The Guide to the New European Machinery Regulation (EU) 2023/1230 Replacing the Old Machinery Directive 2006/42/EC
- C Pickup
- Apr 15
- 5 min read
In 2020, under the commission's initiative ‘A Europe fit for the Digital Age’, an impact assessment of the Machinery Directive identified several gaps. These included the need to address emerging technology risks, clarify scope definitions, enhance provisions for high-risk machinery, promote digital documentation, and resolve divergences in transposition. The assessment emphasized the importance of updating regulations to ensure safety, legal clarity, and technological adaptation, aligning the Machinery Regulation (EU) 2023/12301 with current industry and safety standards.
The Machinery Regulation (EU) 2023/12301 addresses gaps identified in the 2020 impact assessment, focusing on emerging risks, scope clarity, high-risk machines, digital documentation, and transposition divergences. For OEMs, it replaces the Machinery Directive 2006/42/EC, introducing new compliance pathways, revised annexes, enhanced safety requirements, digital documentation, and cybersecurity standards, ensuring better safety and technological adaptation in the EU market.
All new Machines must comply with the requirements of Regulation (EU) 2023/1230 and be accompanied by an EU Declaration of Conformity under that regulation by the 20 January 2027
The updated machinery regulation introduces significant changes, notably the reorganization of annexes from the existing directive 2006/42/EC, emphasizing evolving technologies and cybersecurity threats. Annex I now delineates categories of machinery and related products, divided into Part A and Part B.
Annex I
Part A incorporates safety components and embedded safety systems with self-evolving capabilities, utilizing machine learning to ensure safety functions. This reflects a move towards integrating artificial intelligence into machinery safety.
Part B encompasses most of the machinery listed in Annex IV of the current directive, excluding specific items such as removable mechanical transmission devices, their guards, vehicle servicing lifts, and portable impact machinery. These excluded items are now classified under Part A. The restructuring aims to enhance safety standards, accommodate technological advancements, and address cybersecurity concerns, ensuring the regulation remains relevant in a rapidly changing technological landscape.
Annex II provides an indicative list of safety components, including embedded safety systems that utilize fully or partially self-evolving behaviour through machine learning approaches to ensure safety functions. It also introduces filtration systems designed for integration into machinery cabins, aimed at protecting operators and others from hazardous materials and substances, such as pesticides. The annex further encompasses filters used in these filtration systems, emphasizing safety and protection in industrial environments.
Annex III
Essential health and safety requirements (EHSRs)
This Annex has seen a number of significant additions including:
Ergonomics (Clause 1.1.6) gives consideration to how operators interact with machinery or related products that have either fully or partially self-evolving behaviour.
Protection against corruption (Clause 1.1.9) introduces cyber security requirements related to OT (Operational Technology) and has been added to cover the increase in industrial networks for safety systems, and also the generation of data to support the growth of connected enterprise solutions. It covers both hardware and software requirements.
Autonomous mobile machinery (Clause 3.6.3.3) gains extra requirements, which are included in annex III and the supplementary essential health and safety requirements to offset risks due to the mobility of machinery or related products.
Machinery must ensure that connecting additional devices, whether locally or remotely, does not create hazardous conditions. Critical hardware components that transmit signals or data and have access to essential software for compliance with health and safety standards require robust protection against both accidental and intentional corruption. These components should also record evidence of any legitimate or illegitimate interventions. To safeguard against corruption, software and data vital for the machinery's compliance must be clearly identified and adequately protected from unauthorized modifications or damage. The machinery or related products should be capable of identifying all installed software necessary for safe operation and must be able to provide this information readily and at any time. Additionally, they should collect and preserve evidence of any interventions or modifications—whether legitimate or illegitimate—in the software or its configuration. This approach ensures ongoing compliance with safety standards, enhances traceability, and supports effective maintenance and incident investigation, ultimately contributing to safer machinery operation and regulatory adherence.
Safety and reliability of control systems (Clause 1.2.1)
Control systems shall be designed and constructed in such a way as to prevent hazardous situations from occurring. They also should withstand where appropriate to the circumstances and risks, the intended operating stresses and intended and unintended external influences, including reasonably foreseeable malicious attempts from third parties leading to a hazardous situation.
The connection between safety and cybersecurity is clearly demonstrated in this context. It emphasizes the importance of maintaining a comprehensive tracing log that records data related to interventions and the versions of safety software uploaded after machinery or related products are introduced to the market or put into service. This logging must be maintained for a minimum of five years post-upload, solely to verify compliance with relevant Essential Health and Safety Requirements (EHSRs) upon request from a competent national authority. For original equipment manufacturers (OEMs) developing control systems or logic with autonomous or semi-autonomous capabilities, additional stipulations are included in the EHSRs outlined in Annex III. These systems must not cause machinery or related products to perform actions outside their designated tasks or operational boundaries. Furthermore, data recording concerning safety-related decision-making processes in software-based safety systems is mandatory. This data must be enabled and preserved for at least one year after the machinery or product is placed on the market or commissioned. It is also essential that machinery or related products remain correctable at all times to uphold their inherent safety standards. These measures ensure ongoing safety compliance, facilitate traceability, and support corrective actions, thereby reinforcing the integral link between safety protocols and cybersecurity practices in machinery and product safety management.
The introduction of new definitions;
Substantial modifications – explanation of Article 3 (16) After being placed on the market or put into service, should machinery be modified, by physical or digital means (meaning hardware or software), in a way that is not foreseen by the manufacturer, and which affects the safety of such products by creating a new hazard or increasing an existing risk, the modification should be considered as substantial when significant new protective measures are required. The person that carries out the substantial modification should be required to perform a new conformity assessment before placing the modified product on the market or putting it into service. This conformity assessment can be restricted to the part of the production line that has been modified, and so does not have to be completed for the whole assembly.
Compliance Route
There is more emphasis in the regulation for third-party certification on certain machines. However, self-certification is still possible as long as the machinery is in Annex I Part B and is built preferably using harmonized standards or a common specification. If the machinery is not in Annex I, the preferred route is to follow harmonized standards. The compliance route for this type of equipment is in Annex VI module A. For all other equipment, third-party certification through a notified body is required. The route to compliance is covered in Annexes VII VIII & IX of the Machinery Regulation (EU) 2023/12302.
None Compliance
Article 50 empowers member states to define the exact size of the fines and penalties against the Machinery Regulations (EU) 2023/1230. Although not yet confirmed it is expected that these will align with other recent directives, such as the Network & Information Security Directive (NIS2) which can impose fines of up to €10,000,000 or 2% of global annual revenue.
Going Forward
If you need assistance with upcoming regulatory changes, contact the CE Marking Authority. We provide customized compliance management services to guide you through obtaining the CE mark and ensuring adherence to relevant regulations. Our UK-based experts specialize in UKCA and CE Marking, offering scalable solutions tailored to your product compliance requirements. We conduct comprehensive risk assessments and generate detailed reports to maintain your products' compliance throughout their lifecycle. Our goal is to empower your business to meet industry standards confidently, minimizing risks and ensuring smooth market entry and ongoing compliance.
Tel +44 1779 841842
Mobile +447910 523528




Comments