STALE MEASUREMENTPast this project's own 2-release window: the published result was measured with v0.32.0, 9 releases ago. Why, and what unblocks it

ProductEvidenceTop 10LeaderboardCompliancePricingDocsStar on GitHub Quickstart
ISO 10218-1:2025 · ISO 10218-2:2025

ISO 10218-1/-2:2025

The 2025 overhaul of ISO 10218 - the core industrial-robot safety standard - added cybersecurity provisions for the first time, recognising that a compromised robot controller or policy is a safety problem, not just an IT one.

ISO 10218-1:2025 and ISO 10218-2:2025 were published 5 February 2025.Evidence, not certification.
What it is

The framework

  • ISO 10218-1:2025 covers the robot; ISO 10218-2:2025 covers robot systems and integration.
  • The 2025 revision introduces cybersecurity requirements alongside the traditional mechanical and functional-safety clauses.
  • It is widely referenced by machinery-safety assessors and harmonised standards work in the EU.
  • It adds cybersecurity requirements to the extent they apply to industrial robot safety, and names IEC 62443 only in its informative Bibliography - so it does not hand the detail off to that series. Provael publishes its own mapping onto IEC 62443; that mapping is Provael’s, not something ISO 10218 routes to.
The hook

Where a red-team result fits

Cybersecurity provisions (standard-level mapping — see note)

Paraphrase, not a quotation: the 2025 revision requires security-relevant threats to safety functions to be considered, including manipulation of the control logic that drives motion. Clause-level citation is deliberately omitted — the standard is paywalled and was restructured in 2025, so a clause number cannot be verified against a public source. Read this mapping against your own copy of the standard text before relying on it.

What Provael maps to it

Evidence produced

  • Adversarial-robustness evidence for the policy that drives an industrial robot, in simulation.
  • A mapping from each finding to a security-relevant safety concern (e.g. keep-out-zone violation).
  • A reproducible, versioned report that an integrator can attach to a 10218-2 system assessment.
Timing

Dates (verified 19 Aug 2026)

Published
5 February 2025
This is the publication date of ISO 10218-1:2025 and ISO 10218-2:2025 (5 February 2025), not an entry-into-force date.
How to read this mapping

What it is - and isn’t

  • adversarial-only - Provael measures adversarial robustness - susceptibility to manipulation - not general accuracy, reliability, or functional safety.
  • evidence-not-certification - The output is evidence you file, not a certificate. Provael is not a notified body, a lab, or a certification scheme.
  • behavioural-not-worst-case - The measured result uses templated, auditable attacks; the search-based families (optimized, universal_patch, gradient_patch) have only met the CPU fixture. Results are a floor on susceptibility - a behavioural lower bound, not a certified worst-case bound.
Evidence, not certification

Running Provael does not make a system compliant or certified - it generates measurements you can put into a conformity or assurance file.

Independent project. Not affiliated with or endorsed by ISO, the EU, NIST, IEC, OWASP, or MITRE. Not legal advice.

Clause references are indicative; a wrong clause citation is worse than a missing one.

Turn this into filed evidence.

Download the redacted sample pack, or book an assessment to get the crosswalk filled in for your policy.