

Published in February 2025, ISO 10218-1:2025 and ISO 10218-2:2025 are the safety standards for industrial robots in general — not cobot-only documents. The substance of ISO/TS 15066 (2016), which quantified permissible contact limits based on pain-onset research, is now consolidated into the main standards, making ISO 10218 the technical hub of global robot safety.
Three markets point to that hub in their own ways. The United States adopted them as its national standard, ANSI/A3 R15.06-2025 — a re-convergence for a country that had maintained its own robot safety standard since 1986. The EU Machinery Regulation (Regulation (EU) 2023/1230) applies from 20 January 2027 with no transition period, replacing the Machinery Directive; Official Journal citation of the 2025 editions as harmonized standards is still pending, so an edition gap remains a live practical issue. Korea's KS series currently references the 2011 editions; once harmonization is complete, all three jurisdictions will reference the same document — and Korea's installation-site certification, together with its recognized alternative to physical barriers, already audits against ISO 10218-2 today.
The procedures did not merge: EU conformity assessment and CE marking, US standards conformance, and Korean certification remain separate, with different responsible parties. What converged is the substance they examine — ISO-based technical evidence: an application risk assessment, verification and validation (V&V) of safety-function performance (Performance Level, PL; Safety Integrity Level, SIL), and quantified proof that human contact stays within permissible limits, demonstrated through methods such as Power and Force Limiting (PFL) and Speed and Separation Monitoring (SSM). In Korea, that proof has taken the form of the Collision Risk Index (CRI) under KOROS 1162-1. Three markets, one answer sheet.
The economics change accordingly: from "evidence × N markets" to "one body of evidence + procedure × N." The multiplier is the number of markets a company — manufacturer, system integrator (SI), or end user — is exposed to. Safety verification becomes reusable market-access evidence: one dossier, reused across markets, produced and checked layer by layer through the Application Verification Stack.
The laws differ by market. So do the procedures, and so do the signatures. Yet bring a robot application into any of the three, and the technical question you face is the same one: what evidence will you bring to prove that this application is safe? This section looks at the document that became the yardstick for that question — and at the three mechanisms by which three markets came to point at it.
In February 2025, ISO 10218-1:2025 (third edition) and ISO 10218-2:2025 (second edition) were published. Part 1 covers the industrial robot itself — the manufacturer's scope. Part 2 covers robot applications and the integration of robot cells — the scope of whoever performs the integration, usually a system integrator, or the user company itself where it integrates on its own. Both are Type-C standards built on the risk-reduction framework of ISO 12100. The revision is extensive by the publisher's own account; Part 2 alone roughly tripled in length. That is worth registering, because what three markets are converging on is not an incremental edit but a substantially rebuilt document.
The substance of ISO/TS 15066 (2016), the technical specification that had governed collaborative applications, was consolidated into the main standards in this revision. Most of it went into Part 2 (per the published foreword of ISO 10218-1:2025). The contact-limit figures moved with it. Body-region force and pressure values grounded in pain-onset research now sit in an annex — for the hand and fingers, for example, a quasi-static maximum of 140 N, the same value as in TS 15066. Standardized test methods are to follow, and the annex figures are informative rather than normative (per broad industry reporting).
Setting one thing straight — ISO 10218 is not a "cobot standard." The two titles read "Industrial robots" and "Industrial robot applications and robot cells." These are the safety standards for industrial robots in general; collaborative applications are one case within their scope. The revised foreword states that the terms "collaborative robot" and "collaborative operation" are not used in the body text. The reason: collaboration is a property of the application, not of the robot, and what is verified and validated is the application (per the published foreword). A company running conventional industrial robots behind safeguards falls squarely within this standard's scope.
Three things make this document the hub. First, it is the source of the technical requirements — the three markets below each point to it through a legal mechanism of their own. Second, it is the only document that says how. Law states what must be met; the standard states how to demonstrate it — permissible limits, performance levels, verification and validation. The document lying open on a practitioner's desk is the standard, not the law. Third, the numbers carry through. The 2011 editions laid down the conceptual frame of collaborative operation; TS 15066 turned pain-onset research into figures in 2016; the 2025 editions brought those figures inside the main standards. Editions change, but the substance — what contact a human being can tolerate — runs unbroken through them.
Three markets now hold this hub in place through three different mechanisms: the EU by writing a date into law, the United States by adopting the document as its national standard, and Korea by operating its certification and recognition procedures against its adopted edition. The next three sections take them in that order — the market that set the deadline, the market that came home to the document, and the market where the standard is already an audit criterion.
What the EU created is not a new technical criterion. It is a deadline. The EU Machinery Regulation (Regulation (EU) 2023/1230) replaces the Machinery Directive (2006/42/EC), in place since 2006. It entered into force on 19 July 2023 and applies from 20 January 2027. There is no transition period in which the two laws run in parallel. Until 19 January 2027 the Directive alone applies; from the 20th, the Regulation alone. (A few provisions, such as the designation of conformity assessment bodies, applied earlier.)
Split the roles and the structure comes into focus. The Regulation defines what must be satisfied; ISO 10218 defines how to demonstrate it — the same division as in the hub section. The link between the two is the harmonized-standards mechanism: design to a harmonized standard, and you obtain a presumption of conformity with the Regulation's essential requirements.
And here sits the edition gap this report has to address — the lag between the edition a law cites and the current edition of the standard. To this day, the harmonized-standards list under the current Machinery Directive cites EN ISO 10218-1/-2:2011 (per the legal text). As of this report, the 2025 editions have not yet been cited in the EU Official Journal (OJ). Listing of ISO/IEC-family standards has been delayed in the aftermath of the so-called Malamud ruling on standards copyright (per industry reporting). The harmonized-standards list for the Machinery Regulation, meanwhile, continues to be built out through the end of 2026 (per Commission planning).
Two clocks are running here, and they should not be read as one. "Standard published" and "legally cited" are different layers — publication moves at the speed of engineering consensus, citation at the speed of administration. The practical conclusion cuts one way only: the gap is not a reason to defer preparation but the reason preparation cannot be deferred. Listing is an administrative schedule; 20 January 2027 is a statutory deadline already fixed; and technical evidence takes longer to produce than procedures take to run.
One boundary should be stated clearly: the Machinery Regulation is not equivalent to ISO 10218. The Regulation carries requirements beyond the reach of robot safety standards — cybersecurity among them. This report's convergence thesis is confined to the layer of robot-application safety verification.
If the EU decided when the document would be required, the United States shows what embracing it looks like — and the 2025 adoption is not acquiescence but a homecoming. ANSI/A3 R15.06-2025 is the US national adoption of ISO 10218-1/-2:2025 (per the publisher's announcement). Parts 1 and 2 were approved in August 2025. Part 3 (R15.06-3) followed that October — a joint US–Canada codification of user requirements, covering ground that ISO does not (per industry reporting). The weight of the event shows in the history.
The United States maintained its own robot safety standard from the first R15.06 in 1986 through the 1992 and 1999 editions. It was an era in which the same robot faced different documents in different markets. Yet the modern ISO 10218 series began development around 2000 with that very R15.06-1999 as its starting point (per the chronology given by the standard's development lead at the time). In 2012 the US adopted the international 2011 editions and retired the homegrown original. With that adoption, risk assessment — optional under the 1999 edition — became mandatory (per industry commentary). The 2025 re-adoption completes same-edition convergence.
A document born as a national standard went abroad, became the international standard, and came home. That is not a standard being given up; it is a standard returning. It is also the strongest external evidence of the hub's standing.
Korea completes the pattern — and, for any company operating robots there, it is a market whose procedures already audit against this document. The current KS B ISO 10218-1 and -2 are based on the 2011 editions, reaffirmed in 2017 and 2022. National harmonization of the 2025 editions is in progress and expected to be completed by the end of 2026. When it does, all three jurisdictions will cite the same edition of the same document.
For a reader with Korean operations, three facts about how the system already works matter more than the harmonization calendar.
First, the procedures already audit against ISO 10218 today. Korea's occupational safety rules start from a safeguarding-first principle, and the implementing public notice provides a recognized alternative to physical barriers — the barrier-alternative path — permission to operate without them. Its requirements: safeguarding measures compliant with ISO 10218-2, together with a documented risk assessment. And the audit criterion for Korea's certification of collaborative robot installation sites is KS B ISO 10218-2 itself (per the certifying body's guidance). So the criterion is not waiting on harmonization to take effect here. It is already in force at the adopted edition; harmonization changes which edition the procedures run on, not whether they run on this document.
Second, the locus of responsibility differs from the EU's — and the difference is statutory. For a robot application operated in Korea, the legal duty of risk assessment rests with the business owner of the end-user company, under Article 36 of the Occupational Safety and Health Act. In the EU, as IMPACT details, responsibility sits with the "manufacturer" of the final machinery. A multinational running plants in Korea holds the Korean role regardless of where its headquarters sit.
Third, the numbers were already in circulation. Permissible-contact figures have been available in Korea under two names. KS B ISO/TS 15066 carries the pain-onset-based values that trace back to the Mainz pain research. KOROS 1162-1 — a Korean industry-association standard — carries pain-tolerance-based values, applied through the Collision Risk Index (CRI ≤ 1 as the pass criterion). The document edition lagged; the figures did not. This is why the field record in IMPACT exists at the scale it does. It is also why harmonization, once complete, will be an edition update rather than a zero-to-one event.
The convergence timetable, in one table:
First, two facts that no reading of convergence can erase.
① A standard is not, by itself, law. Binding force arises only through each market's adoption path. "ISO 10218 becomes mandatory in 2027" is therefore a misleading shorthand. Stated precisely: from 20 January 2027, the EU Machinery Regulation applies to whoever places machinery on the EU market. The revised ISO 10218 sits on the practical path to satisfying its requirements.
② Convergence of requirements is not a merger of procedures. No mutual recognition arrangement exists, and each market wired the connection differently: the US through an industry standard, the EU through a statutory deadline, Korea through its certification scheme and public notices. Who is designated responsible also differs by market (IMPACT, "the locus of responsibility"). Here our own terminological distinction becomes the thesis: conformity to a standard is a state; conformity assessment is an activity. What converged is the former, not the latter.
On that foundation, the substance the three procedures examine became the same. Whichever market asks, the answer is the same three items of ISO-based technical evidence: an application risk assessment, verification and validation of safety-function performance, and quantified proof that permitted contact stays within limits. The market-specific vehicles: for the EU, technical documentation and the harmonized-standards path (with the edition-gap caveat above); for the US, R15.06 conformance; for Korea, installation-site certification whose audit criterion is KS B ISO 10218-2, alongside the barrier-alternative path. There is also an observed procurement practice: end-user companies aware of the requirement write certification into their terms of supply (our own field observation). Through it, the requirement travels down the supply chain and lands on the same ISO document. Both things are true at once: the procedures differ, and the evidence is the same.
The payoff is arithmetic. The total cost of safety verification splits in two: producing the technical evidence (large, and an engineering task) and running market procedures (small, and an administrative task). Under divided standards, the cost structure read "evidence × N." Under same-edition convergence it reads "evidence × 1 + procedure × N," and the multiplier is not the number of procedures but the company's market exposure. The same evidence serves every market a company is exposed to.
Multinationals carry one more criterion: the internal global safety standard applied even where local law does not reach — a fourth criterion. The more market requirements converge on ISO, the more rational it becomes to align that internal standard with ISO. The concrete form of that calculation is the first case in IMPACT. What remains is administration. What has been unified is engineering.
If the three markets now demand the same answer, the question left standing is cost. In the era of divided standards, safety verification was a per-market expense. Documents differed by market; even after they converged on one document, the markets sat on different editions for years. The first transition is the unification of the yardstick: for the first time, three markets aim at the same edition of the same document. The second is the deadline: 20 January 2027, with no transition period. Regulations differ; the technical standard is now one. Hence the central proposition of this report: safety verification is not a cost repeated per market, but an asset produced once and reused across as many markets as a company touches.
What this means role by role is the subject of IMPACT. The short version: the unit of preparation shifts from the robot to the application configuration, and the multiplier shifts from the number of procedures to the number of markets you are exposed to.
So whose desk does this change reach, and what does it put there?
Whichever of the three procedures applies, the preparation is the same three items.
① Safety as a configuration — a risk assessment showing that the application configuration is safe: robot, end-effector, workpiece, sensing devices, and motion paths taken together, not the robot unit alone.
② Safety-function performance — verification and validation demonstrating that the required Performance Level is achieved. There are two layers. Safety functions built into the robot are verified by the manufacturer, who supplies that information downstream (Part 1). Safety functions and protective measures configured into the application are verified at integration (Part 2).
③ Contact as a measured quantity — where the configuration permits human contact, proof in numbers that the contact stays within permissible limits (the domain of collision safety).
How the three proofs meet the market procedures, arranged as one layered structure, is the Application Verification Stack.
Three of the four layers are common across markets, and their criteria are ISO standards. L4 is the receiving end for the evidence from L1 through L3 (market-specific requirements, such as EU cybersecurity, are noted as exceptions). The common error is handing in L1's answer for L3's question: the fact that a robot is safety-certified is no substitute for an application risk assessment. Equipment conformity and application verification are different layers.
[Anchor case] A standard that went where no regulation required it — the global single-standard pilot (2023). This is the story of the overseas subsidiary of a major Korean manufacturer. At that site, no local regulatory requirement applied to the application in question. So the question was never "how do we pass the regulation." It was an internal policy question: do we apply the safety standard we use in Korea to a subsidiary abroad? The verification was completed in-house. A headquarters engineer produced a Power and Force Limiting verification report with SafetyDesigner and applied it to the local application. One site, one verification, zero external consulting.
The case shows two things. First, a safety criterion holds where no regulation does — because the permissible limits of human contact belong to the human body, not to a jurisdiction. Second, a multinational carries one criterion beyond regulation: the internal global safety standard applied even to sites the law does not reach — the fourth criterion of the previous section.
The outcome, recorded as it happened: the verification held. Company-wide expansion did not follow at the time. In the regulatory landscape of 2023, extending a voluntary standard to every site before regulation demanded it was an upfront investment with no visible path to payback. That was not one company's judgement. It was the calculation facing every company at the time. What has changed since is not the company but the landscape. As more markets demand evidence against the same criterion, the places one verification can serve have multiplied. For a company that established its verification early, all that remains is the timing of expansion.
[Supporting tally] One method that has answered the same question 1,000+ times. The count combines analyses customers ran themselves in the software with analyses we performed as a service. PFL analysis — computing the Collision Risk Index — has been run on a cumulative total of more than 1,000 robots in Korea, each time to determine whether an application can run collaboratively (as of this report; our own tally). A single question — can this application run collaboratively? — answered by a single method, more than a thousand times. The answers feed three design paths: (a) full-zone PFL operation; (b) PFL in some zones, SSM in others; (c) full-zone SSM, with the result feeding the separation-distance calculation the integrator performs. Whichever path is taken, the starting point is the same number.
[Representative case] PFL in the high-payload domain — a global robot manufacturer's cobot, on site. Proof that contact verification is not the preserve of collaborative robots — the correction above, made concrete. A high-payload collaborative robot from a global robot manufacturer was analyzed with PFL at the site where it was deployed — the domain where permissible limits actually bite. There, the verdict turns on the application configuration, not the equipment class. It is also a live instance of the stack's distinction between L1 equipment conformity and L3 application verification.
The locus of responsibility differs by market — and in Korea, whether verification happens at all comes down to awareness. Who signs differs in every market. In Korea, the legal duty of application risk assessment rests with the business owner of the end-user company — Article 36 of the Occupational Safety and Health Act places it there. In the EU, responsibility sits with the "manufacturer" of the final machinery. Whether a system integrator performed the integration or the end user did it on its own, conformity assessment and the EU declaration of conformity flow from manufacturer status. The United States codified user requirements in a dedicated part of the standard (Part 3 of R15.06-2025). The evidence converged; the signature did not.
The tension in Korea arises exactly here. The law places responsibility on the end user while capability and information sit with manufacturers and integrators. In the field, the dividing line is awareness (our own observation). Companies aware of the requirement write it into their contracts, requiring installation-site certification as a condition of supply. Since that certification's audit criterion is KS B ISO 10218-2, the requirement travels down the procurement chain to the same ISO document. On the other branch, robots are found running without physical barriers and without contact verification — the requirements of the barrier-alternative path unmet. The owner's responsibility stands either way. A company that does not know is operating with the responsibility and without the evidence. And the weight is growing: Korean regulation increasingly asks not whether a risk assessment was done but whether it is being maintained as a live process. Two prescriptions follow: confirm your role, and write the requirement into your contracts (ACTION 1).
What has to be prepared is not market-specific paperwork but ISO-grade technical evidence. In this order:
For items 3 and 4, Safetics SafetyDesigner supports collision safety analysis and report generation against the contact limits set out in the international standards.
The substance of this ISO 10218 revision is not a standards update. It is the moment global markets began demanding the same technical evidence. We read it not as regulatory news but as a change in the structure of an asset. When three markets test against the same criterion, the ability to prove against it works in every market you are exposed to.
The character of safety verification changes with it. In the era of nationally divided standards, verification was a consumable — remade for every market. Now a verification record produced once — the same risk assessment, the same safety-function verification, the same permissible-contact figures — is reused, with nothing changing but where it is submitted. That is not a metaphor. It is a statement about physical documents.
The present gap — laws still citing an earlier edition — is not a grace period but a preparation period. The Regulation's date of application is already fixed, and technical evidence takes longer to produce than procedures take to run. Listings and notices arrive at the speed of administration; evidence is produced only at the speed of engineering. A company that starts from market paperwork keeps producing paperwork. A company that builds ISO-grade verification evidence first spends the same time building an asset.
We know this structure because we have been working inside it. The permissible-contact figures that the 2025 edition consolidated into the main standard were available in Korea years earlier, under two separate names — and we have been applying them at scale ever since, computed through the Collision Risk Index and applied to more than a thousand robots. What the new edition changes is where those numbers live, not what they say. That is why we read the present interval the way we do: for those who built their evidence against these numbers first, the interval is not a blank. It is a head start.
An index of the standards and legislation cited in this report


