MR

Machinery Regulation: penalties and enforcement

The Regulation itself sets no fine amounts. Each Member State lays down the penalties for infringements by economic operators; they must be effective, proportionate and dissuasive and may include criminal penalties for serious infringements (Art. 50). Enforcement runs through market surveillance under Chapter VI: corrective measures, withdrawal, recall and the Union safeguard procedure (Art. 43 to 46).

Member States notify their penalty rules by 20 October 2026 (Art. 50(2)); the Regulation applies from 20 January 2027
Art. 50 Penalties are national: effective, proportionate and dissuasive
20 Oct 2026 Member States notify their penalty rules (Art. 50(2))
Chapter VI Market surveillance and safeguard procedures (Art. 43 to 46)

No EU-wide fine amounts

Unlike the Cyber Resilience Act or the GDPR, the Machinery Regulation does not set maximum fines. The amounts and the kind of penalty follow from the national law of each Member State (Art. 50(1)).

This site does not list national penalty amounts. Check the law of the Member State where you place the product on the market or put it into service.

What enforcement looks like

Market surveillance authorities that have sufficient reason to believe a product presents a risk evaluate it against the Regulation and, where it does not comply, require the economic operator to take corrective measures, to withdraw it or to recall it (Art. 43). Where a product complies with Annex III but still presents a risk, the authority can require measures, withdrawal or recall all the same (Art. 45). Formal non-compliance, such as a missing or wrongly affixed CE marking, a missing notified-body number, an absent or incorrect EU declaration of conformity, incomplete technical documentation or missing identification and contact details, must be ended; if it persists, the product is restricted, withdrawn or recalled (Art. 46). Where Member States disagree about a national measure, the Union safeguard procedure decides (Art. 44). Chapter VI applies from 19 July 2023, also to products placed on the market under the Directive (Art. 52(1)).

Why MR Compliance Matters for Your Business

Beyond avoiding penalties, MR compliance represents a strategic advantage. Companies that implement security by design reduce their risk of costly breaches, build customer trust, and gain competitive differentiation in an increasingly security-conscious market.

Risk Reduction
Proactive compliance reduces the risk of costly breaches and enforcement actions
Market Access
Compliance is a prerequisite for placing products and services on the EU market
Customer Trust
Demonstrable compliance builds confidence with customers and partners

What MR Actually Requires You to Do

The MR establishes essential cybersecurity requirements that apply throughout your product's lifecycle. These aren't just theoretical guidelines—they're practical obligations with legal consequences.

Think of it this way: Just as you need safety standards for physical products (crash tests for cars, fire safety for electronics), the MR creates mandatory security standards for digital products. Every requirement serves a specific purpose in protecting end users and the broader digital ecosystem.

Core Requirement 1

Penalties set nationally

Article 50

This means integrating security considerations from the very first design sketches. No more 'we'll add security later'—it must be part of your core product development process from day one.

Specific Requirements:

• Rules laid down by each Member State
• Effective, proportionate and dissuasive
• May include criminal penalties for serious infringements
• Notified to the Commission by 20 October 2026

Practical Tip:

Start by conducting threat modeling sessions during your product planning phase. Many teams find Microsoft's STRIDE methodology helpful for systematic threat identification.

Core Requirement 2

Products presenting a risk

Articles 43 and 45

You must establish a coordinated vulnerability disclosure process, maintain security throughout the product lifecycle, and respond quickly to security issues. This isn't just about fixing bugs—it's about professional incident response.

Specific Requirements:

• Evaluation by the market surveillance authority
• Corrective measures, withdrawal or recall required
• Also for compliant products that still present a risk
• Union safeguard procedure on disagreement (Art. 44)

Practical Tip:

Set up a [email protected] email address and establish SLAs for response times. Consider partnering with vulnerability disclosure platforms like HackerOne or Bugcrowd.

Core Requirement 3

Formal non-compliance

Article 46

Clear, accessible documentation helps users understand security features and configure products safely. This reduces support calls and prevents security misconfigurations that could lead to breaches.

Specific Requirements:

• CE marking missing or wrongly affixed
• Notified-body number missing
• Declaration absent or incorrect, documentation incomplete
• Identification or contact details absent, false or incomplete

Practical Tip:

Create user-friendly security guides alongside your regular documentation. Include clear setup instructions, common security mistakes to avoid, and troubleshooting guidance.

The Bottom Line

MR requirements aren't just compliance checkboxes—they represent cybersecurity best practices that protect your customers, your business, and the broader digital ecosystem. Companies that implement these requirements early often find they reduce long-term security costs while building stronger, more trustworthy products.

Free MR Compliance Tools

Get started with our comprehensive toolkit designed to simplify your compliance journey. Each tool is built by experts and validated against official requirements.

Common MR Questions

How high are the fines under the Machinery Regulation?

The Regulation does not say. Article 50 leaves the rules on penalties to the Member States and requires them to be effective, proportionate and dissuasive; they may include criminal penalties for serious infringements. Member States notify their rules to the Commission by 20 October 2026.

Can a product that complies with Annex III still be withdrawn?

Yes. Under Article 45, where a Member State finds that a compliant product nevertheless presents a risk to the health or safety of persons, or where appropriate to domestic animals, property or the environment, it requires the economic operator to take measures so that the product no longer presents that risk, to withdraw it or to recall it.

Do the market surveillance rules apply before 20 January 2027?

Yes. Chapter VI applies from 19 July 2023, also to products placed on the market under Directive 2006/42/EC, in place of Article 11 of that Directive (Art. 52(1)).

What counts as formal non-compliance?

Article 46 lists it: the CE marking affixed in violation of the rules or not affixed, the notified-body identification number missing or wrongly affixed, the EU declaration of conformity not drawn up or not drawn up correctly, the technical documentation not available or not complete, the identification and contact information absent, false or incomplete, or any other administrative requirement of Articles 10 or 13 not fulfilled.

Keep the evidence ready

A complete technical file and an up-to-date declaration are the first things an authority asks for. Crosswalk keeps them per requirement, with the article beside each.

Still Feeling Overwhelmed?

EU cybersecurity laws can be complex. Our free tools and guides work great for most people, but if you're dealing with something particularly challenging or have tight deadlines, we're here to help.