The Machinery Directive 2006/42/EC has harmonised essential health and safety requirements (EHSRs) for nearly two decades. However, advances such as digital connectivity, software-based control systems, AI integration, and new cyber threats have revealed gaps in the current framework.
Recognising these changes, the EU introduced Regulation 2023/1230 to:
The Regulation becomes fully applicable on January 20, 2027, following a transition period when both the Directive and Regulation apply to machinery placed on the market.
Understanding the transition timeline is fundamental to proper compliance planning:
During the transition period, manufacturers should begin aligning design, documentation, and conformity processes with the new Regulation, even if mandatory requirements do not apply until 2027.
While the Regulation retains much of the Directive’s structure, with an estimated 90% similarity, it introduces significant enhancements and new obligations.
Unlike a directive, which requires national implementation and may result in varying interpretations, the Regulation is directly applicable EU law. This ensures uniformity and greater legal certainty across all 27 Member States.
The Regulation formally extends its scope to include not only physical machinery but also:
Manufacturers must now consider digital behaviour, not just mechanical hazards, when assessing risks and demonstrating compliance. This acknowledges that software is central to machine safety.
A key change in the new Regulation is the mandatory inclusion of cybersecurity as a safety requirement, referred to as “Protection against corruption.” Manufacturers must treat network threat protection as an ongoing commitment, not a one-time task.
Cybersecurity is now an explicit part of the Regulation’s essential health and safety requirements (EHSRs), elevating IT and OT security to the same level as traditional mechanical safety risks.
Under the Regulation:
This represents a significant change from the Machinery Directive, where software documentation was less central and often only indirectly required.
Post-market software and firmware updates that affect safety functions may require new conformity assessments, a process many manufacturers have not previously included in their compliance workflows.
The Machinery Regulation intersects with other EU legislation, notably the Cyber Resilience Act (CRA), which also takes effect in 2027 and sets broader cybersecurity requirements for digital products.
Compliance with both frameworks requires integrating cybersecurity and digital resilience throughout the machinery lifecycle, maintaining thorough documentation, and addressing both mechanical and cyber risks.
Manufacturers should prepare to demonstrate compliance with both mechanical safety and digital resilience, which will require collaboration among product development, compliance, and IT security teams.
The Regulation updates conformity assessment rules and introduces new procedures for certain machinery categories. Notably:
This shifts some responsibility from self-certification (common under the previous Directive) to formalised third-party assessment for more complex or high-risk machines.
The Regulation imposes strict documentation requirements:
The shift from paper-based to digital documentation reflects current industry practices, reduces administrative costs, but demands robust internal systems to ensure long-term availability and durability.
The Regulation emphasises that obligations extend beyond manufacturers:
This is a significant change, as modifications previously considered routine may now require new conformity assessments and regulatory responsibilities.
Given the scope of these changes, organisations involved in designing, building, selling, or operating machinery in the EU should take the following steps:
Ensure risk assessments explicitly include digital and software hazards, cybersecurity attack vectors, AI behaviours, and human-machine interaction scenarios.
Incorporate secure development lifecycles, threat modelling, and resilience testing into machine design from the outset.
Implement structured systems for version-controlled technical files, certified copies of software logic, and digital access to user instructions.
Determine which conformity assessment module applies to each machine type, and plan for potential third-party Notified Body involvement.
Ensure engineering, cybersecurity, compliance, and product teams understand their roles in meeting Regulation requirements.
Establish processes to determine if post-market changes require reassessment and recertification.
While the Regulation introduces significant obligations, it also presents competitive advantages for forward-thinking manufacturers:
Companies that comply early with the Regulation can differentiate their machines through safety, resilience, and future-readiness. Delayed compliance may result in market exclusion.
The EU Machinery Regulation 2023/1230 is a fundamental shift toward harmonised, digitally informed, and cyber-aware safety governance for machinery and related products across the EU.
With full applicability on January 20, 2027, manufacturers and economic operators should begin aligning design, documentation, and conformity processes with the Regulation’s expanded scope and requirements. Cybersecurity and software integrity must be treated as central elements of machine safety.
Success under the new Regulation will be measured by meeting legal obligations and embedding robust, auditable safety and security practices throughout the machine lifecycle.