How This Relates to CRA
The EU Machinery Regulation 2023/1230 and the Cyber Resilience Act (CRA) have overlapping cybersecurity requirements. If your product is both "machinery" AND a "product with digital elements," you may need to comply with both regulations. Per Article 9 of the Machinery Regulation, where requirements overlap, the more specific regulation applies.
Check if CRA applies to your product →What is the EU Machinery Regulation?
Regulation (EU) 2023/1230 is the new EU legislation governing health and safety requirements for machinery, related products, and partly completed machinery placed on the EU market. It replaces the old Machinery Directive 2006/42/EC and becomes mandatory on 20 January 2027.
Machinery
Assemblies with drive systems, linked parts, at least one moving part, joined for a specific application
Safety Components
Physical or digital components (including software) that fulfill a safety function
Partly Completed Machinery
Assemblies intended to be incorporated into other machinery to form complete systems
Key Dates
Same as CRA!
Note that the Machinery Regulation application date (20 Jan 2027) is close to the CRA deadline (11 Dec 2027). If both apply to your product, you'll need to prepare for two major compliance milestones.
Cybersecurity Requirements (New in 2023/1230)
The new Machinery Regulation introduces mandatory cybersecurity requirements for the first time. These are found in Annex III, Sections 1.1.9 and 1.2.1.
Protection Against Corruption
- Hardware components transmitting signals for safety-critical software must be protected against corruption
- Software and data critical for compliance must be identified and adequately protected
- Machinery must collect evidence of legitimate or illegitimate interventions
- Must identify installed software necessary for safe operation
Safety and Reliability of Control Systems
- Control systems must withstand malicious attempts from third parties
- Faults in hardware or logic must not lead to hazardous situations
- Must maintain a 5-year tracing log of interventions and safety software versions
- For AI/ML systems: 1-year logging of safety-related decision-making
- Wireless control failures must not lead to hazardous situations
AI and Machine Learning Systems
The Machinery Regulation has specific requirements for self-evolving behavior and machine learning systems that ensure safety functions.
Annex I Part A - Mandatory Third-Party Assessment
The following AI/ML products require third-party conformity assessment:
- Safety components with fully or partially self-evolving behavior using machine learning
- Machinery with embedded AI/ML systems ensuring safety functions (if not already assessed independently)
Additional Requirements for AI/ML Control Systems (Section 1.2.1)
- Must not cause machinery to perform actions beyond its defined task and movement space
- Must enable recording of safety-related decision-making data for 1 year
- Must be possible to correct the machinery at all times to maintain inherent safety
- No modifications to safety settings during learning phases that could lead to hazardous situations
CRA + Machinery Regulation: When Both Apply
If your product is BOTH machinery/related product AND a product with digital elements, you need to understand how the two regulations interact.
Products That May Need Both
Industrial IoT
- Connected manufacturing equipment
- Smart sensors with safety functions
- Industrial robots with network connectivity
Smart Machinery
- CNC machines with remote access
- Automated guided vehicles (AGVs)
- Collaborative robots (cobots)
Conformity Assessment Procedures
The Machinery Regulation has a tiered conformity assessment system based on risk:
What's New vs. Directive 2006/42/EC
New Requirements
- Cybersecurity - Sections 1.1.9 and 1.2.1
- AI/ML provisions - Self-evolving behavior
- Software as safety component
- Digital instructions allowed
- Substantial modification definition
Key Changes
- Directive → Regulation (directly applicable)
- Updated product categories in Annex I
- Clearer economic operator obligations
- Digital declarations of conformity
- Extended documentation requirements
Common Industry Challenges
Many companies are facing significant practical challenges with the new regulation:
Compliance Complexity
Stricter safety, design and risk assessment requirements including cybersecurity, AI and digital documentation
Resource Shortages
Not enough personnel, time or budget to analyze, revise designs, and update documentation before 2027
Tight Deadlines
Short transition period given the volume of changes required for January 2027
Harmonised Standards Gap
Many harmonised European standards (hENs) may not be revised or available in time
Digital Documentation
New requirements for digital operating instructions accessible for 10+ years
Regulatory Overlap
Must align with CRA, NIS2, and other EU laws with overlapping requirements
Does Your Product Need CRA Compliance?
If your machinery includes digital elements with network connectivity, you may also need to comply with the Cyber Resilience Act. Use our free assessment tool to find out.