ENBRA - Ingeniería en Automatización y Seguridad Industrial

Machinery regulation

prEN 50742: what protection against corruption means for machinery

By Raúl Bricio ·

If you build connected machinery, there is one acronym worth having on your radar now: prEN 50742. It is the draft European standard Safety of machinery — Protection against corruption, designed to help meet one of the newest requirements of the Machinery Regulation (EU) 2023/1230, which applies from 20 January 2027.

What is prEN 50742?

It is a standard under development within CENELEC, in committee CLC/TC 44X (safety of machinery, electrotechnical aspects). Work started in summer 2024 and the public enquiry closed in February 2026. The "pr" means it is still a draft: once published it will be called EN 50742.

The final vote was scheduled for September 2026 and publication for the end of that year. Check its current status with CENELEC before citing it in a technical file.

Which requirement of the Machinery Regulation does it cover?

Points 1.1.9 (Protection against corruption) and 1.2.1 (Safety and reliability of control systems) of Annex III, which sets out the essential health and safety requirements. In practice they require the machine's connections, software and control logic to withstand reasonably foreseeable malicious attempts, and that tampering cannot lead to a hazardous situation.

It is the first time machinery legislation treats cybersecurity as a safety requirement, and prEN 50742 is intended to be the harmonised standard that gives a concrete route to compliance.

What does "corruption" mean?

In this standard, corruption is any accidental or illegitimate modification of machinery data that could lead to a hazardous situation. It is broader than a cyberattack: it also covers a service error or a wrong configuration.

And it is narrower than general IT security. The goal is not protecting data confidentiality, but making sure the machine's safety functions cannot be defeated or altered.

What does it apply to?

  • Machinery, safety components and partly completed machinery.
  • Hardware, software and data that affect safety, across the whole lifecycle: development, manufacture, commissioning, use, maintenance and decommissioning.
  • All interfaces: networks, service and engineering ports, remote access, USB and cloud connections.

A truly isolated machine has minimal requirements, but as soon as there is connectivity it has to be analysed. The standard is not retroactive: it applies to new machines, although a substantial modification of a machine in service can also bring it into scope.

How does it work? Three steps

  1. Identify critical assets: the safety software, parameters and configurations whose alteration would affect a safety function.
  2. Analyse threats: which vulnerabilities exist and what capability an attacker would have.
  3. Determine the security level (SRSL, Safety-Related Security Level), ranging from isolated environments to machines exposed to untrusted networks. The higher the severity of the hazard and the likelihood of attack, the stricter the measures.

Two routes to compliance

  • Route A, risk-analysis based: the manufacturer analyses threats following the logic of EN ISO 12100 and derives the protective measures. It is the natural option for companies without a cybersecurity department.
  • Route B, IEC 62443 based: it builds on established processes such as the secure development lifecycle of EN IEC 62443-4-1 and the system requirements of IEC 62443-3-3. It suits manufacturers that already work with that family of standards.

prEN 50742 therefore acts as a bridge between machine safety and industrial cybersecurity. If you want to go deeper on the latter, at ENBRA we tackle it with IEC / ISA 62443.

What a manufacturer can do from now on

Whatever the final text of the standard, these are good practices that already reduce risk and save work later:

  1. Inventory the interfaces of each machine: fieldbuses, Wi-Fi, USB, service ports, remote access and cloud.
  2. Identify which software and data are critical for safety functions: the PLC safety program, parameters and safety configuration.
  3. Analyse the threats and define the security environment expected from the customer, for example network segmentation and access control.
  4. Protect integrity and access: roles and authentication on service interfaces, change control, integrity verification of the safety software and event logging.
  5. Define how updates are managed during the machine's service life.
  6. Document it in the technical file and the instructions, including which network environment the machine assumes.

Frequently asked questions

Is prEN 50742 mandatory? Harmonised standards are voluntary. What is mandatory is meeting requirements 1.1.9 and 1.2.1 of Annex III. Applying a harmonised standard, once cited in the Official Journal of the EU, gives a presumption of conformity with those requirements.

Does it replace IEC 62443? No. It can build on it (route B), but it focuses on protecting the machine's safety functions, not the cybersecurity of the whole plant.

Does it replace PL or SIL calculation? No. EN ISO 13849-1 and IEC 62061 calculate the reliability of safety functions; prEN 50742 protects that design from being defeated or altered.

Do I need a notified body? That does not depend on this standard, but on whether the machine falls under Annex I of the Regulation. We explain it in our article on the novelties of the Machinery Regulation 2023/1230.

How ENBRA can help

We assess your machines against the cybersecurity requirements of the Regulation: interface inventory, threat analysis and definition of measures. We work through our OT cybersecurity and machine safety services, and we prepare the documentation for the technical file and CE marking. If you want to know where your machine stands, contact our team.