ECP — European Compliance Platform European Compliance Platform
Machinery Compliance Guide

Machinery Regulation 2023/1230: Transition Guide for Manufacturers

The Machinery Directive that has governed EU machinery safety since 2006 is being replaced by a Regulation — with expanded high-risk categories, explicit cybersecurity requirements, and rules built for AI-enabled and connected machinery. Here's what changes and how to prepare.

Key Dates

DateMilestone
14 June 2023Regulation (EU) 2023/1230 formally adopted
29 June 2023Published in the Official Journal of the EU
20 July 2023Entered into force
20 January 2027Full application date — Machinery Directive 2006/42/EC repealed
⚠ Directive out, Regulation in Unlike the old Machinery Directive, which each EU country transposed into national law with minor variations, the Machinery Regulation applies directly and identically in every member state. There is no national transposition step and no room for local divergence in the core requirements.

What Changes: Directive vs Regulation

Machinery Directive 2006/42/EC (until 20 Jan 2027)Machinery Regulation (EU) 2023/1230 (from 20 Jan 2027)
Legal formDirective — national transpositionRegulation — directly applicable
High-risk category listAnnex IV — fixed listAnnex I — expanded, includes AI/software safety functions
CybersecurityNot addressedExplicit essential requirement
Instructions/DoC formatPaper by defaultDigital format explicitly permitted
Software as safety componentAmbiguous treatmentExplicitly in scope, including post-market software updates
Substantial modificationCase-law/guidance basedFormally defined criteria

Expanded High-Risk Machinery (New Annex I)

The new Annex I list of machinery requiring mandatory third-party (Notified Body) assessment is broader than the old Annex IV. It now explicitly includes:

  • Machinery with fully or partially self-evolving behaviour using AI systems that ensure safety functions
  • Certain machinery intended for use by consumers where an AI system ensures safety functions
  • Machinery designed to remove biological hazards (e.g. certain sanitisation/disinfection machinery)
  • The previously covered high-risk categories from the old Annex IV (certain woodworking machines, presses, injection/compression moulding machines, underground machinery, lifting equipment for persons, etc.), largely carried forward

Manufacturers whose products self-certified under the old Directive should specifically re-check whether embedded AI, autonomous decision-making, or software-driven safety functions now place their machinery in the expanded Annex I — self-declaration may no longer be sufficient.

Cybersecurity as an Essential Requirement

For the first time, machinery essential health and safety requirements explicitly address protection against corruption. Where a machine's safety function depends on a connected or digital system, the manufacturer must design it so that a cybersecurity compromise — malicious or accidental — cannot create a hazardous situation. This overlaps with, but is legally distinct from, obligations under the EU Cyber Resilience Act for products with digital elements; machinery manufacturers with connected products may need to satisfy both frameworks.

Digital Instructions and Declaration of Conformity

The Regulation explicitly permits digital-only instructions for use and a digital EU Declaration of Conformity, provided:

  • The machinery (or accompanying material) clearly indicates how to access the digital version
  • A free paper copy is provided within 15 days if requested by the purchaser at the time of purchase
  • Safety-critical warnings that must be understood before first use may still need to be provided in paper form, depending on risk assessment

Software Updates and Substantial Modification

The Regulation formally addresses when a change to machinery — including a software update — counts as a "substantial modification" requiring a new conformity assessment. Broadly: a modification that was not foreseen or anticipated by the original manufacturer's risk assessment, and that creates a new hazard or increases an existing risk, is substantial and triggers new obligations (potentially for the party making the modification, not just the original manufacturer). This matters increasingly for machinery that receives remote/OTA software updates after being placed on the market.

Transitional Provisions

Machinery lawfully placed on the market under the Machinery Directive before 20 January 2027 can generally continue to be made available and put into service under the old rules, provided its design and intended use remain unchanged. Manufacturers should not wait until the application date to act — Notified Body capacity for the new Annex I categories is expected to be constrained in the run-up to 2027, mirroring the capacity pressure seen with MDR.

Preparing for the Transition

  1. Gap-check against the new Annex I — does your machinery now require third-party assessment where it didn't before?
  2. Review connected/software-driven safety functions against the new cybersecurity requirement
  3. Decide on documentation format — digital instructions can reduce printing/localisation costs but require an access mechanism
  4. Engage a Notified Body early if your product falls into an expanded high-risk category, given expected capacity constraints closer to 2027
  5. Review your substantial-modification policy for products that receive post-market software updates

Not Sure If Your Machinery Needs a New Assessment?

Submit a request on ECP describing your machinery and any AI, software, or connectivity features. We route it to Notified Bodies, testing labs, and machinery compliance consultants who can confirm your Annex I status ahead of the 2027 deadline.

See How ECP Can Help

Frequently Asked Questions

When does the Machinery Regulation 2023/1230 apply?
It entered into force on 20 July 2023 and applies from 20 January 2027, when it repeals the Machinery Directive 2006/42/EC. Machinery placed on the market before then under the old Directive can generally continue to be sold if its design hasn't changed.
Why did the Machinery Directive become a Regulation?
A Regulation applies directly and identically across all member states without national transposition, removing inconsistencies from 27 different implementations, and allowed the EU to modernise the rules for digital, connected, and AI-enabled machinery in one instrument.
What machinery now requires third-party assessment that didn't before?
The new Annex I expands third-party assessment to machinery with self-evolving AI safety functions, certain consumer machinery where AI ensures safety, and machinery removing biological hazards. Re-check your product even if it was previously self-certified.
Are digital instructions for use now allowed?
Yes, provided access is clearly indicated and a free paper copy is given within 15 days if the purchaser requests one at the time of purchase.
Does the Machinery Regulation address cybersecurity?
Yes — machinery with connected safety functions must be designed so a cybersecurity compromise cannot create a hazardous situation, a new essential requirement not present in the old Directive.

Find the right provider

Notified Body

Required for machinery in the expanded Annex I high-risk categories.

Find a Notified Body →

Testing Laboratory

Safety, EMC, and functional testing for machinery and embedded control systems.

Find a Testing Lab →

EU Authorized Representative

Mandatory for non-EU manufacturers placing machinery on the EU market.

Find an EU Representative →

Not sure which you need? See How ECP Can Help and we will match you with the right expert.