Frequently Asked Questions
These questions cover the machinery cybersecurity boundaries that are easiest to misread: product scope, software, protection against corruption, draft standards, IEC 62443, and software change.
Source boundary
The legal source is Regulation (EU) 2023/1230. prEN 50742 and IEC 62443 can support evidence, but their role depends on edition, publication status, certificate scope, and whether a harmonised-standard reference has been cited for the relevant legal requirement.
Product and scope
No. The Machinery Regulation question is safety. A connection matters when corruption through that connection can affect a safety function, protective measure, critical data, or intervention evidence.
Yes, when the software performs a safety function or changes a safety-related control path. Software that only supports business administration is outside the machinery safety file unless it can affect the machinery as a safe product.
Cybersecurity and standards
It is the Annex III cybersecurity anchor. The file should show how the product resists corruption of connected devices, software, data, configuration, and intervention evidence when that corruption can create a hazardous situation.
A draft standard is useful technical input, but it should not be described as a final harmonised standard. Claims about presumption of conformity need the final standard, the legal requirement it covers, and the relevant Official Journal citation.
No by itself. IEC 62443 can support secure development, component, service, or system evidence. The machinery file still has to connect that evidence to the product, hazard, safety function, and Annex III requirement.
Change and evidence
Not always. The file should be revisited when an update changes a safety function, parameter, protective measure, interface, log, or evidence needed to show protection against corruption.
Only if the incident path can affect machinery safety. A compromise of an ERP system, office network, or reporting dashboard is not machinery cybersecurity evidence unless it can change or corrupt the machinery, safety data, configuration, or control path.