
Regulations
Machinery safety in 2027: key changes and deadlines
Machinery Regulation, Cyber Resilience Act, digital documentation and technical standards: the key 2027 deadlines and an operational plan to prepare.
2027 will be a pivotal year for machinery safety. Regulation (EU) 2023/1230 will apply from 20 January, and the main Cyber Resilience Act obligations will apply from December to many products with digital elements. For anyone who designs, manufactures, integrates or modifies machinery, simply changing the legislative reference in the declaration of conformity will not be enough.
In recent years we have seen machines become increasingly connected, up-to-date and dependent on software. The new European framework starts from this reality: safety is no longer only about guards, distances and emergency stops, but also data, remote access, software versions, digital changes and traceability of technical decisions.
At a glance
- From 20 January 2027 Machinery Regulation (EU) 2023/1230 will replace Directive 2006/42/EC.
- Cybersecurity, safety-related software and digital changes will become more explicit in risk assessment.
- instructions for use and declarations may be digital, but they must comply with precise conditions of accessibility and conservation.
- From 11 December 2027, the Cyber Resilience Act will apply to products with digital elements that fall within its scope.
- The revision of ISO 12100 is in development: it must be monitored, but 2010 edition remains the reference published today.

20 January 2027: changes the reference for new machines
The first date to be fixed is 20 January 2027. From that day Regulation (EU) 2023/1230 will be applicable and Machinery Directive 2006/42/EC will be repealed. The Regulation will be directly applicable in all Member States, without passing through a national law of transposition. Reference
For machines already placed on the market before that date there is no general obligation to recertificate. The critical point relates to placing new products on the market and machines subjected to significant changes. For this it is necessary to establish in advance what orders, series and configurations will pass through the pass date.
The transition is not resolved by replacing a line in the documents. We need to reread risk analysis, applicable requirements, tests, instructions for use, EU declaration of conformity and internal procedures. We have collected the route in a practical guide to prepare for the Machinery Regulation. Reference
The novelties that really affect the design
Cybersecurity connected to safety
Annex III introduces specific requirements against accidental or intentional corruption of hardware, software and data relevant to safety. A remote connection, an update or change of parameters should not bring the machine into a dangerous situation. The manufacturer will have to identify the software necessary for safe operation and retain evidence to demonstrate compliance.
This changes the way to build the technical file: it is no longer enough to indicate that the network is protected. We need to link threats, safety functions, measures taken, access management and version control. prEN 50742 project on protection against corruption shows the technical direction well. Reference
Software and Evolutionary behaviour
The Regulation expressly considers software that performs safety functions and components with totally or partially self-evolving behaviour. When a software decision can affect safety, the assessment must include limits, operating conditions, recorded data and reasonably foreseeable behaviour of the machine.
Substantial changes also digital
A physical or digital change after placing on the market may be substantial if it was not provided by the manufacturer, creates a new danger or increases an existing risk and requires new significant protection measures. In that case, those who make the change can assume the obligations of the manufacturer.
Retrofit, revamping, increased performance, new PLC logic, remote access and integration of robots or lines must therefore be evaluated before the operation. In the analysis of the substantial modification of a machine we have collected practical criteria and examples. Reference
Digital instructions for use, but with precise rules
Instructions can be provided in digital format, provided they are accessible, downloadable, printable and available online for the waiting life of the machine and however for at least ten years. If the user requires the paper format at the time of purchase, the manufacturer must provide it free of charge within one month. For machines also intended for non-professional users, the essential safety information must accompany the product in paper format.
Conformity procedures and high-risk machines
Annex I distinguishes the categories subject to stricter procedures. The internal control of production is not sufficient for the products of Part A: a notified body or a quality guarantee system is required in accordance with the required forms. For Part B, the use of internal control also depends on the full coverage offered by the applicable harmonised standards.
11 December 2027: the Cyber Resilience Act enters the system
The second decisive step will come on 11 December 2027, when the Cyber Resilience Act, Regulation (EU) 2024/2847 will become applicable. The CRA covers products with digital elements that fall within its scope and can therefore also affect connected machines, components and software. Reference
The two disciplines do not replace. A machine with digital elements can have to demonstrate both the conformity to the Machinery Regulation and the CRA. The evaluation will cover product safety, vulnerability management, updates, support period and information provided to the user. The reporting obligations of exploited vulnerabilities and serious accidents provided for in Article 14 of CRA are already applicable from September 11 2026.
Our technical FAQ on the Cyber Resilience Act is available to navigate between scope, deadlines and relationship with the Machinery Regulation. Reference
Technical standards: what to monitor in 2027
The legislative change will also require attention to harmonised standards. The old list used for the Directive should not be copied automatically in the dossier: the reference of the standard in the Official Journal of the European Union must be verified with respect to the new Regulation and the requirements actually covered.
In the meantime the revision of ISO 12100. L edition 2010 is under development and is now published and confirmed, while the new project will have to complete its iter before becoming the definitive reference. 2027 will therefore be a year in which to monitor both new publications and their European transposition, avoiding to confuse a draft standard with an already applicable standard.
Also standard already updated, such as EN ISO 13849-1:2023 and EN ISO 13855:2024, are to be read in the correct context: available edition, possible national transposition, European quote and coherence with the real machine.
How to prepare without chasing deadlines
The most effective work starts from the product range, not from the single document model. It is advisable to identify which machines will be placed on the market after 20 January 2027, which contain software or connections, which fall within Annex I and which depend on external suppliers for safety-related functions.

- Map the range and the expected date of placing on the market.
- Perform a gap analysis between Annex I of the Directive and Annex III of the Regulation.
- Evaluate software and cybersecurity along with security features.
- Update documentation: risk analysis, instructions for use, statement, file and version logs.
- Check the CE procedure, especially for the categories of Annex I.
- Keep evidence of evidence, design decisions, changes and controls.
The advantage of starting before is not only to avoid non-compliance. You can update products and procedures with order, involving design, automation, quality, manuals and suppliers without urgent intervention at the end of the contract.
The point to remember
2027 moves the safety boundary of the machines. The mechanical part remains fundamental, but it will have to live with software, data, access, updates and responsibilities more clearly distributed along the supply chain. companies that will arrive prepared will not be those with multiple documents, but those able to connect every requirement to a design choice and to a verifiable evidence.
For high-risk artificial intelligence systems because they are integrated into regulated products, the consolidated text of the AI Act today provides for the application of specific obligations from 2 August 2028. However, 2027 remains the right year to census the adaptive functions and understand which machines will be involved, without giving the standard an early expiry.
FAQ
When does 2023/1230 (EU) Machinery Regulation apply?
The Regulation applies from 20 January 2027. From that date it replaces Machinery Directive 2006/42/EC.
Do the machines already sold have to be re-certificated?
There is no general obligation to re-certificate the machines already placed on the market. However, substantial changes and other obligations applicable to the concrete case must be assessed.
Can the instructions for use only be provided online?
Yes, in the foreseen cases, but it must be accessible, downloadable, printable and available for the established period. Specific obligations remain for the paper copy requested at the time of purchase and essential information for non-professional users.
Does the Cyber Resilience Act apply to all machines?
No. It applies to products with digital elements that fall within its scope. For machines with software, connectivity or remote access, timely verification is required.
Will a new ISO 12100 come into force in 2027?
The revision is in development, but the final date should not be given for certain until publication. ISO 12100:2010 edition is currently the reference published.




