---
title: "Machinery Regulation 2023/1230: cybersecurity for CE marking | Edge SDN"
description: "What the Machinery Regulation asks about cybersecurity from 20 January 2027: protection against corruption (Annex III 1.1.9), control systems that withstand malicious attempts (1.2.1), five-year tracing log. With links to the official text."
url: https://www.edge-sdn.com/regulations/machinery-regulation/
last_updated: 2026-09-30
---

Regulation (EU) 2023/1230

# Prepare your machinery for the Machinery Regulation

Last updated 30 September 2026. A summary, not legal advice. Always check the official text for your case.

What does the Machinery Regulation ask about cybersecurity?

From 20 January 2027 the Machinery Regulation replaces the Machinery Directive. For the first time, protection against cyber threats is part of the essential health and safety requirements for CE marking. A connection must not lead to a hazardous situation, safety software must be protected and the machinery must keep evidence of interventions.

The regulation applies and the Machinery Directive 2006/42/EC is repealed[Articles 51 and 54, as corrected](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32023R1230R%2801%29)

Tracing log of interventions and of safety software uploaded after sale[Annex III, 1.2.1(f)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32023R1230#anx%5FIII)

Member States notify their rules on penalties[Article 50(2), as corrected](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32023R1230R%2801%29)

Who is covered

## Manufacturers, importers, distributors and whoever modifies the machinery

A substantial modification makes you the manufacturer of that machinery, with all its duties.

[Article 18](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32023R1230#art%5F18)

Annex III

## Two essential requirements concern cybersecurity

[Annex III, 1.1.9 Protection against corruption](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32023R1230#anx%5FIII)

- Software and data critical for safety are identified and protected against accidental or intentional corruption
- The machinery identifies the software it needs to operate safely, at all times
- It collects evidence of a legitimate or illegitimate intervention in that software or its configuration

[Annex III, 1.2.1(a) Safety and reliability of control systems](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32023R1230#anx%5FIII)

**What the regulation does not ask**

It names no standard, no product and no technology. It asks for results: no hazardous situation from a connection, protected safety software and evidence of interventions. The penalties are set by each Member State ([Article 50](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32023R1230#art%5F50)).

### What to do first

- Read Annex III, points 1.1.9 and 1.2.1
- Keep safety and security risk assessments separate: security changes several times a year
- Limit and record who can connect to the machinery

Our products

## Which products help, and why

Built for it

### Edge Shield

A connection passes only on declared flows. Traffic analysis and IDS detect malicious attempts and keep a record.

Annex III, 1.1.9 and 1.2.1

[Explore Edge Shield](https://www.edge-sdn.com/products/edge-shield/)

Helps with a part

### Shield Lifecycle

Keeps the list of the software of each delivered machine.

Annex III, 1.1.9

[Explore Shield Lifecycle](https://www.edge-sdn.com/products/shield-lifecycle/)

FAQ

## Questions about the Machinery Regulation

### Why do some sources say 14 January 2027?

That is the date in the text published on 29 June 2023. A corrigendum of 4 July 2023 moved every date by six days, so the regulation applies from 20 January 2027 ([corrigendum, OJ L 169](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32023R1230R%2801%29)).

### Does the CRA also apply to my machinery?

If the machinery contains software and connects to a device or a network, it is also a product with digital elements under the Cyber Resilience Act. The Machinery Regulation looks at safety, the CRA at cybersecurity over the whole support period. See [the CRA page](https://www.edge-sdn.com/regulations/cyber-resilience-act/).

### Is a software update a substantial modification?

It can be. A modification by physical or digital means is substantial when the manufacturer did not foresee or plan it and it creates a new hazard or increases an existing risk ([Article 3](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32023R1230#art%5F3)). Whoever carries it out takes on the duties of the manufacturer ([Article 18](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32023R1230#art%5F18)).

### Which standard gives presumption of conformity for cybersecurity?

As of September 2026, harmonised standards for these points are not yet cited in the Official Journal. You can still prepare the functions and the evidence the text clearly asks for.

## Where are you against 20 January 2027?

Seven questions about how you work today. Three minutes. You get a score out of 10 and what is missing for you.

Meet us at 35.BI-MU, fieramilano Rho, 13–16 October 2026
