Regulation (EU) 2023/1230

Prepare your machinery for the Machinery Regulation

Last updated 30 September 2026. A summary, not legal advice. Always check the official text for your case.

What does the Machinery Regulation ask about cybersecurity?

From 20 January 2027 the Machinery Regulation replaces the Machinery Directive. For the first time, protection against cyber threats is part of the essential health and safety requirements for CE marking. A connection must not lead to a hazardous situation, safety software must be protected and the machinery must keep evidence of interventions.

20 Jan 2027
The regulation applies and the Machinery Directive 2006/42/EC is repealedArticles 51 and 54, as corrected
5 years
Tracing log of interventions and of safety software uploaded after saleAnnex III, 1.2.1(f)
20 Oct 2026
Member States notify their rules on penaltiesArticle 50(2), as corrected
Who is covered

Manufacturers, importers, distributors and whoever modifies the machinery

A substantial modification makes you the manufacturer of that machinery, with all its duties.

A natural or legal person that carries out a substantial modification of machinery or a related product shall be considered to be a manufacturer for the purposes of this Regulation
Article 18
Annex III

Two essential requirements concern cybersecurity

The machinery or related product shall be designed and constructed so that the connection to it of another device […] does not lead to a hazardous situation.
Annex III, 1.1.9 Protection against corruption
  • Software and data critical for safety are identified and protected against accidental or intentional corruption
  • The machinery identifies the software it needs to operate safely, at all times
  • It collects evidence of a legitimate or illegitimate intervention in that software or its configuration
they can withstand […] intended and unintended external influences, including reasonably foreseeable malicious attempts from third parties leading to a hazardous situation
Annex III, 1.2.1(a) Safety and reliability of control systems

What to do first

  • Read Annex III, points 1.1.9 and 1.2.1
  • Keep safety and security risk assessments separate: security changes several times a year
  • Limit and record who can connect to the machinery
FAQ

Questions about the Machinery Regulation

Why do some sources say 14 January 2027?

That is the date in the text published on 29 June 2023. A corrigendum of 4 July 2023 moved every date by six days, so the regulation applies from 20 January 2027 (corrigendum, OJ L 169).

Does the CRA also apply to my machinery?

If the machinery contains software and connects to a device or a network, it is also a product with digital elements under the Cyber Resilience Act. The Machinery Regulation looks at safety, the CRA at cybersecurity over the whole support period. See the CRA page.

Is a software update a substantial modification?

It can be. A modification by physical or digital means is substantial when the manufacturer did not foresee or plan it and it creates a new hazard or increases an existing risk (Article 3). Whoever carries it out takes on the duties of the manufacturer (Article 18).

Which standard gives presumption of conformity for cybersecurity?

As of September 2026, harmonised standards for these points are not yet cited in the Official Journal. You can still prepare the functions and the evidence the text clearly asks for.

Where are you against 20 January 2027?

Seven questions about how you work today. Three minutes. You get a score out of 10 and what is missing for you.

Meet us at 35.BI-MU, fieramilano Rho, 13–16 October 2026