ProductEvidenceTop 10ComplianceDocsStar on GitHubQuickstart
ISO 10218-1:2025 · ISO 10218-2:2025

ISO 10218-1/-2:2025

The 2025 overhaul of ISO 10218 — the core industrial-robot safety standard — added cybersecurity provisions for the first time, recognising that a compromised robot controller or policy is a safety problem, not just an IT one.

ISO 10218-1:2025 and ISO 10218-2:2025 were published 5 February 2025.Evidence, not certification.
What it is

The framework

  • ISO 10218-1:2025 covers the robot; ISO 10218-2:2025 covers robot systems and integration.
  • The 2025 revision introduces cybersecurity requirements alongside the traditional mechanical and functional-safety clauses.
  • It is widely referenced by machinery-safety assessors and harmonised standards work in the EU.
  • It introduces cybersecurity requirements but defers the detailed cyber requirements to the IEC 62443 series — the two are meant to be read together.
The hook

Where a red-team result fits

Cybersecurity clauses

The revision requires that security-relevant threats to safety functions be considered — including manipulation of the control logic that drives motion.

What Provael maps to it

Evidence produced

  • Adversarial-robustness evidence for the policy that drives an industrial robot, in simulation.
  • A mapping from each finding to a security-relevant safety concern (e.g. keep-out-zone violation).
  • A reproducible, versioned report that an integrator can attach to a 10218-2 system assessment.
Timing

Dates (verified 6 Jul 2026)

Published
5 February 2025
This is the publication date of ISO 10218-1:2025 and ISO 10218-2:2025 (5 February 2025), not an entry-into-force date.
How to read this mapping

What it is — and isn’t

  • adversarial-only — Provael measures adversarial robustness — susceptibility to manipulation — not general accuracy, reliability, or functional safety.
  • evidence-not-certification — The output is evidence you file, not a certificate. Provael is not a notified body, a lab, or a certification scheme.
  • behavioural-not-worst-case — Attacks are templated and auditable, not gradient- or search-optimised. Results are a floor on susceptibility — a behavioural lower bound, not a certified worst-case bound.
Evidence, not certification

Running Provael does not make a system compliant or certified — it generates measurements you can put into a conformity or assurance file.

Independent project. Not affiliated with or endorsed by ISO, the EU, NIST, IEC, OWASP, or MITRE. Not legal advice.

Clause references are indicative; a wrong clause citation is worse than a missing one.

Turn this into filed evidence.

Download the redacted sample pack, or book an assessment to get the crosswalk filled in for your policy.