prEN 50742

prEN 50742 is a draft European machinery cybersecurity standard for protection against corruption. It is useful as technical planning material, but it should not be described as a final European Standard, harmonised standard, or OJ-cited route until that status is true.

Draft status

This document is not a European Standard. It is distributed for review and comments. It is subject to change without notice and shall not be referred to as a European Standard.

prEN 50742:2025 draft warning

The CEN-CENELEC 2025 work programme says CLC/TC 44X will continue work on EN 50742, Safety of machinery - Protection against corruption, and that the standard will support the Machinery Regulation by addressing protection against data corruption that could lead to safety-related issues. That public statement confirms the work item direction, not a final harmonised status.

Draft structure

The local draft is not only a control list. It gives a safety-led structure that starts with machinery risk assessment and then adds protection against corruption, process requirements, product requirements, intervention evidence, software/configuration identification, and information for use.

Connections and interfaces

The draft treats a connection as physical, logical, or indirect when it can exchange information. Its examples include network links, Wi-Fi, single wires, power-supply wires, optical links, card-reader interfaces, building networks, cloud services, and service tools.

This broad interface view is useful because Annex III section 1.1.9 refers to another connected device and to remote devices that communicate with the machinery or related product. The safety question is still whether the connection can lead to a hazardous situation.

Approach A and Approach B

The local draft presents two routes. Approach A uses machinery-specific process and product requirements. Approach B uses EN IEC 62443-4-1 for process requirements and maps product requirements to EN IEC 62443-3-3 and EN IEC 62443-4-2.

Approach A

Best read as the draft machinery-specific route for protection against corruption without relying on the EN IEC 62443 series as the main structure.

Approach B

Best read as the draft mapping route for machinery developed in an IEC 62443 system, component, and secure-development context.

Intervention evidence and logs

The draft gives more detail than the Regulation on intervention evidence. It points to safety parameterisation, safety-related embedded software updates, safety-related application software updates, HMI parameterisation that can create hazards, and software relevant for displaying safety instructions.

Minimum evidence

The local draft expects an indication of the intervention type and correlation information such as timestamping or counters.

Deletion visibility

The local draft includes deletion of the log file as evidence to be recorded.

Readable evidence

The draft expects digital intervention evidence to be readable and accessible, with binary formats documented for interpretation.

Protected storage

The draft expects logs to be protected against tampering and deletion to be possible only through an authorised procedure.

Information for use

The draft information-for-use section is short but important. It points to the security context for the machine, software versions and configuration information relevant for safety functions, instructions for accessing that information and changes to it, and permission or prohibition of modifications.

Sources