Home Robotics AI Automation Calculator About
Terms of Service Privacy Policy

ISO 10218:2025 and the New Era of Robot Safety Standards: What Every Integrator Needs to Know

ISO 10218:2025 and the New Era of Robot Safety Standards: What Every Integrator Needs to Know

If you have been deploying collaborative robots under the 2011 edition of ISO 10218 with ISO/TS 15066 as the supplementary guidance document, the 2025 revision is not a version bump you can file away and revisit later. The structural change is significant enough that applications currently in production require review, and applications in design need to be built against a different normative baseline than they were 18 months ago.

ISO/TS 15066's collaborative application content has become normative within ISO 10218-2:2025, replacing the term 'collaborative robot' with 'collaborative application,' and mandatory physical force measurement is now required for Power and Force Limiting validation instead of being an optional requirement. Getting those three changes wrong in a compliance argument is how you end up rebuilding a validation package after the notified body flags it.


The Standards Consolidation: What Actually Changed Architecturally

The robotics industry has been relying on a two-document framework, with ISO 10218-1 and -2 defining safety standards for general industrial robots, while ISO/TS 15066 primarily serves as the reference for collaborative operations. This advisory status introduced an ambiguity in how companies could interpret and comply with the standard's guidelines. Different notified bodies and market surveillance authorities interpreted "advisory guidance" with different degrees of strictness, producing inconsistent enforcement outcomes.

ISO 10218-2:2025 closes that ambiguity by absorbing ISO/TS 15066's collaborative content into the main standard as normative requirements. Biomechanical limits for human-robot contact, the detailed requirements for each collaborative operating mode, and the validation methodology for Power and Force Limiting are now normatively required by the standard rather than recommended by a guidance document. ISO/TS 15066 technically still exists in publication catalogs and is flagged for its own future revision, but for compliance purposes, the operative document is now ISO 10218-2:2025. A sole reliance on ISO/TS 15066 for compliance is no longer defensible.

By adopting the ANSI/A3 R15.06-2025 standard, the U.S. reinforces its commitment to national consistency, thanks to recent ISO updates. The US version adds a third part covering end-user requirements that has no direct ISO 10218 counterpart, which matters specifically for end users who are also acting as their own integrators, which is the common scenario in SME cobot deployments where the purchasing organization also designs and validates the cell.

Diagram showing the 2025 standards consolidation where ISO/TS 15066 (advisory) is superseded by ISO 10218-2:2025 (normative), with US adoption via ANSI/A3 R15.06-2025 and new end-user integrator requirements.
This diagram captures the architectural shift in collaborative robotics safety standards that took effect in 2025. Prior to 2025, two key standards - ISO 10218-1/2 and ISO/TS 15066 - governed industrial safety, providing general guidelines through the former and advisory guidance with non-binding weight via the latter. With immediate effect, the newly adopted international standard, ISO 10218-2:2025, takes precedence, rendering its specifications binding and non-disputable. Citing ISO/TS 15066 in isolation is no longer a viable basis for ensuring compliance. In the US, this is adopted as ANSI/A3 R15.06-2025, with a new Part 3 focused on end-user requirements—critically, it positions the end-user as the system integrator, a common scenario in small-to-medium enterprises (SMEs). This consolidation moves the industry from discretionary best practices to enforceable safety obligations, fundamentally altering risk assessment, system design, and legal liability for collaborative robot applications.

The Application-Safety Principle: Why "Cobot" Is the Wrong Mental Model

The terminology shift from "collaborative robot" to "collaborative application" is the conceptual change that has the most practical consequence for how organizations approach procurement and compliance.

Marketing language around cobots has consistently implied that safety is a property the hardware possesses independently, that buying a certified cobot means buying a safe cobot. Under the 2025 standard, solo operation is no longer justified as a standalone aspect of robot safety and collaboration. For a thorough comprehension, it's essential to assess all components of the application in unison, including the robot arm, end-of-arm tooling, workpiece, programmed trajectory, and cell layout.

The practical implication is concrete. A Universal Robots UR10e running a soft foam block through a slow pick-and-place cycle with adequate force limiting enabled may be a fully compliant PFL collaborative application. Install a sharp deburring tool on the same robot, increase speed to meet cycle time, and you have a different application entirely, one that requires a completely new risk assessment regardless of the underlying robot's collaborative capability certification. Any time the EOAT changes, the workpiece changes, or the speed profile changes materially, the application must be re-assessed as a new application rather than treated as a minor modification of a previously validated one.

This also resolves the most common compliance error in the field: purchasing a robot that a manufacturer has certified as capable of supporting collaborative technologies, then treating that arm certification as equivalent to a certified work cell. The manufacturer ensures compliance with relevant safety standards through hardware-level integration of critical safety functions. In most cases, the organization overseeing the integration takes on the responsibility of ensuring the final application meets safety standards for shared spaces. Conflating these two distinct certifications is where liability exposure accumulates.

Diagram debunking the
This graphic challenges the pervasive misconception that buying a "certified cobot" guarantees a safe, out-of-the-box work cell. In reality, the robot arm's certification only confirms that its hardware supports safety functions—it does not make the entire cell inherently safe. True safety is determined at the application level through work cell certification for shared-space operation. Crucially, any change to the end-of-arm tooling (EOAT)—whether a new gripper, sensor, or welding torch—introduces new risks such as pinch points, inertial changes, or altered force profiles. This invalidates the previous approval and triggers a complete new risk assessment, with the system either passing (PFL compliant) or failing (unsafe). The core takeaway: safety is not inherent to the machine; it is a property of the entire integrated application, and must be continuously re-evaluated as the task or tooling evolves.

A comprehensive analysis of collaborative modes requires dissecting their technical fundamentals.

According to ISO 10218-2:2025, there are four standardized collaboration methods that can be used on their own or blended together within a specific application.

Safety-Rated Monitored Standstill

Clearance is now granted for safe access into the work zone, following a complete halt by the robot. Critically, the robot remains powered with drives energized; the standstill condition is monitored continuously by safety-rated monitoring functions rather than by removing power. The practical advantage is faster restart after the human exits the zone compared to a full power-off cycle, which matters in applications where frequent human access, for part loading or quality inspection, would cause unacceptable productivity loss if every entry required a full stop-and-restart sequence.

In order to meet safety standards outlined in the ISO 13849-1 guidelines, system manufacturers, such as those utilizing Siemens S7-1500F and Pilz PNOZ multi mB, must ensure strict adherence to Category 3 PL d requirements during standstill periods, when diagnostic capabilities can detect isolated faults before the system transitions into an unsafe state. That architecture requirement means single-channel standstill detection is not sufficient; the safety circuit needs redundant position monitoring paths.

Diagram of Safety-Rated Monitored Standstill (SRMS) showing drives energized with continuous monitoring, 1s restart vs. A quick 5-10 second power cycle followed by dual-channel positional feedback that meets the requirements of ISO 13849-1 for Category d and Class. 3.
This graphic explains Safety-Rated Monitored Standstill (SRMS) —a critical safety function in collaborative robotics that keeps robot drives energized while continuously verifying that all axes remain stopped. This allows human operators to enter the work cell for tasks like part loading, maintenance, or teaching, without the time penalty of a full power cycle. The performance improvement is substantial: SRMS provides a quick 1-second restart, compared to the 5-10 second power cycle required for traditional reboots, resulting in a notable productivity gain in high-demand applications. To achieve this safely, the system employs dual‑channel position feedback (e.g., redundant joint encoders) with single fault detection, meeting the requirements of ISO 13849‑1 Performance Level d, Category 3. This architecture ensures that even if one feedback channel fails, the second maintains safe monitoring. The function is implemented using safety-rated controllers such as the Siemens S7‑1500F or Pilz PNOZ, and is a standard feature on robots like the UR10. SRMS represents a practical balance between safety and throughput, enabling human-robot collaboration without unnecessary downtime.

Hand Guiding

The robot arm is controlled manually by the operator using a handheld interface, with movement restricted to direct guidance and reduced speed. Common use cases are lead-through programming in cells where the operator teaches the robot waypoints by physically moving it, and power-assisted material handling where the robot carries the weight of a heavy fixture while the operator controls the positioning. The standard's requirements for the guiding device, specific enabling button design to ensure sustained intentional operator input rather than accidental activation, directly affect the ergonomics and operator fatigue profile of this mode in sustained production use.

Diagram of hand guiding in collaborative robotics, covering lead-through programming, power-assisted handling, enabling-device control, sustained intentional input, and accidental motion prevention. In this collaborative approach, humans physically engage with the robotic arm to pinpoint precise locations or carry out complex procedures. Unlike traditional jogging via teach pendants, hand guiding uses power-assisted handling to amplify the operator's force, making heavy or bulky robots feel light and responsive. However, safety is paramount: motion is only allowed on sustained, intentional input, typically via an enabling device (e.g., a dead-man switch or force/torque sensor thresholds) that must be continuously activated. This prevents accidental motion from bumps or inadvertent contact. The diagram also highlights the importance of ergonomics in sustained production—poorly designed hand-guiding interfaces can lead to operator fatigue or repetitive strain injuries, so optimal handle placement, force scaling, and motion smoothing are critical. Lead-through programming enabled by this mode allows rapid, intuitive path teaching without writing code, significantly reducing setup time for small-batch or frequent-changeover manufacturing lines.

Speed and Separation Monitoring

SSM uses external sensors to continuously measure the distance between the robot and detected humans in the cell, scaling robot speed down as the human approaches and triggering a protective stop if the human enters a defined minimum separation distance. SICK nanoScan3 and Pilz PSENscan safety laser scanners are the dominant hardware implementations for this mode in production applications, providing configurable protective field zones with the safety-rated response times SSM requires.

The separation distance calculation is not a simple fixed number. The minimum permissible separation threshold is calculated by taking into account the robot's shutdown interval, set against a baseline human movement speed of 1.6 meters per second, as well as sensor signal processing times and control system noise levels. Getting that calculation wrong by omitting any of those additive terms produces a protective distance that is smaller than required, which means the robot may not be fully stopped before a human arrives at the robot's current position during the stopping sequence. Safety scanner positioning and field geometry relative to all possible approach vectors is the configuration step that most commonly requires revision during validation.

A visual representation of speed and separation monitoring (SSM) reveals dynamic zones, the additive safety distance formula with robot stopping time, sensor response, and a human approach speed of 1.6 m/s, along with a warning that field geometry revision is the most common validation failure."> This graphic illustrates a fundamental aspect of robotic safety, namely the Speed and Separation Monitoring framework as specified in the ISO/TS 15066 standard. Instead of stopping the robot when a human approaches, SSM dynamically scales the robot's speed based on the measured separation distance, maintaining a minimum protective separation that is continuously recalculated. The robot's overall safety performance is shaped by a multifaceted dynamic interplay among its braking time, sensor response delay, and the approaching pedestrian's velocity, which are balanced against the control system's responsiveness, yielding a comprehensive impact of 1.6 meters per second. If the distance shrinks below the calculated threshold, the robot slows or stops before the human can reach it—but if the distance is too small, the robot may not fully stop in time, creating a collision risk. The diagram also highlights a critical implementation pitfall: field geometry revision is the most common validation failure. SSM relies on protective field geometries (e.g., using a SICK nanoScan3 safety laser scanner) that must account for all possible approach vectors—not just frontal approaches. A field that is too narrow, too short, or improperly oriented leaves blind spots where a human can enter undetected, rendering the entire safety system invalid. This makes thorough risk assessment and field configuration testing essential for compliant SSM deployment.

Power and Force Limiting

PFL is the mode that defines most people's mental image of a "fenceless" collaborative robot. To avoid surpassing the biomechanical injury thresholds stipulated by the current version of ISO 10218-2:2025, both kinetic energy and contact force are limited within the confines of Annex A in the latest edition of ISO/TS 15066. ABB GoFa, KUKA LBR iiwa with its integrated joint torque sensors, and Universal Robots e-Series with joint current monitoring all implement PFL, though the underlying sensing and response mechanism differs between these platforms in ways that directly affect validation.

The 2025 standard makes physical force measurement mandatory for PFL compliance validation. Simulation results alone, regardless of how carefully the model is constructed, are no longer accepted as primary evidence. A calibrated Pressure and Force Measuring Device, the IFA hand-arm measurement tool being the standard-referenced example, must be physically applied at each potential contact location in the robot's workspace to measure actual contact forces under real operating conditions. This is a meaningful increase in validation burden, particularly for applications with complex trajectories where multiple contact scenarios need to be measured rather than simulated.

Diagram of power and force limiting (PFL) showing three robot implementations (ABB GoFa, KUKA LBR iiwa, UR e‑Series), the shift from simulation-only to mandatory physical measurement, biomechanical thresholds per ISO 10218-2:2025, and the validation burden across contact points and trajectories. One of the critical safety features built into this robot is power and force limiting, which helps prevent accidents by regulating the robot's energy output and movement speed. The interaction between humans and robots is safeguarded by PFL's commitment to prevent excessive force from being applied. Three commercial implementations are showcased in the diagram, including ABB's GoFa with joint torque sensing, KUKA's LBR iiwa with integrated joint sensors, and Universal Robots' e-Series which utilizes joint current monitoring. Each sensing mechanism has different accuracy, bandwidth, and friction-compensation characteristics, leading to different validation approaches.

Biomechanical Limits: The Numbers and the Logic Behind Them

The normative force and pressure limits that PFL applications must stay within are defined across 29 specific body areas and 12 broader body regions, with the skull and temples carrying the lowest limits due to their consequences of injury, and the outer thigh and upper arm carrying higher limits due to both the mechanical properties of that tissue and the reduced functional impact of bruising-level injury there.

The transient versus quasi-static distinction is the most important conceptual nuance in applying these limits correctly. During temporary phases, movement restrictions are relaxed, enabling a greater range of motion for the affected limb compared to static states, where it is restricted to half the amplitude experienced when fully immobile. When an object is stuck between a robot and a stationary surface, sustained pressure typically outweighs brief shocks, causing injury at lower forces than comparable brief impacts. Many PFL validation failures in real applications occur at quasi-static clamping scenarios that the initial hazard identification missed, typically at locations where a robot trajectory passes close to a table edge, frame member, or fixturing that a human hand or arm could be trapped against.

Validating PFL against these limits with a PFMD is labor-intensive but straightforward in principle: apply the measurement device at each identified contact scenario, run the robot at maximum application speed and payload, and confirm that measured peak forces stay within the normative limits with adequate margin. The margin question matters because the PFMD measures peak transient impact force, which is velocity-dependent; small changes in robot speed or approaching mass can shift measured values meaningfully, so validating precisely at the limit without margin is not a defensible compliance posture.

Diagram of biomechanical limits for cobot safety, contrasting transient vs. quasi-static contact, showing a color-coded body-area injury map, and emphasizing the need for validation margins beyond normative limits.
This graphic breaks down the biomechanical limits underlying Power and Force Limiting (PFL) as defined in ISO 10218‑2:2025. The human body is divided into 29 body areas, each with distinct injury thresholds—color‑coded from red (severe injury risk, e.g., eyes, throat, spine) to green/yellow (higher force tolerance, e.g., forearm, palm, bruising‑level injury). Transient and non-transient contacts exist, with the latter providing approximately 50% more flexibility when it comes to handling forces. Quasi-static contact conditions are typically more restrictive due to the potential for prolonged tissue compression, which can lead to damage at significantly lower force levels, making it a common source of failure in validation if not properly assessed. A crucial engineering takeaway: validation without margin is indefensible. Peak impact force is velocity‑dependent, meaning even small speed changes shift measured values meaningfully. Validating exactly at the normative limit leaves no room for sensor noise, wear, or payload variations—so a conservative margin is mandatory to ensure repeatable, certifiable safety during real‑world collaborative operations.

Advanced Sensing Technologies for Collaborative Safety

Six-Axis Force-Torque Sensors

High-resolution 6-axis F/T sensors at the tool flange or integrated into robot joints, ATI Gamma and Gamma SI series being the standard reference hardware in research validation, allow the robot to detect contact across all force and torque axes with sub-Newton resolution. For PFL implementation this provides a direct contact force measurement path that is more reliable than current-based torque estimation, which carries motor temperature and bearing friction variability that degrades force estimation accuracy over the operating life of the joint. The trade-off is cost, mechanical integration complexity at the flange, and the additional wiring and connector that adds a potential failure point.

Diagram comparing direct six-axis force-torque sensors (stable, no drift, sub-Newton resolution) versus current-based estimation (drift-prone due to motor temperature and bearing friction), highlighting the trade-offs in complexity and reliability.
This graphic examines the engineering trade-off between direct force-torque sensing and current-based estimation for robotic manipulation. While direct measurement using a dedicated F/T sensor delivers stable, drift-free performance with sub-Newton resolution, it adds mechanical integration complexity, cost, and potential failure points (e.g., wiring, connectors). In contrast, estimating forces from motor currents is cheaper and simpler to integrate but suffers from estimation drift over the robot's lifetime—motor temperature changes and bearing friction introduce cumulative errors, as illustrated by a sample estimated force of 2.8 N that may not reflect reality. This drift undermines precision in delicate tasks like polishing, assembly, or haptic feedback, and complicates safety certification, as contact forces cannot be reliably bounded without periodic recalibration. The choice ultimately depends on application needs: high-accuracy, safety-critical systems favor direct sensing despite added complexity, while cost-sensitive or coarse-force applications may accept estimation's trade-offs.

E-Skin and Advanced Tactile Sensing

Electrical Impedance Tomography applied to compliant conductive skins distributed over robot arm surfaces provides distributed contact sensing at spatial resolutions that discrete sensor arrays cannot match without impractical sensor density. By injecting known current patterns through the conductive skin layer and measuring the resulting voltage distribution, EIT algorithms reconstruct the contact pressure map across the entire sensing area, identifying both the location and magnitude of contact events. Iontronic skins using ion transport in gel matrices as the sensing medium offer self-healing properties that conventional silicone-substrate printed electronics do not, making them considerably more durable under the repeated mechanical stress that robot arm surfaces experience in production environments.

The proximity sensing extension of these e-skin technologies, where the fringe capacitance field beyond the skin surface detects the approaching human hand before physical contact, gives the robot system an anticipatory response capability that allows deceleration to begin before contact rather than after it, which meaningfully reduces peak contact force at the moment of impact compared to systems that detect contact only through force sensing.

Diagram of advanced tactile sensing technologies including Electrical Impedance Tomography for high-resolution contact mapping, self-healing iontronic skins, and proximity sensing using fringe capacitance for anticipatory deceleration before contact. By leveraging cutting-edge e-skin and haptic sensing technologies, this visualization fundamentally alters the landscape of traditional force measurement methodologies. Electrical Impedance Tomography (EIT) enables high‑resolution contact mapping across large, flexible surfaces using fewer electrodes, reconstructing pressure distribution in real time. Iontronic self‑healing skins add robustness by automatically repairing damage from cuts or wear, maintaining sensing performance over long deployments—critical for industrial or prosthetic applications where durability is paramount. The most forward‑looking feature is proximity sensing via fringe capacitance, which detects an approaching object before physical contact occurs. This anticipatory capability allows the robot to initiate pre‑contact deceleration, reducing peak impact force upon interaction. Lower impact forces directly improve safety in human‑robot collaboration and enable gentler handling of fragile objects in picking or assembly. Together, these technologies move tactile sensing from passive contact detection toward proactive, intelligent interaction—bridging the gap between reactive and predictive physical human‑robot interaction.

Safety Laser Scanners for SSM

Safety-rated area scanners for SSM implementation require configuration of at least two protective field zones: an outer slow-down zone where robot speed begins reducing as the human enters, and an inner stop zone where the robot halts completely. The scanner's Safety Integrity Level rating must match the SIL requirement derived from the application's risk assessment, and the scanner's response time is a direct input into the protective separation distance calculation described earlier. Scanner position relative to potential reflective surfaces in the cell, polished metal fixturing and transparent guarding materials being the common problem cases, requires validation that the scanner's object detection is not compromised by those reflective conditions in ways that extend effective response time beyond the value used in the distance calculation.

Diagram of safety laser scanners for SSM showing dual-field zones (slow-down and stop), SIL rating requirements, and a protective distance formula warning that reflective surfaces can inflate the scanner response time term.
This graphic explains the use of safety laser scanners (e.g., SICK nanoScan3, Pilz PSENscan) for Speed and Separation Monitoring (SSM) . The scanner projects two concentric field zones: an outer slow-down zone that reduces robot speed as a human approaches, and an inner stop zone that halts the robot completely if the distance shrinks further. The scanner's SIL rating must align with the assessed risk level to ensure the safety function remains valid. The protective distance formula includes a term for scanner response time, but a critical real‑world pitfall is reflective surfaces. Shiny floors, metal fixtures, or wet areas can cause spurious reflections, misleading the scanner into reporting an object farther away than it actually is—or even missing it entirely. This artificially inflates the response time term and compromises the calculated safe distance. Proper reflective surface validation (e.g., testing with representative objects and surface finishes) is therefore mandatory to ensure the scanner reliably detects humans, preventing the system from allowing unsafe proximity during collaborative operation.

The functional safety architecture is inherently connected to cybersecurity, as both are essential components of a robust and resilient systems design.

Performance Level and Category Requirements

ISO 13849-1 PL d Category 3 has historically been the default architecture requirement for robot safety functions in collaborative applications: two independent safety channels that can each independently achieve the safe state, with diagnostic coverage sufficient to detect a single fault between demands on the safety function. The 2025 standard introduces explicit risk assessment-driven architecture flexibility: if the probability of dangerous failure calculated for a specific safety function is demonstrably low enough, Category 2 single-channel architectures with high diagnostic coverage may be permitted.

This is less permissive than it sounds in practice. Category 2 with high diagnostic coverage requires a test channel that exercises the safety function at intervals short enough that a single-fault-to-dangerous-failure sequence cannot accumulate between tests. Demonstrating that the diagnostic coverage meets the required threshold for the specific hardware used requires detailed failure mode analysis that most standard component data sheets do not provide directly, and the calculation rigor required is comparable to the Category 3 validation effort it nominally simplifies.

Diagram comparing ISO 13849‑1 PL d Cat 3 (dual‑channel, independent inputs/outputs) vs. Cat 2 with high DC (single‑channel plus test signal), highlighting that Cat 2 with high DC requires comparable validation effort and rigorous failure‑mode analysis.
This graphic clarifies the 2025 flexibility in meeting Performance Level d: while Category 3 uses dual, independent channels for fault tolerance, Category 2 with high Diagnostic Coverage is a permitted alternative—but it is not a simpler shortcut. It requires a test channel with a proven short interval, exhaustive failure‑mode analysis, and high DC, making the validation effort comparable to Cat 3. A key obstacle: component data sheets rarely provide required DC values, so deriving them is nontrivial.

IEC 62443 and the Cybersecurity Requirement

Introducing a new cybersecurity mandate as a compulsory robot safety standard for the very first time will undoubtedly come as a shock to many organizations and pose significant challenges. A networked robot cell where safety parameters can be modified over a network connection that is not appropriately authenticated and segmented does not have a complete safety case under the 2025 standard, regardless of how thoroughly the physical safety functions have been validated.

IEC 62443-3-3 provides the system security requirements framework the standard points toward, covering network segmentation, user authentication for safety parameter access, and audit logging of configuration changes. For a typical robot cell connected to a factory OT network running on Profinet or EtherNet/IP, this means the safety PLC's parameter access must be gated behind authenticated access control, the safety network segment must be isolated from the broader IT network by a properly configured industrial firewall, and configuration changes to safety parameters must be logged in a manner that supports audit trail reconstruction. Implementing this on a Siemens TIA Portal-managed S7-1500F cell or a Rockwell Studio 5000-managed ControlLogix safety system requires deliberate configuration work rather than default installation.

Diagram of IEC 62443 cybersecurity requirements for safety systems, showing network segmentation, authenticated access, and audit logging, with a warning that unauthenticated safety‑parameter changes can bypass physical safety validation.
This graphic underscores that cybersecurity is now a mandatory part of the safety case under IEC 62443. Unauthenticated access to safety parameters (e.g., over Profinet/EtherNet/IP) can bypass physical safeguards, leaving organizations off‑guard. A complete safety case requires network segmentation, authentication, and an audit trail of all safety changes—but achieving this demands deliberate configuration in platforms like Siemens TIA Portal or Rockwell Studio 5000, not default installations.

Implementation Discipline: What a Compliant Deployment Actually Requires

Walking through the implementation sequence is useful because the order matters and skipping steps introduces later rework.

Define the application limits concretely before anything else: robot model, exact EOAT mass and center of gravity, intended payload, maximum speed at each stage of the motion cycle. The safety distance calculations and biomechanical limit margin assessments all depend on these numbers being accurately fixed before the design proceeds.

Hazard identification must span the full lifecycle, not just the steady-state production cycle. Commissioning, programming, maintenance access, cleaning, and jam clearance all expose operators to robot-related hazards in ways the normal operating cycle does not, and the risk assessment must enumerate and address each of them specifically. The crushing hazard introduced by a specific EOAT geometry against a specific fixturing surface is the kind of scenario that hazard identification workshops with experienced operators find reliably and that desk-based assessments routinely miss.

Through the application of ISO 12100 guidelines, quantifying hazards by severity and frequency enables organisations to pinpoint the most pressing threats and opt for targeted mitigation approaches. The risk reduction hierarchy applies in order: engineer the hazard out through design first, add engineering safeguards second, and provide administrative information last. Adding PFL to compensate for a EOAT design that could be made inherently safer is not the correct sequence.

Validation requires physical evidence. For PFL mode, that means PFMD measurements at every identified contact scenario. For SSM mode, that means measured stop distances at maximum speed, confirmed against the calculated protective separation distance with the actual scanner response time, not the data sheet typical value.

Documentation that cannot support periodic re-assessment is incomplete documentation. As the application evolves, as part designs change, as EOAT is modified, the risk assessment needs to be re-executed as a new assessment for the changed application rather than annotated as an amendment to the original.

Five‑phase implementation diagram (Define, Identify, Estimate, Validate, Document) showing the mandatory discipline for compliant safety deployment, with warnings that skipping steps causes rework and that physical evidence (not simulation) is required for validation.
Compliant deployment is a linear, non‑negotiable five‑phase process: define fixed application limits, identify risks via ISO 12100 hierarchy, estimate with physical evidence (not simulation), validate through measurement, and document thoroughly. Skipping any step guarantees later rework—and the final assessment must treat the system as an evolving safety case, not a one‑time amendment.

The Honest Productivity Conversation

Marketing for collaborative robots frequently implies productivity gains that independent research does not fully support. A peer-reviewed study of cobot deployment in mechanical assembly tasks found a 10 percent productivity improvement over manual assembly. That is a real and economically meaningful gain. It is not the "multiples" improvement sometimes implied in vendor presentations.

The underlying reason is that the same safety limits that make collaborative operation permissible without fencing also constrain operating speed. A traditional industrial robot on a high-volume part in an isolated cell, a FANUC M-710iC running at 2 meters per second behind a safety fence, delivers throughput that a PFL-limited cobot at its safe collaborative speed cannot approach. For high-volume, single-part production, the fenced industrial robot wins decisively on throughput.

Where collaborative applications genuinely win is high-mix, low-volume production: contract manufacturing job shops where the cell configuration changes frequently, assembly lines where human judgment and flexibility on part placement is genuinely needed mid-cycle, and environments where installing and maintaining safety fencing across a flexible floor plan is itself a significant operational overhead. The strategic fit for collaborative applications is defined by that flexibility requirement, not by peak throughput numbers, and specifications built around the wrong use case produce expensive disappointment regardless of compliance quality.

Diagram contrasting peak throughput (high-volume, single-part) with flexibility (high-mix, low-volume), noting a 10% productivity gain over manual assembly but warning that wrong use cases lead to expensive disappointment.
Cobots win decisively on throughput for high-volume, single-part lines (peer-reviewed: ~10% improvement over manual assembly), but their real strategic advantage is flexibility—enabling rapid cell changes, no fencing, and high-mix/low-volume production. Choosing peak throughput for the wrong application guarantees disappointment, even with perfect safety compliance.

The Practical Upshot

ISO 10218:2025 is the most substantive revision to robot safety standards in over a decade, and the consolidation of ISO/TS 15066's content into the main normative framework means the compliance bar has risen for all collaborative robot applications, not just new ones. The Application-Safety Principle, the mandatory PFMD measurement requirement for PFL, and the new explicit cybersecurity requirement collectively change what a defensible safety case must demonstrate.

For organizations currently operating collaborative applications under the 2011 standard and ISO/TS 15066, a gap assessment against the 2025 requirements is not optional planning; it is the appropriate engineering response to a normative change that affects existing installations. For organizations designing new collaborative cells, building to the 2025 standard from the start is substantially less expensive than validating to the old standard and then remediating the gaps during the transition period.

The underlying engineering principle has not changed: worker protection requires measured evidence, not certified hardware assumptions. The 2025 standard simply makes that principle more precise, more comprehensive, and more enforceable than its predecessor.