Talk to Luna
About TTAN.IO

TTAN.IO Robotics / standards reference

Robotics standards.
What they protect — and where TTAN.IO fits.

Robot safety, functional safety, industrial cybersecurity and middleware security are different disciplines. TTAN.IO Robotics is designed to preserve those boundaries rather than collapse them. This reference explains the major standards commonly encountered around industrial robots, AMRs, collaborative applications, connected radio equipment and ROS 2 / DDS systems.

A standard can define safety, security or engineering practice. TTAN.IO adds the cybersecurity governance boundary around exact physical action and evidence.

Read correctlySafety standard ≠ cybersecurity standard.

Some standards below address functional safety, some industrial cybersecurity, some radio cybersecurity and some middleware trust. TTAN.IO complements each one in a different way.

Open any standard directly.

Industrial robot safety · Part 1

ISO 10218-1:2025

Robotics — Safety requirements — Part 1: Industrial robots. This is the robot-manufacturer side of the ISO 10218 family. It treats the industrial robot itself as partly completed machinery and establishes safety requirements for its design, protective measures and information for use.

It is concerned with hazards created by the robot and its built-in functions before the robot is integrated into a complete application or cell. The standard supports inherently safe design, risk reduction and safety-related robot functions.

Who uses it

Robot manufacturers

Designers and manufacturers of industrial robots, including safety-related robot functions and interfaces.

Primary concern

Safe robot design

Hazard reduction at the robot level, safety-related functions, limits, modes and information needed by downstream integrators.

Cyber relationship

Cyber must not undermine safety

A cyber compromise can invalidate assumptions used by safety functions, but TTAN.IO does not replace the certified safety functions required by the standard.

TTAN.IO relationship

TTAN.IO uses robot identity, approved behavior and current state as cybersecurity inputs. It can deny or HOLD a cyber-authorized action, but it does not claim to implement or certify the robot’s safety-rated functions.

Industrial robot safety · Part 2

ISO 10218-2:2025

Robotics — Safety requirements — Part 2: Industrial robot applications and robot cells. This part shifts the focus from the robot product to the integrated application: robot, end-effector, fixtures, cell, safeguarding, interfaces and surrounding machinery.

It covers integration, commissioning, operation, maintenance and decommissioning. That makes it especially relevant to system integrators and factories building real robot cells.

Who uses it

Integrators + users

Robot-cell designers, integrators, commissioning teams, operators, maintainers and safety specialists.

Primary concern

The complete application

Hazards that appear only after the robot is combined with tooling, materials, other machinery, people and the physical workspace.

TTAN.IO opportunity

Cell-context cybersecurity

TTAN.IO can bind command authority to robot, tool, cell, zone, mission and observed production state rather than evaluate a robot command in isolation.

TTAN.IO relationship

TTAN.IO is designed to sit outside the functional-safety authority while adding cyber eligibility and evidence around physical action. A safety PLC or interlock can still stop motion regardless of TTAN.IO’s cyber decision.

Collaborative robotics

ISO/TS 15066:2016

Robots and robotic devices — Collaborative robots. ISO/TS 15066 supplements ISO 10218-1 and ISO 10218-2 for collaborative industrial robot systems and their work environment.

It is associated with collaborative operation where humans and robot systems can share or alternate access to workspace under defined protective measures. It addresses hazards, collaborative operating concepts and risk-reduction considerations specific to human-robot interaction.

Applies to

Collaborative industrial applications

Industrial robot systems designed for collaborative operation with humans.

Important distinction

“Cobot” is not automatically safe

Safety depends on the complete application, tooling, task, speed, force, environment and risk assessment — not simply the robot marketing category.

Cyber relationship

Unexpected motion matters more

Where people are close to robots, malicious or erroneous commands can have immediate physical consequences.

TTAN.IO relationship

Cyber HOLD, exact command binding and HUMAN_REQUIRED can add a security boundary before physical action, but TTAN.IO does not replace collaborative-operation risk assessment or safety validation.

Machinery risk assessment

ISO 12100:2010

Safety of machinery — General principles for design — Risk assessment and risk reduction. ISO 12100 provides the general methodology for identifying hazards, estimating and evaluating risk, and reducing risk throughout machinery design and lifecycle.

It is one of the foundational ways machinery designers reason about hazards systematically. It is not a cybersecurity standard, but cyber-induced behavior can create or worsen machinery hazards and therefore must be considered in modern connected systems.

Method

Hazard → risk → reduction

Identify hazards, estimate/evaluate risk, remove hazards where possible and reduce residual risk using protective measures and information for use.

Scope

Whole lifecycle

Design, intended use, reasonably foreseeable misuse, maintenance and other lifecycle phases affect the risk picture.

Cyber relationship

Digital changes can alter physical risk

Unauthorized software, parameters or command paths can invalidate the assumptions used by a machinery risk assessment.

TTAN.IO relationship

TTAN.IO can connect approved digital behavior and exact command context to the physical-risk model. It supports cyber governance around machinery behavior but does not perform the legal machinery risk assessment on behalf of the manufacturer or integrator.

Safety-related control systems

ISO 13849-1:2023

Safety of machinery — Safety-related parts of control systems — Part 1: General principles for design. This standard provides methodology and requirements for designing and integrating safety-related parts of control systems (SRP/CS), including software.

It is strongly associated with safety functions and Performance Levels. It is about whether safety-related control structures achieve the required dependability for reducing machinery risk.

Core concept

Safety function reliability

Architectures, diagnostics, failure behavior and systematic measures support the required performance of safety functions.

Applies across

Multiple technologies

Electrical, hydraulic, pneumatic and mechanical technologies can be part of the safety-related control system.

Boundary

Not command cybersecurity

A valid safety function does not determine whether a network-authenticated production command is legitimate in mission context.

TTAN.IO relationship

TTAN.IO must never bypass or reinterpret a safety-rated function. Its role is orthogonal: cyber authority can be denied before dispatch, while safety-related control systems retain independent authority to prevent hazardous motion.

Machinery functional safety

IEC 62061:2021

Safety of machinery — Functional safety of safety-related control systems. IEC 62061 specifies requirements and recommendations for design, integration and validation of safety-related control systems for machinery. It is a machinery-sector standard built within the broader IEC 61508 framework.

The 2021 edition has subsequent amendments. The standard explicitly focuses on functional safety and does not itself replace the need for dedicated cybersecurity measures.

Core concept

Safety Integrity

Safety functions are engineered and validated against defined integrity requirements and lifecycle controls.

System focus

Safety-related control system

Design, verification, validation, configuration and testing of safety control architectures.

Security note

Functional safety is not cyber

Cybersecurity must be addressed through complementary measures; a safety standard does not authenticate robot missions or network participants.

TTAN.IO relationship

TTAN.IO can treat the state of safety systems as important evidence, but does not claim SIL or functional-safety authority. Cyber decisions remain separate from safety-system decisions.

Foundational functional safety

IEC 61508 series

Functional safety of electrical/electronic/programmable electronic safety-related systems. IEC 61508 is the foundational cross-industry functional-safety framework from which sector-specific standards derive concepts such as safety lifecycle and Safety Integrity Levels (SIL).

For robotics, it is usually encountered indirectly through machinery and sector standards rather than used as the only robot-specific safety rule.

Foundation

Safety lifecycle

Structured lifecycle thinking for safety-related E/E/PE systems, from concept through operation, maintenance and modification.

Integrity

SIL concepts

Quantitative and systematic integrity concepts for safety-related functions and systems.

Boundary

Safety ≠ cyber authorization

Functional safety manages dangerous failures; TTAN.IO focuses on cyber-governed physical action and evidence.

TTAN.IO relationship

TTAN.IO is intentionally not a replacement for IEC 61508 lifecycle or SIL engineering. It adds cybersecurity control before and after physical action while leaving certified safety functions independent.

AGV / AMR safety

ISO 3691-4:2023

Industrial trucks — Safety requirements and verification — Part 4: Driverless industrial trucks and their systems. The standard covers driverless industrial trucks and systems, including AGVs, AMRs and related vehicle categories used in industrial environments.

It is especially relevant where navigation, route planning, localization and interactions with people or infrastructure create mobile physical risk.

Applies to

Driverless industrial vehicles

AGVs, AMRs, automated carts and similar industrial transport systems.

Risk context

Dynamic environment

Unlike a fixed robot cell, mobile robots move through changing areas and interact with traffic, people, loads and infrastructure.

Cyber relationship

Mission + route integrity

Unauthorized destination, speed, zone or mission changes can create physical hazards even when the robot remains mechanically healthy.

TTAN.IO relationship

TTAN.IO’s normalized mission, robot identity, zone/destination binding and runtime reconciliation model is directly relevant to mobile-robot cybersecurity without replacing ISO 3691-4 safety requirements.

Personal-care robot safety

ISO 13482:2014

Robots and robotic devices — Safety requirements for personal care robots. ISO 13482 addresses inherently safe design, protective measures and information for use for personal-care robot categories such as mobile servant robots, physical assistant robots and person-carrier robots.

These systems operate in close proximity to people, often outside traditional guarded industrial cells, increasing the importance of trustworthy behavior and bounded autonomy.

Robot types

Human-adjacent robots

Mobile servant, physical assistant and person-carrier robot classes are central examples.

Primary concern

Human physical safety

Hazards and protective measures associated with direct interaction, assistance and movement around people.

Cyber relationship

Autonomy raises consequence

Compromised navigation, assistance behavior or task selection can create safety and trust impacts beyond traditional IT incidents.

TTAN.IO relationship

TTAN.IO can constrain cyber authority and require fresh evidence/human approval for sensitive actions, while personal-care robot safety remains governed by the applicable safety standard and product risk assessment.

Industrial cybersecurity

IEC 62443 series

Security for industrial automation and control systems. IEC 62443 is one of the most important cybersecurity families around industrial robotics because robots, PLCs, cells, gateways and supervisory systems often live inside an IACS/OT environment.

The series addresses different roles and layers: asset-owner security programs, service-provider/integrator processes, zones and conduits, system security requirements/security levels, secure product development lifecycle and component requirements.

Architecture

Zones + conduits

Segmentation and trust boundaries help constrain communication paths and reduce lateral movement across industrial systems.

Product security

Secure development lifecycle

IEC 62443-4-1 covers secure product development processes including requirements, secure design, verification, defect and patch management.

System security

Security requirements + levels

IEC 62443-3-3 defines technical system security requirements associated with foundational security requirements and security levels.

TTAN.IO relationship

IEC 62443 protects the industrial cyber environment broadly. TTAN.IO Robotics adds a robotics-specific semantic boundary inside that environment: identity is not authority, connectivity is not authority, and an authenticated command still must be admissible for the exact robot and physical context.

Radio-equipment cybersecurity

EN 18031:2024 series

Common security requirements for radio equipment. EN 18031-1, -2 and -3 were developed to support cybersecurity essential requirements under the EU Radio Equipment Directive for relevant radio equipment. The series is especially important for internet-connected and data-processing radio products.

For robots and robotics gateways using Wi-Fi, Bluetooth, cellular or other radio interfaces, these requirements can become relevant independently of ROS or DDS security.

Part 1

Internet-connected radio equipment

Common security requirements for internet-connected radio equipment under the RED cybersecurity framework.

Part 2

Data-processing radio equipment

Additional scope for specified classes processing data, including relevant privacy/security concerns.

Part 3

Virtual money / monetary value

Additional requirements for internet-connected radio equipment processing virtual money or monetary value.

TTAN.IO relationship

Radio cybersecurity protects the radio product and interface. TTAN.IO does not replace RED/EN 18031 controls; it ensures that a successfully authenticated wireless path still does not become unrestricted physical robot authority.

Middleware security

DDS Security 1.2 / ROS 2 Security

DDS Security is the OMG security specification used by DDS implementations to provide participant authentication, access control, cryptographic protection and related security plugins. Version 1.2 was formally adopted in 2026.

ROS 2 Security (SROS2 tooling and ROS 2 security model) uses DDS Security concepts such as identity certificates, permissions, signed governance and enclaves. This is the middleware trust layer closest to many modern robot software deployments.

Identity

Who is the participant?

Certificate-based identity and enclave material help establish which DDS/ROS participant is communicating.

Permissions

What may it access?

Governance and permissions can restrict topics, services/actions and protected communications at middleware level.

Critical distinction

Permission ≠ physical authority

A participant may be validly authenticated and permitted to invoke an interface while the requested physical action is still unsafe, stale, replayed or contextually wrong.

TTAN.IO relationship

TTAN.IO consumes middleware identity/transport trust as evidence but does not replace DDS Security or SROS2. It evaluates the next layer: approved behavior, current robot/cell state, exact command binding, execution readiness and observed physical outcome.

Preserve the standard. Add the missing cyber decision.

TTAN.IO Robotics is not built to claim that one cybersecurity product replaces robot safety, functional safety, OT security, radio security or middleware security. Its value is the cross-layer decision boundary that connects trusted identity, approved behavior, current state, exact physical command authority, runtime observation and evidence.

01

Safety remains safety

E-stops, safety PLCs, scanners, certified controllers and safety functions remain independently authoritative.

02

Cyber remains cyber

IEC 62443, EN 18031, PKI, endpoint controls and DDS/ROS security remain active and are not weakened by TTAN.IO.

03

TTAN.IO adds physical-action governance

The exact robot action must still be admissible now — not merely authenticated, encrypted or technically reachable.

← Back to EU Robotics Regulatory Readiness