Machinery Regulation 2027: Cybersecurity Becomes a Safety Issue
The EU Machinery Regulation 2023/1230 applies from 20 January 2027. What Annex III 1.1.9 and 1.2.1 require, how they relate to the CRA, and what to do now.
Zyberum Security Team · Published · 8 min read
From 20 January 2027 the Machinery Regulation (EU) 2023/1230 applies and replaces the Machinery Directive. For the first time, machinery safety law contains explicit requirements against malicious manipulation: Annex III section 1.1.9 (protection against corruption) and section 1.2.1 (safety and reliability of control systems). If a cyberattack can make your machine unsafe, that is now a non-conformity, and it has to be addressed in the risk assessment and the technical file before CE marking. This is what the two sections require, how they relate to the Cyber Resilience Act and what to do in the time left.
What changes on 20 January 2027
Three things. First, the Directive becomes a Regulation, so the text applies directly in every member state (Article 54). Second, the essential health and safety requirements in Annex III now include cybersecurity. Third, Annex I lists machinery categories for which third-party conformity assessment is mandatory (Part A) or possible (Part B); Part A includes safety components and machinery with fully or partially self-evolving behaviour, in other words machine learning in a safety function.
There is no transition period for machinery placed on the market after that date. A machine delivered on 21 January 2027 must comply.
Annex III 1.1.9: Protection against corruption
In plain language, section 1.1.9 requires five things:
- Connecting another device must not create a hazard. Whether through a physical port or a remote connection, a connected device must not be able to put the machine in a hazardous state.
- Hardware that carries safety-relevant signals or gives access to safety-critical software must be protected against accidental or intentional corruption, and the machine must collect evidence of legitimate or illegitimate interventions in that hardware where relevant.
- Software and data critical for compliance must be identified as such and protected against accidental or intentional corruption.
- The machine must be able to identify the software installed on it that is necessary for safe operation and provide that information at any time in an easily accessible form.
- The machine must collect evidence of interventions in and modifications to the software or its configuration.
Translated into engineering: authenticated access to service and engineering interfaces, integrity protection (secure boot, signed updates, write protection) for the safety PLC and safety-relevant parameters, a software inventory the operator can read out, and an audit log that survives a power cycle.
Annex III 1.2.1: Safety and reliability of control systems
Section 1.2.1 requires that control systems prevent hazardous situations and, among other points, that they withstand intended and unintended external influences including reasonably foreseeable malicious attempts from third parties leading to a hazardous situation, that a fault in hardware or software does not lead to a hazardous situation, and that the tracing log of interventions and of safety software versions uploaded after the machine was placed on the market is kept for five years, exclusively to demonstrate conformity.
“Reasonably foreseeable” is the operative phrase. The risk assessment that already exists for ISO 12100 has to gain a chapter that asks which attacks are plausible for this machine: a maintenance laptop with malware, a remote access gateway with a default password, a manipulated parameter file on a USB stick, a compromised OPC UA client on the plant network.
How it relates to the Cyber Resilience Act
Most machines with network connectivity are also products with digital elements under the Cyber Resilience Act, Regulation (EU) 2024/2847. Recital 53 of the CRA states that such machinery has to meet both sets of requirements. The two laws look at the same machine from different sides:
| Cyber Resilience Act | Machinery Regulation | |
|---|---|---|
| Question | Is the product secure and does the manufacturer handle vulnerabilities? | Can a cyberattack make the machine unsafe? |
| Core text | Annex I Parts I and II | Annex III 1.1.9 and 1.2.1 |
| Deliverables | Risk assessment, SBOM, vulnerability handling, updates, reporting | Machinery risk assessment, technical file, EC declaration |
| Applies | Reporting from 11 September 2026, full from 11 December 2027 | 20 January 2027 |
The work overlaps heavily. The CRA security risk assessment, the integrity protection, the authenticated interfaces, the logging and the secure update process are exactly the controls that 1.1.9 and 1.2.1 ask for. Do the analysis once and reference it from both files. Note that the Machinery Regulation comes first: by January 2027 the safety-relevant subset has to be done, even though the CRA’s full requirements follow in December.
For the presumption of conformity, Article 20 of the Machinery Regulation allows harmonised standards and, in paragraph 9, cybersecurity certificates under the Cybersecurity Act (Regulation (EU) 2019/881) to cover 1.1.9 and 1.2.1 as far as the certificate covers them. A dedicated harmonised standard for these sections is in preparation at CENELEC (prEN 50742); until it is cited in the Official Journal, IEC 62443-4-1 for the development process and IEC 62443-4-2 for component requirements are the practical reference, and they are what notified bodies and customers currently ask for.
What to do before January 2027
- Inventory the digital attack surface of every machine type: field buses, Ethernet ports, remote access, USB, HMI, engineering interfaces, cloud connections.
- Extend the risk assessment with foreseeable malicious attempts for each interface and link each to a safety consequence.
- Protect integrity. Secure boot or signed firmware for controllers, signed updates, write protection for safety parameters, authenticated engineering access.
- Log and identify. A readable software inventory per machine and an audit log of interventions with retention of at least five years for safety software versions.
- Harden the network side. Segmentation per IEC 62443 zones and conduits, no default credentials, remote access only through authenticated gateways.
- Test it. A penetration test of the control system and its interfaces shows whether the measures hold and gives you evidence for the technical file.
- Update the technical file and the user information, including which cybersecurity measures the operator has to maintain.
Zyberum does the risk analysis, the hardening concept and the penetration test of machines and controllers; we are not a notified body and issue no certificates. For the industry view see for machine builders and IEC 62443, or book a free consultation.
FAQ
Frequently asked questions
Does the Machinery Regulation replace the Machinery Directive on 20 January 2027?
Yes. Regulation (EU) 2023/1230 applies from 20 January 2027 (Article 54) and the Machinery Directive 2006/42/EC is repealed from that date. As a regulation it applies directly in every member state without national transposition. Machinery placed on the market from that day has to meet the new essential health and safety requirements, including the cybersecurity-related ones.
If my machine complies with the CRA, is it automatically compliant with the Machinery Regulation?
No. Recital 53 of the CRA says that machinery with digital elements has to meet both the CRA essential cybersecurity requirements and the Machinery Regulation essential health and safety requirements. Much of the work can be reused, the risk assessment, the integrity protection and the update process in particular, but the safety view of Annex III 1.1.9 and 1.2.1 has to be shown in the machinery risk assessment and the technical file.
Do we need a notified body because of cybersecurity?
Only if the machinery is listed in Annex I. For machinery in Part A of Annex I, which includes safety components and machinery with self-evolving behaviour, third-party conformity assessment is mandatory. For everything else the manufacturer assesses conformity internally, and the cybersecurity requirements are part of that assessment. Zyberum is not a notified body; we provide the analyses and tests that go into the technical file.