Kexingyu E-Power Group

ISO 10218 and the Robot Safety Standard Update: What Changed for Integrators

Flat infographic of a robot integration timeline with four change markers for collaborative safety, functional safety, cybersecurity and documentation

Quick Answer: The ISO 10218 update pulled collaborative safety out of its technical specification, sharpened functional safety requirements and added cybersecurity, and integrators now work to a single, harder standard that reaches further into wiring, verification and documentation than the old pair did.

ISO 10218 is the safety backbone of industrial robotics: Part 1 governs the robot itself as delivered by the manufacturer, and Part 2 governs what an integrator builds around it. For fifteen years integrators worked with the 2011 pair, plus a technical specification for collaborative operation that sat beside them. The 2025 revision changed that arrangement, and the change matters beyond the standards shelf, because the new requirements land on the same hardware integrators commission every week: control architectures, protective stop functions, sensing systems, and the cabling that ties them together. This guide walks through what actually changed, what it means for an integration project in practice, and where the requirements touch the wiring layer that KXYE supplies into.

Introduction

Standards revisions are easy to shrug off, because most of the physics does not change. A robot that can crush a worker was dangerous in 2011 and is dangerous now. What changes is how the standard expects that danger to be identified, reduced and proven, and who carries the burden of evidence. The 2025 revision of ISO 10218 tightened several of those expectations at once, and integrators who treat the update as a re-papering exercise will find their next project assessment slower and their next audit more expensive than the last one.

This guide is written from the integrator’s side of the line. Robot manufacturers have their own obligations under Part 1; the integrator’s obligations live in Part 2, and they are the ones that arrive with a customer’s cell specification, a floor plan and a delivery deadline. The safety frameworks that sit around machinery wiring in general are laid out in the EN 60204-1 wiring guide, and ISO 10218 adds the robot-specific layer on top of that foundation.

What the 2011 Standards Left Open

To see what changed, it helps to remember what the 2011 pair did not settle. Collaborative operation was the biggest gap: the technical specification ISO/TS 15066 covered power and force limiting and biomechanical thresholds, but as a technical specification it carried less contractual weight than a full standard, and its integration into the main documents was left for a future revision everyone knew was coming. Functional safety references in the 2011 text were sometimes loose, pointing at concepts rather than hard performance levels, which let different integrators reach different conclusions from the same clause. And cybersecurity did not appear at all, because in 2011 robots mostly stood alone; by the 2020s they sat on factory networks with remote access, fleet management and update channels.

None of those gaps made the 2011 standards unusable, and thousands of cells were safely built under them. But they left room for judgment calls, and judgment calls are where integration projects lose time. The revision’s central move is closing that room.

The 2025 Revision: Four Changes That Matter

The first change is consolidation. Collaborative operation requirements from ISO/TS 15066 are now inside the main standards, so the separate specification no longer stands alone. Applications previously designed to the technical specification are now designed to the standard itself, with the same weight in contracts, risk assessments and audits. Integrators who learned the collaborative content years ago will find the substance familiar; what changed is that it is no longer optional reading.

The second change is sharper functional safety language. Safety functions, protective stops, speed monitoring and safety-rated sensing are expected to be specified and verified with defined performance levels rather than described qualitatively. For integrators this pushes the safety function list earlier in the project: you cannot commission your way to a performance level you never specified.

The third change is cybersecurity. The revised standards expect the robot system’s safety-related functions to be protected against unauthorized change, which connects the safety case to network architecture, access control and update management. This is the requirement most integrators had nothing about in 2011 and cannot ignore now.

The fourth change is a tighter link between risk assessment and the specific measures chosen. The revision expects the assessment to drive the design decisions visibly, and expects the evidence, records, verification results and rationale, to survive the project as documentation rather than living in the integrator’s institutional memory.

The changes compress into the comparison below.

ISO 10218: 2011 baseline versus the 2025 revision
Area2011 baseline2025 revisionWhat it means for integrators
Collaborative operationCovered by a separate technical specification, ISO/TS 15066Absorbed into the main standards with full standard statusCollaborative cells designed to the TS need re-verification against the standard's wording
Functional safetyPartly qualitative references to safety functionsDefined performance expectations for safety functions and sensingSafety function lists with performance levels specified at design time, verified at commissioning
CybersecurityAbsent; robots were islandsSafety functions must be protected against unauthorized changeNetwork design, access control and update policy enter the safety file
Risk assessment linkageRequired but loosely tied to specific measuresMeasures must trace visibly to the assessmentDocumentation discipline through the project, not a report at the end
Verification evidenceExpected, format flexibleExpectations tightened across sensing, stops and validationPer-function test records become standard deliverables

Where the Revision Touches Wiring and Cabling

None of the revision’s headlines mention cable, but the wiring layer sits under three of them. Safety functions depend on signal integrity: protective stop circuits, safety-rated sensing and speed monitoring all run on cables whose failure modes, interference behavior and mechanical endurance decide whether the function is available when it matters. An integrator specifying safety functions to defined performance levels inherits the question of what the connecting cables must survive, and a cable chosen for price alone becomes the weakest link in a function the project just paid to harden. The failure patterns that end cable lives in moving machinery are cataloged in the guide to common cable failure causes, and they apply double to safety-related circuits.

The cybersecurity requirement touches wiring more quietly. Physical access to the cell is part of its security posture: cabinet layouts, connector choices and cable routing that make tampering visible and difficult support the requirement that safety functions resist unauthorized change. And the verification regime touches wiring most directly of all, because every safety function the integrator specifies ends in a test, and the test result depends on conductors, terminations and shields that were specified months earlier in a bill of materials.

Integrators working through a cell build also carry the machinery-level electrical obligations, cabinet construction and bonding among them, which are treated in the guide to control cabinet construction. ISO 10218 does not replace that layer; it stacks on it.

What Integrators Should Change on the Next Project

The practical adjustments are mostly sequencing and documentation. Specify the safety functions with their performance expectations before the layout freezes, because sensing and architecture decisions flow downstream from that list. Include the collaborative-operation content in the assessment whether or not the cell is collaborative, because the revised standard’s wording now reaches applications where humans and robots share space intermittently. Bring IT or OT security into the kick-off rather than the acceptance phase, since the cybersecurity requirement touches network design that is expensive to retrofit. And build the evidence file as the project runs: assessment rationale, safety function tests, stop function measurements, access control configuration. Cells integrated this way pass acceptance once; cells integrated the old way negotiate with the assessor instead.

The integration touchpoints, with the wiring-relevant requirement at each step and the evidence that satisfies it, are laid out below.

Integration steps under the revised ISO 10218-2 and their wiring touchpoints
Integration stepWiring-relevant requirementEvidence to keep
Risk assessmentMotion zones, cable routing and maintenance access identified as hazardsAssessment record with cabling explicitly considered
Safety function specificationStops, sensing and speed functions defined with performance expectationsSafety function list with the circuits and cables serving each
Architecture designSeparation of power and signal, shield planning, bonding designElectrical design documents showing EMC and bonding arrangements
Build and installCables rated for the duty, protected along their route, terminations soundComponent records and installation checks
Commissioning and verificationEvery safety function tested through its wiring, not just at the logic levelPer-function test results and measurement records
Security hardeningPhysical and network access to safety functions controlledAccess configuration and cabinet security notes

When ISO 10218 Is Not the Answer

Honest limits: ISO 10218 covers the robot and the integrated system, not the whole factory, and it does not certify individual components. A cable with a compliant datasheet does not make a cell compliant, and a compliant cell does not make every cable adequate. The standard’s performance expectations are floors expressed at system level; whether a given motion cable meets the duty behind a safety function is a component engineering question that the standard delegates to the integrator’s specification. Integrators specifying components for export markets also carry the certification layers per the equipment certification checklist, which is a separate gate from safety conformity. And the standard is not a substitute for the machinery-level wiring code: EN 60204-1 still governs the electrical equipment details, and the two are read together, not instead of each other.

RFQ Checklist: Briefing a Cable Supplier Into an ISO 10218 Project

Attach these items to the cable portion of the RFQ:

  • Duty statement: which axes and services the cables serve, with cycle rates and motion profiles
  • Safety function mapping: which circuits serve safety-rated functions, so construction and documentation match the claim
  • EMC context: drive environment, separation distances, shield landing points
  • Environmental envelope: temperature, coolant and oil exposure, swarf and abrasion conditions
  • Documentation package: test data, material declarations and traceability feeding the integration file
  • Verification support: test reports and records that slot into the per-function evidence the cell must produce

The reading discipline that keeps supplier datasheets honest in this process is covered in the guide to reading equipment datasheets, and it applies with extra force to cables carrying safety functions.

Conclusion

The ISO 10218 update is not a rewrite of robot physics; it is a tightening of proof. Collaborative safety moved inside the standard, functional safety gained defined performance expectations, cybersecurity entered the safety file, and the risk assessment now has to trace visibly into the design. For integrators the practical consequence is earlier specification and continuous documentation, and the wiring layer sits inside that shift, because safety functions are only as available as the cables that serve them.

Kexingyu Cable Group (KXYE) supplies motion and machine cable with the documentation packages integration projects need, from flex test data to material declarations. Send your cell’s cable scope through the RFQ page, and we will quote to the specification the revised standard implies, not just to a part number.

No. Existing cells built to the 2011 standards do not become non-conforming retroactively, and no regulator requires rebuilding installed machinery. The revision governs new projects and, in practice, new assessments of modifications. Cells due for major upgrade or re-validation are where the new requirements first bite.
Its collaborative operation content, power and force limiting, biomechanical threshold guidance and the collaborative application requirements, was absorbed into the main ISO 10218 parts. The technical specification no longer stands alone, and collaborative cells are now designed and assessed against the standard itself with its full contractual and audit weight.
Because robots stopped being islands. Safety functions on networked equipment can be affected by unauthorized access and unauthorized change, so the revised standard expects the safety case to cover protection against exactly that. In practice it means access control, update management and network design join the integration file, and IT or OT security joins the project kick-off.
The methods most integrators already use remain sound. What the revision tightens is traceability: the chosen measures have to link visibly to the assessment findings, and the evidence has to survive the project. Most teams need better documentation discipline, not a different assessment technique.
No. The standard addresses the robot and the integrated system; it does not certify components. Cables serving safety functions must be specified so they support the performance the integrator claims for those functions, which makes component engineering and test documentation an integrator responsibility rather than something the standard hands down.
They stack. EN 60204-1 governs the electrical equipment of the machine, conductors, protection, bonding, identification and verification, and ISO 10218 adds the robot-specific safety layer on top: safeguarding, safety functions, collaborative requirements and the integration process. Integrators read both, and neither substitutes for the other.