Prepare your machinery for the Machinery Regulation
Last updated 30 September 2026. A summary, not legal advice. Always check the official text for your case.
From 20 January 2027 the Machinery Regulation replaces the Machinery Directive. For the first time, protection against cyber threats is part of the essential health and safety requirements for CE marking. A connection must not lead to a hazardous situation, safety software must be protected and the machinery must keep evidence of interventions.
Manufacturers, importers, distributors and whoever modifies the machinery
A substantial modification makes you the manufacturer of that machinery, with all its duties.
A natural or legal person that carries out a substantial modification of machinery or a related product shall be considered to be a manufacturer for the purposes of this Regulation
Two essential requirements concern cybersecurity
The machinery or related product shall be designed and constructed so that the connection to it of another device […] does not lead to a hazardous situation.
- Software and data critical for safety are identified and protected against accidental or intentional corruption
- The machinery identifies the software it needs to operate safely, at all times
- It collects evidence of a legitimate or illegitimate intervention in that software or its configuration
they can withstand […] intended and unintended external influences, including reasonably foreseeable malicious attempts from third parties leading to a hazardous situation
What to do first
- Read Annex III, points 1.1.9 and 1.2.1
- Keep safety and security risk assessments separate: security changes several times a year
- Limit and record who can connect to the machinery
Which products help, and why
Edge Shield
A connection passes only on declared flows. Traffic analysis and IDS detect malicious attempts and keep a record.
Annex III, 1.1.9 and 1.2.1
Explore Edge Shield Helps with a partShield Lifecycle
Keeps the list of the software of each delivered machine.
Annex III, 1.1.9
Explore Shield LifecycleQuestions about the Machinery Regulation
Why do some sources say 14 January 2027?
That is the date in the text published on 29 June 2023. A corrigendum of 4 July 2023 moved every date by six days, so the regulation applies from 20 January 2027 (corrigendum, OJ L 169).
Does the CRA also apply to my machinery?
If the machinery contains software and connects to a device or a network, it is also a product with digital elements under the Cyber Resilience Act. The Machinery Regulation looks at safety, the CRA at cybersecurity over the whole support period. See the CRA page.
Is a software update a substantial modification?
It can be. A modification by physical or digital means is substantial when the manufacturer did not foresee or plan it and it creates a new hazard or increases an existing risk (Article 3). Whoever carries it out takes on the duties of the manufacturer (Article 18).
Which standard gives presumption of conformity for cybersecurity?
As of September 2026, harmonised standards for these points are not yet cited in the Official Journal. You can still prepare the functions and the evidence the text clearly asks for.
Where are you against 20 January 2027?
Seven questions about how you work today. Three minutes. You get a score out of 10 and what is missing for you.
Meet us at 35.BI-MU, fieramilano Rho, 13–16 October 2026