Regulation Statutory · EU
Machinery Regulation (EU Machinery Regulation).
The EU Machinery Regulation (Regulation (EU) 2023/1230) supersedes the previous Machinery Directive 2006/42/EC and applies from 20 January 2027 to the placing on the market of machinery in the EU. New are explicit cybersecurity requirements: machinery with digital elements or safety-relevant functions must be designed so that its safety functions cannot be compromised by unauthorised digital interference. For Swiss machinery manufacturers, the regulation applies as soon as they place their products on the EU market.
01 Triggers
When does Machinery Regulation (EU) 2023/1230 apply to you?
Machinery Regulation (EU) 2023/1230 may apply to you if one of these triggers applies. The Regulatory Check tests them against your details.
- Activity: Products with software (Likely applies): Your machinery contains digital elements or software-controlled safety functions - from January 2027, the EU Machinery Regulation additionally requires, on top of the existing safety requirements, protection against unauthorised digital interference (Annex III, including sections 1.1.9 and 1.2.1).
- Role towards customers: Manufacturer (applies if additionally: Activity: Products with software) (Likely applies): As the manufacturer of machinery with digital elements, you bear the main responsibility for conformity assessment under the Machinery Regulation; importers and distributors who make safety-relevant changes to the machinery are also treated as manufacturers with corresponding obligations. This file specifically covers the new cybersecurity requirements; for machinery with no digital elements at all, check the regulation's classic safety requirements separately.
- Markets: EU (applies if additionally: Activity: Products with software) (Recommend individual review): The Machinery Regulation is triggered by placing on the EU market - if you place machinery with digital elements on the market in the EU, the cybersecurity requirements described here apply regardless of your registered seat in Switzerland.
- Industry: Manufacturing (Recommend individual review): In manufacturing and mechanical engineering, safety functions are increasingly digitally controlled - check whether your machinery falls under the regulation's new cybersecurity requirements.
02 Obligations
What does Machinery Regulation (EU) 2023/1230 require?
- Ensure that machinery is protected against unintentional or deliberate corruption of its safety-relevant software or data (Annex III section 1.1.9).
- Ensure the safety and reliability of controls, including protection against disrupted wireless connections and malfunctions caused by AI components (Annex III section 1.2.1).
- Provide for evidence or logging of legitimate and illegitimate interference with safety-relevant components.
- Carry out CE marking and conformity assessment under the Machinery Regulation; per secondary sources, a combined conformity assessment with the EU AI Act is envisaged where AI safety functions are integrated.
- Maintain technical documentation including cybersecurity evidence.
03 Evidence
What evidence is needed?
- Technical documentation with cybersecurity evidence (Annex III section 1.1.9).
- Declaration of conformity and CE marking.
- Logs of interference with safety-relevant components.
04 Deadlines
Which deadlines apply?
- Regulation (EU) 2023/1230 applies to the placing on the market of machinery and supersedes the Machinery Directive 2006/42/EC.
Information as of: 24 September 2026. Past dates are grey, upcoming ones highlighted (as of when the page was built).
05 Penalties
What are the consequences of violations?
The Machinery Regulation itself primarily harmonises safety requirements and conformity assessment; sanctions for breaches (e.g. market surveillance measures, fines) are governed by the national law of the member states and were not researched in this session.
06 Related
What is connected with it?
- Regulation on cybersecurity requirements for products with digital elements (Cyber Resilience Act): The Cyber Resilience Act (Regulation (EU) 2024/2847) sets EU-wide, uniform cybersecurity requirements for hardware and software products with digital elements across their entire life cycle.
- Regulation (EU) 2017/745 on medical devices: The EU Medical Device Regulation (MDR, Regulation (EU) 2017/745) governs conformity assessment, CE marking, technical documentation and market surveillance for medical devices in the EU; it has applied since 26 May 2021.
07 Open
What is still uncertain?
- The EUR-Lex primary text of Regulation (EU) 2023/1230 (eur-lex.europa.eu/eli/reg/2023/1230/oj) was not retrievable in this session (HTTP 503 or empty response); all statements come from two independent secondary sources (professional articles), not from the regulation's text itself.
- The date of entry into force or publication of the regulation was not verified and is therefore not listed - only the application date of 20.1.2027 is evidenced.
- Specific exemptions from the scope (e.g. for certain machinery categories, as under the old Machinery Directive) were not named in the sources retrieved and are therefore not documented; the 'ausnahmen' field is accordingly empty rather than guessed.
- Sanctions/fine ranges for breaches were not researched (governed by the national law of the member states).
- The statement on a combined conformity assessment with the EU AI Act for integrated AI safety functions comes from a single secondary source and was not cross-checked.
08 Sources
Sources
Information as of: 24 September 2026.
- EU-Maschinenverordnung 2023/1230: Neue Cybersecurity-Anforderungen für Hersteller ab 2027, NTT DATA Deutschland, retrieved on 24 September 2026
- Maschinenverordnung (EU) 2023/1230: Anforderungen an digitale Technologien und Cybersicherheit, WEKA Business Medien, retrieved on 24 September 2026
A professional assessment based on publicly available sources, not legal advice. Whether a given rule applies in your specific case depends on circumstances that are not fully captured here.
FAQ Answers
Questions about Machinery Regulation (EU) 2023/1230.
From when does the new Machinery Regulation apply as binding?
From 20 January 2027, only machinery that complies with Regulation (EU) 2023/1230 may be placed on the market in the EU; it supersedes the previous Machinery Directive 2006/42/EC.
What is new about the cybersecurity requirements compared with the old Machinery Directive?
For the first time, software safety, protection against unauthorised digital interference, and risks from AI algorithms become an explicit part of the essential safety requirements and conformity assessment (Annex III, including sections 1.1.9 and 1.2.1) - the old directive had no such specific cybersecurity requirements.
How does the Machinery Regulation relate to the Cyber Resilience Act?
Both frameworks address cybersecurity for connected products, but the Machinery Regulation is the more specific regime for machinery and its safety functions. The details of how the two frameworks are demarcated case by case have not been conclusively clarified in this knowledge base; see the separate norm file cra.
Does Machinery Regulation (EU) 2023/1230 apply to you?
The Regulatory Check gives an initial assessment. In a conversation, we clarify what really applies in your situation and in which order you address it.
