Functional Safety Certification for Nuclear Decommissioning Robots: IEC TR 63069 Explained

Date
2027-07-29
Location
Online
Host
Zach L

About this event

A Gap Analysis Workshop for Cross-Functional Product Teams pursuing functional safety certification. A live 30-minute gap analysis workshop on IEC TR 63069 (Safety and Security Convergence) for nuclear decommissioning robots, built for cross-functional product teams pursuing functional safety certification. What We'll Cover: What IEC TR 63069 (Safety and Security Convergence) requires and how its scope applies to nuclear decommissioning robots Mapping IEC TR 63069 clauses to the certification evidence assessors expect System-specific hazards and safety functions typical of nuclear decommissioning robots Common findings that delay certification, and how to avoid them A practical readiness roadmap for cross-functional product teams preparing for assessment Related topics: IEC TR 63069 · Nucl

Topics

Registration

View event page

About IEC TR 63069 (Safety and Security Convergence)

This hands-on workshop builds applied knowledge and team exercises around the certification requirements of IEC TR 63069.

IEC TR 63069 provides guidance on applying IEC 61508 functional safety and IEC 62443 cybersecurity together in industrial automation, resolving lifecycle interactions so that neither discipline undermines the other.

What it regulates

Coordination principles: protecting safety functions within secure zones, managing conflicting requirements, and coordinating risk assessments and incident response across safety and security teams.

Who must comply

Organizations running both safety and security programs for IACS — asset owners, integrators, and suppliers aligning SIL-rated systems with 62443 zones and conduits.

Key requirements of IEC TR 63069

  • Framework mapping the safety lifecycle to the security lifecycle
  • Guiding principles including protection of safety implementations by security countermeasures
  • Guidance on co-engineering, roles, and communication between disciplines
  • Treatment of security-relevant events as potential initiators of hazardous events

Key concepts: IEC TR 63069

Security environment for safety
The concept that every safety function must operate inside an adequately secured zone.
Co-engineering
Joint, coordinated engineering of safety and security requirements rather than sequential or siloed treatment.
Conflict resolution
Structured handling of cases where a security measure (like lockout after failed logins) could impede a safety action, and vice versa.
Threat-risk vs hazard-risk assessment
Parallel assessments whose results must be reconciled because attacks can trigger hazards.

Frequently asked questions: IEC TR 63069

Can a cyber attack invalidate a SIL rating?

Effectively yes: SIL calculations assume failure behavior that a deliberate attack can bypass. That is why 63069 requires safety systems to sit within zones whose security level is chosen considering the safety impact of compromise.

Is IEC TR 63069 certifiable?

It is a Technical Report giving guidance, not a certifiable requirements standard; conformity claims remain against IEC 61508 and IEC 62443, with 63069 shaping how the two programs interlock.

Standard information based on the published text of IEC TR 63069 (Safety and Security Convergence). Event content is provided by the host. For authoritative guidance, consult the official standard body.