Compliance with the Machinery Regulation: EN 50742 vs. IEC 62443, which approach should be followed?

Reading time: 4 minutes - Difficulty: Advanced
With EU Machinery Regulation 2023/1230, applicable from January 20, 2027, cybersecurity has become a non-negligible aspect of machinery safety.

The Machinery Regulation closes certain legislative gaps related to the expanded risk assessment of machinery and automation systems, including, and especially, cases in which they are equipped with software and enabled by AI.
Since the beginning of 2026, we have known that the draft standard EN 50742, currently still in draft form, is expected to become the European standard harmonized with the Machinery Regulation, helping to ensure compliance with EHSR 1.1.9, namely protection against corruption caused by accidental, intentional, or malicious manipulation of machinery that could result in safety-related harm.

The scope of EN 50742 covers three fundamental elements:

  • hardware components
  • software
  • data

EN 50742 therefore focuses on the digital aspects that may have a direct impact on machine safety.

Complementary regulatory approaches

A comparison between EN 50742 and IEC 62443 is necessary because:

  • As mentioned, EN 50742 helps demonstrate, in the specific context of machinery, that intentional, accidental, or malicious alterations have been considered and mitigated whenever they may cause hazards.
  • IEC 62443 is the international reference framework for assessing and certifying industrial automation and control components and systems, as well as processes and infrastructures, according to security-by-design principles and continuous improvement of policies and procedures based on predefined cybersecurity objectives.

The combined implementation of the two standards makes it possible to ensure machine compliance in all respects by:

  • integrating cybersecurity into risk assessment
  • identifying critical hardware, software, and data
  • protecting control systems against unauthorized alterations
  • securely managing remote access and updates
  • ensuring software identification and traceability
  • producing documented evidence to support compliance

The difference is that EN 50742 is still a draft standard and has not yet been officially adopted. Does starting work in this direction mean wasting time and resources?


Although what we currently have is still only a draft standard, it can already be said that EN 50742 represents an excellent link between cybersecurity, functional safety, and machinery compliance.

Focusing on hardware, software, and data, while preventing hazardous situations, can never be considered a waste of time or resources.
In particular, if a project for the analysis and implementation of cybersecurity measures for products, processes, and assets has already been initiated under IEC 62443, part of the work will already have been facilitated.

Network architecture, access control, software protection, update management, logging, and traceability must already be considered at the design stage; and if we look at how the industrial environment is evolving, it becomes clear that these are no longer aspects that can be postponed.