Book an Appointment
Product Compliance · Regulation (EU) 2023/1230

EU Machinery Regulation: Safety needs security.

From 20 January 2027, Regulation (EU) 2023/1230 replaces the Machinery Directive – with no transition phase and, for the first time, binding cybersecurity requirements for machinery. We support manufacturers, integrators and operators from risk assessment through to conformity assessment.

20 Jan 2027Date of application – no transition period
1.1.9 & 1.2.1New cybersecurity requirements in Annex III
up to €100,000Fines under Germany's MaschinenDG implementing act

From Machinery Directive to Machinery Regulation

Regulation (EU) 2023/1230 – the Machinery Regulation – replaces the Machinery Directive 2006/42/EC as of 20 January 2027. As an EU regulation, it applies directly in all Member States; national transposition is no longer required. In Germany, the existing 9th ProdSV ceases to apply on that date, while the accompanying MaschinenDG governs market surveillance, language requirements and sanctions, with fines of up to €100,000. The deadline is hard: there is no mixed phase and no early opt-in for placing products on the market.

In substance, the Regulation responds to the digitalisation of machine building: for the first time, cybersecurity requirements for machinery become binding, AI-based safety functions are subject to mandatory third-party assessment, and software can itself be a safety component. Added to this are the EU-wide uniform definition of substantial modification, digital instructions for use and extended documentation obligations. As harmonised standards for the new requirements are still missing and notified bodies have limited capacity, manufacturers should use the remaining time for gap analysis and implementation.

Timeline and key dates

From entry into force to the hard deadline – the dates you should know.

29 Jun 2023

Publication in the EU Official Journal

Regulation (EU) 2023/1230 is published and enters into force on 19 July 2023. It replaces the Machinery Directive 2006/42/EC and, as a regulation, applies directly in every Member State.

20 Jan 2024

Notification of conformity assessment bodies begins

The provisions on the notification of conformity assessment bodies (Articles 26–42) apply ahead of schedule. Manufacturers requiring third-party assessment should secure assessment capacity early.

6 Dec 2025

MaschinenDG enters into force in Germany

The German act implementing the Machinery Regulation (MaschinenDG, BGBl. 2025 I No. 302) governs market surveillance, language and sanction rules; its substantive parts apply from 20 January 2027. The 9th ProdSV is repealed with effect from the end of 19 January 2027.

20 Oct 2026

Deadline for national penalty provisions

Member States notify the Commission of their penalty regimes. In Germany, the MaschinenDG provides for fines of up to €100,000 and, for serious infringements, imprisonment of up to one year.

20 Jan 2027

Date of application – hard deadline

From this day, machinery may only be placed on the market under the new Regulation; up to and including 19 January 2027, only the Machinery Directive applies. Products placed on the market before the deadline may continue to be made available.

What the Regulation changes

Eight changes with a direct impact on design, documentation and market access.

01

Regulation instead of directive

Regulation (EU) 2023/1230 applies directly in every Member State – divergent national transpositions disappear. Germany's existing machinery ordinance (9th ProdSV) is repealed with effect from the end of 19 January 2027; alongside it, the MaschinenDG governs market surveillance and sanctions.

02

Cybersecurity becomes a product requirement

With requirements 1.1.9 (protection against corruption) and 1.2.1 (safety and reliability of control systems), Annex III contains binding security requirements for the first time. Protecting safety-related hardware and software against accidental and intentional interference thus becomes part of CE conformity.

03

Software can be a safety component

The term safety component expressly covers physical and digital components including software (Art. 3(3)). Anyone placing software with a safety function on the market separately bears their own manufacturer obligations, including CE marking.

04

Third-party assessment for ML safety functions

Safety components and embedded systems with fully or partially self-evolving behaviour based on machine learning are listed in Annex I Part A. A notified body must always be involved for them – even where harmonised standards are applied in full.

05

Substantial modification defined for the first time

Art. 3(16) establishes a uniform EU-wide definition of when a physical or digital modification legally turns a machine into a new product. Anyone carrying out a substantial modification – for example in a retrofit – is deemed a manufacturer and must complete the conformity procedure (Art. 18).

06

Digital instructions for use permitted

Instructions for use and the EU declaration of conformity may be provided digitally – printable, downloadable and available online for at least ten years. On request at the time of purchase, a free paper copy must be supplied within one month; for non-professional users, essential safety information must still be provided on paper.

07

Broader definition of machinery

In future, an assembly missing only the upload of the software intended by the manufacturer will also count as machinery (Art. 3(1)(f)). CE obligations can therefore no longer be circumvented by installing software downstream.

08

More documentation, more evidence

For sensor-based, remote-controlled or autonomous machinery, the technical documentation under Annex IV also covers the description of data, testing and validation processes. The source code or programming logic of safety-related software must be made available to authorities on reasoned request; documentation must be kept for at least ten years.

Cybersecurity requirements 1.1.9 and 1.2.1 in detail

For the first time, EU machinery law makes protection against digital manipulation mandatory – as a precondition for CE marking.

Protection against corruption (Annex III 1.1.9)

Connecting other devices – including via remote access – must not lead to hazardous situations. Safety-related hardware, software and data must be identified and adequately protected against accidental and intentional corruption. The protection goal is the safety of the machine, not confidentiality or data protection.

Evidence of intervention and software transparency

The machine must collect evidence of legitimate and illegitimate interventions in safety-related hardware and software – in effect, security logging at product level. In addition, the software installed for safe operation must be identifiable at all times in an easily accessible form.

Resilient control systems (Annex III 1.2.1)

Control systems must withstand intended and unintended external influences – including reasonably foreseeable malicious attempts by third parties leading to a hazardous situation. The benchmark is risk-based: the scope and depth of measures depend on the circumstances and risks. Hardware faults, errors in the control logic and foreseeable operator errors must not lead to hazards either.

Logs and self-learning systems

The traceability log of interventions and of subsequently uploaded versions of the safety software must remain accessible to authorities for up to five years after upload. Control systems with self-evolving behaviour must record safety-related decision data for one year, must not exceed the defined task and movement envelope, and must remain correctable at all times.

The Machinery Regulation's cybersecurity requirements do not stand alone: from 11 December 2027, machinery with digital elements additionally falls under the Cyber Resilience Act, whose reporting obligations for actively exploited vulnerabilities already apply from 11 September 2026. There is no automatic presumption of conformity from the CRA to the Machinery Regulation – synergies must be demonstrated case by case. A presumption of conformity for 1.1.9 and 1.2.1 arises only via harmonised standards or via certifications under a Cybersecurity Act scheme (Art. 20(9) of the Machinery Regulation). The standard envisaged for this, EN 50742, currently exists only as a draft (prEN 50742); whether it will be listed in the EU Official Journal before the deadline remains open. For ML-based safety functions, the high-risk obligations of the AI Act additionally apply from 2 August 2027 and are integrated into the Machinery Regulation conformity assessment.

Who the Regulation affects

The obligations reach across the entire supply chain – from the manufacturer to the operator carrying out retrofits.

Manufacturers of machinery and related products

They carry the core obligations: risk assessment, design in line with Annex III, technical documentation, conformity assessment, EU declaration of conformity and CE marking. Documentation and declaration must be kept for at least ten years; parallel obligations with a declaration of incorporation and assembly instructions apply to partly completed machinery.

Importers and distributors

Before placing products on the market, importers verify that the conformity procedure, documentation and marking are in place and add their own contact details; distributors check the CE marking, the declaration of conformity and the language version of the instructions for use. Anyone selling products under their own brand or modifying them in a way that affects conformity assumes the full manufacturer obligations (Art. 17).

Operators, integrators and retrofit providers

Anyone substantially modifying machinery – physically or digitally, for instance through subsequent connectivity or new safety functions – is deemed the manufacturer of the modified machine. For assemblies of machinery, the obligations may be limited to the part concerned; this requires a robust risk assessment.

Providers of software and AI safety functions

Software that performs safety functions can be a standalone safety component subject to CE marking. ML-based safety components are subject to mandatory third-party assessment under Annex I Part A and at the same time qualify as high-risk AI within the meaning of the AI Act, whose relevant obligations take effect on 2 August 2027.

Conformity assessment: the path to CE marking

Four steps, from classification to ongoing conformity assurance.

01

Classify the product and choose the procedure

First, clarify whether your product falls under Annex I. Part A (including ML safety components) always requires a notified body – EU type-examination with conformity to type, full quality assurance or unit verification; for Part B, internal production control is permissible only if harmonised standards cover all relevant requirements. All other machinery goes through internal production control (Module A).

02

Carry out and extend the risk assessment

The risk assessment is the starting point of conformity: limits of the product, hazard identification, risk estimation and risk reduction in the order of priority inherently safe design, protective measures, user information. What is new is the obligation to include safety-related cyber threats and the intended evolution of self-learning functions.

03

Compile the technical documentation under Annex IV

The documentation includes, among other things, the risk assessment, the standards applied and test and validation reports; for sensor-based or autonomous machinery, it also covers the description of capabilities, limits and data processes. You also need a process for making the source code or programming logic of safety-related software available on reasoned request by authorities.

04

Issue the declaration, affix the CE mark, maintain conformity

With the EU declaration of conformity, the manufacturer assumes responsibility for conformity; where a product is covered by several legal acts, a single declaration is issued. After CE marking – including the notified body's identification number where third-party assessment applies – series conformity, changes to standards and corrective measures must be monitored on an ongoing basis.

Frequently asked questions about the Machinery Regulation

Concise answers to questions we hear regularly in our advisory work.

When does the Machinery Regulation apply – and is there a transition period?

The Regulation applies from 20 January 2027; up to and including 19 January 2027, machinery must be placed on the market under the Machinery Directive 2006/42/EC – there is no mixed or opt-in phase. Products placed on the market in conformity with the Directive before the deadline may continue to be made available; EC type-examination certificates remain valid until they expire. A postponement of the cybersecurity requirements to the CRA date, as called for by industry associations, has not been adopted so far – 20 January 2027 remains binding.

Do we always need a notified body for the conformity assessment?

No. The standard route remains internal production control (Module A) without an external body. A notified body is mandatory for the six categories in Annex I Part A – including ML-based safety components – and for Part B machinery where no harmonised standards covering all relevant requirements are applied.

What does 'protection against corruption' require in concrete terms?

Annex III 1.1.9 requires that connections and remote access do not lead to hazardous situations, that safety-related hardware, software and data are identified and protected against accidental and intentional interference, and that the machine collects evidence of interventions. Installed safety-related software must also be identifiable at all times. In practice this means: threat analysis, hardening, tamper detection and logging become part of machine design.

Is CRA conformity enough to meet the Machinery Regulation's cybersecurity requirements?

No, not automatically. The Cyber Resilience Act contains no presumption of conformity in favour of the Machinery Regulation's requirements 1.1.9 and 1.2.1; both conformity assessments must be completed. Synergies are expressly envisaged but must be demonstrated by the manufacturer – for instance through shared evidence and, in future, through mutually aligned standards.

When does a retrofit become a 'substantial modification'?

When a physical or digital modification not foreseen by the manufacturer creates a new hazard or increases an existing risk, so that additional guards requiring adaptation of the safety control system, or additional measures to ensure stability or strength, become necessary (Art. 3(16)). The modifier is then deemed a manufacturer – with conformity assessment, declaration and CE marking. Software and connectivity retrofits can also cross this threshold.

Are there already harmonised standards for the cybersecurity requirements?

No, not as of mid-2026. The envisaged standard EN 50742 ('protection against corruption') so far exists only as a draft (prEN 50742); whether it will be listed in the EU Official Journal before the deadline remains open. Until then, the IEC 62443 series and the technical specification IEC/TS 63074 provide technical orientation – but they do not establish a presumption of conformity. That makes a robust, risk-based line of argument in the technical documentation all the more important.

Our Machinery Regulation services

From initial classification to robust CE evidence – technical and regulatory expertise from a single source.

Machinery Regulation gap analysis & readiness check

We assess your products, processes and documentation against the Regulation's requirements – including classification under Annex I and a review of cybersecurity gaps against 1.1.9 and 1.2.1. You receive a prioritised implementation roadmap through to the deadline.

Risk assessment & threat analysis (TARA)

We extend your existing risk assessment to cover safety-related cyber threats: a systematic threat and risk analysis for control systems, interfaces and remote access. The results feed directly into your protective measures and technical documentation.

Implementing the security requirements

We support the design-level implementation: hardening of control systems, secure remote access and update concepts, tamper evidence, security logging and software inventories. In doing so, we follow the state of the art, in particular the IEC 62443 series.

Penetration testing for machinery & control systems

Our OT and product pentests check whether your machine withstands foreseeable malicious access – from network and radio interfaces to remote maintenance access. The results provide robust evidence for your risk assessment and conformity documentation.

Support through the conformity assessment

We guide you through the appropriate procedure – from choosing the route and compiling the technical documentation under Annex IV to preparing for the notified body. We align the evidence for the Machinery Regulation, the CRA and the AI Act to avoid duplicated work.

Training & awareness

Hands-on training for design, engineering, product management and CE officers: the new requirements, security fundamentals for machine builders and how to handle substantial modifications. On request, delivered as an in-house workshop built around your product lines.

Ready for 20 January 2027?

The deadline comes without a transition period – and the standards landscape is still in flux. Talk to us before timelines and assessment capacity get tight.