Machinery
Machinery Regulation cybersecurity: what applies from 20 January 2027
The EU Machinery Regulation (EU) 2023/1230, which applies from 20 January 2027, turns cybersecurity into a safety requirement: machines must be protected against corruption (Annex III, section 1.1.9) and their control systems must withstand reasonably foreseeable malicious attempts (section 1.2.1). Makers must protect safety-critical software and data, identify the safety software installed, and keep evidence of interventions and modifications.
Free plan, no card required.
When does the Machinery Regulation apply?
Regulation (EU) 2023/1230 was adopted on 14 June 2023 and replaces the Machinery Directive 2006/42/EC. As a regulation, it applies directly in every Member State without national transposition. It applies from 20 January 2027: the original Official Journal text said 14 January 2027, and a corrigendum published on 4 July 2023 corrected that and other dates. The Directive is repealed from the same date, and products placed on the market in conformity with it before 20 January 2027 can continue to be made available.
Recital 25 explains the logic: measures against malicious third parties are limited to protecting the safety of the product, and other EU laws on cybersecurity, such as the Cyber Resilience Act, can apply alongside. Regulation (EU) 2026/1744, the Digital Omnibus on AI, has since amended the text: the Commission is to add requirements for high-risk AI systems that are safety components of machinery, or are machinery themselves, to Annex III through delegated acts that apply by 2 August 2028.
What does Annex III section 1.1.9, protection against corruption, require?
Section 1.1.9 targets the software, data and connections on which the machine's safety depends. In engineering terms, it calls for an inventory of safety-relevant software that the machine can report itself, integrity protection for that software and its configuration, protected interfaces, and tamper-evident records. In summary, the section requires that:
- Connecting another device, directly or through a remote device that communicates with the machine, does not lead to a hazardous situation.
- A hardware component that transmits signals or data relevant for connection or access to safety-critical software is adequately protected against accidental or intentional corruption, and the machine collects evidence of legitimate or illegitimate interventions in it.
- Software and data critical for compliance with the essential health and safety requirements are identified as such and adequately protected against accidental or intentional corruption.
- The machine identifies the software installed on it that is necessary to operate safely, and can provide that information at all times in an easily accessible form.
- The machine collects evidence of legitimate or illegitimate interventions in its software, and of modifications of the software or its configuration.
What does section 1.2.1 require of control systems?
Section 1.2.1 requires control systems to prevent hazardous situations and, among other things, to withstand the intended operating stresses and intended and unintended external influences, including reasonably foreseeable malicious attempts from third parties leading to a hazardous situation. Faults in hardware or logic and errors in the control logic must not lead to hazardous situations either.
Two record-keeping duties follow. A tracing log of the data generated in relation to an intervention, and of the versions of safety software uploaded after the machine is placed on the market or put into service, must be enabled for five years after each upload, used only to demonstrate conformity on a reasoned request from a national authority. For control systems with self-evolving behaviour, data on the safety-related decision-making process must be recorded and kept for one year, and the machine must not act beyond its defined task and movement space.
How does the Machinery Regulation relate to the Cyber Resilience Act?
A connected machine or robot can be both machinery under Regulation (EU) 2023/1230 and a product with digital elements under the CRA, Regulation (EU) 2024/2847. CRA recital 53 says such manufacturers should comply with both, and that meeting the CRA's essential cybersecurity requirements could facilitate compliance with sections 1.1.9 and 1.2.1. The synergy is not automatic: the manufacturer has to demonstrate it, for example by applying harmonised standards or other technical specifications after a risk assessment covering those risks, and must follow the conformity assessment procedures of both regulations.
The Machinery Regulation offers its own presumption for these two sections. Under Article 20(9), machinery certified, or covered by a statement of conformity, under a European cybersecurity certification scheme adopted under the Cybersecurity Act, Regulation (EU) 2019/881, and referenced in the Official Journal is presumed to conform with 1.1.9 and 1.2.1 as far as the certificate covers them.
| Machinery Regulation (EU) 2023/1230 | Cyber Resilience Act (EU) 2024/2847 | |
|---|---|---|
| Purpose of the cyber provisions | Safety: corruption or malicious attempts must not create hazards | Cybersecurity of the product and its data for the support period |
| Applies from | 20 January 2027 | 11 December 2027; Article 14 reporting since 11 September 2026 |
| Software records | Identify safety software on the machine; log interventions and safety-software versions | SBOM covering at least top-level dependencies; documented vulnerabilities |
What should robot and machine makers prepare now?
Machinery with embedded systems that use machine learning to ensure safety functions deserves an early look: Annex I, Part A lists it, which rules out internal production control alone and requires EU type-examination, full quality assurance or unit verification. Harmonised standards give a presumption of conformity only once their references are published in the Official Journal, so check their status before relying on a draft.
With the date of application in January 2027, the slowest work is design work: deciding what counts as safety-critical software, how it is protected and how the machine proves what it runs. Changes to bootloaders, storage and update mechanisms take release cycles, not weeks. A practical preparation list:
- Map the safety functions and the software, firmware, configuration and data they depend on; mark them as safety-critical.
- Keep a software inventory per machine model and version, and let the machine report its safety-relevant software on demand.
- Protect integrity: signed software, verified boot where feasible, and access control for safety parameters.
- Log interventions and software or configuration changes in a tamper-evident way, with storage for the five-year tracing log.
- Review every interface, including fieldbus, USB, wireless and remote service access, for ways a connected device could create a hazard.
- Reuse your CRA inventory and vulnerability handling where they fit, and document how each regulation's requirements are met.
Available in KROMSE today
KROMSE has no Machinery Regulation workflow today, but it produces the software inventory and vulnerability evidence that sections 1.1.9 and 1.2.1 work depends on.
- Dependency scans and source code analysis for 11 languages, including C and C++, of the software that runs on your machines.
- Linux firmware image analysis up to 512 MB: unpacking, package listing, vulnerability matching and root file system checks.
- CycloneDX JSON and SPDX JSON SBOMs from every scan, and SBOM upload for components your suppliers deliver.
- A CRA evidence pack (JSON or PDF), VEX export and a signed audit-log export that record findings and decisions.
- Bare-metal and RTOS controller firmware is not supported yet.
Coming next
On the roadmap, not available yet. Dates are targets, not promises; this page changes the day a capability is live.
- Coming · Q1 2027Machinery Regulation evidence. KROMSE will collect evidence for the cybersecurity-related requirements of the EU Machinery Regulation (EU) 2023/1230, next to your CRA record.
- Coming · Q4 2026CRA conformity assessment. A guided workflow will map your evidence to the Annex I requirements, for a person to review and complete.
- Coming · Q4 2026 (December)Robotics security. KROMSE will add ROS 2 advisories, component identification inside PX4 and ArduPilot firmware, and robot-specific vulnerability data.
Frequently asked questions
When does the EU Machinery Regulation apply?
Regulation (EU) 2023/1230 applies from 20 January 2027, as corrected by a corrigendum of 4 July 2023, and the Machinery Directive 2006/42/EC is repealed from that date. Products placed on the market in conformity with the Directive before 20 January 2027 can continue to be made available.
Does the Machinery Regulation require an SBOM?
Not in those words. Annex III section 1.1.9 requires the machine to identify the software installed on it that is necessary to operate safely, and to provide that information at all times in an easily accessible form. An SBOM is a practical way to keep that inventory, and the Cyber Resilience Act separately requires an SBOM covering at least the top-level dependencies of products with digital elements.
Does complying with the CRA cover the Machinery Regulation's cybersecurity requirements?
Not automatically. CRA recital 53 says meeting the CRA's essential cybersecurity requirements could facilitate compliance with sections 1.1.9 and 1.2.1 of the Machinery Regulation, but the manufacturer must demonstrate it and follow both conformity assessment procedures. The Machinery Regulation grants a presumption of conformity for those sections through European cybersecurity certification under the Cybersecurity Act, as far as the certificate covers them.
Are robots covered by the Machinery Regulation?
A robot with a drive system and linked moving parts joined for a specific application generally meets the Regulation's definition of machinery, unless an exclusion applies. Machinery with embedded systems that use machine learning to ensure safety functions is listed in Annex I, Part A and needs EU type-examination, full quality assurance or unit verification. Means of transport by air are excluded.
Does KROMSE support the Machinery Regulation?
Not as a workflow. KROMSE has no Machinery Regulation module today and does not issue declarations of conformity or support CE marking. It scans software, SBOMs and Linux firmware, exports SBOMs and keeps evidence records you can use in your own technical documentation. Machinery Regulation evidence next to your CRA record is on the roadmap.
Related guides
Sources
- Regulation (EU) 2023/1230 (Machinery Regulation), EUR-Lex
- Corrigendum to Regulation (EU) 2023/1230, OJ L 169, 4.7.2023, EUR-Lex
- European Commission: Machinery
- Regulation (EU) 2024/2847 (Cyber Resilience Act), EUR-Lex
- European Commission: Cyber Resilience Act implementation FAQ (interplay with the Machinery Regulation)
- Regulation (EU) 2019/881 (Cybersecurity Act), EUR-Lex
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), EUR-Lex