{"id":4121,"date":"2025-11-06T12:05:00","date_gmt":"2025-11-06T11:05:00","guid":{"rendered":"https:\/\/pilz-magazine.com\/de\/?p=4121"},"modified":"2025-11-06T15:04:13","modified_gmt":"2025-11-06T14:04:13","slug":"machinery-lifecycle-security-cra-nis2","status":"publish","type":"post","link":"https:\/\/pilz-magazine.com\/en\/machinery-lifecycle-security-cra-nis2\/","title":{"rendered":"Safely moved, precisely controlled"},"content":{"rendered":"\n<p>The machine life\u00adcycle is much more than the sum of its tech\u00adnical phases \u2013 it is a com\u00adplex cycle, which places new demands on safety, effi\u00adciency and com\u00adpli\u00adance in each phase.&nbsp;A machine\u2019s life\u00adcycle extends from plan\u00adning and design to com\u00admis\u00adsioning and oper\u00ada\u00adtion, including retro\u00adfits, through to decom\u00admis\u00adsioning.&nbsp;&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Aim: CE marking&nbsp;<\/h2>\n\n\n\n<p>The plan\u00adning and design involve a def\u00adi\u00adn\u00adi\u00adtion of the require\u00adments and the pur\u00adpose of the machine. The rel\u00ade\u00advant direc\u00adtives and reg\u00adu\u00adla\u00adtions can then be iden\u00adti\u00adfied. This is fol\u00adlowed by the imple\u00admen\u00adta\u00adtion of the risk assess\u00adment and the devel\u00adop\u00adment of a safety con\u00adcept. Imple\u00admen\u00adta\u00adtion then con\u00adsists of the inte\u00adgra\u00adtion of safety-related func\u00adtions, the selec\u00adtion of suit\u00adable com\u00adpo\u00adnents and val\u00adi\u00adda\u00adtion. The designer or machine builder is respon\u00adsible for this. If every\u00adthing is done in accor\u00addance with the applic\u00adable laws and direc\u00adtives, then at the end of this phase the machine builder can issue an EU dec\u00adla\u00adra\u00adtion of con\u00adfor\u00admity and affix a CE mark.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Things get dynamic during the operational phase&nbsp;<\/h2>\n\n\n\n<p>The oper\u00ada\u00adtional phase covers actual oper\u00ada\u00adtion, including inte\u00adgra\u00adtion and com\u00admis\u00adsioning, the var\u00adious oper\u00adating modes such as main\u00adte\u00adnance, but also adjust\u00adments and retro\u00adfits. Com\u00adpared to the design phase, the oper\u00ada\u00adtional phase is much more dynamic in terms of safety. During oper\u00ada\u00adtion, safety must be guar\u00adan\u00adteed at all times. It would there\u00adfore be wrong for the oper\u00adator to assume that CE marking would resolve all their safety issues.&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"640\" src=\"https:\/\/pilz-magazine.com\/en\/wp-content\/uploads\/sites\/24\/2025\/11\/Pilz-Lebenszyklus-Ueberblick-1024x640.jpg\" alt class=\"wp-image-4125\" srcset=\"https:\/\/pilz-magazine.com\/en\/wp-content\/uploads\/sites\/24\/2025\/11\/Pilz-Lebenszyklus-Ueberblick-1024x640.jpg 1024w, https:\/\/pilz-magazine.com\/en\/wp-content\/uploads\/sites\/24\/2025\/11\/Pilz-Lebenszyklus-Ueberblick-300x188.jpg 300w, https:\/\/pilz-magazine.com\/en\/wp-content\/uploads\/sites\/24\/2025\/11\/Pilz-Lebenszyklus-Ueberblick-768x480.jpg 768w, https:\/\/pilz-magazine.com\/en\/wp-content\/uploads\/sites\/24\/2025\/11\/Pilz-Lebenszyklus-Ueberblick-1536x960.jpg 1536w, https:\/\/pilz-magazine.com\/en\/wp-content\/uploads\/sites\/24\/2025\/11\/Pilz-Lebenszyklus-Ueberblick-540x338.jpg 540w, https:\/\/pilz-magazine.com\/en\/wp-content\/uploads\/sites\/24\/2025\/11\/Pilz-Lebenszyklus-Ueberblick-1080x675.jpg 1080w, https:\/\/pilz-magazine.com\/en\/wp-content\/uploads\/sites\/24\/2025\/11\/Pilz-Lebenszyklus-Ueberblick.jpg 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\"><figcaption class=\"wp-element-caption\">An overview of the machine life\u00adcycle: From the ini\u00adtial assess\u00adment, spec\u00adi\u00adfi\u00adca\u00adtion and design through to imple\u00admen\u00adta\u00adtion, com\u00adpli\u00adance with legal require\u00adments and ongoing main\u00adte\u00adnance \u2013 each phase places par\u00adtic\u00adular demands on safety, effi\u00adciency and com\u00adpli\u00adance. \u00a9&nbsp;Pilz GmbH &amp; Co. KG, Ost\u00adfildern<\/figcaption><\/figure>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>It is the oper\u00ada\u00adtor\u2019s own respon\u00adsi\u00adbility to assess the safety of the machine in the envi\u00adron\u00adment in which it is oper\u00adated \u2013 on an ongoing basis. The frame\u00adwork direc\u00adtive on Safety and Health at Work applies in Europe to ensure that this hap\u00adpens. This has been imple\u00admented in Ger\u00admany with the Ordi\u00adnance on Indus\u00adtrial Safety and Health (Betr\u00adSichV), for example. The Ordi\u00adnance on Indus\u00adtrial Safety and Health gov\u00aderns health and safety pro\u00adtec\u00adtion when using work equip\u00adment and instal\u00adla\u00adtions sub\u00adject to mon\u00adi\u00adtoring. The ordi\u00adnance stip\u00adu\u00adlates reg\u00adular inspec\u00adtions of work equip\u00adment and instal\u00adla\u00adtions to ensure that they con\u00adtinue to meet the require\u00adments and can be oper\u00adated safely.&nbsp;&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Retrofit \u2013 or the question about substantial modification&nbsp;<\/h2>\n\n\n\n<p>It is not uncommon for the oper\u00ada\u00adtional phase to last sev\u00aderal decades. Over the years, the state-of-the-art changes and machines are reju\u00adve\u00adnated with a retrofit to ensure con\u00adtinued pro\u00adduc\u00adtivity and safety. If the changes com\u00adpro\u00admise the safety of the machine by cre\u00adating a new hazard or increasing an existing risk, this is called a sub\u00adstan\u00adtial mod\u00adi\u00adfi\u00adca\u00adtion. In this case, the oper\u00adator becomes the man\u00adu\u00adfac\u00adturer \u2013 with all the asso\u00adci\u00adated oblig\u00ada\u00adtions. This means that they them\u00adselves must then carry out a con\u00adfor\u00admity assess\u00adment pro\u00adce\u00addure.&nbsp;<\/p>\n\n\n\n<p>Regard\u00adless of whether or not a new dec\u00adla\u00adra\u00adtion of con\u00adfor\u00admity is needed: ulti\u00admately, work equip\u00adment must always be safe in line with the Ordi\u00adnance on Indus\u00adtrial Safety and Health (Betr\u00adSichV), if nec\u00ades\u00adsary with a fresh CE mark.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Liability protection: \u201cWrite it down, stay in the game\u201d&nbsp;<\/h2>\n\n\n\n<p>In the event of an inci\u00addent, this means that the oper\u00adator must prove that they have car\u00adried out reg\u00adular hazard assess\u00adments, for example; it means they must pro\u00adduce test reports or doc\u00adu\u00adment training and per\u00admis\u00adsions for employees. In prac\u00adtice, these doc\u00adu\u00adments are often incom\u00adplete and are stored in dif\u00adferent loca\u00adtions and for\u00admats, either as hard copies or dig\u00adi\u00adtally.&nbsp;&nbsp;<\/p>\n\n\n\n<p>In machine oper\u00ada\u00adtion, it is not enough to imple\u00adment safety mea\u00adsures as a one-off \u2013 they must be con\u00adtin\u00adu\u00adously reviewed, doc\u00adu\u00admented and kept up to date. Oper\u00ada\u00adtors are liable and there\u00adfore have a duty to be able to prove at any time that their machines comply with the applic\u00adable legal require\u00adments. This applies not only to tech\u00adnical safety func\u00adtions, but also to organ\u00adi\u00adsa\u00adtional mea\u00adsures, IT pro\u00adtec\u00adtion and data pro\u00adtec\u00adtion.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Why an overview of documentation is crucial&nbsp;<\/h2>\n\n\n\n<p>A fully doc\u00adu\u00admented safety process is the basis for legal pro\u00adtec\u00adtion. Oper\u00ada\u00adtors bear full respon\u00adsi\u00adbility for the safety of their machinery \u2013 and must be able to prove that all mea\u00adsures were imple\u00admented cor\u00adrectly in the event of an inci\u00addent.&nbsp;<\/p>\n\n\n\n<p>A full, struc\u00adtured overview of all safety-related doc\u00adu\u00adments is essen\u00adtial \u2013 for sev\u00aderal rea\u00adsons:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Legal cer\u00adtainty:<\/strong> Only those who keep com\u00adplete doc\u00adu\u00admen\u00adta\u00adtion can prove that all oblig\u00ada\u00adtions have been met in the event of an inci\u00addent.&nbsp;<\/li>\n\n\n\n<li><strong>Legal com\u00adpli\u00adance:<\/strong> New reg\u00adu\u00adla\u00adtions require oper\u00ada\u00adtors to know at all times whether their machines comply with cur\u00adrent require\u00adments \u2013 and to be able to prove it.&nbsp;&nbsp;<\/li>\n\n\n\n<li><strong>Respon\u00adsive\u00adness:<\/strong> In the event of safety inci\u00addents or audits, it must quickly be apparent which mea\u00adsures have been taken and which pro\u00adtec\u00adtive mech\u00ada\u00adnisms are in place.&nbsp;<\/li>\n\n\n\n<li><strong>Effi\u00adciency:<\/strong> Well-struc\u00adtured doc\u00adu\u00admen\u00adta\u00adtion makes main\u00adte\u00adnance, training and emer\u00adgency man\u00adage\u00adment easier \u2013 and helps to min\u00adimise down\u00adtimes.&nbsp;&nbsp;<\/li>\n<\/ul>\n\n\n\n<p>The chal\u00adlenge lies not only in cre\u00adating this doc\u00adu\u00admen\u00adta\u00adtion, but in main\u00adtaining it on an ongoing basis. Mod\u00adi\u00adfi\u00adca\u00adtions to the machine, new soft\u00adware ver\u00adsions or amended legal require\u00adments must be recorded promptly and doc\u00adu\u00admented so as to be trace\u00adable. This is the only way for oper\u00ada\u00adtors to main\u00adtain con\u00adtrol \u2013 and fulfil their respon\u00adsi\u00adbil\u00adi\u00adties towards employees, author\u00adi\u00adties and their own organ\u00adi\u00adsa\u00adtion.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Security creates new requirements&nbsp;<\/h2>\n\n\n\n<p>Machine net\u00adworking is increasing, which brings with it new risks. For the first time, the EU Machinery Reg\u00adu\u00adla\u00adtion requires manda\u00adtory cyber\u00adse\u00adcu\u00adrity mea\u00adsures. Machines must be designed in such a way that external access does not present a hazard. The Cyber Resilience Act extends these require\u00adments to all net\u00adworked prod\u00aducts. Oper\u00ada\u00adtors must doc\u00adu\u00adment how they deal with vul\u00adner\u00ada\u00adbil\u00adi\u00adties, pro\u00advide secu\u00adrity updates and respond to inci\u00addents. The NIS 2 Direc\u00adtive obliges oper\u00ada\u00adtors of crit\u00adical infra\u00adstruc\u00adtures (which also includes com\u00adpa\u00adnies in the engi\u00adneering and auto\u00admo\u00adtive sec\u00adtors with more than 50 employees or an annual turnover of more than \u20ac10 mil\u00adlion) to imple\u00adment com\u00adpre\u00adhen\u00adsive organ\u00adi\u00adsa\u00adtional and tech\u00adnical mea\u00adsures for IT secu\u00adrity \u2013 including risk analyses, emer\u00adgency plans and reporting oblig\u00ada\u00adtions in the event of secu\u00adrity inci\u00addents. The imple\u00admen\u00adta\u00adtion must also be doc\u00adu\u00admented and reg\u00adu\u00adlarly reviewed.&nbsp;<\/p>\n\n\n\n<p>This means that secu\u00adrity require\u00adments are increasing for both machine builders and oper\u00ada\u00adtors. In addi\u00adtion to the actual safety of the machine, it is now nec\u00ades\u00adsary to ensure that nobody can cor\u00adrupt the machine. And this applies not only in the case a hacker attack, but also to internal manip\u00adu\u00adla\u00adtion by employees \u2013 whether inten\u00adtional or oth\u00ader\u00adwise. This is what oper\u00ada\u00adtors will demand from machine builders in future. Oper\u00ada\u00adtors need a system that can be used to clearly assign and con\u00adtrol per\u00admis\u00adsions for safety func\u00adtions.&nbsp;<\/p>\n\n\n\n<p>These days, the machine life\u00adcycle is inex\u00adtri\u00adcably linked to com\u00adpre\u00adhen\u00adsive safety, secu\u00adrity, doc\u00adu\u00admen\u00adta\u00adtion and IT pro\u00adtec\u00adtion oblig\u00ada\u00adtions. Oper\u00ada\u00adtors must not only ensure the pro\u00adtec\u00adtion of human and machine, but must also guar\u00adantee the integrity of dig\u00adital sys\u00adtems and com\u00adpli\u00adance with legal require\u00adments. The key here is full, struc\u00adtured doc\u00adu\u00admen\u00adta\u00adtion that\u2019s avail\u00adable at all times \u2013 both for legal cer\u00adtainty and for smooth, pro\u00adduc\u00adtive oper\u00ada\u00adtion.&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Machines also go through a life\u00adcycle. Each phase places spe\u00adcific demands on Safety \u2013 and on those who must ensure it. What\u2019s impor\u00adtant here, and what role does Secu\u00adrity now play? <\/p>\n","protected":false},"author":29,"featured_media":4124,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"wp_typography_post_enhancements_disabled":false,"footnotes":""},"categories":[19,75,1,11],"tags":[],"class_list":["post-4121","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industrial-security","category-issue-2-2025","category-pilz-magazine","category-trends"],"acf":[],"_links":{"self":[{"href":"https:\/\/pilz-magazine.com\/en\/wp-json\/wp\/v2\/posts\/4121","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pilz-magazine.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pilz-magazine.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pilz-magazine.com\/en\/wp-json\/wp\/v2\/users\/29"}],"replies":[{"embeddable":true,"href":"https:\/\/pilz-magazine.com\/en\/wp-json\/wp\/v2\/comments?post=4121"}],"version-history":[{"count":1,"href":"https:\/\/pilz-magazine.com\/en\/wp-json\/wp\/v2\/posts\/4121\/revisions"}],"predecessor-version":[{"id":4451,"href":"https:\/\/pilz-magazine.com\/en\/wp-json\/wp\/v2\/posts\/4121\/revisions\/4451"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/pilz-magazine.com\/en\/wp-json\/wp\/v2\/media\/4124"}],"wp:attachment":[{"href":"https:\/\/pilz-magazine.com\/en\/wp-json\/wp\/v2\/media?parent=4121"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pilz-magazine.com\/en\/wp-json\/wp\/v2\/categories?post=4121"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pilz-magazine.com\/en\/wp-json\/wp\/v2\/tags?post=4121"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}