---
title: "Machinery Regulation point 1.1.9: what to prepare | Edge SDN"
description: "The new Machinery Regulation puts cybersecurity into CE marking. What points 1.1.9 and 1.2.1 of Annex III ask and how a machine builder prepares."
url: https://www.edge-sdn.com/use-cases/machinery-regulation-point-1-1-9/
last_updated: 2026-09-19
---

Machinery Regulation · Machine builder

# Prepare for point 1.1.9: what your machine must know about its own software from 20 January 2027

By Aldo Campi, co-founder and CEO of Stoorm5 · Published 19 September 2026 · Last updated 19 September 2026

What are the cybersecurity requirements of the Machinery Regulation 2023/1230?

From 20 January 2027, Annex III of Regulation (EU) 2023/1230 sets four cybersecurity duties. Connections to a machine must not create hazardous situations. Safety-critical software and data must be protected against corruption. The machine must identify its installed safety software and collect evidence of interventions. A log of safety software versions must be enabled for five years.

Where are you against 20 January 2027? [Take the Check 2027](https://www.edge-sdn.com/check-2027/): seven questions, three minutes.

## Key facts

- Regulation (EU) 2023/1230 applies from 20 January 2027 and replaces the Machinery Directive 2006/42/EC. The corrigendum of 4 July 2023 fixed the date, which some copies still show as 14 January. [\[Corrigendum to Regulation (EU) 2023/1230, OJ L 169\]](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32023R1230R%2801%29)
- Annex III, point 1.1.9 covers protection against corruption. Point 1.2.1 covers the safety and reliability of control systems, including malicious attempts from third parties. [\[Regulation (EU) 2023/1230, Annex III\]](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32023R1230#anx%5FIII)
- A person who substantially modifies a machine takes on the obligations of the manufacturer for that machine. [\[Regulation (EU) 2023/1230, Article 18\]](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32023R1230#art%5F18)

## The situation

The CE marking manager of a machine builder has done risk assessments according to ISO 12100 for twenty years. Guards, emergency stops, performance levels. The technical file is in good order.

Then the new Machinery Regulation arrives. Two points of Annex III speak of software, remote devices and malicious third parties. Nobody in the technical office has ever done cybersecurity, and the software that produces the technical file has no chapter for it.

## What the two points ask

### Point 1.1.9, Protection against corruption

In plain words:

- Connecting another device to the machine, directly or through a remote system, must not lead to a hazardous situation.
- Hardware that transmits signals or data relevant for safety must be protected against accidental or intentional corruption.
- Software and data that are critical for compliance with the safety requirements must be identified and protected against corruption.
- The machine must **identify the installed software** that is necessary for it to operate safely, and be able to give that information at any time in an accessible form.
- The machine must **collect evidence** of a legitimate or illegitimate intervention in that software, or of a modification of the software or its configuration.

### Point 1.2.1, Safety and reliability of control systems

Control systems must withstand intended and unintended external influences, including **reasonably foreseeable malicious attempts from third parties** that lead to a hazardous situation. A tracing log of interventions and of the versions of safety software uploaded after the machine is placed on the market must be enabled for **five years**.

## Why this is different from what you did before

These are **functions of the machine**, not pages of a document. A machine that cannot tell which safety software version it runs, or that keeps no record of who changed it, does not meet the text, however good the technical file is.

They are also **never finished**. A guard that was safe in 2027 is safe in 2032. A piece of software that had no known vulnerability in 2027 will have several by 2032.

## The steps to prepare

### 1. Find the safety-relevant software

List the software and data that the safety functions depend on: safety PLC program, drive parameters, HMI functions that change safety settings. Give each a version.

### 2. Control who can connect

Every path into the machine is a possible source of corruption: the plant network, the service laptop, the remote access gateway, the USB port. Decide which paths exist in which operating state, and close the rest.

### 3. Record interventions

Log who connected, when, in which state and which software or configuration changed. Keep the log for five years at least.

### 4. Watch for new vulnerabilities

A new vulnerability in a component can turn an acceptable risk into an unacceptable one. You need a process that tells you when this happens, per delivered machine.

### 5. Do not wait for the standards

The harmonised standards will describe how to show conformity. They will not change what the regulation asks. The five steps above are valid in any case.

## How our products help

[Edge Shield](https://www.edge-sdn.com/products/edge-shield/) covers the network side. It allows only the declared flows for each operating state, inspects them and records profile changes and blocked attempts. It addresses who can connect to the machine. It does not replace the identification of software inside your PLC.

[Shield Lifecycle](https://www.edge-sdn.com/products/shield-lifecycle/) keeps the component list of each delivered machine and checks new vulnerabilities against it every day. It tells you when the security side of your risk assessment needs a new look.

Neither product replaces your risk assessment, your technical file or your declaration of conformity. They give you the functions and the evidence for the part that your current tools do not cover.

## Frequently asked questions

### Can someone certify today that my machine meets point 1.1.9?

Not with presumption of conformity. The harmonised standards for these points are not yet cited in the Official Journal. You can prepare the functions and the evidence that the text clearly asks for, and adjust when the standards arrive.

### Is the Machinery Regulation the same as the CRA?

No. The Machinery Regulation looks at cybersecurity only where it can create a safety hazard. The CRA looks at the cybersecurity of any product with digital elements. A connected machine usually falls under both.

### Should I put safety and security in the same risk assessment?

Keep them linked and separate. A safety assessment is stable for years. A security assessment must be reviewed whenever a new relevant vulnerability appears, which can be several times a year.

Product

### Edge Shield

[Explore Edge Shield](https://www.edge-sdn.com/products/edge-shield/)

Product

### Shield Lifecycle

[Explore Shield Lifecycle](https://www.edge-sdn.com/products/shield-lifecycle/)

Related use case

### Same model, two machines, one exposed: find which shipped machines a new CVE hits

[Read](https://www.edge-sdn.com/use-cases/find-which-machines-a-new-cve-exposes/)

Related use case

### Reduce the attack surface of an old machine: protect what you cannot patch

[Read](https://www.edge-sdn.com/use-cases/protect-a-machine-you-cannot-patch/)

This article is a summary for practitioners and not legal advice. Always check the official text for your case.

## Where are you against 20 January 2027?

Seven questions about how you work today. Three minutes. You get a score out of 10 and what is missing for you.

Meet us at 35.BI-MU, fieramilano Rho, 13–16 October 2026
