Machinery Regulation replaces the Machinery Directive: new CE requirements including cybersecurity and software
What changes
Regulation (EU) 2023/1230 applies to all machinery placed on the EU market from 20 January 2027 with no transition. It adds requirements for software safety, protection against malicious tampering, self-evolving (AI) behaviour, digital instructions, and mandatory third-party assessment for certain high-risk machinery categories.
Who is affected
Manufacturers, importers and distributors of machines, robots, lifting equipment, partly completed machinery and safety components (including safety software), of any size.
Sizes: micro, small, medium, large · Sectors: Manufacturing, Hardware / electronics, Construction, Agriculture / food · Applies if: We make connected hardware / devices; We import goods into the EU
What to do
Gap-assess existing machine models against Annex III essential requirements, especially cybersecurity and control-system software. Update technical files, risk assessments and declarations of conformity; check whether your product is in Annex I Part A requiring a notified body. Decide on digital vs paper instructions (paper still on request).
Penalty
Set nationally; non-compliant machinery cannot be placed on the market
Sources
- EU-OSHA – Regulation 2023/1230/EU on machinery (osha.europa.eu)
- Pilz – Machinery Regulation 2027: the most important changes (www.pilz.com)
Last verified 7 September 2026. Informational only, not legal advice.