Compliance guide

MR

Six steps to conformity with the Machinery Regulation

From deciding what falls in scope to keeping conformity after the product is on the market. Each step names the articles that require it; the text itself is one click away.

Applies from 20 January 2027 (Art. 54). Products placed under Directive 2006/42/EC before that date may continue to be made available (Art. 52).

The steps

What the Regulation asks of a manufacturer

The same six steps as on the overview page, spelled out. Importers and distributors check that the manufacturer did them (Art. 13 to 16); whoever substantially modifies a machine does them again for the modified part (Art. 18).

  1. 1

    Establish scope and category

    Decide which of your products fall under the Regulation and which conformity route applies to each

    • List machinery, related products and partly completed machinery you place on the market or put into service (Art. 2(1))
    • Check the exclusions of Art. 2(2), for example fairground equipment, weapons and means of transport
    • Check Annex I: Part A needs a notified body, Part B allows internal control only with full standards coverage (Art. 6, Art. 25)
    • Decide whether a change to an existing product is a substantial modification that makes you the manufacturer (Art. 3(16), Art. 18)

    Art. 2 (scope), Art. 3 (definitions), Art. 6 and Annex I (categories), Art. 18 (substantial modification)

    Note. Software that fulfils a safety function and is sold separately is a safety component in its own right (Art. 3(3)).

  2. 2

    Assess the risks and meet Annex III

    Run the risk assessment the Regulation requires and design out the hazards, including the digital ones

    • Carry out and document the risk assessment following the general principles of Annex III
    • Apply the essential health and safety requirements that follow from that assessment (Art. 10(1), Annex III)
    • Design connections and remote access so they cannot lead to a hazardous situation; protect and identify safety-critical software and data; collect evidence of interventions (Annex III, 1.1.9)
    • Design control systems that withstand reasonably foreseeable malicious attempts and whose faults or logic errors do not lead to hazardous situations (Annex III, 1.2.1)

    Art. 8 and 10(1), Annex III (general principles, 1.1.9 protection against corruption, 1.2.1 safety and reliability of control systems)

    Note. Where machinery is also a product with digital elements, the Cyber Resilience Act applies as well; its recital 53 notes that meeting its cybersecurity requirements can facilitate meeting the Machinery Regulation requirements that cover similar risks.

  3. 3

    Draw up the technical documentation

    Annex IV lists what the file must contain before you place the product on the market

    • Describe the product and its intended use (Annex IV, Part A(a))
    • Include the risk assessment documentation with the list of applicable essential requirements (Annex IV, Part A(b))
    • Keep the documentation and the EU declaration of conformity available for at least 10 years (Art. 10(3))
    • Be ready to provide source code or programming logic on a reasoned request when it is needed to check compliance (Art. 10(3))

    Art. 10(2) and (3), Art. 11(2), Annex IV

    Note. Build the file while designing. A file assembled afterwards rarely shows the reasoning the risk assessment requires.

  4. 4

    Run the conformity assessment procedure

    Internal production control, or one of the notified-body modules, depending on Annex I

    • Outside Annex I: internal production control, module A (Art. 25(4), Annex VI)
    • Annex I, Part B: module A only when designed fully to harmonised standards or common specifications; otherwise module B with C, module H or module G (Art. 25(3))
    • Annex I, Part A: EU type-examination (module B, Annex VII) with conformity to type (module C, Annex VIII), full quality assurance (module H, Annex IX) or unit verification (module G, Annex X) (Art. 25(2))
    • Choose a notified body where required (Art. 26 to 42)

    Art. 25, Art. 26 to 42 (notified bodies), Annexes VI to X

    Note. Notified bodies must take the interests and needs of small and medium-sized enterprises into account when setting fees (Art. 25(5)).

  5. 5

    Declare, mark and inform

    EU declaration of conformity, CE marking, identification, contact details and instructions

    • Draw up the EU declaration of conformity per Annex V, Part A, keep it updated and translated as required (Art. 21)
    • Affix the CE marking visibly, legibly and indelibly before placing on the market or putting into service (Art. 24)
    • Mark model, series or type, year of construction and serial or batch identification, and your name and contact details (Art. 10(5) and (6))
    • Supply the instructions and Annex III information, digital where allowed, with the safety information for non-professional users on paper (Art. 10(7))

    Art. 10(5) to (8), Art. 21, Art. 23 and 24, Annex III section 1.7.4, Annex V

    Note. The declaration must be continuously updated (Art. 21(2)): a software change that affects safety usually means a new version of the declaration.

  6. 6

    Keep conformity after placing on the market

    Series production, complaints, corrective action and cooperation with market surveillance

    • Keep procedures so series production stays in conformity, including after changes in design, production or standards (Art. 10(4))
    • Sample-test and investigate where the risks warrant it; keep a register of complaints, non-conforming products and recalls (Art. 10(4))
    • Take corrective action, withdraw or recall when a product is not in conformity, and inform the national authorities where it presents a risk (Art. 10(9))
    • Provide information and documentation on a reasoned request and cooperate on risk-eliminating actions (Art. 10(10))

    Art. 10(4), (9) and (10), Art. 43 to 46, Art. 52

    Note. A substantial modification after placing on the market, including by digital means, restarts the obligations for the person who makes it (Art. 18).

Why this is a cyber law

Two sections of Annex III

The Directive did not have them. The Regulation requires that connections cannot create a hazardous situation, that safety-critical software and data are protected, and that control systems withstand malicious attempts.

Annex III, section 1.1.9

Protection against corruption

The machinery or related product shall be designed and constructed so that the connection to it of another device, via any feature of the connected device itself or via any remote device that communicates with the machinery or related product does not lead to a hazardous situation.
  • Hardware transmitting signals or data that is relevant for connection or access to safety-critical software is protected against accidental or intentional corruption.
  • The machinery collects evidence of a legitimate or illegitimate intervention in that hardware.
  • Software and data critical for compliance are identified as such and protected.

Annex III, section 1.2.1

Safety and reliability of control systems

they can withstand, where appropriate to the circumstances and the risks, the intended operating stresses and intended and unintended external influences, including reasonably foreseeable malicious attempts from third parties leading to a hazardous situation;
  • A fault in the hardware or the logic of the control system does not lead to hazardous situations.
  • Errors in the control system logic do not lead to hazardous situations.
  • The limits of the safety functions are set in the risk assessment; no modifications to settings or rules, including during a learning phase, where they could be hazardous.

Related law. Machinery with digital elements also falls under the Cyber Resilience Act; its recital 53 notes that meeting the CRA's cybersecurity requirements can facilitate meeting the Machinery Regulation requirements that cover similar risks. A certificate under a cybersecurity certification scheme of Regulation (EU) 2019/881 gives presumption of conformity with sections 1.1.9 and 1.2.1 insofar as it covers them (Art. 20(9)).

Assess the Regulation next to the CRA

Crosswalk puts the Machinery Regulation, the CRA and the other laws in one file: the article beside each control, evidence per requirement, to-dos with owners.

Still Feeling Overwhelmed?

EU cybersecurity laws can be complex. Our free tools and guides work great for most people, but if you're dealing with something particularly challenging or have tight deadlines, we're here to help.