CNN Robotics Automation logo
<- Back to blogs

Blog Post

Industrial Robot Safety & Cybersecurity in Europe

31 Aug 2026 CNN Robotics ApS 10 min read

European robot projects now sit at the intersection of machine safety, CE responsibilities and OT cybersecurity. This practical guide explains ISO 10218:2025, cobot risk assessment, NIS2, CRA and the EU Machinery Regulation for manufacturers.

Industrial Robot Safety & Cybersecurity in Europe

Industrial Robot Safety & Cybersecurity in Europe

Installing a robot in a European factory is no longer only a question of payload, reach, cycle time and return on investment. Modern cells are connected systems linking robots with PLCs, HMIs, vision, production networks, engineering laptops and remote-service tools.

That creates two linked engineering challenges: physical safety and digital security. Poorly controlled connectivity can affect production availability and, in some cases, safety-related machine behaviour.

For manufacturers planning robotic welding, machine tending, palletising, assembly or inspection systems, the practical lesson is simple: safety, cybersecurity and conformity responsibilities should be defined during engineering, not added after commissioning.

This guide explains the key EU rules, standards and project decisions European manufacturers should consider before the design is frozen.

Safety and cybersecurity increasingly intersect in connected robotic production systems.

Start by separating law, standards and engineering practice

Start by separating legal requirements, technical standards and recommended engineering practice.

EU machinery legislation sets legal requirements for machinery placed on the EU market or put into service. Regulation (EU) 2023/1230, the EU Machinery Regulation, generally applies from 20 January 2027 and replaces the Machinery Directive framework for machinery covered by the new Regulation.

CE marking is part of the EU product-conformity process. It is not an EU authority's safety certificate. The manufacturer is responsible for identifying applicable requirements, carrying out the appropriate conformity assessment, preparing required technical documentation and declarations, and affixing CE marking where required.

ISO 10218 addresses industrial robot safety. ISO 10218-1:2025 covers industrial robots, while ISO 10218-2:2025 addresses industrial robot applications and robot cells, including integration, commissioning, operation, maintenance and decommissioning.

ISO/TS 15066:2016 remains published and provides requirements and guidance for collaborative industrial robot systems and work environments. ISO marks it for revision, so it should not simply be described as obsolete.


NIS2 concerns cybersecurity risk management and incident reporting for qualifying organisations. The Cyber Resilience Act (CRA) primarily addresses cybersecurity requirements for products with digital elements. IEC 62443 is an important industrial automation and control-system cybersecurity standards family. These frameworks overlap in practical projects, but they are not the same legal obligation.

Industrial robot safety: assess the complete application

The 2025 editions of ISO 10218 reinforce a core integration principle: the robot arm is only one part of the risk picture.

Consider a robotic welding cell. The complete application can include the robot, welding torch, power source, fixtures, positioners, fume extraction, guarding, safety devices, PLCs, operator stations and material handling. Hazards can come from motion, crushing points, hot parts, arc radiation, fumes, tooling, stored energy and access during fault recovery.

A machine-tending cell can create trapping points between the robot, CNC machine, fixture and workpiece. Palletising and food-production cells add access, load, hygiene and maintenance considerations.

ISO 12100 remains a key general reference for machinery risk assessment and risk reduction. [6] The practical objective is to assess the complete machine and reasonably foreseeable use, not to treat the robot's safety specification as the end of the process.

Do not confuse the newest ISO edition with EU harmonisation status

For European conformity work, one technical detail matters: the newest ISO edition and EU harmonisation status are separate questions.

As checked on 1 September 2026, the current EU harmonised-standards list under the Machinery Directive still cites EN ISO 10218-1:2011 and EN ISO 10218-2:2011. [7] The 2025 ISO editions are the current international technical standards, but they do not automatically have the same presumption-of-conformity status under the existing Machinery Directive framework.

For a real project, the standards strategy should therefore be checked against the date the machinery will be placed on the market or put into service, the applicable legislation, the current Official Journal references, the actual machine design and any contractual requirements.

A cobot is not a safety strategy

A common mistake in collaborative robotics is to assume that buying a cobot removes the need for a risk assessment or guarding.

It does not.

The correct question is whether the complete collaborative application can operate at an acceptable level of risk for the intended human interaction. The assessment may need to consider the end effector, payload, workpiece geometry, accessible pinch points, speed, force, stopping behaviour, operator position, loading and unloading, cleaning, maintenance and fault recovery.

A cobot welding application is a clear example. Collaborative functions in the robot do not remove hazards from heat, arc radiation, welding fumes, sharp workpieces or the welding torch. An automotive handling application may also need additional protective measures if the robot carries a heavy or sharp-edged part.

The application determines the safeguarding concept. "Cobot" should describe the technology, not substitute for safety engineering.

CE marking: define responsibility before the project starts

Automation projects often combine equipment from multiple suppliers: robots, grippers, conveyors, welding equipment, machine tools, vision systems, PLCs, safety controllers, guarding, custom fixtures and software. Individual components may arrive with their own declarations or instructions, but that does not automatically complete the conformity process for the integrated machine.

Before detailed engineering starts, define the responsibility boundary. Key questions include:

Who will act as the manufacturer of the completed machinery?

Who owns the overall risk assessment?

Who prepares the required technical documentation and declaration?

Who validates safety functions and records the evidence?

Which supplied subsystems are partly completed machinery or separately CE-marked products?

What happens if the machine is modified after handover?

Unclear responsibility creates redesign, handover and liability problems. Make ownership explicit before commissioning pressure begins.

The EU Machinery Regulation makes cybersecurity a machinery issue

The EU Machinery Regulation makes the connection between machinery safety and cybersecurity clearer. Annex III includes requirements on protection against corruption and addresses connections to other devices, including remote connections, where interference could lead to hazardous situations. It also addresses protection of hardware, software and data that are critical to safety requirements. [1]

This matters for connected automation: welding cells may allow remote controller access, palletising lines use networked PLCs and HMIs, and automotive workstations can depend on software across several devices.Cybersecurity therefore is not relevant only because production data could be stolen. If an unauthorised change can alter a safety-related function or machine behaviour, cybersecurity becomes part of the safety engineering discussion.

NIS2: does it actually apply to your manufacturing company?

NIS2 is often described too broadly. It does not automatically apply to every factory that uses robots.

At EU Directive level, applicability depends on factors including the entity's activity, sector, size and other criteria, and the Directive is implemented through Member-State legislation. [8] Some food businesses involved in industrial production and processing and certain manufacturing categories, including machinery and motor vehicles, are listed in Annex II. Actual applicability still needs to be checked for the specific organisation and national implementation.

For an in-scope organisation, NIS2 requires appropriate and proportionate technical, operational and organisational cybersecurity risk-management measures. Relevant areas include incident handling, business continuity, supply-chain security, vulnerability management, access control, asset management and multi-factor authentication where appropriate. [8]

A robot integrator cannot make an entire manufacturer "NIS2 compliant" by configuring one cell. But the automation architecture can either support or undermine the manufacturer's wider OT security programme. Cybersecurity requirements therefore belong in the project specification.

Cyber Resilience Act: product cybersecurity becomes a lifecycle issue

The Cyber Resilience Act applies to hardware and software products with digital elements made available on the EU market, subject to its scope and economic-operator rules. [9]

The dates are especially relevant in late 2026. CRA reporting obligations under Article 14 apply from 11 September 2026, while the Regulation becomes fully applicable from 11 December 2027. [9][10]

For automation buyers, the point is not that every installed robot becomes a CRA project. Product cybersecurity, vulnerability handling, software support and supplier responsibilities increasingly matter when selecting connected components. Ask how vulnerabilities are communicated and updates are managed without destabilising production.

Practical OT cybersecurity for a robot cell

Good OT cybersecurity starts with practical engineering controls rather than slogans.

Know what is connected. Maintain an inventory of robot controllers, PLCs, safety controllers, HMIs, industrial PCs, cameras, engineering workstations, switches, gateways and remote-access equipment. Record relevant software and firmware versions where they matter for maintenance and recovery.

Limit unnecessary exposure. Robots and PLCs rarely need unrestricted access to the corporate network. Use segmentation and controlled communication paths that match the production requirement. IEC 62443 provides a useful industrial-security framework for this type of architecture. [11]

Engineer remote access. Define who can connect, how identity is verified, what assets are accessible, whether sessions are approved and logged, and how access is removed when no longer needed. Permanent shared credentials should not become the default because they are convenient during commissioning.

Plan changes and updates. Industrial automation cannot always be patched like office IT. Firmware and software changes can affect communications, compatibility, validated behaviour and production availability. Use a risk-based process to assess, test and deploy changes.

Protect configuration and recovery. Robot programs, PLC projects, safety settings, HMI configurations, recipes and vision parameters can be production-critical. Apply role-based access where appropriate and maintain tested backups so a cell can be restored after failure or corruption.

Documentation and lifecycle ownership matter after commissioning

A successful factory acceptance test is not the end of the lifecycle. Machines change, products change, operators change and software is updated.

Depending on the project and applicable requirements, controlled documentation may include risk assessments, applied standards, electrical and control drawings, safety concepts, validation results, software or firmware identification, operating instructions, declarations from incorporated equipment, maintenance information and backup/recovery records.

Change control matters as well. If a customer later changes a gripper, adds a new product, modifies PLC logic or opens a new remote-access path, the impact on safety, cybersecurity and conformity responsibilities should be assessed rather than assumed.

Safety and cybersecurity decisions are most effective when addressed across the automation project lifecycle.

CNN Robotics' engineering approach

CNN Robotics' documented capabilities include industrial robot and cobot integration, PLC and control-system integration, vision, custom fixtures and machines, simulation, installation, commissioning and after-sales support.

For European projects, the strongest engineering approach is to connect these disciplines early. Production requirements such as cycle time and quality should be considered alongside machinery hazards, safety functions, controls architecture, IT/OT interfaces, remote support and handover responsibilities.

CNN Robotics should not be presented as a legal adviser, notified body or provider of a blanket NIS2/CRA compliance guarantee unless such services and qualifications are separately established. The practical value is engineering the automation system with clear boundaries and requirements from the start.

This is particularly relevant in CNN Robotics' priority sectors. In welding and metal fabrication, the cell may combine robots, welding processes, fixtures and operator access. In food manufacturing, hygiene, frequent intervention and end-of-line connectivity can affect the design. Automotive Tier 1 and Tier 2 projects often add traceability, quality systems, production-network integration and strict handover requirements.

Questions to answer before approving a robot project

Before approving a new robot project, manufacturers should be able to answer a short set of questions:

Who is responsible for the completed machinery and conformity process?

Which legislation and standards apply at the planned commissioning date?

What hazards come from the complete application, including maintenance and fault recovery?

If the system is collaborative, what human-robot interaction is actually intended?

Which devices connect to production or corporate networks?

Who needs local or remote engineering access, and how will it be controlled?

Who owns the robot, PLC, HMI and safety credentials after handover?

How will software, firmware and configuration changes be assessed and documented?

What will be backed up, and has recovery been tested?

What safety, technical and cybersecurity documentation must be delivered at handover?

If several of these questions remain unanswered late in the project, the design is carrying avoidable risk.

Frequently asked questions

Is a cobot automatically safe without guarding?

No. Safety depends on the complete collaborative application, including tooling, payload, workpiece, speed, force, access, process hazards and foreseeable intervention. A risk assessment is still required.

What is the current ISO 10218 standard?

ISO 10218-1:2025 and ISO 10218-2:2025 are the current international ISO editions. For EU conformity work, manufacturers should separately check which harmonised standards are currently cited under the applicable machinery legislation.

Does NIS2 apply to every European manufacturer?

No. NIS2 scope depends on factors including sector, activity, size and national implementation. Some food and manufacturing activities are listed in the Directive, but each organisation should confirm its own legal position.

Build safety and cybersecurity into the project definition

Safety and cybersecurity should not be treated as two checklists added after a robot cell has already been designed.

The better approach is to define the production process, hazards, responsibilities, connectivity and lifecycle requirements together. That reduces late-stage redesign and gives production, engineering, EHS and IT/OT teams a common basis for decision-making.


Planning a new robot cell or upgrading an existing production line in Europe?

CNN Robotics can discuss the manufacturing process, automation concept, system interfaces and project boundaries with your engineering team

before the design is locked.

Discuss Your Automation Project

View Automation Projects


WhatsApp CNN Robotics Automation