Functional Safety in Manufacturing: ISO 13849, IEC 62061 and the January 2027 Deadline
Functional safety in manufacturing works differently from functional safety in process plants, and manufacturers who borrow process industry practice usually produce documentation that machinery assessors do not accept. Machinery uses ISO 13849 and IEC 62061 rather than IEC 61511, measures capability in Performance Levels as well as SILs, and is governed in Europe by product regulation rather than by operator process safety rules.
That regime changes on 20 January 2027, when Regulation (EU) 2023/1230 replaces the Machinery Directive and becomes directly applicable law. For the first time, machinery legislation contains express provisions on safety-relevant cybersecurity and on systems with self-evolving behaviour. Any manufacturer placing machinery on the EU market, including North American exporters, needs to be ready. If you are unsure which standards govern your equipment at all, start with our guide to functional safety standards.
ISO 13849 or IEC 62061: Which One
Both are recognized routes for machinery safety-related control systems, and either can demonstrate conformity. The practical choice comes down to technology and to what your customers and assessors expect.
|
ISO 13849 |
IEC 62061 |
|
|
Measures |
Performance Level, PL a to PL e |
Safety Integrity Level, SIL 1 to SIL 3 |
|
Best suited to |
Mixed technology including hydraulic, pneumatic and mechanical |
Complex programmable electronic control systems |
|
Method |
Category, MTTFd, diagnostic coverage, common cause |
Architectural constraints, PFHd, systematic capability |
|
Commonly used by |
Most machine builders, general machinery |
Machinery with substantial software and electronic control |
Neither is superior. Applying both to the same safety function, which some manufacturers attempt in order to satisfy varied customer specifications, generally produces contradictory evidence rather than broader coverage.
What the EU Machinery Regulation Changes
Regulation (EU) 2023/1230 repeals Directive 2006/42/EC with effect from 20 January 2027. Most existing harmonized standards carry over, so machinery conforming to current standards will in most cases retain presumption of conformity. The substantive changes sit elsewhere.
- Cybersecurity becomes a safety requirement. Where connectivity, remote access, software updates or configuration changes can affect a safety function, that is now a legal obligation rather than an IT concern.
- Self-evolving behaviour is addressed explicitly. Machinery with machine learning that changes its own behaviour carries specific requirements, a first in machinery legislation.
- Digital documentation is accepted. Physical declarations of conformity are no longer mandatory.
- Substantial modification is clarified. When a modification makes you the manufacturer of a new machine is more explicitly defined, which matters for anyone upgrading installed equipment.
|
Why this is harder than it looks The cybersecurity provisions do not ask you to secure your factory network. They ask whether any digital function can change the behaviour of the machine, the control system, or a safety function, and put a person into a hazardous situation. Answering that requires someone who understands both the safety function and the attack surface. Most machinery consultancies have the first competence and not the second. |
Where Safety and Cybersecurity Now Meet
The regulation effectively forces machine builders into territory that process industry operators entered through IEC 61511 Clause 8.2.4, which requires a cybersecurity risk assessment as part of the safety lifecycle. The mechanism differs but the question is identical: can a cyber event defeat a safety function.
For machinery, the practical answer involves applying IEC 62443 principles to the machine control architecture, assessing whether remote access and update paths can reach safety-related control, and documenting the analysis alongside the risk assessment. Our guide to how IEC 61511 and IEC 62443 work together covers the underlying method, which transfers directly.
What Manufacturers Should Do Before January 2027
- Confirm which of ISO 13849 or IEC 62061 you are working to for each safety function, and stop applying both
- Review harmonized standard citations as they publish, since the first batch under the new Regulation was expected during 2026
- Identify every digital function that can influence a safety function: remote access, update paths, configuration, connectivity
- Document the cybersecurity analysis alongside the machine risk assessment rather than separately
- Check whether any installed-base modification program makes you the manufacturer of a new machine
- Confirm your technical file can be produced digitally
Why Choose Arista Cyber
Arista Cyber works across functional safety and OT cybersecurity as a single engineering discipline, which is precisely what the new Machinery Regulation now requires. Our practitioners are TUV Rheinland certified in functional safety and work daily in IEC 62443 environments.
For manufacturers, that means the safety analysis and the cybersecurity analysis are produced by the same team against the same architecture, rather than by two suppliers whose documents have to be reconciled afterwards. We also work extensively across manufacturing OT environments, so the recommendations account for how machines are actually operated and maintained.
Next Steps
If you place machinery on the EU market, the practical first step is identifying which digital functions can affect a safety function. Explore our functional safety services, read about functional safety assessment stages, or contact the Arista Cyber team.
Common Questions
Does the EU Machinery Regulation apply to North American manufacturers?
Yes, if you place machinery on the EU market. The Regulation applies to the product rather than to the manufacturer location, so exporters are in scope regardless of where the machine is built. It becomes applicable on 20 January 2027.
Will our existing ISO 13849 documentation still be valid?
In most cases yes. The majority of existing harmonized standards are being carried over, so machinery conforming to current standards generally retains presumption of conformity. The gap is the new cybersecurity and self-evolving behaviour requirements, which existing documentation will not address.
Is cybersecurity now mandatory for CE marking of machinery?
Where a digital function can affect a safety function, yes. The Regulation frames it as a safety requirement rather than a separate cybersecurity obligation. Machines with no connectivity, remote access or updatable software that could influence safety behaviour are less affected.
|
Ready for the January 2027 machinery deadline? Arista Cyber delivers machinery functional safety and the cybersecurity analysis the new Regulation requires, from one engineering team. |