Six months to go before the new European Machinery Regulation takes full effect. From 20 January 2027, manufacturers and users of machinery, robots included, will need to demonstrate that safety and security go hand in hand. At its annual press conference, safety specialist Pilz laid out what this means in practice for anyone deploying, integrating or operating robots.
Managing Partner Thomas Pilz opened the conference with a message that ran through the whole session: the German word “Sicherheit” covers both safety and security, and in regulatory terms the two are now converging for good. Alongside the Machinery Regulation, he pointed to the NIS2 Directive and the Cyber Resilience Act, which together establish that cybersecurity is no longer optional for control and safety systems. For machine manufacturers and operators within the EU, this translates into stricter, and in some cases entirely new, requirements on both security and safety if they want to keep access to the European market.
Pilz also flagged a very current risk: AI models capable of exploiting vulnerabilities on their own. For the safety functions of machinery, and certainly of humanoid robots, that scenario can never be allowed to occur. Securing AI-driven functions is therefore becoming an explicit focus within safety development itself.
The Machinery Regulation: what changes for users?
Jürgen Bukowski, senior manager consulting at Pilz, outlined the core of the regulation. A few points that are directly relevant for users and integrators of robots:
- Security by design, for users too. Assessing machine risk alone is no longer enough. Manufacturers must define how updates are handled, who gets access, and under what conditions secure remote access is allowed, and users must in turn be able to show they comply with those rules.
- Digital documentation is now mandatory. The familiar ten-year retention period for technical documentation still applies, but that documentation must now also be available in digital format.
- Combining robots can make you a manufacturer. If a company buys multiple machines or robots and links them together, that combination can qualify as a “new machine.” The integrator or end user then becomes the (co-)manufacturer in the eyes of the law, with all the accompanying CE obligations. The same applies if an end user makes a substantial modification to an existing machine.
- Testability of safety functions. Manufacturers must specify how end users can test safety functions themselves, so that safety remains demonstrable throughout the machine’s entire life cycle.
Bukowski illustrated this with an example from the pharmaceutical industry: an Asian OEM supplies machine modules to a European end user, who then assembles the modules themselves. Each module carries its own CE mark, but the end user combining them may need to carry out their own safety assessment of the assembly, and could become (co-)responsible for the CE marking of the whole. The takeaway: manufacturer and end user need to coordinate much more closely from the outset, including on documentation and security arrangements such as update management.
Security architecture: zones, conduits and network separation
Andreas Willert, industrial security specialist at Pilz Austria and a member of a relevant standards committee, went deeper into the technical implementation. At the heart of it lies the zones and conduits principle: the network is divided into zones, with controlled transitions between them, enabling a layered “defense in depth” strategy. The IEC 62443 series and the emerging prEN 50742 provide the framework for this.
For robot users, the practical recommendation is clear: keep safety functions strictly separated from the standard automation network, both organisationally and technically. Benefits Willert mentioned include:
- Safety functions remain unaffected by updates, bugs or attacks in the standard part of the network.
- Less duplicated effort for certification and maintenance.
- Less in-depth security knowledge required from operators, since the architecture itself provides the protection.
- Components without network capability, such as certain safety relays, are inherently immune to remote attacks.
Status of the prEN 50742 standard
Asked from the floor, Willert gave a concrete timeline: the text of the new harmonised standard prEN 50742 (164 pages) is content-complete. The formal vote by national standards committees is scheduled for September 2026, with publication expected in November 2026, just in time to appear in the EU’s Official Journal before the Machinery Regulation becomes applicable.
Compliance as an ongoing process: from manufacturer to operator
According to Bukowski, compliance is shifting from a one-off exercise to a continuous process that stays with the end user after delivery: risks and security aspects need to be reassessed on an ongoing basis, with validations and inspections. Pilz presented its life-cycle platform MYZEL (SaaS) for this purpose, which:
- supports risk assessments in line with ISO 12100, including an AI feature that suggests risks and possible mitigations based on a photo of the machine (always to be validated by a competent person, product manager Marco Fritzmann stressed);
- centrally manages digital documentation and certificates, with automatic notifications when inspections or certificates are about to expire;
- works with a digital twin that travels with the machine when it is handed over to the end user;
- also applies to existing machinery (“brownfield”), not just new installations, as Christoph Baumeister confirmed during the Q&A.
Access management: who is allowed to do what, on which machine?
Baumeister, responsible for identity and access management at Pilz, highlighted an often-underestimated aspect of the Machinery Regulation: protection against tampering also requires being able to prove who has access to a machine, and whether that person is qualified to use it. Alongside the Machinery Regulation, some countries have additional requirements: in Germany, for example, the Work Equipment Directive already requires a role-based access system with authentication.
Where this used to be managed with mechanical keys, password notes and paper certificates, hard to track and error-prone, Pilz advocates digital identification (RFID badges, digital qualification certificates with expiry dates) linked to a central system. This allows those responsible for production to demonstrate at any time that only authorised, qualified personnel have worked on a machine, complete with an audit log of who accessed it and when.
What does this mean for the robotics sector?
Pilz’s message to integrators, system builders and operators of robot installations is clear: whoever combines robots into a cell or line can legally become a manufacturer and take on CE responsibility themselves. Security measures, network segmentation, access management, update policy, are no longer “nice to have” but a precondition for the safety functions of a robot cell to hold up. And documentation that used to end up in a filing cabinet now has to be digital, current and retrievable for ten years.
With the 20 January 2027 deadline in sight, Pilz’s advice to companies that aren’t fully ready yet is to start with the basics now: segregate safety and control circuits, put password policies and change management in place, and build up from there towards full compliance with the Machinery Regulation.
