What cybersecurity evidence is needed for connected or software-enabled machinery?
The evidence should start with the Machinery Regulation safety question: could a connected device, remote communication path, software change, data change, or control-system logic failure create a hazardous situation? If yes, the cybersecurity record belongs inside the machinery risk assessment and technical documentation, not only in a separate IT security file.
Annex III section 1.1.9 requires protection against corruption for safety-critical signal or data hardware, software, and data. It also requires the machinery or related product to identify software necessary for safe operation and to collect evidence of legitimate or illegitimate interventions in relevant hardware, software, installed software, or configuration.
Scope the controls to machinery safety. The Regulation calls for proportionate protection against malicious third parties where interference can affect product safety; it does not make the machinery technical file a substitute for a separate assessment under other cybersecurity legislation that may apply to the product.
These Machinery Regulation requirements apply from 20 January 2027. Before that date, document the legal basis used for the product placed on the market and keep this Annex III analysis as transition evidence; do not present it as replacing any separate Cyber Resilience Act, radio-equipment, network-security, or sector-specific assessment that applies.
- List each external connection, remote access route, safety bus, update path, configuration interface, and supplier component that can reach software or data relevant to essential health and safety requirements.
- Identify the installed software needed for safe operation and keep a version record that can be produced in an easily accessible form.
- Show how are protected against accidental or intentional corruption, including configuration changes and uploaded safety software.
- Keep intervention evidence: authorised changes, unauthorised attempts where detectable, configuration modifications, firmware or software uploads, test results, and remediation records.
- Tie each control to the machinery risk assessment, the relevant Annex III EHSR, and the design-verification evidence that shows hazardous situations are prevented.
Does the Machinery Regulation require for every connected machine?
From 20 January 2027, Regulation (EU) 2023/1230 requires machinery-safety evidence where connection, access, software, data, or control-system logic is relevant to essential health and safety requirements or could lead to a hazardous situation. It does not turn every networked feature into a standalone cybersecurity compliance file, and other applicable cybersecurity legislation still needs its own assessment.
What should the cybersecurity record prove?
It should prove that were identified, protected against accidental or intentional corruption, monitored for relevant interventions, and assessed with the control-system hazards in Annex III section 1.2.1.
Annex III section 1.1.9 sets the protection-against-corruption evidence requirements; Articles 52 and 54 establish the pre-20 January 2027 transition and application date.
Supports treating IT-security and cybersecurity threats as machinery safety considerations when they can influence machinery safety.