The ISO 12100 standard is important in software-defined systems.
This is because it provides a logical framework for risk assessment – defining the limits of the machine’s capabilities, intended use, reasonably foreseeable misuse, life cycle stages, hazards, hazardous situations, hazardous events and residual risk.
In software-dependent systems, the ISO 12100 standard helps to structure the assessment of how data, updates, configuration, network communications and remote access affect safety.
The early recognition of cybersecurity as part of ensuring the integrity and safety of equipment reflects the growing overlap between machine safety and cybersecurity. Networked machines now typically incorporate remote access, industrial networks, software updates and data integration with wider enterprise systems. In such an environment, unauthorised changes to parameters, manipulation of software or compromised communications can affect safety-related behaviour.
ISO 12100 is not a specialised standard on cybersecurity and is unlikely to become one. However, the growing emphasis on this standard is significant. It reflects a broader industry reality: if digital integrity can affect safety functions, then cybersecurity can no longer be viewed as entirely separate from equipment safety strategy.
The ISO 12100 standard remains the foundation that brings all these concepts together. With the adoption of the new regulation, it has not lost its importance; on the contrary, it has become even more significant.
A qualitative risk assessment begins with defining the boundaries of the equipment, rather than with a list of protective devices. To begin with, it is necessary to determine, at a minimum, the following:
· what the intended purpose of this equipment is
· what constitutes a reasonably foreseeable misuse
· what operating modes and life cycle stages exist
· what tasks are performed by users, maintenance services and technical staff
· what hazards, hazardous situations and hazardous events may arise
· what safety measures are in place
· what residual risk remains
It is only on top of this framework that it makes sense to add the aspect of cybersecurity, for example, using the IEC 62443 standard. And only then will it be possible to reasonably assess the relationship with the CRA (Cyber Resilience Act / EU Regulation 2024/2847), which applies to products with digital elements. The CRA does not replace the risk assessment of equipment. It is a different regulatory act with a different purpose.
Without such a framework, it is easy to produce documentation that looks neat but describes a reality that no longer exists. Following integration, an update or connection to a network, a machine may turn out to be a completely different entity from the one described on paper.