prEN 50742
prEN 50742 is a draft European machinery cybersecurity standard for protection against corruption. It is useful as technical planning material, but it should not be described as a final European Standard, harmonised standard, or OJ-cited route until that status is true.
Draft status
This document is not a European Standard. It is distributed for review and comments. It is subject to change without notice and shall not be referred to as a European Standard.
prEN 50742:2025 draft warning
The CEN-CENELEC 2025 work programme says CLC/TC 44X will continue work on EN 50742, Safety of machinery - Protection against corruption, and that the standard will support the Machinery Regulation by addressing protection against data corruption that could lead to safety-related issues. That public statement confirms the work item direction, not a final harmonised status.
Draft structure
The local draft is not only a control list. It gives a safety-led structure that starts with machinery risk assessment and then adds protection against corruption, process requirements, product requirements, intervention evidence, software/configuration identification, and information for use.
The draft covers protection against corruption for machinery, related products, and partly completed machinery, referred to in the draft as machinery. It focuses on hardware components, interfaces, software, and data if they could influence machinery safety.
The local draft also says interfaces to external systems and services are in scope, while the external systems and services themselves are out of scope.
The draft common path starts from ISO 12100 risk assessment, protection against corruption, and information for use. That keeps cybersecurity tied to machinery safety rather than a separate IT baseline.
Approach A is the machinery-specific route for manufacturers that are not using the EN IEC 62443 series as the basis for the machinery cybersecurity work.
Approach B maps the draft to EN IEC 62443-3-3, EN IEC 62443-4-1, and EN IEC 62443-4-2 for machinery systems, secure development, and machinery components.
Connections and interfaces
The draft treats a connection as physical, logical, or indirect when it can exchange information. Its examples include network links, Wi-Fi, single wires, power-supply wires, optical links, card-reader interfaces, building networks, cloud services, and service tools.
This broad interface view is useful because Annex III section 1.1.9 refers to another connected device and to remote devices that communicate with the machinery or related product. The safety question is still whether the connection can lead to a hazardous situation.
Approach A and Approach B
The local draft presents two routes. Approach A uses machinery-specific process and product requirements. Approach B uses EN IEC 62443-4-1 for process requirements and maps product requirements to EN IEC 62443-3-3 and EN IEC 62443-4-2.
Approach A
Best read as the draft machinery-specific route for protection against corruption without relying on the EN IEC 62443 series as the main structure.
Approach B
Best read as the draft mapping route for machinery developed in an IEC 62443 system, component, and secure-development context.
Intervention evidence and logs
The draft gives more detail than the Regulation on intervention evidence. It points to safety parameterisation, safety-related embedded software updates, safety-related application software updates, HMI parameterisation that can create hazards, and software relevant for displaying safety instructions.
Minimum evidence
The local draft expects an indication of the intervention type and correlation information such as timestamping or counters.
Deletion visibility
The local draft includes deletion of the log file as evidence to be recorded.
Readable evidence
The draft expects digital intervention evidence to be readable and accessible, with binary formats documented for interpretation.
Protected storage
The draft expects logs to be protected against tampering and deletion to be possible only through an authorised procedure.
Information for use
The draft information-for-use section is short but important. It points to the security context for the machine, software versions and configuration information relevant for safety functions, instructions for accessing that information and changes to it, and permission or prohibition of modifications.