Why the Regulation Matters

The Machinery Directive 2006/42/EC has harmonised essential health and safety requirements (EHSRs) for nearly two decades. However, advances such as digital connectivity, software-based control systems, AI integration, and new cyber threats have revealed gaps in the current framework.

Recognising these changes, the EU introduced Regulation 2023/1230 to:

  • Modernise safety requirements to account for digitalisation and connectivity.
  • Strengthen cybersecurity and digital resilience as intrinsic elements of machine safety.
  • Standardise compliance across all EU Member States without national transposition differences.
  • Clarify conformity assessment procedures and expectations for documentation.
  • Expand regulatory obligations to economic operators beyond manufacturers, including importers, distributors, and machine modifiers.

The Regulation becomes fully applicable on January 20, 2027, following a transition period when both the Directive and Regulation apply to machinery placed on the market.

Transition Timeline: What to Expect

Understanding the transition timeline is fundamental to proper compliance planning:

  • June 14, 2023: The Regulation was formally published in the EU Official Journal.
  • July 19, 2023: It came into force across all EU Member States.
  • January 19, 2027: Last day to place machinery on the EU market under the old Directive.
  • January 20, 2027: Only machinery conforming to Regulation 2023/1230 may be placed on the EU market.

During the transition period, manufacturers should begin aligning design, documentation, and conformity processes with the new Regulation, even if mandatory requirements do not apply until 2027.

Key Differences Between Regulation 2023/1230 and the Machinery Directive

While the Regulation retains much of the Directive’s structure, with an estimated 90% similarity, it introduces significant enhancements and new obligations.

1. From directive to regulation: uniformity and legal certainty

Unlike a directive, which requires national implementation and may result in varying interpretations, the Regulation is directly applicable EU law. This ensures uniformity and greater legal certainty across all 27 Member States.

2. Expanded scope: software, AI, and digital connectivity

The Regulation formally extends its scope to include not only physical machinery but also:

  • Software and firmware that influence machine safety.
  • AI-enabled machinery and systems with learning or adaptive control elements.
  • Connected devices, including those that interface with Industrial Internet of Things (IIoT) systems.

Manufacturers must now consider digital behaviour, not just mechanical hazards, when assessing risks and demonstrating compliance. This acknowledges that software is central to machine safety.

A digital blue padlock icon is centered within a circular futuristic interface, symbolizing cybersecurity and data protection against a blurred blue background.

Cybersecurity and “protection against corruption”

A key change in the new Regulation is the mandatory inclusion of cybersecurity as a safety requirement, referred to as “Protection against corruption.” Manufacturers must treat network threat protection as an ongoing commitment, not a one-time task.

  • Ensure safety-related control systems are resilient against both accidental failures and cyber-attacks.
  • Implement safeguards to prevent external actors from compromising safety functions through connected systems.
  • Integrate threat modelling and appropriate protections into design and documentation.

Cybersecurity is now an explicit part of the Regulation’s essential health and safety requirements (EHSRs), elevating IT and OT security to the same level as traditional mechanical safety risks.

A technician operates a laptop connected to an automated industrial machine, monitoring system data and controls in a manufacturing environment.

New requirements for software and firmware

Under the Regulation:

  • Safety-related software must be developed and maintained following structured processes that ensure reliability.
  • Source code or programming logic for safety software must be available to authorities upon request and retained for compliance verification for at least ten years.

This represents a significant change from the Machinery Directive, where software documentation was less central and often only indirectly required.

Post-market software and firmware updates that affect safety functions may require new conformity assessments, a process many manufacturers have not previously included in their compliance workflows.

European flag

Cyber resilience and cross-regulation interactions

The Machinery Regulation intersects with other EU legislation, notably the Cyber Resilience Act (CRA), which also takes effect in 2027 and sets broader cybersecurity requirements for digital products.

Compliance with both frameworks requires integrating cybersecurity and digital resilience throughout the machinery lifecycle, maintaining thorough documentation, and addressing both mechanical and cyber risks.

Manufacturers should prepare to demonstrate compliance with both mechanical safety and digital resilience, which will require collaboration among product development, compliance, and IT security teams.

A person use his tablet to check a list

Redefining conformity assessment procedures

The Regulation updates conformity assessment rules and introduces new procedures for certain machinery categories. Notably:

  • Notified body involvement is now required for a broader set of high-risk machinery types, including those with advanced technologies (such as AI, human-robot collaboration systems, or complex software safety functions).
  • The Regulation introduces new modules such as internal production control combined with EC or CE type examination, and unit verification for individual machine certification.

This shifts some responsibility from self-certification (common under the previous Directive) to formalised third-party assessment for more complex or high-risk machines.

 extreamly close up stacking of office working document with paper clip folder

Documentation and data accessibility

The Regulation imposes strict documentation requirements:

  • Technical files (risk assessments, test reports, safety evaluations) must be complete, well-organised, and retrievable for inspection by market surveillance authorities.
  • Digital documentation (EU Declaration of Conformity, operating instructions) can be provided via digital channels such as online portals, QR codes on machines, or integrated machine software, provided it remains accessible for the duration of the machine’s service life (minimum 10 years).
  • Paper copies must still be provided upon request.

The shift from paper-based to digital documentation reflects current industry practices, reduces administrative costs, but demands robust internal systems to ensure long-term availability and durability.

Obligations for operators and modifiers

The Regulation emphasises that obligations extend beyond manufacturers:

  • Importers and distributors must verify that machinery meets Regulation requirements before placing it on the market.
  • Operators or third parties who perform significant modifications that alter safety-relevant functions may be considered “manufacturers” of the modified machinery and therefore bear full compliance obligations.

This is a significant change, as modifications previously considered routine may now require new conformity assessments and regulatory responsibilities.

Practical Steps to Achieve Compliance

Given the scope of these changes, organisations involved in designing, building, selling, or operating machinery in the EU should take the following steps:

1. Re-evaluate risk assessments

Ensure risk assessments explicitly include digital and software hazards, cybersecurity attack vectors, AI behaviours, and human-machine interaction scenarios.

2. Integrate cybersecurity into safety engineering

Incorporate secure development lifecycles, threat modelling, and resilience testing into machine design from the outset.

3. Upgrade documentation workflows

Implement structured systems for version-controlled technical files, certified copies of software logic, and digital access to user instructions.

4. Map new conformity procedures

Determine which conformity assessment module applies to each machine type, and plan for potential third-party Notified Body involvement.

5. Train cross-functional teams

Ensure engineering, cybersecurity, compliance, and product teams understand their roles in meeting Regulation requirements.

6. Plan for firmware and AI updates

Establish processes to determine if post-market changes require reassessment and recertification.

Competitive opportunities in compliance

While the Regulation introduces significant obligations, it also presents competitive advantages for forward-thinking manufacturers:

  • Enhanced machine trust due to demonstrable safety and security resilience.
  • Market access confidence across all EU Member States without national interpretation divergence.
  • Reduction of liability risk through documented cybersecurity and failure prevention systems.

Companies that comply early with the Regulation can differentiate their machines through safety, resilience, and future-readiness. Delayed compliance may result in market exclusion.

Conclusion

The EU Machinery Regulation 2023/1230 is a fundamental shift toward harmonised, digitally informed, and cyber-aware safety governance for machinery and related products across the EU.

With full applicability on January 20, 2027, manufacturers and economic operators should begin aligning design, documentation, and conformity processes with the Regulation’s expanded scope and requirements. Cybersecurity and software integrity must be treated as central elements of machine safety.

Success under the new Regulation will be measured by meeting legal obligations and embedding robust, auditable safety and security practices throughout the machine lifecycle.