EU Regulation
Machinery Regulation (EU) 2023/1230
Background
Background
The Machinery Regulation, formally Regulation (EU) 2023/1230, replaces the current Machinery Directive (2006/42/EC) and becomes applicable on 20 January 2027.
The directive has served the EU market since 2006, but technological developments – particularly in artificial intelligence, cybersecurity, and autonomous systems – have made an update necessary. As a regulation, the new legislation applies directly in all member states without national transposition, eliminating the differences in interpretation that arose between countries under the directive.
The Machinery Regulation expands its scope and introduces new essential requirements reflecting the complexity of modern machinery, including cybersecurity requirements and protection against risks from AI-based control systems.
Scope
Who is affected?
The regulation affects manufacturers, importers, distributors, and authorised representatives of machinery and related products. The scope covers:
- Machinery
- Interchangeable equipment
- Safety components
- Lifting accessories
- Chains, ropes, and webbing
- Removable mechanical transmission devices
- Partly completed machinery
Importantly, the regulation also covers substantial modifications to machinery – if a machine is modified in a way that affects its safety, the person carrying out the modification may be considered a manufacturer with full responsibility.
Companies that develop or integrate AI systems into machinery are particularly affected by the new requirements.
Requirements
Key requirements
The central changes compared to the Machinery Directive:
- Cybersecurity: Machinery with digital components must be protected against intentional tampering and unauthorised access. Safety-related control systems must be robust against cyberattacks
- AI and autonomous functions: Machinery with AI-based control systems affecting safety functions must meet specific requirements for transparency, reliability, and human oversight
- Digital instructions: Instructions for use may be provided digitally by default, but a paper copy must be supplied free of charge upon user request
- Updated risk assessment requirements: Risk assessment must cover the entire machine lifecycle, including cybersecurity risks and risks related to AI functions
- Extended third-party review: The high-risk products listed in Annex I require mandatory third-party conformity assessment via a notified body (an independent certification body designated by the member state)
- EU Declaration of Conformity: The declaration must contain expanded information and may be provided digitally
Timeline
Timeline and milestones
- 14 June 2023: The regulation was adopted
- 29 June 2023: Published in the Official Journal of the EU
- 20 January 2027: The Machinery Regulation becomes applicable – the new requirements are fully in force
The Machinery Directive (2006/42/EC) is repealed on the same date. Type-examination certificates and decisions issued under the directive remain valid until they expire, but no later than 20 January 2032.
Compliance
Consequences of non-compliance
Non-compliance means:
- Products may not be placed on the EU market and existing products may be withdrawn
- Member states shall establish penalties that are effective, proportionate, and dissuasive
- Fines and market surveillance measures vary by country but can be significant
- Risk of personal injury liability for accidents caused by non-compliant machinery
- Delayed market access: If certification by a notified body is required (Annex I machinery) and has not been planned in time, launch can be significantly delayed
- Particular risk for AI-integrated machinery: The link to the AI Act means that non-compliance can trigger parallel sanction proceedings
Action plan
What should you do now?
- Map your product portfolio: Identify which products fall under the Machinery Regulation's scope
- Analyse classification: Check whether your products belong to a high-risk category in Annex I requiring third-party assessment
- Update risk assessments: Include cybersecurity and AI risks in existing risk analyses
- Review technical documentation: Ensure documentation covers the new essential requirements
- Plan certification: If third-party assessment is required, contact notified bodies well in advance – capacity may be limited close to the transition date
- Prepare digital instructions: Ensure instructions for use can be delivered digitally while maintaining accessibility
- Train relevant teams: Ensure designers, compliance officers, and product managers are aware of the new requirements
Verca
How Verca helps
Verca supports the transition from the Machinery Directive to the Machinery Regulation by updating its classification logic as the new requirements come into force.
The platform automatically identifies whether your products fall under high-risk categories requiring third-party assessment and guides you through the expanded documentation requirements – including cybersecurity and AI aspects.
Verca's risk assessment workflow adapts to the Machinery Regulation's extended requirement scope, and you receive notifications when harmonised standards are updated or replaced. Technical documentation and the EU Declaration of Conformity are generated based on the new template requirements.