Related EU Regulation Last updated: September 5, 2026

EU Machinery Regulation 2023/1230

The new EU Machinery Regulation introduces cybersecurity requirements for machinery with digital elements. Learn how it intersects with CRA and what it means for industrial IoT, robotics, and smart manufacturing.

How This Relates to CRA

The EU Machinery Regulation 2023/1230 and the Cyber Resilience Act (CRA) have overlapping cybersecurity requirements. If your product is both "machinery" AND a "product with digital elements," you may need to comply with both regulations. Per Article 9 of the Machinery Regulation, where requirements overlap, the more specific regulation applies.

Check if CRA applies to your product →

What is the EU Machinery Regulation?

Regulation (EU) 2023/1230 is the new EU legislation governing health and safety requirements for machinery, related products, and partly completed machinery placed on the EU market. It replaces the old Machinery Directive 2006/42/EC and becomes mandatory on 20 January 2027.

Machinery

Assemblies with drive systems, linked parts, at least one moving part, joined for a specific application

Safety Components

Physical or digital components (including software) that fulfill a safety function

Partly Completed Machinery

Assemblies intended to be incorporated into other machinery to form complete systems

Key Dates

29 June 2023
Published - Regulation (EU) 2023/1230 published in Official Journal
19 July 2023
Entry into Force - Regulation enters into force
20 January 2027
Applies - Full application date. Directive 2006/42/EC repealed.

Same as CRA!

Note that the Machinery Regulation application date (20 Jan 2027) is close to the CRA deadline (11 Dec 2027). If both apply to your product, you'll need to prepare for two major compliance milestones.

Cybersecurity Requirements (New in 2023/1230)

The new Machinery Regulation introduces mandatory cybersecurity requirements for the first time. These are found in Annex III, Sections 1.1.9 and 1.2.1.

1.1.9

Protection Against Corruption

  • Hardware components transmitting signals for safety-critical software must be protected against corruption
  • Software and data critical for compliance must be identified and adequately protected
  • Machinery must collect evidence of legitimate or illegitimate interventions
  • Must identify installed software necessary for safe operation
1.2.1

Safety and Reliability of Control Systems

  • Control systems must withstand malicious attempts from third parties
  • Faults in hardware or logic must not lead to hazardous situations
  • Must maintain a 5-year tracing log of interventions and safety software versions
  • For AI/ML systems: 1-year logging of safety-related decision-making
  • Wireless control failures must not lead to hazardous situations

AI and Machine Learning Systems

The Machinery Regulation has specific requirements for self-evolving behavior and machine learning systems that ensure safety functions.

Annex I Part A - Mandatory Third-Party Assessment

The following AI/ML products require third-party conformity assessment:

  • Safety components with fully or partially self-evolving behavior using machine learning
  • Machinery with embedded AI/ML systems ensuring safety functions (if not already assessed independently)

Additional Requirements for AI/ML Control Systems (Section 1.2.1)

  • Must not cause machinery to perform actions beyond its defined task and movement space
  • Must enable recording of safety-related decision-making data for 1 year
  • Must be possible to correct the machinery at all times to maintain inherent safety
  • No modifications to safety settings during learning phases that could lead to hazardous situations

CRA + Machinery Regulation: When Both Apply

If your product is BOTH machinery/related product AND a product with digital elements, you need to understand how the two regulations interact.

Article 9
Specific regulation takes precedence
Where risks are covered by more specific EU harmonization legislation, that legislation applies instead of the Machinery Regulation for those specific risks.
Article 20(9)
Cybersecurity certification presumption
Products certified under Regulation (EU) 2019/881 (Cybersecurity Act) are presumed compliant with sections 1.1.9 and 1.2.1 if the certificate covers those requirements.

Products That May Need Both

Industrial IoT

  • Connected manufacturing equipment
  • Smart sensors with safety functions
  • Industrial robots with network connectivity

Smart Machinery

  • CNC machines with remote access
  • Automated guided vehicles (AGVs)
  • Collaborative robots (cobots)

Conformity Assessment Procedures

The Machinery Regulation has a tiered conformity assessment system based on risk:

Not in Annex I
Self-Assessment (Module A)
Internal production control. No third-party involvement required.
Annex I Part B
Self-Assessment OR Third-Party
Module A (if using harmonized standards) OR Module B+C, H, or G with notified body.
Annex I Part A
Mandatory Third-Party Assessment
Module B+C, H, or G with notified body. Includes AI/ML safety components.

What's New vs. Directive 2006/42/EC

New Requirements

  • Cybersecurity - Sections 1.1.9 and 1.2.1
  • AI/ML provisions - Self-evolving behavior
  • Software as safety component
  • Digital instructions allowed
  • Substantial modification definition

Key Changes

  • Directive → Regulation (directly applicable)
  • Updated product categories in Annex I
  • Clearer economic operator obligations
  • Digital declarations of conformity
  • Extended documentation requirements

Common Industry Challenges

Many companies are facing significant practical challenges with the new regulation:

⚠️

Compliance Complexity

Stricter safety, design and risk assessment requirements including cybersecurity, AI and digital documentation

👥

Resource Shortages

Not enough personnel, time or budget to analyze, revise designs, and update documentation before 2027

📅

Tight Deadlines

Short transition period given the volume of changes required for January 2027

📜

Harmonised Standards Gap

Many harmonised European standards (hENs) may not be revised or available in time

📄

Digital Documentation

New requirements for digital operating instructions accessible for 10+ years

🔗

Regulatory Overlap

Must align with CRA, NIS2, and other EU laws with overlapping requirements

Does Your Product Need CRA Compliance?

If your machinery includes digital elements with network connectivity, you may also need to comply with the Cyber Resilience Act. Use our free assessment tool to find out.