Emergency stop and power‑off are often treated as if they mean the same thing.
They do not.
That distinction matters because CE conformity is not only about whether the safety architecture was engineered correctly. It is also about whether the evidence explains the architecture clearly enough for operators, maintenance teams, integrators, and assessors to understand what the machine will actually do. The LinkedIn article frames this well: the recurring issue is often not the design itself, but how the emergency stop concept is expressed across manuals, HMI text, LOTO instructions, training material, and the technical file.
Emergency stop is not the same as electrical isolation
An emergency stop is intended to stop a dangerous movement or process. Emergency switching off, or power‑off, is intended to remove electrical power where there is an electrical hazard, such as electric shock or another electrical-origin risk.
That difference can be easy to lose in everyday language.
If an operator presses an E‑stop, they may assume the whole machine is de‑energized. But in many modern systems, especially interconnected lines, the E‑stop may only stop a defined zone or bring motion to a controlled stop before removing torque. That may be the right engineering decision. It just needs to be explained clearly.
The risk is the wrong mental model
A poorly written manual or HMI message can quietly change expectations.
If the documentation describes a zoned emergency stop as if it were plant-wide, people may assume hazards outside that zone have also been addressed. If “STO,” “SS1,” or “motor off” are simplified too far, users may misunderstand whether energy has been removed, motion has stopped, or the system is safe to reset.
That is not just a documentation issue. It becomes a safety issue.
It also becomes a conformity evidence issue.
What CE teams need to show
For CE conformity, the technical file should tell a coherent story. It should show that hazards were identified, risk reduction measures were selected, residual risks were communicated, and safe use is supported across the machine lifecycle.
That evidence should make clear:
- What each emergency stop device controls.
- Whether the function is zoned or plant-wide.
- What energy remains after activation.
- What must happen before reset, restart, or maintenance.
The goal is not to add more paperwork. The goal is to make the safety argument understandable and defensible.
Emergency stop is a protective measure, not a substitute for safeguarding
ISO 13850 defines requirements and design principles for emergency stop functions, independent of the type of energy used. It also treats the emergency stop as a function intended to avert or reduce hazards, not as a replacement for good safeguarding.
That point is important.
An E‑stop should not be used to compensate for unclear guarding, poor access control, or weak risk reduction. It is part of the safety system, but it does not remove the need to design hazards out or apply proper protective measures first.
Why this matters more in integrated lines
In a standalone machine, the emergency stop concept may be relatively easy to explain.
In an integrated line, it becomes harder. Different suppliers may provide different zones, stop categories, reset logic, and interfaces. A single operator action may trigger different responses across different parts of the system. IEC 60204-1 recognizes different stop categories, including immediate removal of power and controlled stopping approaches, with the appropriate choice depending on the machine risk assessment.
The engineering may be sound, but if the manuals, HMI messages, LOTO instructions, and training materials do not align, the user is left to interpret the system on their own. That is not a strong safety position.
How Intertek can support
Intertek can support manufacturers and integrators by reviewing whether the safety concept is clearly reflected in the conformity evidence.
That includes looking at the risk assessment, emergency stop architecture, technical documentation, HMI wording, operating instructions, maintenance instructions, and reset/restart logic. For integrated systems, it also means checking whether the boundaries between machines, zones, suppliers, and safety functions are clearly described.
The objective is simple: make sure the documentation reflects the actual behavior of the machine.
Not what people assume it does.
Not what the button label implies.
What it actually does.
Final thought
Emergency stop and power‑off are not interchangeable ideas.
One is about stopping dangerous movement or processes. The other is about removing electrical power to address electrical hazards. Both can be essential. But confusing them can weaken user understanding and the CE evidence behind the machine.
In machinery safety, clear design matters.
Clear explanation matters too.

/Passle/5e4a7839abdfeb03584d01f6/MediaLibrary/Images/2026-03-31-21-45-54-751-69cc4092bd1f61a396ba5dbf.png)
/Passle/5e4a7839abdfeb03584d01f6/SearchServiceImages/2026-06-28-04-04-39-010-6a409d5721063c14756b64bc.jpg)
/Passle/5e4a7839abdfeb03584d01f6/SearchServiceImages/2025-09-03-18-33-58-511-68b88a161d680d7ad1a2a038.jpg)