BLOG

Date
08-09-2026

Functional Safety

Functional Safety in Manufacturing: ISO 13849, IEC 62061 and the January 2027 Deadline

Functional safety in manufacturing works differently from functional safety in process plants, and manufacturers who borrow process industry practice usually produce documentation that machinery assessors do not accept. Machinery uses ISO 13849 and IEC 62061 rather than IEC 61511, measures capability in Performance Levels as well as SILs, and is governed in Europe by product regulation rather than by operator process safety rules.

That regime changes on 20 January 2027, when Regulation (EU) 2023/1230 replaces the Machinery Directive and becomes directly applicable law. For the first time, machinery legislation contains express provisions on safety-relevant cybersecurity and on systems with self-evolving behaviour. Any manufacturer placing machinery on the EU market, including North American exporters, needs to be ready. If you are unsure which standards govern your equipment at all, start with our guide to functional safety standards.

 

ISO 13849 or IEC 62061: Which One

Both are recognized routes for machinery safety-related control systems, and either can demonstrate conformity. The practical choice comes down to technology and to what your customers and assessors expect.

 

 

ISO 13849

IEC 62061

Measures

Performance Level, PL a to PL e

Safety Integrity Level, SIL 1 to SIL 3

Best suited to

Mixed technology including hydraulic, pneumatic and mechanical

Complex programmable electronic control systems

Method

Category, MTTFd, diagnostic coverage, common cause

Architectural constraints, PFHd, systematic capability

Commonly used by

Most machine builders, general machinery

Machinery with substantial software and electronic control

 

Neither is superior. Applying both to the same safety function, which some manufacturers attempt in order to satisfy varied customer specifications, generally produces contradictory evidence rather than broader coverage.

 

What the EU Machinery Regulation Changes

Regulation (EU) 2023/1230 repeals Directive 2006/42/EC with effect from 20 January 2027. Most existing harmonized standards carry over, so machinery conforming to current standards will in most cases retain presumption of conformity. The substantive changes sit elsewhere.

  • Cybersecurity becomes a safety requirement. Where connectivity, remote access, software updates or configuration changes can affect a safety function, that is now a legal obligation rather than an IT concern.
  • Self-evolving behaviour is addressed explicitly. Machinery with machine learning that changes its own behaviour carries specific requirements, a first in machinery legislation.
  • Digital documentation is accepted. Physical declarations of conformity are no longer mandatory.
  • Substantial modification is clarified. When a modification makes you the manufacturer of a new machine is more explicitly defined, which matters for anyone upgrading installed equipment.

 

 

Why this is harder than it looks

The cybersecurity provisions do not ask you to secure your factory network. They ask whether any digital function can change the behaviour of the machine, the control system, or a safety function, and put a person into a hazardous situation. Answering that requires someone who understands both the safety function and the attack surface. Most machinery consultancies have the first competence and not the second.

 

Where Safety and Cybersecurity Now Meet

The regulation effectively forces machine builders into territory that process industry operators entered through IEC 61511 Clause 8.2.4, which requires a cybersecurity risk assessment as part of the safety lifecycle. The mechanism differs but the question is identical: can a cyber event defeat a safety function.

For machinery, the practical answer involves applying IEC 62443 principles to the machine control architecture, assessing whether remote access and update paths can reach safety-related control, and documenting the analysis alongside the risk assessment. Our guide to how IEC 61511 and IEC 62443 work together covers the underlying method, which transfers directly.

 

What Manufacturers Should Do Before January 2027

  • Confirm which of ISO 13849 or IEC 62061 you are working to for each safety function, and stop applying both
  • Review harmonized standard citations as they publish, since the first batch under the new Regulation was expected during 2026
  • Identify every digital function that can influence a safety function: remote access, update paths, configuration, connectivity
  • Document the cybersecurity analysis alongside the machine risk assessment rather than separately
  • Check whether any installed-base modification program makes you the manufacturer of a new machine
  • Confirm your technical file can be produced digitally

 

Why Choose Arista Cyber

Arista Cyber works across functional safety and OT cybersecurity as a single engineering discipline, which is precisely what the new Machinery Regulation now requires. Our practitioners are TUV Rheinland certified in functional safety and work daily in IEC 62443 environments.

For manufacturers, that means the safety analysis and the cybersecurity analysis are produced by the same team against the same architecture, rather than by two suppliers whose documents have to be reconciled afterwards. We also work extensively across manufacturing OT environments, so the recommendations account for how machines are actually operated and maintained.

 

Next Steps

If you place machinery on the EU market, the practical first step is identifying which digital functions can affect a safety function. Explore our functional safety services, read about functional safety assessment stages, or contact the Arista Cyber team.

 

Common Questions

Does the EU Machinery Regulation apply to North American manufacturers?

Yes, if you place machinery on the EU market. The Regulation applies to the product rather than to the manufacturer location, so exporters are in scope regardless of where the machine is built. It becomes applicable on 20 January 2027.

Will our existing ISO 13849 documentation still be valid?

In most cases yes. The majority of existing harmonized standards are being carried over, so machinery conforming to current standards generally retains presumption of conformity. The gap is the new cybersecurity and self-evolving behaviour requirements, which existing documentation will not address.

Is cybersecurity now mandatory for CE marking of machinery?

Where a digital function can affect a safety function, yes. The Regulation frames it as a safety requirement rather than a separate cybersecurity obligation. Machines with no connectivity, remote access or updatable software that could influence safety behaviour are less affected.

 

Ready for the January 2027 machinery deadline?

Arista Cyber delivers machinery functional safety and the cybersecurity analysis the new Regulation requires, from one engineering team.

Book a Free Consultation

BOOK YOUR CONSULTATION