EU Machinery Regulation: Preparing for Cybersecurity and AI Requirements 

Published:

by

Colleagues prepare for eu machinery regulation.

A controls engineer pushes a firmware update to the safety controller on a robot cell already running at a customer site. Months later, a market surveillance authority asks which safety functions the update touched, how the software was protected against tampering, and where the record of the change lives.  

When safety requirements, software versions, and verification results are linked in advance, those answers come from a query. Without that record, the team rebuilds the history from email threads and shared drives while the request stays open. 

On January 20, 2027, the EU Machinery Regulation, formally Regulation (EU) 2023/1230, replaces Machinery Directive 2006/42/EC across the European Union (EU). There’s no grace period for new placements, so machinery placed on the EU market from that date must conform to the regulation. For the first time, EU machinery law treats cybersecurity as a safety requirement and puts safety functions based on machine learning under mandatory third-party assessment. 

This guide covers what the regulation requires, who it applies to, how it overlaps with the Cyber Resilience Act, what it means for artificial intelligence (AI) in safety functions, and how to prepare before the application date. 

What Is the EU Machinery Regulation? 

The EU Machinery Regulation is the EU law that sets essential health and safety requirements for the design and construction of machinery, related products, and partly completed machinery placed on the EU market. It was published in the Official Journal on June 29, 2023, entered into force on July 19, 2023, and applies from January 20, 2027. 

The shift from a directive to a regulation has practical weight. Each member state had to transpose the 2006 directive into national law, which produced national variation in how it was applied. A regulation applies directly and uniformly in all 27 member states, and national rules survive only where the text leaves room for them, such as document language and penalties. 

Teams that know the Machinery Directive will recognize much of the technical content. The Essential Health and Safety Requirements (EHSRs) in Annex III remain the core, and standards such as ISO 12100 and ISO 13849-1 remain the practical reference for meeting them. The changes concentrate where machinery has changed most over the past two decades: software, connectivity, autonomy, and documentation. 

Who the Machinery Regulation Applies To 

The regulation covers machinery, partly completed machinery, and related products, including interchangeable equipment, safety components, lifting accessories, chains, ropes, and removable mechanical transmission devices. Safety components explicitly include digital components. Software that performs a safety function and is placed on the market separately carries its own manufacturer obligations, including CE marking. 

Obligations follow the economic operator’s role. Manufacturers carry out conformity assessment, draw up the EU declaration of conformity, and affix the CE marking. Importers and distributors verify that those obligations were met before machinery reaches users, and authorized representatives act for manufacturers within the EU. 

Article 3(16) also defines substantial modification for the first time. A substantial modification is a physical or digital change made after machinery is placed on the market or put into service that the manufacturer didn’t foresee or plan and that affects safety by creating a new hazard or increasing an existing risk. Whoever makes that change takes on manufacturer obligations for the modified machinery. For system integrators and in-house automation teams, a software update can now carry the same compliance consequences as a physical retrofit. 

New Machinery Cybersecurity Requirements 

The regulation brings cybersecurity into CE conformity through two sections of Annex III. These sections don’t create a separate IT security program. They treat corruption of safety-related hardware, software, and data as a hazard source that the machinery design has to control. 

Protection Against Corruption (Annex III, Section 1.1.9) 

Section 1.1.9 requires that connecting machinery to another device, or communicating with it remotely, doesn’t lead to a hazardous situation. Safety-related hardware, software, and data must be identified and protected against accidental and intentional corruption. The machinery must also collect evidence of legitimate or illegitimate interventions in its software or configuration, and the software needed for safe operation must be identifiable. 

In engineering terms, threat analysis, hardening, tamper detection, and intervention logging become inputs to the safety design. A new standard, prEN 50742, addresses how to meet Sections 1.1.9 and 1.2.1, and its publication is scheduled for November 2026. 

Safety and Reliability of Control Systems (Annex III, Section 1.2.1) 

Section 1.2.1 requires control systems to withstand intended operating stresses and external influences, including reasonably foreseeable malicious attempts by third parties, without creating hazardous situations. The same section covers faults in hardware and software, errors in control logic, and reasonably foreseeable human error. 

Section 1.2.1 also sets a lifecycle evidence obligation. For safety software uploaded after machinery is placed on the market, the tracing log of intervention data and software versions must remain available for 5 years after the upload. Manufacturers use that log to demonstrate conformity when a national authority submits a reasoned request. 

How the Machinery Regulation and Cyber Resilience Act Overlap 

Connected machinery sold in the EU will often fall under both regulations. The Machinery Regulation asks whether a cyber event can compromise safety. The Cyber Resilience Act (CRA) asks whether a product with digital elements stays secure across its support period, including vulnerability handling and reporting. 

The two regulations are complementary, and they aren’t interchangeable. CRA conformity doesn’t automatically satisfy Sections 1.1.9 and 1.2.1, so manufacturers of connected machinery should plan for both conformity assessments. The practical overlap is shared evidence. One threat model, one set of security requirements, and one body of test results can support both assessments, provided each requirement keeps an explicit trace to the regulation it satisfies. IEC 62443, already common in industrial automation, gives safety and security engineers a shared vocabulary for zones, conduits, and security levels that informs both. 

Dimension EU Machinery Regulation Cyber Resilience Act 
Primary concern Health and safety of persons, including the safety impact of cyber events Cybersecurity of products with digital elements across their support period 
Key security provisions Annex III, Sections 1.1.9 and 1.2.1 Annex I security and vulnerability handling requirements 
Application dates January 20, 2027 Reporting from September 11, 2026; full application December 11, 2027 
Conformity route Self-assessment for most machinery; notified body involvement for Annex I categories Self-assessment for default products; notified body involvement for certain important and critical products 
Lifecycle evidence Tracing log of safety software interventions and versions, retained for 5 years Software Bill of Materials (SBOM), vulnerability handling records, and security updates 
Reporting obligations No dedicated vulnerability reporting clock 24-hour, 72-hour, and final reports under Article 14 

Table 1. How the EU Machinery Regulation and the Cyber Resilience Act divide cybersecurity obligations for connected machinery. 

AI and Self-Evolving Behavior in Safety Functions 

Why Self-Evolving Safety Components Are High-Risk Machinery 

Annex I, Part A lists the machinery categories that always require notified body assessment. Two entries are new. Item 5 covers safety components with fully or partially self-evolving behavior using machine learning approaches that ensure safety functions, and Item 6 covers machinery that embeds those systems. Applying harmonized standards in full doesn’t remove the notified body requirement for these products. 

The trigger is how the safety function behaves. Deterministic safety logic stays on the conformity routes teams already use. A safety function whose behavior comes from machine learning moves onto the mandatory third-party route, and that shift affects program schedules because notified body capacity has to be secured in advance. 

Designing Safety Functions That Stay Within Defined Limits 

Annex III places design constraints on machinery with self-evolving behavior or logic that operates with varying levels of autonomy. Under Section 1.2.1, that machinery must not perform actions beyond its defined task and movement space, and data on its safety-related decision-making must be recorded and retained for 1 year after collection. Section 1.1.6 extends ergonomic requirements to how operators interact with machinery that has self-evolving behavior. 

These provisions turn AI governance into specifications. A defined task and movement space is a set of requirements with limits that can be tested. A decision log is a feature with its own verification. Operator interaction constraints need design rationale and usability evidence. Each one needs an owner, a trace to the hazard it controls, and verification results that will hold up in front of a notified body. 

What the Digital Omnibus on AI Means for Machinery Manufacturers 

Until mid-2026, many machinery manufacturers expected a second compliance track, because an AI safety component under the Machinery Regulation would also have been a high-risk AI system under the EU AI Act. The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on July 27, 2026, and changed that picture. It removed the Machinery Regulation from the AI Act’s scope, so AI in machinery safety functions answers to sector-specific safety rules. The European Commission can also adopt delegated acts under the Machinery Regulation that add health and safety requirements for systems that would otherwise have been high-risk AI. 

The relief is real, and it’s narrower than it may appear. The Machinery Regulation now carries the full regulatory weight for AI safety functions in machinery, and future delegated acts may add to Annex III. Teams that already manage AI safety requirements as traceable engineering artifacts are better positioned to absorb those additions as requirement changes rather than redesigns. 

Watch on Demand: How to Prepare for the EU Cyber Resilience Act >> 

Machinery Regulation Compliance Timeline and Penalties 

The regulation applies 42 months after entry into force. Provisions on notified bodies and a small set of other articles applied early so that conformity assessment capacity could be in place before the main application date. Everything else applies from January 20, 2027. 

Machinery placed on the market under the directive before January 20, 2027, may continue to be made available. New placements from that date must conform to the regulation, and the EU declaration of conformity must reference Regulation (EU) 2023/1230. Programs that won’t reach the market until after the application date should already be designed against the new requirements. 

Documentation obligations extend well past release. Instructions for use and the EU declaration of conformity may be supplied digitally, provided they stay accessible for at least 10 years or the expected lifetime of the machinery. When a customer requests paper at the time of purchase, a free printed copy must follow within one month. 

Under Article 50, member states set the penalties for infringements. Market surveillance authorities can also require corrective action, restrict availability, withdraw products from the market, or order recalls, and those actions often cost more than a fine. 

Why Machinery Regulation Compliance Depends on Traceability 

Both new requirement areas ask a version of the same question: can you show how a safety claim connects to the design, the software, and the evidence behind it? Answering it requires a traceability chain.  

For a safety function exposed to cyber risk, that chain links five elements: 

  • The hazard identified in the ISO 12100 risk assessment 
  • The threat that could defeat the protective measure 
  • The safety and security requirements that control both 
  • The verification results that demonstrate performance 

The chain matters most when something changes. A firmware update, a new network interface, or a retrained model each raises two questions. Does the change affect a safety function, and does it create a new hazard or increase an existing risk? Without impact analysis across connected artifacts, teams answer by meeting and memory. With it, engineers can see which requirements, tests, and risk controls sit downstream of the change before anyone approves it. 

The 5-year tracing log and the 10-year documentation horizon stretch that need across the service life. A record assembled at release and filed away won’t answer a question about a software version uploaded 3 years later. 

How to Prepare for the EU Machinery Regulation 

Most machinery manufacturers already run structured risk assessment and functional safety processes. Preparation means extending those processes to cover security and autonomy, and connecting the evidence they produce. These five areas give teams a practical starting point. 

Portfolio Classification 

Each product line needs a documented determination against Annex I, Parts A and B, with particular attention to safety functions that use machine learning. That determination sets the conformity route and the lead time for notified body capacity. 

Security-Informed Risk Assessment 

The ISO 12100 risk assessment should treat corruption of safety-related hardware, software, and data as a hazard source. IEC 62443 threat modeling supplies the attack scenarios that Sections 1.1.9 and 1.2.1 expect the design to withstand, and it fits within existing risk management practices. 

Security and AI Requirements as Design Inputs 

Protection against corruption, intervention logging, task and movement limits, and decision data recording belong in the same specification as functional safety requirements. Planning verification and validation at the same time keeps evidence production inside the development cycle. 

Change and Modification Criteria 

A documented test for substantial modification, applied to software updates as well as physical retrofits, gives service teams, integrators, and customers a consistent basis for decisions. 

Lifecycle Documentation Plan 

Digital instructions, access to the declaration of conformity, and tracing log retention each need an owner and a hosting approach that holds up for 10 years or more. 

Teams already preparing for the CRA can reuse much of this work, since the threat models, security requirements, and test evidence serve both regulations. 

How Jama Connect® Supports Machinery Regulation Compliance 

The Machinery Regulation asks manufacturers to show that safety holds up against corruption, autonomy, and change across a long service life. Jama Connect is a requirements management and traceability platform for complex, regulated product development, and it keeps hazards, requirements, design, and verification evidence connected as each of them changes. 

Live Traceability™ links hazards and risk controls to safety and security requirements, design elements, and test results in one connected record. When an upstream requirement or risk control changes, suspect links flag the downstream items that need review. That gives engineers a defined starting point for deciding whether a change affects a safety function or meets the threshold for substantial modification. 

Baselines capture the approved state of each release at placing on the market, and reviews record who approved which requirements and when. For industrial machinery teams, Jama Connect item types and relationship rules can reflect the standards they already work with, including ISO 12100, ISO 13849-1, IEC 62061, and IEC 62443. 

Building Readiness Before January 2027 

January 20, 2027, is a fixed date with no transition window for new placements, and the harder work sits upstream of the declaration of conformity. Security requirements, AI safety constraints, and change criteria take time to specify, verify, and connect. Organizations that produce traceable requirements and evidence during development will reach the application date with a record they can stand behind. 

Build Traceability Into Your Strategy 

Preparing for the EU Machinery Regulation means connecting safety, security, software changes, and verification evidence across the product lifecycle. See how Jama Connect helps engineering teams maintain traceability, manage change, and keep compliance evidence connected as requirements evolve. 

Explore Jama Connect for industrial manufacturing. 

Frequently Asked Questions About the EU Machinery Regulation 

When does the EU Machinery Regulation apply? 

The EU Machinery Regulation applies from January 20, 2027. It entered into force on July 19, 2023, and replaces Machinery Directive 2006/42/EC in full on the application date. Machinery placed on the market under the directive before that date may continue to be made available. 

Does the Cyber Resilience Act apply to machinery? 

Connected machinery that qualifies as a product with digital elements can fall under both the CRA and the Machinery Regulation. The two regulations address different questions, and CRA conformity doesn’t automatically satisfy the cybersecurity requirements in Annex III, Sections 1.1.9 and 1.2.1. Shared threat models, requirements, and test evidence can support both assessments. 

Is AI in machinery covered by the EU AI Act? 

The Digital Omnibus on AI, in force since July 27, 2026, removed the Machinery Regulation from the scope of the EU AI Act. AI safety functions in machinery answer to the Machinery Regulation, which requires notified body assessment for safety components with self-evolving behavior based on machine learning. The European Commission can add AI-related health and safety requirements through delegated acts under the Machinery Regulation. 

What counts as a substantial modification? 

A substantial modification is a physical or digital change, made after machinery is placed on the market or put into service, that the manufacturer didn’t foresee or plan and that affects safety by creating a new hazard or increasing an existing risk. Whoever makes the change takes on manufacturer obligations for the modified machinery. Software updates are included, so update processes need the same criteria as physical retrofits. 

ABOUT JAMA SOFTWARE 

Jama Software is focused on accelerating product velocity with AI-driven development across multidisciplinary engineering organizations. Using Jama Connect, engineering organizations can now adopt AI-driven development while intelligently managing the complexity and compliance of parallel development, automated pipelines, and industry standards. Our rapidly growing customer base spans aerospace & defense, automotive, medtech & life sciences, semiconductor, industrial manufacturing, consumer electronics, infrastructure, robotics, and energy. For more information about Jama Connect services, please visit www.jamasoftware.com 

See Jama Connect in Action!

Our Jama Connect experts are ready to guide you through a personalized demo for requirements management for medical device development, answer your questions, and show you how
Jama Connect can help you identify risks, improve cross-team collaboration, and drive faster time to market through AI-native engineering management.