockholm metro. The goal is to replace a relay-based interlocking with a PLC-based one so that train drivers and traffic managers notice no difference. No new features or improvements, just a pure migration to digital technology. 

Our first step was to invite providers of off-the-shelf standard industrial PLCs at the highest safety integrity level that is required for signaling systems. There is a suitable standard, IEC 61131, that defines what a PLC is, but we also require that they be CENELEC SIL 4 certified.

We planned the project so that it would be possible to switch over between the old relay-based solution and the new PLC-based one. This enables commissioning without the risk of an irreversible cutover: test it, verify it, revert if needed. It changes the risk profile of the entire project.

The logic portability approach addresses a gap in IEC 61131. The standard exists, but vendors implement dialects, serialization formats differ, and I/O configuration methods vary across platforms. Our strategy to handle I/O variations became to design a hardware interface adapted to the PLC we chose and to do it in such a way that the hardware interface could be redesigned if the PLC model would be replaced in the future. On the software side, we based the process on code generation. That will allow us to generate new code adapted to a new PLC if we need to change models.

To achieve replaceability, it is important to work with modularity and loose coupling, to minimize cross-dependency and lock-in.

Why the starting point matters

37% of webinar respondents said they need stronger technical ownership and control. They are not asking for more internal engineering capacity. They are asking for the ability to understand what they own, manage change without lock-in, and retain leverage in future procurement decisions. That is only possible if the architecture is designed to support it from the start.

The poll results taken together sketch the situation clearly: the pressure to modernize is real, the engineering capacity to execute exists or can be assembled, and the fear of lock-in is the dominant strategic concern. Open Signaling is the framework that turns that fear into a strategy, one that guides from the first technical decisions.

Learn more about open signaling at opensignaling.org.

Share this article

Learn to build a solid safety case for rail control systems using formal verification

Fill out your information here.

Do you want news and upcoming events from Prover?

Fill out your information here.

More News & Articles