Cobot Safety Standards ISO 10218 and ISO TS 15066 Explained
Collaborative cobots face legally binding force and pressure limits across 29 body zones.

Advertisement
ISO 10218 and ISO/TS 15066 together form the safety framework, and it governs how industrial robots are designed, installed, and operated around people. The 2025 revision folded that framework into two documents instead of three, and the change reassigns obligations across manufacturers, integrators, and end users, with real compliance deadlines already in motion.
Why ISO 10218 and ISO/TS 15066 Exist
Industrial robot safety standards were originally written for a world where robots and people did not share space. A robot operated inside a fenced cell, a light curtain or interlocked gate kept workers out while it ran, and the safety logic was simple: separation. That premise held for decades, and you can see it in ISO 10218's original 2011 edition.
Collaborative robots broke that premise. A new question followed: if contact between a robot and a worker is allowed, under what conditions is it acceptable? ISO/TS 15066 answered that question in 2016, introducing the governing principle for collaborative operation: contact may be permitted only if it does not cause pain or injury. It addressed a class of robot use the core standard had never contemplated, so it needed its own technical specification, published separately from ISO 10218.
The result, for nearly a decade, was a three-document framework: ISO 10218-1 for manufacturers, ISO 10218-2 for integrators, and ISO/TS 15066 as a cross-referenced technical specification covering collaborative contact. That structure solved the immediate problem but created a navigational one. If you configured a collaborative cell, you had to work across three separate publications to understand a single operating mode, and ISO/TS 15066 was only a technical specification, so its requirements carried a different legal weight than the core standard itself.
The 2025 revision that consolidated the framework into two parts
ISO 10218-1:2025 and ISO 10218-2:2025 were published in February 2025, the first update to the core robot-safety standard since 2011. The fourteen-year gap matters on its own, but the structural change inside the revision matters more.
The pre-2025 framework spread collaborative robot requirements across three documents with uneven authority. The 2025 framework consolidates everything into two parts, so ISO 10218-2:2025 now absorbs the collaborative-application content that previously lived in ISO/TS 15066. The four collaborative techniques, hand-guided control, speed and separation monitoring, power and force limiting, and safety-rated monitored stop, are not being retired or replaced. They are specified directly inside ISO 10218-2:2025.
That move changes the practical status of those requirements. A technical specification carries less formal weight within the ISO system than a full international standard, and folding its content into ISO 10218-2:2025 elevates it to the same mandatory status as every other clause integrators must satisfy. The consolidation is a change in legal and technical obligation.
Each gets its own treatment later in this framework, but together with the ISO/TS 15066 consolidation, they mean the 2025 editions are a rewrite of how responsibility is assigned across the robot supply chain, not a minor refresh of the 2011 text.
The references of EN ISO 10218-1:2025 and EN ISO 10218-2:2025 appear in the Official Journal of the European Union, which makes them harmonised standards under the Machinery Directive. The presumption-of-conformity route for CE marking runs through the 2025 editions now. If your risk assessment or purchase specification still cites ISO/TS 15066:2016, it needs to reference ISO 10218-1:2025 and ISO 10218-2:2025 directly, because the collaborative-application clauses now live there.
What ISO 10218-1 requires of robot manufacturers
ISO 10218-1:2025, now in its third edition, addresses the robot manufacturer's side of the relationship: mechanical safety, control system architecture, stopping functions, speed and force monitoring, and the safety-rated outputs a robot has to provide so that an integrator can build a safe cell around it. What happens to that machine once it leaves the factory is a separate question, governed by a separate document.
The 2025 revision introduces robot classifications that did not exist in the 2011 edition. Class 1 covers robots that, based on reasonable judgment, do not pose a significant hazard, and those robots face reduced control requirements. Class 2 covers all other industrial robots, and they remain subject to the full, higher set of requirements. So if you manufacture smaller, inherently lower-risk robots, you can apply requirements proportionate to actual risk, instead of the uniform blanket requirements the 2011 framework applied no matter the payload or size.
The revision also closes a gap around manual reduced-speed mode, which you may know as T1 or teach mode. A new Annex C addresses a related source of inconsistency by listing, without room for interpretation, which safety functions are mandatory, which are conditionally required, and which are optional, along with how those functions must be structured.
None of this adds up to a certification that any particular installation is safe. A manufacturer's ISO 10218-1:2025 declaration tells an integrator what safety capability the robot ships with. It does not certify that any specific cell built around that robot is safe or collaborative. That certification depends entirely on what happens next, under a different part of the standard, in the hands of a different party.
What ISO 10218-2 Requires of System Integrators
ISO 10218-2:2025, now in its second edition, governs how a robot gets installed, guarded, and integrated into a working production system. Safeguarding selection, safe distances, and task-based risk assessment all sit here, and the 2025 edition adds the full set of collaborative-application requirements that used to live in ISO/TS 15066.
That addition is not a relabeling exercise. The biomechanical contact limits cover force and pressure thresholds across 29 body zones grouped into 12 body regions, and the standard folds them in directly, with explicit sections on how a cell moves between safeguarded and collaborative modes. Part 2 makes compliance testing for power and force limiting mode a mandatory component, and it is not optional guidance.
The risk assessment scope has expanded in a way integrators frequently underestimate. Task-based risk assessment under ISO 10218-2:2025 covers every reasonably foreseeable operator interaction, including setup, teaching, maintenance, and fault-clearing, not only the robot's normal production cycle. A cell that is perfectly safe during an automated run can still fail a conformance assessment if the maintenance technician's access, the teach-mode interaction, or the fault-recovery sequence was not assessed with the same rigor as production operation. That expanded scope is where integrators most often discover, late, that documentation they assumed was complete is not.
A manufacturer's ISO 10218-1:2025 declaration and an integrator's ISO 10218-2:2025 conformance work are not interchangeable, and they do not substitute for each other. Even a robot that fully complies with ISO 10218-1:2025 does not produce a compliant installation by itself. The integrator's work under Part 2 is what makes the cell safe and CE-markable, and no manufacturer declaration can stand in for that work.
The biomechanical limits that make fenceless operation possible, and constrained
Power and force limiting mode lets a robot and a person share space without a fence between them, by keeping every possible contact event under a pain-onset threshold. The underlying body-region data comes from University of Mainz research, and it assigns force and pressure limits to 29 body areas grouped into regions, each with a spring constant that shows how that part of the body absorbs impact force. The skull and forehead, being far less compliant than soft tissue, have a much higher spring constant than the abdomen. The same impact energy therefore translates into very different injury risk depending on where contact occurs.
The standard distinguishes two contact scenarios, and the distinction matters because the physics of each is different. Transient contact describes an impact or brief contact event, where the body can recoil and absorb some of the energy, and it is governed by force and pressure limits calibrated to that momentary exposure. Quasi-static contact describes clamping or sustained contact, where the body cannot recoil and the load does not dissipate, and the standard sets lower limits for this scenario precisely because sustained loading is more dangerous at equivalent force than a momentary impact.
The body-region data itself now sits in Annex M of ISO 10218-2:2025, labeled informative. The main text, however, references that annex as an essential parameter for configuring safety functions, and that creates a genuine ambiguity. An informative annex is not, by the ordinary conventions of ISO documents, a source of binding requirements, yet the standard's own main text treats its contents as necessary for correct configuration. So if you configure power and force limiting mode, you need to resolve that tension yourself; the question has no settled answer.
Pressure limits matter most for contact geometries with sharp edges, such as a workpiece corner or a robot tool tip. Force limits matter most for large-area contact events, such as when you touch the padded surface of a robot arm. Both kinds of limit have to be checked, because a configuration can satisfy one while violating the other.
Known Gaps and Ongoing Debate in the Compliance Framework
The biomechanical limits at the center of power and force limiting mode rest on genuine pain-onset research, and the framework built around them functions for the overwhelming majority of deployments. Two documented weaknesses still appear in real installations, and a competent integrator needs a plan for each rather than an assumption that the standard has already resolved them.
The first concerns quasi-static clamping. Academic review of the ISO approach to mobility-dependent constraints in clamping situations has identified that it may underestimate risk compared to more conservative formulations of the same problem. Integrators working with clamping-prone geometries should treat the standard's quasi-static values as a floor to verify against, not a ceiling that settles the question automatically.
The second concerns the informative status of Annex M itself. The annex is labeled informative, but the main text treats its contents as essential for configuring safety parameters, so you cannot tell from the document structure alone whether conformance requires meeting those specific values or just consulting them as reference. That ambiguity is not cosmetic: a conformance assessor and an integrator could reasonably reach different conclusions about what the standard actually demands. So in practice, you resolve it by documenting the body-region values an installation was designed against and treating them as binding design inputs, regardless of the annex's formal label.
A third gap occurs at the tooling level rather than in the standard's text. To verify this, you need either calculation specific to the tool and part geometry or direct measurement with a force-and-pressure test device against the actual tooling and workpiece in the deployed configuration, not against the robot's generic spec.
None of these three gaps is a reason to avoid power and force limiting mode. They are reasons to conduct biomechanical verification with the actual tooling, the actual workpiece, and the actual clamping geometry the deployed cell will use, rather than relying on the robot manufacturer's general compliance claims as a substitute for cell-specific testing.
The cybersecurity requirements that enter the standard for the first time
The 2025 revision adds cybersecurity requirements to ISO 10218 for the first time, and the scope is deliberately narrow: the standard addresses how cybersecurity affects physical safety, not general information-technology security practice. The underlying concern is mechanical. If someone alters a safety parameter through unauthorized access to a robot's control system, that translates directly into a physical injury risk on the shop floor, and that link is what brings cybersecurity inside a safety standard instead of leaving it to separate IT security frameworks.
The obligations this creates are specific: locking safety parameters, restricting access, and auditing changes. Safety parameters that were previously unprotected now have to be locked against modification. Access to safety-relevant controls has to be restricted to authorized personnel and systems. Any change made to a safety parameter has to be audited under defined cybersecurity controls, creating a record of who altered what and when. Medium-sized and smaller robot manufacturers are not exempt from these obligations, because robotics installations typically stay in service for a long time after deployment.
These requirements connect directly to broader regulatory movement already underway in the EU, including the Cyber Resilience Act and the Machinery Regulation, both of which take a stricter posture on connected industrial equipment than the frameworks they replace. ISO 10218-1:2025's cybersecurity provisions anticipate that stricter posture, so they do not exist independently of it.
The regulatory deadlines that make the 2025 revision urgent, not optional
January 20, 2027 is the date the EU Machinery Directive gives way to the Machinery Regulation, and any product placed on the EU market from that date forward has to comply with the Regulation. That deadline is an active compliance target that manufacturers and integrators building toward EU market access need to be designing against now.
The EU and North American timelines run in parallel but are not identical, and anyone deploying cobots in either market faces a distinct version of the same urgency. In the EU, EN ISO 10218-1:2025 and EN ISO 10218-2:2025 had their references published in the Official Journal of the European Union on 7 September 2026, making them harmonised standards under the Machinery Directive and putting the presumption-of-conformity route for CE marking through the 2025 editions. The transition to the Machinery Regulation on January 20, 2027 follows close behind that harmonisation date, leaving manufacturers and integrators only a narrow window to align documentation before the legal framework itself changes underneath the standard.
In one other major market, ANSI/A3 R15.06-2025 came out across September and October 2025, and it replaces the ANSI/RIA R15.06-2012 edition that still appears in most compliance documentation in circulation today.
Risk assessments completed under ISO/TS 15066 alone do not satisfy current requirements in either market. The current framework evaluates the deployed system, the robot, its tooling, its task program, and its operating environment together, as a single unit of assessment. That shift in what gets evaluated is the practical reason the 2025 revision demands action now.
Sources
- ISO 10218 Robot Safety Standard, 2025 Edition
- Analysis of Deep-Learning Methods in an ISO/TS 15066–Compliant Human–Robot Safety Framework
- ISO 10218-1:2025(en), Robotics — Safety requirements — Part 1: Industrial robots
- Evolution of safety requirements in industrial robotics: Comparative analysis of ISO 10218-1/2 (2011 vs. 2025) and integration of ISO/TS 15066 - ScienceDirect
- ISO 10218-1:2025—Robots And Robotic Devices Safety - The ANSI Blog
- ISO 10218-2:2025—Industrial Robot Applications - The ANSI Blog
- Safetics Insight - ISO 10218-2:2025 Revision Guide - Help Center
- A Statistical Model to Determine Biomechanical Limits for Physically Safe Interactions With Collaborative Robots


