Digitalising a safety-critical instruction sounds like an IT project. When what is changing is how signallers and drivers communicate during a disruption, it is a testing and human-factors problem, and that is where these programmes are won or lost.
European Instructions are the standardised instructions a signaller issues to a driver when normal signalling cannot be relied on, authorising a movement past an end of authority, imposing a speed restriction, or handling a degraded situation. They are harmonised at European level in the OPE TSI. In the Netherlands the spoken aanwijzing from signaller to driver was withdrawn on 1 September 2023 and replaced by the harmonised European Instruction, on the model set out in TSI OPE 2023 (Appendix C2). Today they are passed by telephone.
Written from inside the programme. Erik van Bekkum, founder of Efios Rail, is the programme manager for the DEI (Digitalisering European Instructions) programme, a digitalisation initiative of ProRail Verkeersleiding (Traffic Control). DEI is not part of the ERTMS programme. GSM-R is used purely as the data bearer for the message; that is a transport choice, not an ERTMS function. This piece draws only on publicly published material, principally ProRail's own annual report and ERA documentation, and on general test-management practice.
What is actually being digitalised is the process, not the form. Under the programme the signaller creates and assigns the instruction through a digital interface; the driver receives an announcement on the GSM-R cab radio; the driver then retrieves the instruction, through an application, or by telephone where no device is available, and confirms it. Note what that means: the message is a notification that an instruction is waiting, not the instruction itself, and confirmation remains a spoken exchange in the first step. Digitalising the form would have been the easy half. The programme covers creating, announcing, retrieving, confirming, and the record that all of it leaves behind.
ProRail states the problem plainly in its 2025 annual report: "Bij verstoringen is er nog veel telefonische communicatie tussen treinverkeersleiders en machinisten. Dat kost tijd en is foutgevoelig.", during disruptions there is still a great deal of telephone communication between signallers and drivers; it costs time and is error-prone. The programme is being run with operators and suppliers, delivery is by SMS over the GSM-R radio network, and the expectation is roughly a 50% reduction in conversation time. A pilot has been under way.
This did not start as a technology proposal. ProRail and several railway undertakings ran an extended study between 2020 and 2022 into whether the European Instruction could be digitalised at all. It concluded that the business case was positive for operators and infrastructure manager alike, and that the technical route was viable. Only then did an initiation phase follow: a technical proof-of-concept for delivering SMS messages to a GSM-R cab radio, and practical tests with a range of railway undertakings. Those tests were as much about human factors as about the technology, which is the right order, and rarer than it should be.
The benefit is easy to state and easy to underestimate. Voice instruction under disruption is slow, it is serialised, one signaller can hold one conversation at a time, and it is the step where readback errors and misheard numbers enter the system. Removing it attacks delay minutes and a safety-relevant error path at once.
The technology here is not exotic. Preparing structured text on a workstation and delivering it to a cab radio is well-understood engineering. What makes the programme demanding is that it changes a safety-critical human procedure at precisely the moment when the humans involved are under the most pressure. Four things make it harder than it looks.
Degraded mode is the worst place to introduce a new interaction. European Instructions exist because something has already gone wrong. Workload is elevated, the situation is non-standard, and both parties are working from rules they use rarely. A new interface, introduced exactly there, has to be unambiguous on first use by someone who has not used it in months.
The bearer constrains the design. GSM-R is a narrowband, prioritised operational network, not a consumer data service. Delivery latency, message length, acknowledgement and what happens on failure are design parameters with operational consequences, not implementation details. The question "what does the signaller do when delivery cannot be confirmed?" has to have an answer that works at 02:00 in a real disruption.
Rules, training and technology have to move together. A digital instruction is only valid if the operational rulebook says it is, if drivers and signallers have been trained on it, and if the fallback to voice is defined and practised. The technical delivery can be finished and the change still not be usable.
It is a chain, not a component. The thing that has to work is signaller → system → radio network → cab → driver → acknowledgement. Every element can pass its own acceptance test while the chain still fails, because chain failures live in the handovers: timing, state mismatch, what the two ends believe about each other when a message is late.
Experience across infrastructure and rolling-stock test campaigns is that programmes of this shape fail in predictable places. The test strategy should be built around them from the start rather than discovered during the pilot.
Test the degraded scenarios, not the happy path. The happy path, instruction prepared, sent, received, acknowledged, is the easy case and it will pass early. The value is in the awkward ones: message delayed past relevance, driver changes cab mid-sequence, radio registration lost and regained, instruction superseded before acknowledgement, two instructions in flight at once. These are precisely the scenarios that are hardest to stage, which is why they get deferred, which is why they surface in service.
Decide what the acknowledgement means. There is a real difference between announced to the cab radio, retrieved by the driver, and confirmed by the driver. Voice procedure conflated all three through readback. Splitting announcement from retrieval separates them, and the operational rules have to say which step authorises the movement, a question that gets sharper, not easier, if confirmation itself later moves from spoken to digital.
Instrument the whole chain before the pilot, not after. If the only evidence from the pilot is anecdotal, it felt faster, there was a problem one evening, the pilot has cost time without producing findings. End-to-end timing and delivery data collected from day one turns a pilot into measurement.
Set the entry criteria for going live in human terms. Not merely "the system passes its tests" but "a signaller who has not touched this in six weeks can issue the right instruction correctly under load, and knows what to do when it fails."
One important distinction: the 50% figure is a benefit target, not an acceptance criterion. A change that halves conversation time while introducing one new ambiguity into degraded-mode communication is not a good trade. The measure that matters is whether the instruction the driver acts on is the instruction the signaller intended, every time, including when the technology does not cooperate.
The Netherlands is not doing this alone, and not doing it first for long. Other countries are introducing European Instructions and working on digitalising them, through the SFERA working group and the ERA's OH working group, and a European specification for digitalised European Instructions is expected within a few years. Any infrastructure manager who has looked at how much of disruption handling is spent on the telephone is looking at the same question, and will eventually be looking at the same specification.
That coming specification is itself an argument for doing the operational thinking now rather than later: the country that has already worked out what an announcement means, what a confirmation means and what it takes to test them is in a better position to shape a standard than to receive one.
The generalisable lesson is not about messaging technology. It is that when a programme replaces a human procedure rather than a piece of equipment, the centre of gravity of the risk moves from the technical specification to the operational concept, and test programmes that are structured around subsystems rather than around the chain will not find the problems that matter.
ProRail Jaarverslag 2025 — Informatie- en communicatietechnologie — the DEI programme, GSM-R delivery, the ~50% expectation and the pilot.
ERA — Application Guide for the OPE TSI — operational principles and rules, including European Instructions.
If a programme replaces a human procedure rather than a piece of equipment, the test strategy needs to be built differently. Efios Rail has run test and V&V programmes for ERTMS, high-speed and metro systems since 2002.