Lockout-Tagout, Gets

Lockout-Tagout Gets European Standard as Germany's Industrial Safety Regime Tightens Ahead of CRA Fines

Published on 06/17/2026 at 18:09 | Redaktion boerse-global.de

New LOTO standard and Pilz controller certification signal early compliance steps; CRA penalties of €35M/7% revenue loom; NIS-2 readiness low at 14%; AI Act inventory due Aug 2026.

European Industrial Safety Regulations: Key Compliance Deadlines for 2026-2027
Lockout-Tagout Gets European Standard as Germany's Industrial Safety Regime Tightens Ahead of CRA Fines Illustration mit AI erstellt übermittelt durch boerse-global.de

A new European standard for safely isolating energy during maintenance — lockout-tagout (LOTO) — entered force on the same day that a critical safety controller received formal certification under the European Union's updated Machinery Regulation.

On June 16, TÜV SÜD issued an EU type-examination certificate for Pilz's configurable small controller PNOZmulti 2, confirming its compliance with the new EU Machinery Regulation (2023/1230). That regulation will not become mandatory until January 20, 2027, giving manufacturers and integrators early planning certainty. The controller handles core safety functions such as monitoring emergency-stop devices, guarding doors, and safely shutting down safety valves.

The same day, the standard DIN EN 17975 took effect, governing lockout-tag-out procedures for securing energy isolation during maintenance — covering electrical, mechanical, hydraulic and thermal systems. The requirement for companies to conduct their own risk assessments for specific installations remains unaffected. Industry experts advise firms to begin integrating new safety components now, noting lead times of several months are common.

Advertisement

With the new lockout?tagout standard demanding thorough risk assessments for energy isolation, having the right documentation is critical. A free Risk Assessment Toolkit provides 41 ready?to?use templates and checklists to ensure your workplace risk management is compliant and effective. Download the free Risk Assessment Toolkit

CRA Penalties Loom: €35 Million or 7% of Global Turnover

The industrial safety landscape is growing more complex. Alongside the Machinery Regulation, the Cyber Resilience Act (CRA) and the NIS-2 Directive are moving into focus.

Starting September 11, 2026, manufacturers must report actively exploited vulnerabilities. Security incidents must be notified preliminarily within 24 hours and in full within 72 hours. From December 11, 2027, full CRA requirements for connected products apply: weak passwords and hard-coded credentials will be banned, and every device will need its own cryptographic identity.

Penalties for non-compliance are severe: up to €35 million or 7% of worldwide annual revenue. Industry analysts stress that hardware design cycles of 18 to 24 months make immediate engagement with these rules essential.

NIS-2: Only One in Seven Companies Fully Prepared

A mid-June survey found that just 14.3 percent of German companies surveyed have fully implemented NIS-2 requirements. The directive demands that affected firms appoint a contact person within one month and implement comprehensive protective measures within ten months.

Liability for lapses increasingly falls on boards personally. Outdated access-control systems are considered a security risk under the new rules. Since early 2026, additional certification obligations for critical components have been in force — for example, mandatory BSI-NESAS certification for 5G core network components.

Advertisement

As liability for compliance lapses increasingly falls on boards personally, having systematic health and safety documentation is more important than ever. A free Health & Safety Toolkit provides ready?to?use risk assessments, checklists, and templates covering UK regulations like COSHH and PUWER to keep your business compliant. Get the free Health & Safety Toolkit

AI Act and Updated DGUV Rules Add Further Deadlines

From August 2, 2026, a new compliance phase under the EU AI Act begins. Companies using high-risk AI systems in production must then submit a full inventory of their AI applications and build corresponding governance frameworks.

On the organisational side, the reformed DGUV Vorschrift 2 has been in effect since January 1, 2026. The threshold for mandatory occupational safety supervision was raised from 10 to 20 employees. Additionally, digital remote supervision by occupational safety specialists is now legally anchored.

Disclaimer regarding our articles: No investment advice, no buy or sell recommendation. Information on prices, companies, and markets is provided without guarantee; changes are possible at any time. Stock market transactions can lead to substantial losses. Our articles are created and reviewed in whole or in part automatically with the support of AI.

en | boerse | 69564577 |