Technical article

Planned standard for protection against corruption

prEN 50742 for (cyber) security requirements of the Machinery Regulation (EU) 2023/1230

Don't miss out on any news and changes relating to CE! Register now for the CE InfoService

Draft standard prEN 50742: ‘Protection against corruption’


Share Article
Share Button Linkedin Share Button Xing Share Button X Share Button Email

In a networked production environment, the functional safety of a machine is inextricably linked to its digital integrity. Defeating control systems – whether through targeted attacks or human error – can have catastrophic physical consequences. The prEN 50742 standard (‘Safety of machinery – Protection against corruption’) provides the methodological framework for this.

This article provides an overview of the most important definitions and explains how machine builders can align cybersecurity requirements with MR requirements.

Note: This technical article is therefore updated on an ongoing basis. Don't miss any important updates and register now for our free newsletter, the CE InfoService, or follow us on LinkedIn.

When is the new prEN 50742 standard for ‘Protection against corruption’ expected to be published?

In summer 2024, Technical Committee 44X (Safety of machinery and equipment: electrotechnical aspects) of CENELEC, the European Committee for Electrotechnical Standardisation, started work on a harmonised standard prEN 50742 (Safety of machinery - Protection against corruption) to cover the relevant sections 1.1.9. and 1.2.1. of Machinery Regulation 2023/1230.1

This standardisation project is currently in the survey phase. The corresponding draft standard for public comment was published by Austrian Standards on 15 January 2026. Feedback on the document could be submitted via the national standardisation institutes until 15 February 2026.

By mid-July 2026, all comments on the standard had been addressed and incorporated; an accelerated procedure is now planned for the remaining formal steps. Following a positive final vote in September, publication is scheduled for November 2026.
 

How does prEN 50742 relate to the MR – ‘Security for Safety’? 

Section 1.1.9. of Annex III to the new EU Machinery Regulation 2023/1230 defines requirements for protection against interference, or in the wording ‘corruption’ (Protection against corruption). The legislator requires that neither the connection of a device (meaning all interfaces and connections to other equipment) nor the connection to ‘remote devices’, i.e. via the Internet, may lead to dangerous situations. 

prEN 50742 specifies these requirements. Its aim is not to define general IT security, but to ensure that the control functions – in particular safety functions – of a machine cannot be compromised by external unauthorised interference. 

The publication of prEN 50742 creates, for the first time a normative framework for protecting machines against safety-related manipulation (corruption). The standard shows a way to meet the requirements of Annex III, points 1.1.9 ‘Protection against corruption’ and 1.2.1 ‘Safety and reliability of control systems’ of the Machinery Regulation (EU) 2023/1230. 

prEN 50742 addresses the question of how defeating software, data and interfaces can impair the effectiveness of protective measures. It becomes clear that the focus is not on new hazards, but on maintaining the effectiveness of already identified safety functions throughout the entire life cycle of the machine.
 

How broad is the scope of prEN 50742?

The standard generally applies to: 

  • Machines, safety-related products and incomplete machines 
  • Hardware, software and data, insofar as they affect safety 

It is also intended to cover all lifecycle steps, including development, manufacture, commissioning, operation, maintenance and decommissioning.

All interfaces are covered, including, for example: 

  • Networks (fieldbus, Ethernet, WLAN) 
  • Service and engineering interfaces (USB, SD cards) 
  • Remote access and cloud connections 

The standard does not apply to machinery installed before the publication of EN 50742.
 

What content in the draft standard prEN 50742:2025 is particularly noteworthy?

The basis for this is a dynamic risk assessment that accompanies the entire life cycle of the machine. This risk-based approach is implemented in a three-stage model. 

1. Identification of critical assets 

In this initial phase, the focus is on a holistic view of the machine control system in order to identify those components whose defeat would have a direct impact on functional safety. The analysis concentrates on safety-relevant software, communication between sensors and actuators, and all physical and digital interfaces, for example for remote maintenance or cloud connection. Only by defining the elements to be protected is it possible to develop a security strategy that is optimally tailored to a particular machine and thus effective. 

2. Threat analysis and assessment of the probability of corruption 

The second step, threat analysis, focuses on the interaction between potential vulnerabilities and active threat factors. In this phase, a systematic investigation is carried out to determine which vectors – such as physical interfaces or network access points – could be used to defeat the previously identified critical assets. The likelihood of a successful attack is determined by comparing the capabilities of potential attackers with the effort required to carry out a defeat. In this way, new threats and current attack methods can also be continuously incorporated into the assessment. 

3. Determination of the required security level (SL)

Finally, the findings from asset identification and threat analysis are brought together in the final risk assessment. In this phase, the decisive consideration is made between the severity of potential physical damage and the probability of successful digital defeating. 

The aim is to define an appropriate security level at which the robustness of the digital barriers increases in proportion to the hazard to people and the environment. This approach ensures that cyber resilience is in harmony with functional safety requirements. The result is a requirements profile that not only guides the technical design, but also provides the necessary documentation basis for proof of conformity within the framework of the EU Machinery Regulation. 

To this end, the standard works with the SRSL (Safety-Related Security Level) and defines its levels from SRSL0 (low security, for completely isolated networks) to SRSL3 (significant or critical attack potential, i.e. a highly probable or almost guaranteed attack).
 

How does prEN 50742 relate to standards EN ISO 12100 and the IEC 62443 series?

prEN 50742 acts as a link between the standards. It combines the proven risk assessment of EN ISO 12100 (safety of machinery) with the safety concepts of IEC 62443 (industrial control systems). The interaction with EN ISO 12100 is summarised in the following table:

AspectClassic safety (EN ISO 12100)Protection against corruption (prEN 50742)
Source of dangerMechanical, electrical, etc.Intentional/unintentional defeating
Protection focusPhysical barriers, redundancyAccess control, encryption, integrity
DynamicsMostly static over the service lifeHighly dynamic (new vulnerabilities/exploits)

A key feature of prEN 50742 is its methodological openness: the standard provides specific requirements for processes and products tailored to mechanical engineering (Approach A). However, it gives manufacturers the freedom to use the established IEC 62443 series of standards as an alternative (Approach B). If the relevant parts of this international standard are applied consistently, prEN 50742 recognises this as an equivalent way of fulfilling the protection objectives.

In detail, this looks as follows:

Approach A – Independent machine approach

This approach is aimed at manufacturers who do not fully apply IEC 62443 and is based on a manufacturer-specific threat analysis in accordance with EN ISO 12100, from which specific technical and organisational protective measures are derived.

A Safety-Related Security Level (SRSL) is then defined for each safety-related function in order to establish the required level of protection in a comprehensible and consistent manner. This creates a structured but pragmatic way of systematically addressing cyber risks at the machine level.

Approach B – IEC 62443-based approach

Manufacturers with established industrial cybersecurity processes can build directly on the IEC 62443 family of standards. The development processes according to EN IEC 62443-4-1 are implemented and linked to system requirements according to IEC 62443-3-3.

In addition, component requirements in accordance with IEC 62443-4-2 are used to ensure consistent security properties across all levels. This approach enables a holistic, standard-compliant implementation of cybersecurity across the entire life cycle of machines, systems and components.
 

What strategic protective measures does prEN 50742 prescribe?

The standard also follows the principle of defence in depth. Since there is no absolute security against digital corruption, several barriers must be connected in series. These can be divided into three categories:

1. System hardening and access control

The first line of defence focuses on reducing the attack surface and deactivating unused services: only ports and services that are absolutely necessary for communication should be active. Anything else represents an unnecessary risk. Strong authentication: access to security-relevant parameters (e.g. limits for engine speeds or maximum pressure) must be protected by secure procedures. This prevents unauthorised persons – or malware – from manipulating configurations that have a direct impact on functional safety.

2. Securing communication integrity

Since modern machines are often modular in design, data exchange between components is a critical asset. Data authenticity: It must be ensured that control commands actually originate from the authorised source and have not been fed in by a ‘man-in-the-middle’. Integrity protection: Cryptographic procedures (such as checksums or digital signatures) are used to detect whether data packages have been manipulated during transmission. As soon as an irregularity in the data integrity of the safety control system is detected, the machine must be put into a safe state.

3. Protection of software integrity and update management

A significant part of ‘corruption’ concerns the modification of software code. Secure Boot is a mechanism that ensures that the machine only starts software that has been digitally signed by the manufacturer. This means that manipulated firmware has no chance of being executed. Another factor is secure update processes: since security vulnerabilities are unavoidable over the lifetime of a machine (often 20 years or more), prEN 50742 defines requirements for the update process. Updates must be able to be installed in such a way that functional safety is guaranteed during and after the process.
 

To what extent does prEN 50742 provide guidelines for implementing the logging requirements of the Machinery Regulation?

The Machinery Regulation requires that ‘machinery or related products (...) collect evidence of lawful or unlawful interference with the software or modification of the software installed in machinery or related products or its configuration’.

prEN 50742 defines clear requirements for logging interventions in machinery and related products. The aim is to ensure traceable and reliable traceability of changes and defeats.
Digital evidence must be legible and accessible. The accompanying documentation must describe how the logs are accessed and how they are to be interpreted. If binary log formats are used, they must be documented in such a way that third parties can develop a converter to make the data legible.

If digital recording of interventions is not reasonably possible, physical evidence (e.g. defeating a seal) must be provided.

Annex A of prEN 50742 lists recognised logging standards such as the Common Log Format (CLF), Syslog, the extended W3C log file format and the Common Event Format (CEF) as guidance.
 

Does prEN 50742 provide specific examples of a threat analysis?

Such examples are listed in Annex B of prEN 50742. A table shows the assignment of the exposure level of a machine, the assessment of the capabilities of a potential attacker and the assessment of the available time window. On this basis, the exposure level is assessed and the attack potential is determined.

Finally, the assignment of Security Risk Severity Levels (SRSLs) to the respective safety functions is defined depending on the attack potential. The tabular presentation thus forms the basis for performing a structured threat analysis of the machine.
 

What content does prEN 50742 provide with regard to threat modelling for security systems?

Annex C of prEN 50742 describes a structured process for determining suitable and appropriate countermeasures to protect machines against defeating them, using two machines as examples. This approach is illustrated using various machine examples, with a focus on preventing the falsification of safety functions.

To establish a clear practical relevance, Annex C contains specific machine examples, including a packaging machine and a radio-controlled loading crane. These examples demonstrate how different operating environments affect the threat situation and what impact exposure, access options and usage scenarios have on the required protection.

Annex C helps manufacturers to define SRSLs in a systematic and comprehensible manner, select appropriate safety measures and transparently document assumptions about use and environment.

Annex C thus provides the methodological tools for analysing tampering threats in a structured manner and deriving well-founded safety-related protective measures. Further examples are already being developed for future versions of the standard.
 

Product note

Safexpert 9.1 - The CE software already supports the new Machinery Regulation (EU) 2023/1230


Since version 9.1, Safexpert has been providing you with targeted support when switching to the new Machinery Regulation (EU) 2023/1230. For machines with a long service life that are placed on the market from 20 January 2027, you can now use the CE guide in accordance with the new Machinery Regulation!

Conclusion

prEN 50742 requires machine builders to rethink their approach. Safety is no longer a condition that is certified once during acceptance, but rather a continuous process. The risk-based approach ensures that the effort required for security measures is proportionate to the potential risk.

For companies, this means that the design (safety) and IT/automation (security) departments must work more closely together from the early design phase onwards. This is the only way to create machines that are both safe from technical failure and resilient to digital defeating.

The new standard specifically closes the gap between functional safety and industrial security by normatively anchoring the protection of safety-related functions against unintentional and intentional manipulation. This extends the classic risk assessment to include a structured threat analysis without introducing new hazards or pursuing purely cybersecurity objectives. The only decisive factor is maintaining the effectiveness of safety functions throughout the entire life cycle of the machine.

With its two equivalent approaches, EN 50742 offers both a practical introduction for traditional machine manufacturers and compatible integration of existing IEC 62443 processes. Clear requirements for interfaces, traceability, logging and graduated protective measures ensure feasibility and proportionality.

Overall, prEN 50742 creates a clear, traceable and future-proof basis for safe, networked machines and is thus set to become a central building block for the implementation of the new Machinery Regulation (EU) 2023/1230.
 


Posted on: 2026-07-31 (Last amendment)

Authors

Hendrik Stupin

Trained technical editor (tekom-certified) and certified CE coordinator. Previously 11 years of experience in technical communication and as a CE coordinator in the field of mechanical and plant engineering, specialising in ‘Engineered to Order (ETO)’ products.

E-Mail: hendrik.stupin@ibf-solutions.com| www.ibf-solutions.com

 

Wolfgang Reich
CE marking and safety expert HTL electrical engineering, specialising in power engineering (Dipl.-HTL-Ing.),  20 years of experience in CE marking, machine safety, conversion of machines, electrical engineering and explosion protection, 10 years of which at TÜV Austria and Intertek Deutschland GmbH. Chairman of the master craftsman examination commission in the Styrian Chamber of Commerce for mechatronics (automation technology and electronics).

E-Mail: wolfgang.reich@ibf-solutions.com


Share Article
Share Button Linkedin Share Button Xing Share Button X Share Button Email

Support by IBF

CE Software Safexpert

CE software for systematic and professional safety engineering

Seminars

Practical seminars on aspects of risk assessment and ce marking

Stay Up-to-Date!

With the CE InfoService you stay informed about important developments in the field of product safety.