ISO 8102-20:2022 remains published while ISO prepares a revision. It sets cybersecurity requirements for new connected lifts, escalators and moving walks across their lifecycle.
Current status
ISO 8102-20:2022, Electrical requirements for lifts, escalators and moving walks - Part 20: Cybersecurity, is the published first edition and was issued in August 2022.
ISO lists the edition at stage 90.92, meaning that it remains an International Standard but is marked to be revised. A separate ISO/DIS 8102-20 record shows edition 2 at stage 40.60, under development as a Draft International Standard. The draft is intended to replace the 2022 edition, but does not do so unless and until ISO completes its process and publishes a new International Standard.
Although this article's title refers to lifts and escalators, the published standard's scope also includes moving walks.
Scope and boundaries
The standard addresses new lifts, escalators and moving walks as equipment under control, or EUC. This includes compatible equipment designed to similar standards and lift-related equipment connected to the EUC.
It applies where an EUC can connect to building networks, cloud services or service tools. The connection may be permanent or introduced temporarily through service equipment. The EUC interfaces to those systems and services are within scope; the external systems and services themselves are not.
The lifecycle coverage includes:
- product development
- manufacturing
- installation
- operation and maintenance
- decommissioning
EUC installed before the publication date is outside the stated scope. That exclusion does not determine whether voluntary security work or other risk controls may be appropriate for an existing installation.
Roles and documentation
ISO 8102-20 addresses the roles of the product supplier and system integrator for the EUC. It does not directly address the asset-owner role.
However, suppliers and system integrators are required to provide documentation that helps the EUC owner achieve and maintain security. This establishes a documentation interface between those responsible for the product or integration and those operating the equipment; it does not mean that an owner has no security responsibilities.
Areas addressed by the standard
The published standard covers product and system cybersecurity requirements across the EUC lifecycle. Its visible structure addresses areas including:
- security management, requirements definition, threat modelling, secure design and secure implementation
- verification and validation activities
- management of security-related issues and security updates
- security guidance, including hardening, secure operation, account management and secure disposal
- risk assessment, EUC security levels, controls and countermeasures, and zones and conduits
- information for use and lifecycle security management
- minimum cybersecurity requirements for essential, safety and alarm functions
These areas describe the standard's subject matter. They are not a complete implementation recipe, nor do cybersecurity requirements replace all functional-safety duties or apply identically to every EUC function.
Relationship with IEC 62443
ISO 8102-20 is an industry-specific product-security application that uses concepts from the IEC 62443 series. It does not make a product automatically equivalent to, or certified under, the full IEC 62443 series.
Its visible normative references include the following editions:
| IEC document | Subject relevant to ISO 8102-20 |
|---|---|
| IEC 62443-3-2:2020 | Security risk assessment and system design |
| IEC 62443-3-3:2013 | System security requirements and security levels |
| IEC 62443-4-1:2018 | Secure product development lifecycle requirements |
| IEC 62443-4-2:2019 | Technical security requirements for IACS components |
The sector-specific standard applies these referenced foundations to the EUC context, its functional domains and the information needed for use. Applying ISO 8102-20 should not be presented as proof of compliance with a particular law, as a presumption of conformity, or as evidence that certification is required or available.