Machinery Regulation (EU) 2023/1230
The Machinery Regulation sets the essential health and safety requirements for machinery, related products and partly completed machinery placed on the EU market or put into service (Art. 1 and 2). New compared with the Directive: protection against corruption of the software and data that keep a machine safe, and control systems that withstand reasonably foreseeable malicious attempts (Annex III, sections 1.1.9 and 1.2.1).
The Machinery Regulation in plain English
If you design, build, import, distribute or substantially modify machinery, you must make sure it meets the essential health and safety requirements of Annex III before it is placed on the market or put into service (Art. 10). You show that with a risk assessment and technical documentation (Annex IV), a conformity assessment procedure (Art. 25), an EU declaration of conformity (Art. 21) and the CE marking (Art. 23 and 24). The Regulation applies directly in every Member State from 20 January 2027 and replaces Directive 2006/42/EC (Art. 51 and 54). For connected and software-driven machinery the requirements now include protection against corruption of safety-critical software and data, evidence of interventions, and control systems that withstand malicious attempts (Annex III, sections 1.1.9 and 1.2.1).
Start here: pick what fits you
The Regulation article by article, its obligations, the steps to conformity, and how Crosswalk assesses against it
Articles
The full consolidated text: 66 articles and 12 annexes, chapter by chapter
Obligations
What manufacturers, importers, distributors and modifiers must do, drawn from the articles
Compliance guide
Six steps from scope to market surveillance, with the articles behind each step
Timeline
From entry into force in July 2023 to full application on 20 January 2027
Penalties and enforcement
Penalties are set by the Member States; enforcement runs through market surveillance (Chapter VI)
Standards
Presumption of conformity, common specifications and the cybersecurity guidance Crosswalk uses
Why MR Compliance Matters for Your Business
Beyond avoiding penalties, MR compliance represents a strategic advantage. Companies that implement security by design reduce their risk of costly breaches, build customer trust, and gain competitive differentiation in an increasingly security-conscious market.
What MR Actually Requires You to Do
The MR establishes essential cybersecurity requirements that apply throughout your product's lifecycle. These aren't just theoretical guidelines—they're practical obligations with legal consequences.
Think of it this way: Just as you need safety standards for physical products (crash tests for cars, fire safety for electronics), the MR creates mandatory security standards for digital products. Every requirement serves a specific purpose in protecting end users and the broader digital ecosystem.
Risk assessment and Annex III
Design and construction to the essential health and safety requirements that follow from the risk assessment
This means integrating security considerations from the very first design sketches. No more 'we'll add security later'—it must be part of your core product development process from day one.
Specific Requirements:
Practical Tip:
Start by conducting threat modeling sessions during your product planning phase. Many teams find Microsoft's STRIDE methodology helpful for systematic threat identification.
Protection against corruption
Annex III, section 1.1.9: connections, safety-critical software and data
You must establish a coordinated vulnerability disclosure process, maintain security throughout the product lifecycle, and respond quickly to security issues. This isn't just about fixing bugs—it's about professional incident response.
Specific Requirements:
Practical Tip:
Set up a [email protected] email address and establish SLAs for response times. Consider partnering with vulnerability disclosure platforms like HackerOne or Bugcrowd.
Safe and resilient control systems
Annex III, section 1.2.1: control systems that withstand faults, errors and malicious attempts
Clear, accessible documentation helps users understand security features and configure products safely. This reduces support calls and prevents security misconfigurations that could lead to breaches.
Specific Requirements:
Practical Tip:
Create user-friendly security guides alongside your regular documentation. Include clear setup instructions, common security mistakes to avoid, and troubleshooting guidance.
Technical documentation
Annex IV, kept for at least 10 years (Art. 10(3))
Products must be assessed for their potential impact if compromised. Critical infrastructure products face stricter requirements than consumer apps, reflecting their different risk profiles.
Specific Requirements:
Practical Tip:
Use risk assessment frameworks like NIST Cybersecurity Framework to systematically evaluate your product's risk level. Document your reasoning for audit purposes.
Conformity assessment and CE marking
Art. 25 routes, EU declaration (Art. 21), CE marking (Art. 23 and 24)
You're responsible for the security of all components in your product, including third-party libraries and dependencies. This creates accountability throughout the entire supply chain.
Specific Requirements:
Practical Tip:
Implement Software Bill of Materials (SBOM) tracking from the start. Tools like Syft, CycloneDX, or SPDX can help automate component inventory management.
Instructions and information
Art. 10(5) to (8) and Annex III, 1.7.4
CE marking for cybersecurity works like CE marking for other product safety aspects. It's your declaration that the product meets EU security requirements and is safe to place on the market.
Specific Requirements:
Practical Tip:
Work with a notified body early in your process to understand specific conformity assessment requirements for your product category and risk level.
The Bottom Line
MR requirements aren't just compliance checkboxes—they represent cybersecurity best practices that protect your customers, your business, and the broader digital ecosystem. Companies that implement these requirements early often find they reduce long-term security costs while building stronger, more trustworthy products.
Free MR Compliance Tools
Get started with our comprehensive toolkit designed to simplify your compliance journey. Each tool is built by experts and validated against official requirements.
Common MR Questions
Does the Machinery Regulation cover cybersecurity?
Yes, in two places of Annex III, and both are new compared with the Directive:
- Section 1.1.9, protection against corruption: connections and remote devices may not lead to a hazardous situation, safety-critical software and data are identified and protected, and the machine collects evidence of interventions
- Section 1.2.1, safety and reliability of control systems: control systems withstand reasonably foreseeable malicious attempts, and faults or logic errors do not lead to hazardous situations
- A certificate under a cybersecurity certification scheme of Regulation (EU) 2019/881 gives presumption of conformity with those two sections insofar as it covers them (Art. 20(9))
- Machinery with digital elements also falls under the Cyber Resilience Act; both sets of requirements apply (CRA recital 53)
Is software a safety component?
It can be. Article 3(3) defines a safety component as a physical or digital component, including software, of a product within the scope of the Regulation, designed or intended to fulfil a safety function and independently placed on the market, whose failure or malfunction endangers the safety of persons.
What changes for machinery already sold under the Directive?
Article 52 keeps the market open for it:
- Products placed on the market in conformity with Directive 2006/42/EC before 20 January 2027 may continue to be made available
- EC type-examination certificates and approval decisions under Article 12 of the Directive remain valid until they expire
- Chapter VI on market surveillance applies to those products from 19 July 2023, in place of Article 11 of the Directive
Who is the manufacturer after a modification?
The person who carries out a substantial modification. Article 3(16) defines it as a modification, by physical or digital means, after placing on the market or putting into service, not foreseen or planned by the manufacturer and affecting safety. Under Article 18 that person takes on the manufacturer obligations of Article 10 for the modified product, or for the affected part of an assembly, and applies the relevant conformity assessment procedure.
Can I self-certify?
It depends on Annex I (Art. 25):
- Not listed in Annex I: internal production control, module A
- Annex I, Part B: module A only when the product is designed and constructed to harmonised standards or common specifications covering all relevant essential requirements; otherwise EU type-examination with conformity to type, full quality assurance or unit verification
- Annex I, Part A: always one of those three notified-body routes
Can the instructions be digital?
Yes, under the conditions of Article 10(7):
- The product, its packaging or an accompanying document says how to access them
- They can be printed, downloaded and saved, also when embedded in the software
- They stay online for the expected lifetime and at least 10 years after placing on the market
- On request at purchase, a paper copy follows free of charge within one month; essential safety information is on paper where non-professional users may use the machine
Start your Machinery Regulation file
Crosswalk maps the Regulation onto your product file next to the CRA and the other laws. The articles are here to read in full.


