Safety remains safety
E-stops, safety PLCs, scanners, certified controllers and safety functions remain independently authoritative.
TTAN.IO Robotics / standards reference
Robot safety, functional safety, industrial cybersecurity and middleware security are different disciplines. TTAN.IO Robotics is designed to preserve those boundaries rather than collapse them. This reference explains the major standards commonly encountered around industrial robots, AMRs, collaborative applications, connected radio equipment and ROS 2 / DDS systems.
A standard can define safety, security or engineering practice. TTAN.IO adds the cybersecurity governance boundary around exact physical action and evidence.
Some standards below address functional safety, some industrial cybersecurity, some radio cybersecurity and some middleware trust. TTAN.IO complements each one in a different way.
Quick navigation
Robotics — Safety requirements — Part 1: Industrial robots. This is the robot-manufacturer side of the ISO 10218 family. It treats the industrial robot itself as partly completed machinery and establishes safety requirements for its design, protective measures and information for use.
It is concerned with hazards created by the robot and its built-in functions before the robot is integrated into a complete application or cell. The standard supports inherently safe design, risk reduction and safety-related robot functions.
Designers and manufacturers of industrial robots, including safety-related robot functions and interfaces.
Hazard reduction at the robot level, safety-related functions, limits, modes and information needed by downstream integrators.
A cyber compromise can invalidate assumptions used by safety functions, but TTAN.IO does not replace the certified safety functions required by the standard.
TTAN.IO uses robot identity, approved behavior and current state as cybersecurity inputs. It can deny or HOLD a cyber-authorized action, but it does not claim to implement or certify the robot’s safety-rated functions.
Robotics — Safety requirements — Part 2: Industrial robot applications and robot cells. This part shifts the focus from the robot product to the integrated application: robot, end-effector, fixtures, cell, safeguarding, interfaces and surrounding machinery.
It covers integration, commissioning, operation, maintenance and decommissioning. That makes it especially relevant to system integrators and factories building real robot cells.
Robot-cell designers, integrators, commissioning teams, operators, maintainers and safety specialists.
Hazards that appear only after the robot is combined with tooling, materials, other machinery, people and the physical workspace.
TTAN.IO can bind command authority to robot, tool, cell, zone, mission and observed production state rather than evaluate a robot command in isolation.
TTAN.IO is designed to sit outside the functional-safety authority while adding cyber eligibility and evidence around physical action. A safety PLC or interlock can still stop motion regardless of TTAN.IO’s cyber decision.
Robots and robotic devices — Collaborative robots. ISO/TS 15066 supplements ISO 10218-1 and ISO 10218-2 for collaborative industrial robot systems and their work environment.
It is associated with collaborative operation where humans and robot systems can share or alternate access to workspace under defined protective measures. It addresses hazards, collaborative operating concepts and risk-reduction considerations specific to human-robot interaction.
Industrial robot systems designed for collaborative operation with humans.
Safety depends on the complete application, tooling, task, speed, force, environment and risk assessment — not simply the robot marketing category.
Where people are close to robots, malicious or erroneous commands can have immediate physical consequences.
Cyber HOLD, exact command binding and HUMAN_REQUIRED can add a security boundary before physical action, but TTAN.IO does not replace collaborative-operation risk assessment or safety validation.
Safety of machinery — General principles for design — Risk assessment and risk reduction. ISO 12100 provides the general methodology for identifying hazards, estimating and evaluating risk, and reducing risk throughout machinery design and lifecycle.
It is one of the foundational ways machinery designers reason about hazards systematically. It is not a cybersecurity standard, but cyber-induced behavior can create or worsen machinery hazards and therefore must be considered in modern connected systems.
Identify hazards, estimate/evaluate risk, remove hazards where possible and reduce residual risk using protective measures and information for use.
Design, intended use, reasonably foreseeable misuse, maintenance and other lifecycle phases affect the risk picture.
Unauthorized software, parameters or command paths can invalidate the assumptions used by a machinery risk assessment.
TTAN.IO can connect approved digital behavior and exact command context to the physical-risk model. It supports cyber governance around machinery behavior but does not perform the legal machinery risk assessment on behalf of the manufacturer or integrator.
Safety of machinery — Safety-related parts of control systems — Part 1: General principles for design. This standard provides methodology and requirements for designing and integrating safety-related parts of control systems (SRP/CS), including software.
It is strongly associated with safety functions and Performance Levels. It is about whether safety-related control structures achieve the required dependability for reducing machinery risk.
Architectures, diagnostics, failure behavior and systematic measures support the required performance of safety functions.
Electrical, hydraulic, pneumatic and mechanical technologies can be part of the safety-related control system.
A valid safety function does not determine whether a network-authenticated production command is legitimate in mission context.
TTAN.IO must never bypass or reinterpret a safety-rated function. Its role is orthogonal: cyber authority can be denied before dispatch, while safety-related control systems retain independent authority to prevent hazardous motion.
Safety of machinery — Functional safety of safety-related control systems. IEC 62061 specifies requirements and recommendations for design, integration and validation of safety-related control systems for machinery. It is a machinery-sector standard built within the broader IEC 61508 framework.
The 2021 edition has subsequent amendments. The standard explicitly focuses on functional safety and does not itself replace the need for dedicated cybersecurity measures.
Safety functions are engineered and validated against defined integrity requirements and lifecycle controls.
Design, verification, validation, configuration and testing of safety control architectures.
Cybersecurity must be addressed through complementary measures; a safety standard does not authenticate robot missions or network participants.
TTAN.IO can treat the state of safety systems as important evidence, but does not claim SIL or functional-safety authority. Cyber decisions remain separate from safety-system decisions.
Functional safety of electrical/electronic/programmable electronic safety-related systems. IEC 61508 is the foundational cross-industry functional-safety framework from which sector-specific standards derive concepts such as safety lifecycle and Safety Integrity Levels (SIL).
For robotics, it is usually encountered indirectly through machinery and sector standards rather than used as the only robot-specific safety rule.
Structured lifecycle thinking for safety-related E/E/PE systems, from concept through operation, maintenance and modification.
Quantitative and systematic integrity concepts for safety-related functions and systems.
Functional safety manages dangerous failures; TTAN.IO focuses on cyber-governed physical action and evidence.
TTAN.IO is intentionally not a replacement for IEC 61508 lifecycle or SIL engineering. It adds cybersecurity control before and after physical action while leaving certified safety functions independent.
Industrial trucks — Safety requirements and verification — Part 4: Driverless industrial trucks and their systems. The standard covers driverless industrial trucks and systems, including AGVs, AMRs and related vehicle categories used in industrial environments.
It is especially relevant where navigation, route planning, localization and interactions with people or infrastructure create mobile physical risk.
AGVs, AMRs, automated carts and similar industrial transport systems.
Unlike a fixed robot cell, mobile robots move through changing areas and interact with traffic, people, loads and infrastructure.
Unauthorized destination, speed, zone or mission changes can create physical hazards even when the robot remains mechanically healthy.
TTAN.IO’s normalized mission, robot identity, zone/destination binding and runtime reconciliation model is directly relevant to mobile-robot cybersecurity without replacing ISO 3691-4 safety requirements.
Robots and robotic devices — Safety requirements for personal care robots. ISO 13482 addresses inherently safe design, protective measures and information for use for personal-care robot categories such as mobile servant robots, physical assistant robots and person-carrier robots.
These systems operate in close proximity to people, often outside traditional guarded industrial cells, increasing the importance of trustworthy behavior and bounded autonomy.
Mobile servant, physical assistant and person-carrier robot classes are central examples.
Hazards and protective measures associated with direct interaction, assistance and movement around people.
Compromised navigation, assistance behavior or task selection can create safety and trust impacts beyond traditional IT incidents.
TTAN.IO can constrain cyber authority and require fresh evidence/human approval for sensitive actions, while personal-care robot safety remains governed by the applicable safety standard and product risk assessment.
Security for industrial automation and control systems. IEC 62443 is one of the most important cybersecurity families around industrial robotics because robots, PLCs, cells, gateways and supervisory systems often live inside an IACS/OT environment.
The series addresses different roles and layers: asset-owner security programs, service-provider/integrator processes, zones and conduits, system security requirements/security levels, secure product development lifecycle and component requirements.
Segmentation and trust boundaries help constrain communication paths and reduce lateral movement across industrial systems.
IEC 62443-4-1 covers secure product development processes including requirements, secure design, verification, defect and patch management.
IEC 62443-3-3 defines technical system security requirements associated with foundational security requirements and security levels.
IEC 62443 protects the industrial cyber environment broadly. TTAN.IO Robotics adds a robotics-specific semantic boundary inside that environment: identity is not authority, connectivity is not authority, and an authenticated command still must be admissible for the exact robot and physical context.
Common security requirements for radio equipment. EN 18031-1, -2 and -3 were developed to support cybersecurity essential requirements under the EU Radio Equipment Directive for relevant radio equipment. The series is especially important for internet-connected and data-processing radio products.
For robots and robotics gateways using Wi-Fi, Bluetooth, cellular or other radio interfaces, these requirements can become relevant independently of ROS or DDS security.
Common security requirements for internet-connected radio equipment under the RED cybersecurity framework.
Additional scope for specified classes processing data, including relevant privacy/security concerns.
Additional requirements for internet-connected radio equipment processing virtual money or monetary value.
Radio cybersecurity protects the radio product and interface. TTAN.IO does not replace RED/EN 18031 controls; it ensures that a successfully authenticated wireless path still does not become unrestricted physical robot authority.
DDS Security is the OMG security specification used by DDS implementations to provide participant authentication, access control, cryptographic protection and related security plugins. Version 1.2 was formally adopted in 2026.
ROS 2 Security (SROS2 tooling and ROS 2 security model) uses DDS Security concepts such as identity certificates, permissions, signed governance and enclaves. This is the middleware trust layer closest to many modern robot software deployments.
Certificate-based identity and enclave material help establish which DDS/ROS participant is communicating.
Governance and permissions can restrict topics, services/actions and protected communications at middleware level.
A participant may be validly authenticated and permitted to invoke an interface while the requested physical action is still unsafe, stale, replayed or contextually wrong.
TTAN.IO consumes middleware identity/transport trust as evidence but does not replace DDS Security or SROS2. It evaluates the next layer: approved behavior, current robot/cell state, exact command binding, execution readiness and observed physical outcome.
TTAN.IO principle
TTAN.IO Robotics is not built to claim that one cybersecurity product replaces robot safety, functional safety, OT security, radio security or middleware security. Its value is the cross-layer decision boundary that connects trusted identity, approved behavior, current state, exact physical command authority, runtime observation and evidence.
E-stops, safety PLCs, scanners, certified controllers and safety functions remain independently authoritative.
IEC 62443, EN 18031, PKI, endpoint controls and DDS/ROS security remain active and are not weakened by TTAN.IO.
The exact robot action must still be admissible now — not merely authenticated, encrypted or technically reachable.