Skip to content
Zyberum Cyber Security Firm
Menu
GlossaryRegulation

Machinery Regulation (EU) 2023/1230

The Machinery Regulation 2023/1230 replaces the Machinery Directive from 20 January 2027 and adds cybersecurity to machine safety. What Annex III requires.

Updated This page as Markdown

In short

The Machinery Regulation (EU) 2023/1230 replaces Directive 2006/42/EC and applies from 20 January 2027. For the first time it makes protection against corruption and the security of safety-related control systems part of the essential health and safety requirements (Annex III, sections 1.1.9 and 1.2.1). Machine builders must show that a cyberattack cannot create a hazardous situation and must protect safety-relevant software and data.

What is the Machinery Regulation?

The Machinery Regulation (EU) 2023/1230 is the EU product law for machinery, partly completed machinery and related products. It replaces the Machinery Directive 2006/42/EC, entered into force in July 2023 and applies from 20 January 2027. As a regulation it applies directly in every member state without national transposition. The core mechanism stays the same: a manufacturer performs a risk assessment, meets the essential health and safety requirements, draws up a technical file and a declaration of conformity and affixes the CE marking.

What is new for security engineers is that the essential requirements now include cybersecurity. A machine must stay safe when someone attacks its control system, and the manufacturer must be able to show that.

Where is it defined?

The cybersecurity requirements sit in Annex III of the Regulation, the essential health and safety requirements:

  • Section 1.1.9, Protection against corruption: the connection of another device to the machine, over any interface or remotely, must not lead to a hazardous situation. Hardware components that are essential for connectivity or access to software critical for compliance must be protected against accidental or intentional corruption and must collect evidence of a legitimate or illegitimate intervention. Software and data critical for compliance must be identified and protected against corruption, and the machine must be able to identify the safety software loaded on it.
  • Section 1.2.1, Safety and reliability of control systems: control systems must withstand, where appropriate to the circumstances and risks, intended and unintended external influences, including malicious attempts from third parties to create a hazardous situation, and must keep a log of interventions on the safety software.

Presumption of conformity through harmonised standards follows Article 20; the Cyber Resilience Act adds a presumption for sections 1.1.9 and 1.2.1 for products that meet its own essential requirements.

What it means in practice

For a machine builder the Regulation closes a gap: the safety risk assessment asked what fails, not who attacks. From 2027 the question of what an attacker with network access to the PLC, the HMI or the remote maintenance gateway can do becomes part of the CE process. In practice that means:

  • A security risk assessment alongside the safety risk assessment, with the same machine boundaries. For most machines a threat analysis along IEC 62443-3-2 (zones, conduits, target security levels) fits well and produces the documentation the technical file needs.
  • Protected access to the control system: no default passwords on the HMI and PLC, authenticated engineering access, remote maintenance that the operator enables per session, and a firewall or gateway that separates the machine network from the plant network.
  • Integrity of safety software: signed firmware, a verifiable record of what is loaded, and a log of changes that an auditor or an accident investigator can read.
  • Testing: an OT penetration test of a representative machine, done on a test setup or with the operator’s agreement, is the evidence that the measures work.

Zyberum does this work as gap analyses, risk assessments and OT penetration tests. We are not a notified body and do not issue certificates or conformity assessments; those stay with the manufacturer or an appointed body.

Common misunderstandings

The Regulation does not require a specific standard or a specific security level; it requires that the risk assessment addresses attacks and that the measures match the risk. It does not apply retroactively to machines in the field. And it is not replaced by the Cyber Resilience Act: the CRA covers the product with digital elements and its vulnerability handling, the Machinery Regulation covers whether the machine stays safe. Both will usually apply to the same connected machine.

FAQ

Frequently asked questions

Does the Machinery Regulation apply to machines already in service?

No. Like the Directive before it, the Regulation applies to machinery placed on the market or put into service from the date of application, 20 January 2027. Existing machines are not affected until they are substantially modified, which under the Regulation can make the modifier the manufacturer of a new machine. Software changes that alter safety behaviour can count as such a modification.

If my machine complies with the Cyber Resilience Act, is the cybersecurity part done?

Largely. The Cyber Resilience Act contains a presumption of conformity: a product with digital elements that meets the CRA essential requirements and whose EU declaration of conformity says so is presumed to meet Annex III sections 1.1.9 and 1.2.1 of the Machinery Regulation. You still need the safety risk assessment to show that security measures do not interfere with safety functions, and the rest of the Machinery Regulation is untouched.

Is there a harmonised standard for the cybersecurity requirements?

Not yet published. CENELEC is working on EN 50742 (Safety of machinery, protection against corruption) for sections 1.1.9 and 1.2.1. Until it is cited in the Official Journal, manufacturers show compliance with their own risk assessment and the state of the art, for which IEC 62443-3-3 and IEC 62443-4-2 are the usual technical references.

Sources

Related pages

Get started

A term that applies to your product?

In 15 minutes we tell you what it means for you in practice, which requirement follows from it and what the sensible next step is.

  • Direct answer from a security engineer
  • Which standard or law applies to you
  • Free and without obligation
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usAsk a security engineer

Pick a time that suits you

Open in a new tab