Published:
prEN 50742: Cybersecurity is becoming part of machine safety
Cybersecurity is now becoming part of machine safety. Are you ready for the change?

Cybersecurity is now becoming part of machine safety. The new draft standard prEN 50742 requires machines to be protected against manipulation through networks and interfaces—with new security levels, traceability, and clearer responsibilities for manufacturers. Are you ready for the change?
The new draft standard EN 50742 marks a clear shift: cybersecurity is becoming an integral part of machine safety. In short, it is no longer enough for a machine to be mechanically safe. It must also be protected against manipulation through networks, service ports, or other connections.
This introduces a requirement to supplement the traditional risk assessment with a cybersecurity analysis that identifies safety-critical functions and how they could be affected by unauthorized access or altered configurations. The goal is clear: communication within and with the machine must never be able to create a hazardous situation.
New security levels for interfaces and functions
A central change is the introduction of security levels (SRSL) for each interface and function—effectively a cybersecurity classification for the machine.
In practice, a local, locked USB interface may be assigned a low level (SRSL1), while a connection to a factory network requires a higher level (SRSL2), and an internet-connected machine requires the highest level (SRSL3).
The higher the level, the stricter the requirements—from simple authentication to role-based access control, software integrity checks, and in some cases encrypted communication and secure boot. The standard also places clear demands on traceability: changes to safety functions must be logged and traceable for up to five years.
What does this mean in practice?
Machines must now be designed with both safety and cybersecurity in mind from the outset, especially when they are connected, have service ports, or integrate with production systems. For many organizations, this means new working methods, new competence requirements, and a stronger focus on systematic safety work.
NodeCE is already prepared for this development. A structured approach to both risk assessment and safety-critical functions provides a strong foundation for meeting the draft prEN 50742 requirements and future harmonized standards.