Artifact GuideEU

EU Machinery Regulation Software and cybersecurity considerations

From 20 January 2027, Regulation (EU) 2023/1230 requires machinery and related products to address software, data, connections, and malicious influence where they can create hazardous situations or affect Annex III compliance.

Map each relevant asset and connection to a machinery-safety consequence, then retain the version, intervention, control-system, and validation evidence required for that safety case.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 31, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 31, 2026
Overview

Regulation (EU) 2023/1230 applies from 20 January 2027. Its cyber-safety rules focus on machinery hazards: connections must not create hazardous situations, compliance-critical software and data must resist accidental or intentional corruption, and must withstand reasonably foreseeable malicious attempts where the circumstances and risks make that appropriate. Products placed on the EU market before 20 January 2027 must comply with Machinery Directive 2006/42/EC, while other applicable cybersecurity legislation must be assessed separately.

Section 1

Start with safety impact, not a general cyber label

Classify software and connectivity by their machinery-safety role. Review a maintenance portal, firmware update path, sensor-data pipeline, machine-learning safety component, or remote-control channel when corruption, loss of integrity, or malicious influence could create a hazardous situation or undermine compliance with an applicable Annex III requirement.

The Regulation defines source code as the currently installed software version written in a programming language that is unambiguous and understandable to humans. Annex IV requires source code or programming logic for safety-related software when needed to demonstrate conformity. Article 10 requires a manufacturer to provide relevant source code or programming logic to a competent national authority only after a reasoned request and only when the authority needs it to check Annex III compliance. The rule does not make source code public.

  • Map safety-related software to the hazard, safety function, sensor input, actuator, control-system state, or compliance requirement it supports.
  • Identify software and data that are critical for compliance with essential health and safety requirements, and record that identification in the technical file.
  • Separate operational software with no safety impact from software that can affect stopping, guarding, speed, torque, access control, autonomous motion, or operator response.
Section 2

Protect corruption paths that can affect safety

Annex III section 1.1.9 first requires the machinery or related product to be designed and constructed so that connecting another device, directly or remotely, does not create a hazardous situation. It then requires adequate protection against accidental or intentional corruption for hardware that transmits signals or data relevant to access to compliance-critical software, and for software and data that are critical to applicable EHSRs.

The product must identify the software installed on it that is necessary for safe operation and make that information easily accessible at all times. It must also collect evidence of legitimate or illegitimate intervention in relevant hardware and of intervention in, or modification of, installed software or its configuration. Tie the evidence record to the protected asset, access route, safety consequence, protection measure, and recorded intervention.

  • List external connections, update interfaces, removable media, remote-access paths, diagnostic ports, sensor-data feeds, and safety-parameter stores that can reach safety-related software or data.
  • Record protection measures such as access control, integrity checks, secure update controls, configuration baselines, logging, recovery procedures, and segregation of safety-critical functions where they support the safety case.
  • Keep intervention evidence for compliance-critical hardware, installed software, and configuration changes, including what changed, when it changed, and how the affected safety function was reverified.
Section 3

Document control-system reliability and autonomous behaviour

Annex III section 1.2.1 requires to be designed and constructed so that they prevent hazardous situations and withstand relevant operating stresses and external influences, including reasonably foreseeable malicious attempts from third parties where appropriate to the risks.

Section 1.2.1 sets two distinct retention rules. A tracing log of intervention data and safety-software versions uploaded after market placement or putting into service must be enabled for five years after each upload, exclusively to demonstrate Annex III conformity after a reasoned authority request. For fully or partially self-evolving operating with varying autonomy, recording of data on the safety-related decision-making process must be enabled and the data retained for one year after collection for the same limited purpose.

  • Tie each control-system claim to a test, verification record, simulation, validation dataset, fault analysis, or safety function review.
  • For uploaded safety software, enable the intervention-and-version tracing log for five years after each upload; for qualifying self-evolving or autonomous systems, retain recorded safety-decision data for one year after collection.
  • Establish safety-function limits in the risk assessment and prevent changes to settings or rules, including during a learning phase, when those changes could create hazardous situations.
  • Reassess the safety case after changes to sensors, models, firmware, remote-control features, safety parameters, external interfaces, or operating limits.
Section 4

Evidence to keep in the technical documentation

Annex IV requires technical documentation to specify the means used to ensure conformity with applicable essential health and safety requirements. For software-heavy machinery, connect the released configuration, hazards, controls, and verification evidence; a repository, ticket queue, or security policy alone does not show conformity.

Keep the evidence version-specific. A reviewer should be able to connect a released machinery configuration to the safety-related software version, programming logic, protected data, control-system design, tests, residual risks, and update history.

  • Safety-related software inventory: modules, versions, parameters, data sets, and interfaces that can affect Annex III compliance.
  • Corruption-protection record: protected assets, access paths, integrity controls, intervention logs, update approvals, and revalidation evidence.
  • Control-system evidence: architecture, safety functions, fault and external-influence analysis, malicious-attempt assumptions, test results, and residual-risk decisions.
  • Authority-response record: location of relevant source code or programming logic, responsible disclosure contact, confidentiality handling, and the reasoned request showing why the material is needed for an Annex III compliance check.
  • Change log: release notes, supplier changes, security fixes, model changes, sensor changes, standards changes, and the resulting risk-assessment decision.
Recommended next step

Build a Machinery Regulation software evidence pack

Map safety-related software, control-system assumptions, corruption-protection measures, update triggers, and Annex IV evidence before release or technical-file review.

Section 5

Review triggers and standards context

Reopen the software and cybersecurity assessment whenever a change could affect a safety function or the evidence behind it. Typical triggers include firmware releases, supplier component changes, remote-access changes, new sensor inputs, model retraining, changed operating envelopes, vulnerability remediation, incident reports, or a revised harmonised standard used in the conformity argument.

ISO/TR 22100-4:2018 gives machinery manufacturers guidance for identifying and addressing IT-security threats that can influence machinery safety, but it does not provide detailed implementation specifications. It does not replace the Regulation or establish a presumption of conformity on its own. Map each chosen measure to the relevant Annex III requirement and retain the supporting Annex IV evidence.

Regulation (EU) 2026/1744 was published on 24 July 2026 and entered into force on 27 July 2026. It moves the Machinery Regulation into Section B of AI Act Annex I and requires the Commission to add corresponding health and safety requirements to Machinery Regulation Annex III through delegated acts that apply by 2 August 2028 for AI systems classified as high-risk under Article 6(1) because they are safety components of machinery or are themselves machinery.

  • Assess other applicable cybersecurity laws separately; evidence prepared for another regime supports this machinery file only to the extent that it addresses the relevant Annex III requirement.
  • A cybersecurity certificate creates the Article 20(9) presumption only if it comes from an EU Cybersecurity Act certification scheme whose references have been published in the Official Journal, and only for the parts of Annex III sections 1.1.9 and 1.2.1 that the certificate or statement covers.
  • For qualifying high-risk AI, Article 20(10) creates a separate interim presumption: until machinery-specific harmonised standards or common specifications exist, compliance with relevant AI Act harmonised standards or common specifications can support presumption of conformity with the AI-related Annex III requirements.
  • When relying on standards, record the exact standard, edition, clauses used, gaps against Annex III, and why the standard remains suitable for the released product configuration.
  • For machinery with self-evolving behaviour or autonomy, include lifecycle hazards that are foreseeable at placing on the market as intended evolution of the product's behaviour or logic.
Primary sources

References and citations

single-market-economy.ec.europa.eu
Referenced sections
  • Confirms the Regulation's mandatory application from 20 January 2027 and the Directive 2006/42/EC rule for products placed on the EU market before that date.
"applies on a mandatory basis as of 20 January 2027"
iso.org
Referenced sections
  • Supports documenting and verifying the risk assessment and risk reduction process for machinery design.
"documentation and verification of the risk assessment"
iso.org
Referenced sections
  • Provides machinery-specific cyber-safety context while noting that it gives guidance rather than detailed implementation specifications.
"does not provide detailed specifications"
data.europa.eu
Referenced sections
  • Supports foreseeable lifecycle hazard assessment, the limited Article 20(9) cybersecurity-certification presumption, and mapping standards or specifications to Annex III requirements.
"foreseeable at the time of placing"
eur-lex.europa.eu
Referenced sections
  • Published on 24 July 2026 and in force from 27 July 2026. Article 3 adds the delegated Annex III AI-requirements mechanism and interim Article 20(10) presumption, with the delegated requirements applying by 2 August 2028.
Related guides

Explore more topics

Declaration of Conformity vs Declaration of Incorporation | Machinery Regulation FAQ
FAQ on when machinery needs an EU Declaration of Conformity and when partly completed machinery needs an EU Declaration of Incorporation under Regulation (EU) 2023/1230.
Directive 2006/42/EC to Machinery Regulation transition
Transition guide for moving EU machinery files from Directive 2006/42/EC to Regulation (EU) 2023/1230, focused on the 20 January 2027 changeover, pipeline products, declarations, standards, technical documentation, software, cybersecurity, and digital instructions.
EU Machinery Regulation Applicability Test
Test whether a product is machinery, a related product, partly completed machinery, a safety component, substantially modified, excluded, or covered by overlapping EU product laws.
EU Machinery Regulation compliance
Machinery Regulation compliance checklist covering scope, EHSR risk assessment, technical documentation, instructions, conformity assessment, EU declarations, CE marking, software, transition, and market surveillance.
EU Machinery Regulation compliance checklist
Checklist for Regulation (EU) 2023/1230 covering scope, EHSR risk assessment, technical documentation, instructions, conformity assessment, EU declarations, CE marking, digital duties, transition, and market surveillance.
EU Machinery Regulation deadlines and compliance calendar
Calendar for Regulation (EU) 2023/1230 dates, Directive 2006/42/EC transition, release documentation gates, standards monitoring, and substantial-modification reviews.
EU Machinery Regulation FAQ
Answers to Machinery Regulation questions on scope, partly completed machinery, Annex I categories, Article 25 conformity assessment, digital instructions, software, cybersecurity, transition, CE files, and overlap with other EU product laws.
EU Machinery Regulation Partly Completed Machinery
What counts as partly completed machinery under Regulation (EU) 2023/1230, what documents travel with it, and where the final assembler takes over.
EU Machinery Regulation requirements
Requirements under Regulation (EU) 2023/1230: machinery scope, EHSR risk assessment, technical documentation, instructions, conformity assessment, EU declaration, CE marking, software evidence, transition, and surveillance.
EU Machinery Regulation Safety Components
Definition, scope, conformity assessment, technical documentation, declaration, CE marking, and cited examples for safety components under Regulation (EU) 2023/1230.
EU Machinery Regulation scope and machine categories
Scope guide for Regulation (EU) 2023/1230 covering machinery, related products, partly completed machinery, Annex I categories, exclusions, substantial modification, and category evidence.
EU Machinery Regulation substantial modification decision workflow
Workflow for assessing substantial modification under Regulation (EU) 2023/1230: change facts, hazard and risk impact, manufacturer obligations, conformity assessment, CE marking, and evidence.
EU Machinery Regulation vs LVD
Compare the EU Machinery Regulation and Low Voltage Directive boundary for machinery EHSRs, electrical risks, excluded electrical products, CE documentation, and evidence reuse.
EU Machinery Regulation vs Market Surveillance Regulation: compliance comparison
Compare Machinery Regulation product compliance duties with EU MSR market surveillance duties, authority requests, online sales, corrective action and evidence records.
EU Machinery Regulation: autonomous mobile and collaborative machinery
Official source guide to Regulation (EU) 2023/1230 requirements for autonomous mobile machinery, human-machine interaction, controls, software, cybersecurity, risk assessment, technical documentation, and conformity routes.
EU Machinery Regulation: when does a modification constitute substantial modification?
Guide to substantial modification under Regulation (EU) 2023/1230: change triggers, risk assessment, EHSRs, technical documentation, conformity assessment, CE marking, and records.
EU Machinery Risk Assessment Method
How to document an EU Machinery Regulation risk assessment: ISO 12100 hazard identification, EHSR mapping, risk reduction, residual risk, software, cybersecurity, and technical-file evidence.
How to map Annex III EHSRs under the EU Machinery Regulation | Machinery Regulation FAQ
FAQ on mapping Annex III essential health and safety requirements to hazards, risk reduction, software controls, technical documentation, and Annex I classification under Regulation (EU) 2023/1230.
Machinery CE documentation template for Regulation (EU) 2023/1230
Template fields for Machinery Regulation CE documentation: product identity, scope, EHSR risk assessment, standards, tests, instructions, EU declaration, CE marking, notified body route, software, cyber, and substantial modification checks.
Machinery Regulation and EU AI Act overlap for AI-enabled safety functions
FAQ on Machinery Regulation overlap with the EU AI Act for self-evolving or machine-learning safety functions, Annex I categories, standards work, and technical documentation boundaries.
Machinery Regulation Annex I conformity route workflow
Classify machinery against Annex I Part A and Part B, choose the Article 25 conformity assessment route, and assemble the technical evidence file.
Machinery Regulation Annex I high-risk categories
Explain what Annex I does under Regulation (EU) 2023/1230, which listed machinery categories trigger special conformity routes, and what evidence to keep.
Machinery Regulation category and scope checks
Check whether a product is machinery, a related product, partly completed machinery, a safety component, excluded from scope, or listed in Annex I under Regulation (EU) 2023/1230.
Machinery Regulation conformity assessment and CE marking
EU Machinery Regulation guide to Article 25 conformity assessment routes, Annex I machinery categories, technical documentation, EU declarations, CE marking, and instructions.
Machinery Regulation cybersecurity evidence FAQ
What cybersecurity evidence connected or software-enabled machinery should keep for protection against corruption, safety-related control systems, and machinery risk assessment.
Machinery Regulation digital instructions
EU Machinery Regulation guide to digital instructions for use: access marking, print and download access, paper copies, non-professional safety information, languages, and records.
Machinery Regulation penalties and enforcement
EU Machinery Regulation enforcement guide covering Member State penalty rules, corrective action, market surveillance powers, and cross-border authority cooperation.
Machinery Regulation related products scope guide
Classify EU Machinery Regulation related products, including interchangeable equipment, safety components, lifting accessories, lifting chains, ropes, webbing, and removable transmission devices.
Machinery Regulation Technical Documentation and Technical File
What to keep in the EU Machinery Regulation technical file: product identification, risk assessment, EHSR mapping, standards, tests, instructions, declarations, software evidence, retention, and notified-body records.
Machinery Regulation technical file acceptance workflow
Release-gate workflow for accepting an EU Machinery Regulation technical file: scope, EHSR risk evidence, standards, tests, declarations, notified-body records, software, cyber, and signoff.
Machinery Regulation Timeline and Transition: practical guide
EU Machinery Regulation timeline covering corrected application dates, the Directive 2006/42/EC changeover, certificate continuity, product placement decisions, and transition evidence.
Machinery Regulation vs EMC Directive
Compare EU machinery safety duties with EMC duties for equipment, CE documentation, harmonised standards, declarations, and combined technical files.
Machinery Regulation vs EU AI Act: machinery safety overlap
A cited-source comparison of the EU Machinery Regulation and EU AI Act for machinery with AI-enabled safety functions, software, cyber-safety and technical documentation overlap.
Machinery Regulation vs Machinery Directive
Official source comparison of Regulation (EU) 2023/1230 and Directive 2006/42/EC across legal form, timing, scope, digital instructions, cybersecurity, conformity assessment, documentation, and CE marking.
Machinery vs RED comparison
Compare EU Machinery Regulation and Radio Equipment Directive boundaries for machinery safety, radio equipment scope, CE documentation, and shared evidence.
What counts as machinery under Regulation (EU) 2023/1230?
FAQ on the Machinery Regulation definition of machinery, including assemblies, drive systems, missing components, software, related products, partly completed machinery, safety components, and exclusions.
When can a software update affect Machinery Regulation compliance?
FAQ on when machinery software updates can trigger Machinery Regulation review, including safety functions, substantial modification, corruption protection, instructions, and CE technical-file evidence.
When does used or modified machinery need a new conformity assessment? | Machinery Regulation FAQ
FAQ on used and modified machinery under Regulation (EU) 2023/1230, including substantial modification, first EU use, technical documentation, and market surveillance evidence.
When is a notified body needed under the EU Machinery Regulation?
FAQ on when Machinery Regulation Annex I products need a notified body, how to find designated bodies, and what manufacturers still own.
Which Article 25 conformity assessment module applies? | EU Machinery Regulation FAQ
FAQ on Article 25 of Regulation (EU) 2023/1230: Module A, Module B plus C, Module H, Module G, Annex I triggers, notified body involvement, and technical file evidence.