Machinery Regulation 2023/1230: Transition Guide for Manufacturers
The Machinery Directive that has governed EU machinery safety since 2006 is being replaced by a Regulation — with expanded high-risk categories, explicit cybersecurity requirements, and rules built for AI-enabled and connected machinery. Here's what changes and how to prepare.
Key Dates
| Date | Milestone |
|---|---|
| 14 June 2023 | Regulation (EU) 2023/1230 formally adopted |
| 29 June 2023 | Published in the Official Journal of the EU |
| 20 July 2023 | Entered into force |
| 20 January 2027 | Full application date — Machinery Directive 2006/42/EC repealed |
What Changes: Directive vs Regulation
| Machinery Directive 2006/42/EC (until 20 Jan 2027) | Machinery Regulation (EU) 2023/1230 (from 20 Jan 2027) | |
|---|---|---|
| Legal form | Directive — national transposition | Regulation — directly applicable |
| High-risk category list | Annex IV — fixed list | Annex I — expanded, includes AI/software safety functions |
| Cybersecurity | Not addressed | Explicit essential requirement |
| Instructions/DoC format | Paper by default | Digital format explicitly permitted |
| Software as safety component | Ambiguous treatment | Explicitly in scope, including post-market software updates |
| Substantial modification | Case-law/guidance based | Formally defined criteria |
Expanded High-Risk Machinery (New Annex I)
The new Annex I list of machinery requiring mandatory third-party (Notified Body) assessment is broader than the old Annex IV. It now explicitly includes:
- Machinery with fully or partially self-evolving behaviour using AI systems that ensure safety functions
- Certain machinery intended for use by consumers where an AI system ensures safety functions
- Machinery designed to remove biological hazards (e.g. certain sanitisation/disinfection machinery)
- The previously covered high-risk categories from the old Annex IV (certain woodworking machines, presses, injection/compression moulding machines, underground machinery, lifting equipment for persons, etc.), largely carried forward
Manufacturers whose products self-certified under the old Directive should specifically re-check whether embedded AI, autonomous decision-making, or software-driven safety functions now place their machinery in the expanded Annex I — self-declaration may no longer be sufficient.
Cybersecurity as an Essential Requirement
For the first time, machinery essential health and safety requirements explicitly address protection against corruption. Where a machine's safety function depends on a connected or digital system, the manufacturer must design it so that a cybersecurity compromise — malicious or accidental — cannot create a hazardous situation. This overlaps with, but is legally distinct from, obligations under the EU Cyber Resilience Act for products with digital elements; machinery manufacturers with connected products may need to satisfy both frameworks.
Digital Instructions and Declaration of Conformity
The Regulation explicitly permits digital-only instructions for use and a digital EU Declaration of Conformity, provided:
- The machinery (or accompanying material) clearly indicates how to access the digital version
- A free paper copy is provided within 15 days if requested by the purchaser at the time of purchase
- Safety-critical warnings that must be understood before first use may still need to be provided in paper form, depending on risk assessment
Software Updates and Substantial Modification
The Regulation formally addresses when a change to machinery — including a software update — counts as a "substantial modification" requiring a new conformity assessment. Broadly: a modification that was not foreseen or anticipated by the original manufacturer's risk assessment, and that creates a new hazard or increases an existing risk, is substantial and triggers new obligations (potentially for the party making the modification, not just the original manufacturer). This matters increasingly for machinery that receives remote/OTA software updates after being placed on the market.
Transitional Provisions
Machinery lawfully placed on the market under the Machinery Directive before 20 January 2027 can generally continue to be made available and put into service under the old rules, provided its design and intended use remain unchanged. Manufacturers should not wait until the application date to act — Notified Body capacity for the new Annex I categories is expected to be constrained in the run-up to 2027, mirroring the capacity pressure seen with MDR.
Preparing for the Transition
- Gap-check against the new Annex I — does your machinery now require third-party assessment where it didn't before?
- Review connected/software-driven safety functions against the new cybersecurity requirement
- Decide on documentation format — digital instructions can reduce printing/localisation costs but require an access mechanism
- Engage a Notified Body early if your product falls into an expanded high-risk category, given expected capacity constraints closer to 2027
- Review your substantial-modification policy for products that receive post-market software updates
Frequently Asked Questions
Ready to Start?
What changes under the new EU Machinery Regulation (EU) 2023/1230: expanded high-risk categories, cybersecurity requirements, digital instructions, and how to prepare before the 20 January 2027 application date.
Search Testing Labs Free →