KUKA's iiQKA.OS2 First Robot OS Certified to IEC 62443-4-2 SL2
iiQKA.OS2, KUKA's robot operating system, earns Security Level 2 cybersecurity certification under IEC 62443-4-2, aligned with EN ISO 10218-1:2025.
KUKA says its iiQKA.OS2 robot operating system is the first from any robotics manufacturer to be certified to Security Level 2 (SL2) under IEC 62443-4-2, the international cybersecurity standard for industrial-automation components. The certification, announced July 21, applies to iiQKA.OS2 as it runs on KUKA’s KR C5 and KR C5 micro controllers — a platform KUKA says spans every kinematic type it builds, from six-axis arms to SCARA and Delta robots, across its payload classes.
It is worth being precise about what actually happened here: iiQKA.OS2 is not new. It has been shipping on KUKA hardware since early 2025. What’s new is that an independent certification body has now verified the OS meets SL2’s technical bar for resisting intentional attacks carried out with simple tools and modest resources — the kind of low-effort intrusion attempt that’s become a routine risk once equipment is on a network.
Two different standards, two different failure modes
The distinction that trips up a lot of buyers: IEC 62443-4-2 and ISO 10218 are not the same standard measuring the same thing, and one does not stand in for the other.
EN ISO 10218-1:2025 — the revised global robot safety standard Industrial Robotics Hub covered in detail on July 20, which folded in the collaborative-safety content formerly carried by ISO/TS 15066 — governs physical safety: guarding, emergency stops, speed and separation monitoring, force limits, what happens when a person’s arm ends up where a robot’s arm is about to be. IEC 62443-4-2 governs something else entirely: whether an outside party can remotely tamper with, disable, or take control of the robot’s software. A robot can pass every physical-safety check and still be trivially reachable over a network if its OS has no authentication hardening, no secure boot chain, no protection against firmware tampering. KUKA is positioning the SL2 certification as complementary to its ISO 10218-1:2025 compliance work, not a replacement for it — the two are evaluated on different axes and, increasingly, buyers in regulated industries want to see both.
Why a certified OS is a procurement differentiator now, not just marketing
The proximate reason this matters is structural, not promotional. Industrial robots that used to run in relative isolation now sit behind fleet-management dashboards, cloud-based diagnostics, and remote firmware updates — each of those connections is a new attack surface that didn’t exist on a stand-alone robot cell a decade ago. At the same time, the EU’s Cyber Resilience Act (Regulation 2024/2847) is imposing real compliance deadlines on connected products sold into the EU market, industrial equipment included. For an automotive body shop, a pharmaceutical fill-finish line, or an aerospace supplier — sectors where a compromised controller isn’t just downtime but a regulatory or safety incident — a third-party-verified cybersecurity certification turns from a nice-to-have line item into something a procurement team can actually specify and audit against, rather than taking a vendor’s word for it.
“With iiQKA.OS2, we are creating the foundation for a new generation of industrial automation: more intuitive, more connected, and more secure,” said Marc Steigerwald, Strategic Program Manager at KUKA. “Product Security Level 2 marks a significant milestone in our platform strategy.”
Two of KUKA’s LBR iiSy cobots — the LBR iiSy 3 R760 and the larger LBR iiSy 11 R1300 — already ran on the original iiQKA.OS, making them a natural early illustration of where a hardened successor OS would land first inside KUKA’s own portfolio. On the industrial side, arms like the KR 20 R1810, built on the KR C5 controller family, fall within the scope KUKA describes for the new certification.
Sources
- KUKA iiQKA.OS reaches Product Security Level 2 — KUKA, Jul 21, 2026
- KUKA reaches Security Level 2 in robotics — Packaging Journal, Jul 21, 2026
Robots mentioned
Tap a card to open the full spec sheet.
Collaborative
LBR iisy 3 R760
Collaborative
LBR iisy 11 R1300
Articulated arm
KR 20 R1810Frequently asked questions
What is IEC 62443-4-2 and why does Security Level 2 matter for a robot OS? +
IEC 62443-4-2 is the component-level standard in the ISA/IEC 62443 industrial-automation cybersecurity series; it sets technical requirements for things like authentication, access control, and resistance to tampering or intrusion. Security Level 2 (SL2) certifies that a product can resist deliberate attacks using simple means and low-to-moderate resources and skill — a step up from SL1's protection against casual or accidental misuse, and the level most buyers in regulated sectors now specify for networked industrial equipment.
Does this certification cover all KUKA robots, or just certain models? +
It covers any KUKA robot running on the KR C5 or KR C5 micro controller family with iiQKA.OS2, which KUKA says spans all of its robot kinematic types (six-axis arms, SCARA, and Delta) across its payload range. It does not automatically extend to robots still running the older KR C4 controller or the original iiQKA.OS.
How is this different from ISO 10218 robot safety standards? +
ISO 10218 (now EN ISO 10218-1:2025) governs physical safety — guarding, emergency stops, speed and force limits, collision avoidance. IEC 62443-4-2 governs cybersecurity — keeping unauthorized actors from remotely tampering with or taking control of the robot. A robot can be mechanically safe and digitally wide open, or vice versa; the two standards address different failure modes and increasingly get evaluated together, but neither substitutes for the other.
Is this a new product launch, or a certification of an existing one? +
It's a certification milestone, not a launch. iiQKA.OS2 has been running on KUKA hardware since early 2025; the July 21, 2026 announcement is KUKA securing third-party SL2 certification for that existing operating system, which it can now cite in procurement processes without needing an integrator or customer to commission separate testing.
More news