The Machinery Regulation (EU) 2023/1230 replaces the long-standing Machinery Directive 2006/42/EC and, from 20 January 2027, becomes the reference text for placing a machine on the European market. The change is not only one of form — from directive to regulation — but of substance: for the first time, machinery safety includes explicit requirements on cybersecurity and on artificial intelligence. Those who design and build machines therefore encounter, within the same CE marking, topics until now foreign to mechanical safety, and have to coordinate them with rules that operate on different levels: IEC 62443, the CRA, NIS2. This guide gathers what the official sources provide on what changes, on the new essential requirements and on the supporting standards, and on how the Regulation sits alongside the other obligations.
This guide reports the framework of Regulation (EU) 2023/1230 and its relationship with Directive 2006/42/EC, with references to the relevant annexes and sections. Some references, in particular the supporting technical standards, are to documents still under development, and any updates published after this guide should be verified before formal use.
From the Directive to the Regulation: what changes
The Machinery Directive 2006/42/EC has been, for almost twenty years, the basis of CE marking for machinery in Europe. Regulation (EU) 2023/1230 repeals and replaces it. Three differences matter more than the others.
From directive to regulation. A directive sets common objectives but requires a national transposing law in each Member State, with the risk of divergent application. A regulation is directly applicable and identical in all Member States: the transposition step disappears and fragmentation between legal systems is reduced. It is the same logic that led the European legislator to choose the form of a regulation for the CRA (Cyber Resilience Act) and the AI Act as well.
The essential requirements move annex. The essential health and safety requirements (EHSRs) — the technical core that every machine must meet — move from Annex I of the old Directive to Annex III of the Regulation. Anyone who knows the numbering of 2006/42/EC by heart has to redraw the map.
The digital topics appear. Annex III introduces requirements on protection against corruption (tampering) and on the safety of control systems that explicitly address the cyber dimension; and Annex I brings among the “high-risk” machinery — subject to conformity assessment by a notified body — some categories linked to artificial intelligence. These are the two new blocks covered in the sections that follow.
What remains are the pillars of always: risk analysis and reduction, the technical file, the EU declaration of conformity, CE marking, instructions for use.
The dates
Regulation (EU) 2023/1230 is dated 14 June 2023, published in the Official Journal of the European Union on 29 June 2023 and entered into force twenty days later. The date that matters operationally, however, is another: the Regulation applies from 20 January 2027. From that day Directive 2006/42/EC is repealed and new machines placed on the market must comply with the Regulation.
There is no long transitional regime like that of other rules: the date is single for machinery in general. Machines already placed on the market before that date do not have to be requalified merely because of the change of rule, but every new placing on the market from 20 January 2027 follows the Regulation. It is a near horizon for those designing today machines with a multi-year development cycle: conformity must be thought through from the earliest design stages.
The new digital EHSRs: cybersecurity
The most discussed novelty is that the Regulation brings, for the first time explicitly, requirements of a cyber nature into machinery safety. It is not a general cybersecurity discipline — that is the CRA — but a targeted set of requirements where information security affects physical safety, that is, where cybersecurity and safety meet: the tampering that generates a hazard to people. Two sections of Annex III are central.
Protection against corruption (Annex III, 1.1.9). The machine must be designed and constructed so that the connection to another device, of any kind, does not lead to a hazardous situation because of a corruption — accidental or intentional — of hardware or software components, or of data, relevant to safety. The requirement asks, in substance, that tampering (including malicious tampering by third parties) cannot translate into hazardous behaviour of the machine, and that there is evidence of legitimate or illegitimate intervention on the components critical to safety.
Safety and reliability of control systems (Annex III, 1.2.1). Control systems must be designed and constructed so as to prevent hazardous situations from arising. In particular, they must withstand the intended effects of a corruption, and the software and data critical for compliance with safety must be identified as such and adequately protected against accidental or intentional corruption.
The scope must be read precisely: it is not about protecting the confidentiality of data or the continuity of service in a broad sense, but about preventing an alteration of the components or the data relevant to safety from producing physical harm. It is cybersecurity in the service of safety, and it is this that distinguishes it, despite evident overlaps, from the object of the CRA and from industrial security frameworks.
The new EHSRs: artificial intelligence and evolving behaviour
The second new block concerns machines that integrate systems with evolving behaviour or based on machine learning. The Regulation does not ban AI in machines: it brings it inside the perimeter of conformity assessment and imposes specific safety requirements on it.
Entering the list of high-risk machinery. Annex I lists the categories of machinery and related products subject to an enhanced conformity assessment procedure, with the mandatory involvement of a notified body (EU type-examination or full quality assurance). Among these categories now appear safety components integrating systems with fully or partially self-evolving behaviour using machine-learning approaches and ensuring safety functions, and the machines that incorporate such components. In practice, when AI performs a safety function and can evolve its own behaviour, the manufacturer can no longer certify it on its own: a notified body is required.
The requirements on evolving behaviour. Consistently, the essential requirements of Annex III require that, where a machine has evolving behaviour or logic that adapts over time, such evolution must not generate hazardous situations: the limits of safe operation must be maintained even while the system learns or adapts, the machine must be able to be monitored and, if necessary, corrected, and the decision-making logic relevant to safety must remain traceable. It is the translation, into safety language, of the underlying problem of AI in functional safety: a system that changes behaviour over time undermines the assumption — on which the classic functional-safety standards rest — of behaviour that is predictable and verifiable once and for all.
Author’s note. Here the Machinery Regulation touches the same object as the AI Act, but from a different angle. The AI Act qualifies as “high-risk” the AI systems that are safety components of products already subject to harmonisation legislation, and machinery is the textbook example. The result is that a safety function entrusted to machine learning can fall, together, under the Machinery Regulation and under the AI Act. They should not be read as alternatives: they are two lenses on the same component. It is worth mapping their requirements in parallel, from the design stage, in a unified way.
The supporting technical standards
The essential requirements say what to achieve, not how. The “how” is provided by the technical standards: when a standard is harmonised (cited in a list published by the Commission), applying it gives presumption of conformity with the essential requirement it covers. Two standards deserve attention because they are born precisely for the new digital EHSRs.
EN 50742 — protection against corruption. The standard EN 50742 (“Safety of machinery — Protection against corruption”), to date still at draft stage (prEN 50742), is a candidate to become the harmonised reference standard for requirement 1.1.9 of Annex III. It provides requirements and recommendations to prevent accidental and intentional corruption of machines — including malicious tampering by third parties that results in a hazardous situation — applying to hardware components (including interfaces to remote devices and control systems able to transmit signals or data) and to software and data when they can affect safety. Two clarifications: the standard does not cover the safety of control systems as such (requirement 1.2.1 remains the object of other standards), and its scope overlaps with the domain of cybersecurity without coinciding with it — it is protection against corruption in the service of safety, not information security across the board.
To reach conformity with requirement 1.1.9, the standard provides two alternative routes:
- Approach A — based on risk assessment, intended for machines not originally designed according to the criteria of IEC 62443 (clauses 5 and 7).
- Approach B — based on the targeted adoption of the requirements of the IEC 62443 series, adapted to the machinery sector (clauses 6 and 8).
The choice is not indifferent: those already working along IEC 62443 lines find in Approach B a direct route, while those starting from a “traditional” machine can move from Approach A without first adopting the whole framework of 62443.
ISO/IEC TS 22440 — functional safety and AI systems. The technical specification ISO/IEC TS 22440 (“Artificial intelligence — Functional safety and AI systems”), arranged in several parts (Part 1 – Requirements, Part 2 – Guidance, Part 3 – Examples of application), is the first international reference designed for the functional safety of AI-based systems in the industrial domain. It addresses the knot that the classic functional-safety standards (such as IEC 61508) were not born to handle: the non-deterministic and adaptive nature of AI, behaviour that evolves over time, decisions that are hard to trace. It offers a methodology to analyse, assess and mitigate the risks linked to AI when it enters a safety function: exactly the scenario that the Machinery Regulation brings into the list of high-risk machinery.
Neither of the two, as at the date of this guide, is yet published as a harmonised standard in the official list of the Regulation: they should be regarded as technical references still maturing, useful for setting up the work but to be verified as to their publication status before invoking presumption of conformity.
The Machinery Regulation and IEC 62443
The IEC 62443 series is the reference framework for the cybersecurity of industrial automation and control systems (IACS): it covers the secure development processes (62443-4-1) and the technical requirements of components (62443-4-2), besides the system and organisational aspects. In relation to the Machinery Regulation, a clear distinction and, together, a practical bridge should be kept.
The distinction: 62443 is industrial cybersecurity across the board — confidentiality, integrity, availability, defence in depth — whereas EHSRs 1.1.9 and 1.2.1 look at only the portion where information security affects physical safety. Applying 62443 does not, in itself, amount to meeting the requirements of the Regulation, and vice versa.
The bridge, today, is explicit inside EN 50742 itself. Its Approach B to conformity with requirement 1.1.9 consists precisely of adopting the requirements of the IEC 62443 series, adapted to the machinery sector (vulnerability management, access control, integrity of software and data, protection of interfaces): for a manufacturer already working along 62443 lines (often because it serves OT customers or is preparing for the CRA), that work is not merely “reusable evidence”, but the main road towards presumption of conformity. There remains, however, a clarification of roles: the harmonised standard that gives presumption of conformity is EN 50742, not 62443 as such; 62443 is the technical substrate on which one of EN 50742’s two routes rests. Those starting from a machine not designed according to 62443 can instead follow Approach A, based on risk assessment, without having to adopt the whole framework.
The Machinery Regulation and the CRA
The Machinery Regulation and the Cyber Resilience Act (Regulation (EU) 2024/2847) apply in parallel. A modern machine with digital elements and data connections (for example a controller, a communication module) is typically a “product with digital elements” within the meaning of the CRA and, together, a machine within the meaning of Regulation 2023/1230. The manufacturer does not choose one of the two: it satisfies both, and the EU declaration of conformity cites both together with the standards applied.
The point of coordination is the overlap on cyber requirements. According to the reading of the relationship between the two acts, compliance with the cybersecurity requirements of the CRA may cover the safety requirements of points 1.1.9 and 1.2.1 of Annex III to the Machinery Regulation, provided the manufacturer demonstrates it: where the two acts address similar risks, the work done for the CRA facilitates compliance with the Machinery Regulation, avoiding duplication. A distinction of purpose remains, not to be lost: the CRA looks at the cyber resilience of the product as a whole (integrity, confidentiality, vulnerability management for the whole useful life), the Machinery Regulation at only the tampering that generates a physical hazard.
For the framework of the CRA’s deadlines and obligations, the reference guide is The CRA in one hour; for the calendar, The CRA deadlines.
The Machinery Regulation and NIS2
The relationship with NIS2 is one of level, not of direct overlap. The Machinery Regulation, the CRA and IEC 62443 are product rules and standards: they say how the machine must be made. NIS2 is an organisational rule: it requires a broad audience of companies to manage cyber risk, to make top management accountable for it and to notify significant incidents. A machine builder meets them as two different things: as a manufacturer it must bring the product into conformity (Machinery Regulation + CRA); as a company, if it falls within scope — and the manufacture of machinery and equipment is among the sectors of Annex II — it must structure itself as a NIS2 entity.
The two levels touch in practice: the measures on secure development, vulnerability management and supply-chain security required by NIS2 (Article 21) are largely the same as those needed to build products compliant with the cyber requirements of the Machinery Regulation and the CRA.
For the scope, deadlines and requirements of NIS2 and its Italian transposition, the guide is NIS2: what it is, who it applies to, deadlines and requirements; for the case of those who are both a manufacturer and a company in scope, You are a manufacturer subject to the CRA. Does NIS2 also concern you as a company?.
In short
- Regulation (EU) 2023/1230 replaces Directive 2006/42/EC and applies from 20 January 2027; being a regulation, it is directly applicable without national transposition.
- The essential requirements move to Annex III and include, for the first time, the digital dimension: protection against corruption (1.1.9) and safety of control systems (1.2.1).
- Machines with AI of evolving behaviour ensuring safety functions enter the high-risk machinery of Annex I, with conformity assessment by a notified body.
- The supporting technical standards are EN 50742 (protection against corruption, harmonised candidate, still in draft, with two conformity routes: risk assessment or adoption of IEC 62443) and ISO/IEC TS 22440 (functional safety of AI systems); IEC 62443 is the industrial-security substrate on which EN 50742’s Approach B rests.
- The CRA and the Machinery Regulation apply in parallel and coordinate on cyber requirements; NIS2 operates on a different level — the organisation, not the product.
References (official sources)
EU legislation:
- Regulation (EU) 2023/1230 of 14 June 2023 on machinery, repealing the Machinery Directive (in particular: application from 20 January 2027, Annex I on high-risk categories, Annex III on the essential health and safety requirements, sections 1.1.9 and 1.2.1)
- Directive 2006/42/EC (Machinery Directive, repealed from 20 January 2027)
- Regulation (EU) 2024/2847 (Cyber Resilience Act)
- Directive (EU) 2022/2555 (NIS2)
Technical standards:
- prEN 50742 “Safety of machinery — Protection against corruption” (CENELEC/TC 44X; draft, not yet published as a harmonised standard — official catalogue at standards.cencenelec.eu)
- ISO/IEC TS 22440-1 “Artificial intelligence — Functional safety and AI systems — Part 1: Requirements” (and Parts 2–3, under development)
- IEC 62443-4-1 (secure product development) and IEC 62443-4-2 (technical component requirements), IEC 62443 series
The dates of the Regulation and the sections of Annex III are verified against the structure of the text; the section and clause numbers, the publication status of the technical standards and their possible harmonisation should be confirmed against the act and the Commission’s official list before formal use. The EUR-Lex links point to the consolidated/in-force version of the act.