MR

Machinery Regulation (EU) 2023/1230

The Machinery Regulation sets the essential health and safety requirements for machinery, related products and partly completed machinery placed on the EU market or put into service (Art. 1 and 2). New compared with the Directive: protection against corruption of the software and data that keep a machine safe, and control systems that withstand reasonably foreseeable malicious attempts (Annex III, sections 1.1.9 and 1.2.1).

Applies from 20 January 2027 (Art. 54); Directive 2006/42/EC is repealed on that date (Art. 51)
20 Jan 2027 Applies in full; Directive 2006/42/EC repealed (Art. 51 and 54)
54 articles and 12 annexes; the emergency Articles 25a to 25e stand with Article 25
10 years Technical documentation kept for the authorities (Art. 10(3))

The Machinery Regulation in plain English

If you design, build, import, distribute or substantially modify machinery, you must make sure it meets the essential health and safety requirements of Annex III before it is placed on the market or put into service (Art. 10). You show that with a risk assessment and technical documentation (Annex IV), a conformity assessment procedure (Art. 25), an EU declaration of conformity (Art. 21) and the CE marking (Art. 23 and 24). The Regulation applies directly in every Member State from 20 January 2027 and replaces Directive 2006/42/EC (Art. 51 and 54). For connected and software-driven machinery the requirements now include protection against corruption of safety-critical software and data, evidence of interventions, and control systems that withstand malicious attempts (Annex III, sections 1.1.9 and 1.2.1).

Applies to machinery, interchangeable equipment, safety components, lifting accessories, chains, ropes and webbing, removable mechanical transmission devices, and partly completed machinery (Art. 2(1))
A safety component can be digital: software that fulfils a safety function and is placed on the market independently counts as a safety component (Art. 3(3))
Whoever substantially modifies a machine, by physical or digital means, is treated as its manufacturer for the modified product or part (Art. 3(16) and Art. 18)
Categories listed in Annex I need a procedure with a notified body (Part A), or may use internal production control only when designed to harmonised standards or common specifications covering all relevant requirements (Part B) (Art. 6 and Art. 25)
Safety components with self-evolving behaviour using machine learning that ensures safety functions, and machinery embedding such systems, are in Annex I, Part A (items 5 and 6)
Technical documentation and the EU declaration of conformity are kept for at least 10 years; source code or programming logic goes to the national authorities on a reasoned request when needed to check compliance (Art. 10(3))
Instructions may be digital: printable, downloadable, online for the expected lifetime and at least 10 years, with a paper copy within a month on request at purchase (Art. 10(7))
Products placed on the market under Directive 2006/42/EC before 20 January 2027 may continue to be made available; EC type-examination certificates stay valid until they expire (Art. 52)
Penalties are set by each Member State and must be effective, proportionate and dissuasive; they may include criminal penalties for serious infringements (Art. 50)
A certificate under a cybersecurity certification scheme of Regulation (EU) 2019/881 gives a presumption of conformity with sections 1.1.9 and 1.2.1 of Annex III insofar as it covers them (Art. 20(9))

Why MR Compliance Matters for Your Business

Beyond avoiding penalties, MR compliance represents a strategic advantage. Companies that implement security by design reduce their risk of costly breaches, build customer trust, and gain competitive differentiation in an increasingly security-conscious market.

Risk Reduction
Proactive compliance reduces the risk of costly breaches and enforcement actions
Market Access
Compliance is a prerequisite for placing products and services on the EU market
Customer Trust
Demonstrable compliance builds confidence with customers and partners

What MR Actually Requires You to Do

The MR establishes essential cybersecurity requirements that apply throughout your product's lifecycle. These aren't just theoretical guidelines—they're practical obligations with legal consequences.

Think of it this way: Just as you need safety standards for physical products (crash tests for cars, fire safety for electronics), the MR creates mandatory security standards for digital products. Every requirement serves a specific purpose in protecting end users and the broader digital ecosystem.

Core Requirement 1

Risk assessment and Annex III

Design and construction to the essential health and safety requirements that follow from the risk assessment

This means integrating security considerations from the very first design sketches. No more 'we'll add security later'—it must be part of your core product development process from day one.

Specific Requirements:

• Risk assessment per the general principles of Annex III
• Applicable requirements identified and documented
• Residual risks explained to users (Annex III, 1.7)

Practical Tip:

Start by conducting threat modeling sessions during your product planning phase. Many teams find Microsoft's STRIDE methodology helpful for systematic threat identification.

Core Requirement 2

Protection against corruption

Annex III, section 1.1.9: connections, safety-critical software and data

You must establish a coordinated vulnerability disclosure process, maintain security throughout the product lifecycle, and respond quickly to security issues. This isn't just about fixing bugs—it's about professional incident response.

Specific Requirements:

• Connections and remote devices cannot create a hazardous situation
• Safety-critical hardware protected against accidental or intentional corruption
• Evidence of legitimate and illegitimate interventions collected

Practical Tip:

Set up a [email protected] email address and establish SLAs for response times. Consider partnering with vulnerability disclosure platforms like HackerOne or Bugcrowd.

Core Requirement 3

Safe and resilient control systems

Annex III, section 1.2.1: control systems that withstand faults, errors and malicious attempts

Clear, accessible documentation helps users understand security features and configure products safely. This reduces support calls and prevents security misconfigurations that could lead to breaches.

Specific Requirements:

• Reasonably foreseeable malicious attempts withstood
• Hardware faults and logic errors not hazardous
• Safety-function limits fixed in the risk assessment, no hazardous changes by operators or self-learning

Practical Tip:

Create user-friendly security guides alongside your regular documentation. Include clear setup instructions, common security mistakes to avoid, and troubleshooting guidance.

Core Requirement 4

Technical documentation

Annex IV, kept for at least 10 years (Art. 10(3))

Products must be assessed for their potential impact if compromised. Critical infrastructure products face stricter requirements than consumer apps, reflecting their different risk profiles.

Specific Requirements:

• Description, intended use and risk assessment
• Standards and specifications applied, test results
• Source code or programming logic on reasoned request

Practical Tip:

Use risk assessment frameworks like NIST Cybersecurity Framework to systematically evaluate your product's risk level. Document your reasoning for audit purposes.

Core Requirement 5

Conformity assessment and CE marking

Art. 25 routes, EU declaration (Art. 21), CE marking (Art. 23 and 24)

You're responsible for the security of all components in your product, including third-party libraries and dependencies. This creates accountability throughout the entire supply chain.

Specific Requirements:

• Module A, or B with C, H or G depending on Annex I
• EU declaration per Annex V, continuously updated
• CE marking before placing on the market

Practical Tip:

Implement Software Bill of Materials (SBOM) tracking from the start. Tools like Syft, CycloneDX, or SPDX can help automate component inventory management.

Core Requirement 6

Instructions and information

Art. 10(5) to (8) and Annex III, 1.7.4

CE marking for cybersecurity works like CE marking for other product safety aspects. It's your declaration that the product meets EU security requirements and is safe to place on the market.

Specific Requirements:

• Identification, year of construction and contact details on the product
• Instructions, digital where allowed, online for at least 10 years
• Essential safety information on paper for non-professional users

Practical Tip:

Work with a notified body early in your process to understand specific conformity assessment requirements for your product category and risk level.

The Bottom Line

MR requirements aren't just compliance checkboxes—they represent cybersecurity best practices that protect your customers, your business, and the broader digital ecosystem. Companies that implement these requirements early often find they reduce long-term security costs while building stronger, more trustworthy products.

Common MR Questions

Does the Machinery Regulation cover cybersecurity?

Yes, in two places of Annex III, and both are new compared with the Directive:

  • Section 1.1.9, protection against corruption: connections and remote devices may not lead to a hazardous situation, safety-critical software and data are identified and protected, and the machine collects evidence of interventions
  • Section 1.2.1, safety and reliability of control systems: control systems withstand reasonably foreseeable malicious attempts, and faults or logic errors do not lead to hazardous situations
  • A certificate under a cybersecurity certification scheme of Regulation (EU) 2019/881 gives presumption of conformity with those two sections insofar as it covers them (Art. 20(9))
  • Machinery with digital elements also falls under the Cyber Resilience Act; both sets of requirements apply (CRA recital 53)

Is software a safety component?

It can be. Article 3(3) defines a safety component as a physical or digital component, including software, of a product within the scope of the Regulation, designed or intended to fulfil a safety function and independently placed on the market, whose failure or malfunction endangers the safety of persons.

What changes for machinery already sold under the Directive?

Article 52 keeps the market open for it:

  • Products placed on the market in conformity with Directive 2006/42/EC before 20 January 2027 may continue to be made available
  • EC type-examination certificates and approval decisions under Article 12 of the Directive remain valid until they expire
  • Chapter VI on market surveillance applies to those products from 19 July 2023, in place of Article 11 of the Directive

Who is the manufacturer after a modification?

The person who carries out a substantial modification. Article 3(16) defines it as a modification, by physical or digital means, after placing on the market or putting into service, not foreseen or planned by the manufacturer and affecting safety. Under Article 18 that person takes on the manufacturer obligations of Article 10 for the modified product, or for the affected part of an assembly, and applies the relevant conformity assessment procedure.

Can I self-certify?

It depends on Annex I (Art. 25):

  • Not listed in Annex I: internal production control, module A
  • Annex I, Part B: module A only when the product is designed and constructed to harmonised standards or common specifications covering all relevant essential requirements; otherwise EU type-examination with conformity to type, full quality assurance or unit verification
  • Annex I, Part A: always one of those three notified-body routes

Can the instructions be digital?

Yes, under the conditions of Article 10(7):

  • The product, its packaging or an accompanying document says how to access them
  • They can be printed, downloaded and saved, also when embedded in the software
  • They stay online for the expected lifetime and at least 10 years after placing on the market
  • On request at purchase, a paper copy follows free of charge within one month; essential safety information is on paper where non-professional users may use the machine

Start your Machinery Regulation file

Crosswalk maps the Regulation onto your product file next to the CRA and the other laws. The articles are here to read in full.

Still Feeling Overwhelmed?

EU cybersecurity laws can be complex. Our free tools and guides work great for most people, but if you're dealing with something particularly challenging or have tight deadlines, we're here to help.