Mitsubishi certifies controller for EU machinery rules

Mitsubishi certifies controller for EU machinery rules

Mitsubishi certifies safety controller against incoming EU machinery regulation requirements. The certification also addresses cyber-safety risks affecting connected industrial control systems.


Mitsubishi Electric has obtained EU type-examination certification for its MELSEC iQ-R Series safety programmable controller under Regulation (EU) 2023/1230, moving the product family into conformity with machinery rules that become mandatory across the European Union on 20 January 2027. TÜV Rheinland issued the certificate after assessing requirements covering functional safety and protection against cyber-related interference.

The certification is the first of its kind within Mitsubishi Electric’s factory-automation business. Its significance extends beyond another product approval because the Machinery Regulation changes the compliance framework for machinery and related products, adding explicit cyber-safety provisions alongside established physical and functional-safety requirements.

Safety programmable controllers are used where failure of a control function could create a hazardous condition. Typical applications include emergency stops, guarded machinery and safety interlocks, where the controller must detect defined faults and move equipment into an appropriate safe state.

Mitsubishi’s iQ-R safety CPU combines general machine control and safety control within the same platform. Standard and safety programmes can therefore operate within a common automation architecture rather than requiring completely separate controller systems for every application.

The current iQ-R safety range is designed for applications up to SIL 3 under IEC 61508 and Performance Level e under ISO 13849-1. Mitsubishi also supports safety and non-safety communications through its industrial networking architecture, allowing ordinary control information and safety-related data to be carried within an integrated system while maintaining the required separation of safety functions.

The certified configuration uses CC-Link IE TSN to communicate with equipment including servo drives and inverters. Time-sensitive networking is intended to combine deterministic industrial communication with wider Ethernet-based data exchange, allowing motion, safety, diagnostics and production information to coexist on more integrated networks.

That convergence increases the importance of cybersecurity within machinery safety. Modern controllers are rarely isolated devices: engineering software, remote maintenance, industrial Ethernet and connected drives create several routes through which safety-related software or parameters can potentially be altered.

The Machinery Regulation reflects that change by addressing the protection of software and data relevant to conformity and safety. A controller can therefore no longer be assessed solely against random hardware faults if unauthorised access or software manipulation could also compromise a safety function.

Mitsubishi says the certified iQ-R architecture includes measures intended to address threats such as unauthorised access and software tampering. Those controls form part of the product assessment, but they do not make the controller a complete cybersecurity system for the machine in which it is installed.

Secure machinery still depends on network architecture, account management, engineering access, update procedures, device configuration and the behaviour of connected equipment. Machine builders consequently have to address cybersecurity at system level rather than treating a certified controller as a substitute for wider protective measures.

The immediate issue for equipment manufacturers is the regulatory transition. Regulation (EU) 2023/1230 replaces the existing Machinery Directive for products placed on the market or put into service from 20 January 2027. New machine projects approaching design completion therefore have relatively little time remaining to establish the components, documentation and conformity-assessment routes required under the new framework.

The regulation also alters how software fits into conventional machinery safety. Mechanical hazards, electrical protection and predictable control-system failures remain important, but connected automation creates additional ways for behaviour to change after commissioning. Remote access, software updates and network dependencies can all affect systems whose physical hardware remains otherwise unchanged.

Using a controller already examined against the new requirements can remove part of that uncertainty for machine builders. It provides evidence around the assessed device and its safety functions, potentially reducing the amount of component-level work required when the finished machine is documented.

It does not transfer responsibility for the complete machine. Integrators still have to undertake the appropriate risk assessment, select and validate safety functions and demonstrate conformity of the equipment as a whole. The type-examination certificate relates to the controller configuration rather than every system in which the product may eventually be installed.

Mitsubishi’s integrated architecture may simplify that engineering where manufacturers want ordinary control and safety functions within the same environment. Its GX Works3 software can manage both types of programme, while safety CPUs can share an iQ-R base with other modules, reducing the need for completely separate control structures.

Integration still has to preserve the independence and fault behaviour required by the application’s safety level. A simpler hardware layout is useful only if the system remains predictable when controllers, networks or connected devices fail.

With the January 2027 application date approaching, early certification gives machinery manufacturers another component option for projects being designed around the new rules. The wider transition will depend on equivalent work across drives, sensors, safety devices, networking products and engineering software.

A compliant controller is therefore one part of a much larger engineering exercise. The regulatory deadline applies to complete machinery, leaving manufacturers to ensure that individually certified components still form a system whose safety and cybersecurity behaviour can be demonstrated at the point it enters the European market.


Stories for you