
Cybersecurity
Machinery cybersecurity: what manufacturers need to know
What machinery manufacturers need to know about cybersecurity, Machinery Regulation (EU) 2023/1230, IEC 62443 and network security.
Machinery cybersecurity is no longer an issue reserved for IT departments. When a machine connects to a network, receives software updates, communicates with MES or SCADA systems, permits remote access or includes diagnostic functions, a cyber event can directly affect functional safety and operator protection.
Manufacturers must distinguish corporate cybersecurity from product cybersecurity. The first concerns the organisation, its networks and internal processes. The second concerns the machine placed on the market: its architecture, software, access controls, updates, logs, protection of safety functions and technical documentation.
Why cybersecurity concerns machine safety
A cybersecurity vulnerability can become a machinery risk when it allows unauthorised changes to parameters, control logic, recipes, speeds, thresholds, safety functions or operating modes. The issue is not limited to data loss: the machine may behave in a hazardous way.
Cybersecurity must therefore be included in the risk assessment whenever a digital system can influence a safety-related function. Not every cyber vulnerability creates a safety risk, but the manufacturer must assess every vulnerability that could degrade safety. Reference
Requirement 1.1.9 of the Machinery Regulation
Regulation (EU) 2023/1230 introduces the 1.1.9 requirement dedicated to protection against corruption. The manufacturer must design the machine so that connection to another device, network or remote system does not cause hazardous situations due to accidental or intentional corruption.
This requirement is also closely linked to the safety of control systems. If an unauthorized attack or modification may alter a safety function, the theme must be treated together with the safety design, validation and software documentation.
NIS2, Cybersecurity Act, CRA and Machinery Regulation: Different Roles
Several European instruments apply, but their roles must not be confused. The NIS2 Directive addresses the cyber resilience of critical and important entities and sectors. The Cybersecurity Act establishes a European cybersecurity certification framework. The Cyber Resilience Act introduces horizontal requirements for products with digital elements. The Machinery Regulation, by contrast, addresses cybersecurity from the perspective of machine and operator safety. The CRA entered into force on 10 December 2024; its main obligations apply from 11 December 2027, while reporting obligations apply from 11 September 2026.
The Machinery Regulation defines product safety requirements, while other European standards and acts help build a consistent system of security by design, managing vulnerabilities, updates and response to accidents.
EN 50742:2025 and machinery security
EN 50742:2025 addresses the protection of machinery against corruption of data and software that could impair safety functions. It does not replace machinery risk assessment; it helps connect assets, threats, protection requirements, technical measures and verification evidence.
The assessment must consider the complete system: architecture, communications, access, maintenance, updates and lifecycle. The IEC 62443 series may provide complementary elements where required by the context, but it is not the reference applied by the Waves service.
A machinery-specific reference
EN 50742:2025 is published and addresses corruption-protection measures relevant to requirements 1.1.9 and 1.2.1 of Annex III to the Machinery Regulation. Publication does not automatically mean harmonisation: any presumption of conformity depends on citation of the reference in the Official Journal of the European Union.
The method requires relevant assets to be identified, threats that may affect safety to be assessed, protection measures to be defined and verification to be documented. Methods from the IEC 62443 series may be considered only where they are consistent with the project and its applicable requirements.
What a connected machine manufacturer needs to do
- Map all digital interfaces and machine assets: network, ports, remote access, software, HMI, cloud, diagnostics.
- Identify which digital functions can affect machine safety.
- Integrate risk of corruption into risk analysis and technical file by determining SRSL (or SL) levels Reference
- Define technical measures: authentication, segregation, hardening, backup, log, version management, protected access.
- Validate that a predictable cyber event cannot degrade safety functions.
- Create instructions for use and maintenance with information related to cybersecurity such as software update and access management.
Frequently Errors
treat cybersecurity only as a user's IT problem
leave standard remote access, weak passwords or shared credentials
not document software versions and modifications
not to distinguish machine network, plant network and safety network
do not include cyber risk in risk analysis when it can compromise safety
provide insufficient instructions for backup, updates and restore.
How Waves Engineering supports manufacturers
Waves Engineering helps manufacturers integrate cybersecurity and machinery safety in a practical way. We analyse architectures, connections, safety functions, access and documentation, then develop a matrix of risks and technical measures for inclusion in the technical file.
Our goal is to ensure that protection against corruption is considered in the design, documentation and validation of the potentially hazardous machine assets and make it possible to demonstrate that the machine has been designed to withstand foreseeable corruption scenarios that could compromise safety.
FAQ
Is cybersecurity mandatory for all machines?
Not the same way. It becomes central when the machine is connected, can receive updates or is remotely controlled or when software and network can affect safety-related functions.
Which reference should be used for machinery security?
For corruption-related aspects that may affect safety, Waves refers to EN 50742:2025 and to the applicable requirements of the Machinery Regulation and Cyber Resilience Act. Other standards may be considered where required by the market or contract.
Is the NIS2 about the machine product?
NIS2 primarily concerns entities and organisations. However, it can influence the requirements imposed by industrial customers on machine suppliers, especially in critical or important sectors.



