Regulations

EU Machinery Regulation (EU) 2023/1230 — what changes on 20 January 2027

The new Machinery Regulation replaces Directive 2006/42/EC with no transition period. Six categories lose self-certification, cybersecurity becomes a safety requirement, and documentation can go digital.

Author: myDPP Team

EU Machinery Regulation (EU) 2023/1230 — what changes on 20 January 2027

The Machinery Directive 2006/42/EC lasted two decades and became as unremarkable to machine builders as mains electricity. In under eighteen months it stops applying. From 20 January 2027, all machinery placed on the EU market must comply with Regulation (EU) 2023/1230 — and there is no transition window in which both regimes run side by side.

For most manufacturers this is not a cosmetic change. The legal form of the act changes, so does the list of machinery requiring a notified body, the status of software and cybersecurity in risk assessment, the definition of substantial modification, and the form in which instructions and the declaration of conformity may be supplied. That last point pulls machinery into the same movement the digital product passport is bringing to other sectors: the compliance document stops being a sheet of paper in the crate and becomes a data record that has to stay reachable for a decade.


Key takeaways

  • Regulation (EU) 2023/1230 of 14 June 2023 (OJ L 165, 29.06.2023, in force 19 July 2023) applies from 20 January 2027 and repeals Directive 2006/42/EC on the same date.
  • There is no transition period. Machinery placed on the market before 20 January 2027 under the Directive stays lawful and can continue to be made available; EC type-examination certificates remain valid until they expire. But every machine placed on the market from that date must meet the Regulation.
  • A regulation rather than a directive means direct applicability — no national transposition and no 27 interpretations. Member States legislate only enforcement and penalties (in Germany, the MaschinenDG).
  • The old Annex IV becomes Annex I, split into Part A and Part B. The six categories in Part A lose the self-certification route — notified body involvement is mandatory even when harmonised standards are applied in full.
  • Among them are safety components with self-evolving behaviour based on machine learning, and machinery embedding such systems. This is the first explicit treatment of machine learning in EU machinery safety law.
  • Cybersecurity becomes an essential health and safety requirement (now in Annex III): protection against both accidental and intentional corruption of safety-related software and data.
  • Substantial modification is defined in EU law for the first time — whoever makes one becomes the manufacturer for the aspects affected.
  • Instructions and the declaration of conformity may be digital, provided they stay available for the expected lifetime of the machinery and at least 10 years. A paper version must be supplied free of charge within one month on request at purchase. For non-professional users, safety information essential for putting into service and use must be on paper regardless.
  • myDPP does not carry out conformity assessment, is not a notified body and does not issue declarations of conformity. myDPP stores, versions and serves verified product data and provides the data carrier that opens it.

From directive to regulation — what that actually changes

The difference between a directive and a regulation is often treated as legal trivia. In machinery practice it is very concrete. A directive must be transposed into national law, and each Member State transposes it in its own language and its own enforcement culture. A manufacturer exporting to ten Member States therefore faced one EU text and ten readings of it.

A regulation applies directly and identically across the Union. National law is still needed for what the Regulation does not settle — designating market surveillance authorities, procedures and penalties. In Germany that role falls to the implementing act (MaschinenDG). The effect for manufacturers: the wording of the requirements stops depending on the destination market, and interpretive divergence moves from the text of the law to enforcement practice.

The second structural change is quieter but reorganises the whole document. The essential health and safety requirements, which lived in Annex I of the Directive, move to Annex III. Their old place is taken by a new Annex I listing the categories subject to a special assessment procedure. Anyone whose technical documentation cites annex numbers has a simple but wide-reaching housekeeping job here.

What the Regulation covers

The scope stays recognisable, but the vocabulary has changed. The Regulation works with three concepts:

  • Machinery — close to the previous meaning: an assembly of parts or components, at least one of which moves under a drive system.
  • Related products — a collective category covering interchangeable equipment, safety components, lifting accessories, chains, ropes and webbing, and removable mechanical transmission devices. The Directive listed these separately; they now share a name and a regime.
  • Partly completed machinery — still a separate route, with a declaration of incorporation and assembly instructions instead of a declaration of conformity.

What is new is that the Regulation treats software and connectivity as part of the machine rather than its surroundings. Software ensuring safety functions and placed on the market independently is a safety component. That has consequences for anyone selling controllers, safety function libraries and updates as a product.

Six changes you need to know

Annex I Part A — the end of self-certification for six categories

This is the most expensive change for the manufacturers it touches. The old Annex IV listed hazardous machinery for which the manufacturer could choose internal control if harmonised standards were applied in full; otherwise a notified body stepped in. The new Annex I splits that list into two parts with different rigour.

Part A covers six categories where notified body involvement is always mandatory — full application of harmonised standards no longer opens the self-assessment route:

  1. Removable mechanical transmission devices, including their guards.
  2. Guards for removable mechanical transmission devices.
  3. Vehicle servicing lifts.
  4. Portable cartridge-operated fixing and other impact machinery.
  5. Safety components with fully or partially self-evolving behaviour using machine-learning approaches and ensuring safety functions.
  6. Machinery embedding such systems where those systems have not been placed on the market independently — in respect only of those systems.

Part B is the longer list, largely carried over from the old Annex IV, where self-assessment remains available when harmonised standards are applied in full.

The practical conclusion: if a product lands in Part A, planning has to account for a notified body’s queue and lead time. The rules on designating and notifying conformity assessment bodies apply earlier than the rest of the Regulation — from 20 January 2024 — precisely so that bodies can be designated against the new requirements in time. That does not mean capacity will be there for everyone in the final quarter before the deadline.

Machine learning in safety functions

This is the first EU machinery act to address self-evolving systems head-on. The reason given in the recitals is matter-of-fact: data dependency, opacity, autonomy and connectivity can considerably increase both the probability and the severity of harm.

It is worth being precise here, because the topic is easy to inflate. The Regulation does not put every machine containing any machine-learning algorithm under a special regime. What lands in Part A is a system that ensures a safety function and whose behaviour evolves fully or partially after being placed on the market. A vision model sorting products by quality is not a safety component. The same model taking over the decision to stop the machine when a person enters the working zone is.

Cybersecurity as a safety requirement

The essential requirements in Annex III now include protection against corruption of safety-related software and data — both accidental and intentional. Tampering with the control system stops being a matter of the customer’s IT policy and becomes part of the manufacturer’s risk assessment and technical documentation.

An evidentiary duty follows. The manufacturer must be able to show how the integrity of safety-related software is protected, how safety-relevant events are recorded, and how the legitimacy of updates is verified. For many companies that means control software version data has to be tied to an individual machine — not just to a type.

Substantial modification defined in law

Until now, “substantial modification” of machinery was a construct built from enforcement practice and national guidance, and it differed between Member States. The Regulation defines it explicitly: a physical or digital change made after placing on the market or putting into service, not foreseen or planned by the manufacturer, which affects safety by creating a new hazard or increasing an existing risk.

Whoever makes such a modification becomes the manufacturer for the aspects of the machinery affected and must carry out a new conformity assessment — limited to what the modification touches. Updates carried out by the manufacturer and foreseen by them are, as a rule, not substantial modifications.

For industrial users, integrators and anyone retrofitting a machine park, this has real consequences. A control retrofit, adding a robot to an existing line, changing safety logic in software — each now has to be assessed against a statutory definition rather than a local reading.

Digital documentation: instructions and declaration

This is the one change that removes work rather than adding it — provided the data is in order.

Instructions for use may be supplied in digital format. The conditions: the manufacturer states on the machinery, its packaging or an accompanying document how to reach them; the user must be able to print, download and save them; the content must remain available online for the expected lifetime of the machinery and in any case for at least ten years after it was placed on the market. Anyone asking for a paper version at the time of purchase gets it free of charge within one month. For machinery intended for non-professional users — or which may reasonably be expected to be used by them — the safety information essential for putting the machine into service and using it safely must be supplied in paper form regardless.

The EU declaration of conformity works the same way: it may be supplied with the machinery, or as an internet address or machine-readable code from which it can be retrieved, under the same availability duration. We cover the wider shift in our article on when the passport replaces the declaration of conformity.

Software and the post-sale lifecycle

Earlier regimes in practice lost interest in a machine at the moment it was placed on the market. The Regulation no longer holds that assumption: software updates, a decade of documentation availability and protection against deliberate interference are obligations stretched across years of service life. A manufacturer with no way to say which software version and which instruction version a five-year-old serial number shipped with will struggle under this regime.

Timeline

DateWhat happens
14 June 2023Regulation (EU) 2023/1230 adopted
29 June 2023Published in the Official Journal (L 165)
19 July 2023Entry into force
20 January 2024Provisions on conformity assessment bodies apply — designation and notification
20 July 2024Selected procedural and empowering provisions apply
20 January 2027Full application; Directive 2006/42/EC repealed

Machinery placed on the market before 20 January 2027 in accordance with Directive 2006/42/EC may continue to be made available and does not require recertification. EC type-examination certificates issued under the Directive remain valid until they expire.

What this means for product data

The Machinery Regulation does not establish a digital product passport. Worth saying plainly, because the two get confused: the passport obligation comes from ESPR and from sectoral acts that mandate it explicitly — the Toy Safety Regulation, the Construction Products Regulation, the Batteries Regulation. Machinery is covered by none of them today.

The direction of travel is the same, though, and the data requirements overlap enough to be worth exploiting:

  • A persistent unit identifier. Ten-year documentation availability only means anything if you can say unambiguously which machine a record belongs to. That is the same precondition every passport implementation starts from.
  • A resolvable data carrier. A machine-readable code leading to a declaration and instructions is technically the same thing as a code leading to a passport. We compare the variants in our article on QR code vs GS1 Digital Link.
  • Versioning instead of overwriting. Instructions and declarations describe the machine as it was on the day it was placed on the market. Updating the content cannot erase the earlier state, since five-year-old machines are still running.
  • Multilingualism as a data model property. Instructions must be in the language of the Member State where the machine is made available. With digital documentation this stops being a translation project and becomes a field that has versions.
  • Hosting continuity. Ten years of resolvability is a service commitment that has to survive system migrations, domain changes and a change of provider.

Get these right once and they serve both the Machinery Regulation and a future ESPR delegated act, should one cover industrial products. If you are starting from the data side, our article on why product data is the foundation of the DPP is the place to begin; the full field inventory is in our DPP data requirements list.

An honest note on where a provider’s role ends: myDPP does not perform risk assessment, does not assess conformity against Annex III, is not a notified body and does not issue or sign declarations of conformity. It stores, versions and serves verified data and keeps the carrier resolvable. Responsibility stays with the manufacturer.

Preparing — five steps

  1. Check whether any product lands in Annex I Part A. This is the only change that can add months to time-to-market. If it does, start the notified body conversation now, not in 2026.
  2. Revisit risk assessment for software and connectivity. Ask concrete questions: which safety functions depend on software, how are they protected against deliberate interference, how is update authenticity verified, what gets logged.
  3. Fix annex references in your documentation. The essential requirements are now Annex III. Declaration templates, checklists and technical documentation all need a pass.
  4. Decide on digital documentation — and where it lives. If you want to use the digital instructions and declaration option, ten-year availability has to be settled at architecture level rather than deferred. Establish who maintains the identifiers and what happens to them at a system change.
  5. Set a policy on substantial modifications. Agree with service, integrators and customers who assesses post-sale changes and who becomes the manufacturer if one occurs.

Our DPP implementation checklist walks through the wider data programme.

Frequently asked questions

Do I have to recertify machines sold before 2027?

No. Machinery placed on the market before 20 January 2027 in accordance with Directive 2006/42/EC remains compliant and can continue to be made available. EC type-examination certificates stay valid until they expire. One caveat: a substantial modification of such a machine after that date triggers a new conformity assessment — under the Regulation.

Does the Machinery Regulation introduce a digital product passport for machinery?

No. It introduces the option of supplying instructions and the declaration of conformity digitally, with an availability requirement covering the expected service life and at least ten years. The passport obligation comes from ESPR and from sectoral acts that mandate it explicitly; machinery is covered by none of them today. The data requirements do converge, though, so one clean-up serves both.

Does every machine with an AI algorithm now need a notified body?

No. What lands in Annex I Part A are safety components with fully or partially self-evolving behaviour based on machine learning that ensure a safety function, and machinery embedding them — in respect only of those systems. An algorithm optimising throughput or sorting products does not perform a safety function and does not on its own trigger this.

Can I drop paper instructions entirely?

Not quite. Instructions may be digital if the availability conditions are met, but a paper version has to be supplied free of charge within one month to anyone who asks for it at purchase. For machinery used by non-professional users, the safety information essential for putting it into service and using it safely must be on paper in every case.

Sources