Skip to content
ReadinessNavigator

Regulation (EU) 2023/1230

Machinery Regulation: cybersecurity where it affects safety

From 20 January 2027, the Machinery Regulation replaces Directive 2006/42/EC. Its requirements address how interference with software, data and control systems can create hazards. This explainer focuses on that cybersecurity-to-safety connection.

From Directive to Regulation

The Regulation is directly applicable across the EU and generally applies from 20 January 2027. Assess the relevant obligations for placing a product on the market or putting it into service; these are distinct legal events.

Article 52(1) protects the continued making available of products placed on the market in conformity with Directive 2006/42/EC before 20 January 2027. Article 52(2) keeps EC type-examination certificates and approval decisions issued under the Directive valid until they expire. The date alone does not require every machine already in use to undergo a new conformity assessment.

That transition is separate from substantial modification. Articles 3(16) and 18 address physical or digital changes after placing on the market or putting into service that meet the Regulation’s conditions, including a change not foreseen or planned by the manufacturer that affects safety by creating a new hazard or increasing an existing risk and requires the protective measures specified in Article 3(16). A software update is not automatically a substantial modification; a qualifying modification can create manufacturer obligations for the person making it.

The cybersecurity requirements

Annex III, Part B, sections 1.1.9 and 1.2.1 connect protection against corruption with the safety and reliability of control systems. In practical terms, the relevant requirements include:

  • Connections to another device, including remote connections, must not lead to a hazardous situation.
  • Protect hardware components that transmit signals or data relevant to accessing software critical to compliance, and collect evidence of legitimate or illegitimate intervention in those components.
  • Identify and protect software and data critical to compliance against accidental or intentional corruption. Identification of installed software necessary for safe operation must be readily accessible.
  • Collect evidence of intervention in software and of modifications to software or configuration.
  • Design and construct control systems to withstand, where appropriate to the circumstances and risks, reasonably foreseeable malicious attempts by third parties leading to hazardous situations.
  • Under section 1.2.1(f), keep a tracing log of data generated in relation to an intervention and of safety-software versions uploaded after placing on the market or putting into service, for five years after upload. This is a specific tracing requirement, not a five-year retention rule for every security log.

Why this is a safety subject

An unauthorised change to a speed limit, an interlock configuration or a control command can change a machine’s physical behaviour. A loss of availability can also matter where safe operation depends on a control function.

Consider these foreseeable pathways in the machinery risk assessment and show how the resulting measures reduce the relevant risks. Security findings need to connect to hazards, operating conditions and protective measures rather than remain in a separate security file. This connection does not replace the wider machinery risk assessment.

What this means for evidence

The technical documentation must support the applicable requirements, including the risk assessment, protective measures, relevant specifications and test results. Annex IV distinguishes the documentation for machinery and related products from that for partly completed machinery.

Useful engineering evidence can include an interface inventory, identified safety-related software and versions, a threat model linked to hazards, access and update controls, intervention records and test results. These are practical examples of supporting evidence, not a claim that each is a separately named statutory deliverable.

IEC 62443-4-1 can support evidence about secure product development and maintenance. IEC 62443-4-2 can support evidence about an industrial component’s technical security capabilities. This is an engineering connection between their scopes, not a complete clause-by-clause crosswalk. Neither standard alone establishes Machinery Regulation conformity or whole-machine safety.

Applying a standard is not the same as obtaining a presumption of conformity. Article 20 ties that presumption to the applicable conditions and the requirements covered; for harmonised standards, the relevant references must be published in the Official Journal. No harmonised status for either IEC part is asserted here.

Machinery and the CRA together

A machine that is also a product with digital elements may fall under both regimes. CRA recital 53 explains that meeting CRA cybersecurity requirements can facilitate compliance with the Machinery Regulation’s requirements, but the manufacturer must demonstrate the synergy. Evidence reuse needs a risk-based mapping; it is not automatic equivalence.

Each applicable conformity assessment procedure still applies. That does not mean two mandatory external audits or two separate declaration documents: Machinery Article 21(3) provides for a single EU declaration covering the applicable Union acts.

Machinery Article 9 concerns risks covered more specifically by other Union harmonisation legislation. Its effect is limited to those risks and that legislation; it is not a blanket exemption whenever the CRA applies.

The dates are different: CRA Article 14 reporting obligations have applied since 11 September 2026; the Machinery Regulation generally applies from 20 January 2027; and the CRA generally applies from 11 December 2027. Do not treat the CRA’s main application date as a reason to postpone the machinery work.

Where to start

Identify the product, its placing-on-the-market or putting-into-service date, safety-related software and exposed interfaces. Check which legislation applies and connect the cybersecurity evidence to the machinery risk assessment. The resources below address supporting processes and CRA questions; neither CRA questionnaire assesses Machinery Regulation conformity.

Discuss your product and applicable requirements

Source review: 24 September 2026. Machinery text: consolidated version of 27 July 2026.