Robotics and Safety-Related Control
Robot cybersecurity analysis should stay tied to industrial robot safety. ISO 10218-1:2025 adds cybersecurity only to the extent that it applies to industrial robot safety, and the Machinery Regulation asks whether corruption can lead to a hazardous situation.
Robot product boundary
This document addresses robots as partly completed machinery as defined in ISO 12100.
ISO 10218-1:2025 introduction
ISO 10218-1:2025 addresses the robot. ISO 10218-2:2025 addresses robot applications and cells. This distinction matters for cybersecurity because the relevant corruption path may sit in the robot controller, teach pendant, safety-related parameter set, external control capability, cell integration, or application software.
The Machinery Regulation analysis should follow the product and integration boundary used for the conformity assessment. A standalone robot, a partly completed robot, and a complete robot cell can have different safety responsibilities and evidence.
Safety parameterisation
ISO 10218-1:2025 treats software-based parameterisation of safety-related application software as a safety-related aspect. Once a safety function is activated, the safety function must remain active on power-up, changes to settings need to be identifiable, and manual changes to safety-related parameters require a restart after the change.
For cybersecurity, this makes parameter integrity a central evidence point. The file should show which settings are safety-related, how changes are identified, and how unauthorised or accidental changes are prevented from creating a hazardous situation.
Safety communications
ISO 10218-1:2025 separates internal and external communication contexts for safety functions. It treats an internal robot communication network as a more controlled category and external networks as less controlled categories, depending on access and network trust.
- internal communication can still need countermeasures when it implements a safety function;
- external network capability can increase the need to address unauthorised access, delay, corruption, insertion, deletion, replay, or masquerade;
- the Machinery Regulation question remains the same: whether the communication path can lead to a hazardous situation.
Robotics evidence
The useful robotics evidence links the robot safety function to the cybersecurity path. A generic statement that the robot is connected, or that the factory network is segmented, is too loose unless it shows the effect on safe robot behaviour.
Version and configuration
Identify controller firmware, safety-related application software, safety parameters, and configuration identifiers.
Safety function effect
Link each relevant interface or update path to the motion, stop, mode, limit, or protective function it can affect.
Source status
ISO 10218-1:2025 is a final industrial robot safety standard. prEN 50742 remains a draft machinery cybersecurity standard. Regulation (EU) 2023/1230 is the binding legal source for protection against corruption in the EU Machinery Regulation context.