Machinery & Equipment
Enhance your machinery safety expertise, reduce workplace hazards, and gain the skills to operate equipment responsibly.
The EU Machinery Regulation 2027 introduces major changes for machinery manufacturers, importers, distributors and system integrators. This guide explains new requirements for AI-enabled safety functions, cybersecurity, digital documentation, substantial modifications, conformity assessment, CE marking and practical preparation steps before 20 January 2027.
Enhance your machinery safety expertise, reduce workplace hazards, and gain the skills to operate equipment responsibly.
A manufacturer may currently produce machinery that complies with Machinery Directive 2006/42/EC. However, connected control systems, safety-related software, machine-learning safety functions, remote updates, or major digital modifications may create new compliance questions when Regulation (EU) 2023/1230 becomes generally applicable.
20 January 2027 is the principal application date that machinery manufacturers, importers, distributors, system integrators, and other affected organisations should mark in their compliance calendars.
The changes affect more than legal or product-compliance departments. Depending on the machinery and the organisation’s role, engineering, procurement, health and safety, cybersecurity, IT, maintenance, quality, technical documentation, and supply-chain teams may all need to participate.
Early preparation can reduce the risks of:
Understanding what is changing—and which products will be affected—will help organisations prepare before machinery is designed, purchased, modified, imported, or placed on the EU market.
From 20 January 2027, Regulation (EU) 2023/1230 will generally replace Machinery Directive 2006/42/EC for machinery and related products newly placed on the EU market or put into service.
The Regulation introduces or clarifies requirements concerning:
However, the Regulation does not mean that every machine already operating in an EU workplace must automatically be reassessed and CE marked again on 20 January 2027. The compliance position depends on when the machinery was placed on the market or put into service and whether it is subsequently substantially modified.
Regulation (EU) 2023/1230 on machinery establishes product-safety and market-access rules for:
It establishes essential health and safety requirements and governs activities such as:
Unlike a Directive, an EU Regulation is binding in its entirety and directly applicable across EU Member States. National legislation will still be relevant for matters such as enforcement authorities, penalties, workplace use, and occupational safety obligations.
The Machinery Regulation is primarily product legislation. It addresses the design, manufacture, conformity, and market placement of machinery.
It is not the same as an employer’s obligations concerning the safe use of work equipment.
Employers may also need to comply with:
A machine may have been legally placed on the market but still require suitable installation, guarding, inspection, maintenance, supervision, and operating procedures in the workplace.
The main transition timeline is:
|
Date |
Main Compliance Position |
|
Before 20 January 2027 |
Machinery placed on the EU market must generally comply with Machinery Directive 2006/42/EC |
|
From 20 January 2027 |
Regulation (EU) 2023/1230 generally becomes mandatorily applicable |
|
Preparation period |
Businesses should review designs, procedures, documentation, suppliers, and conformity-assessment responsibilities |
The European Commission’s official machinery legislation and compliance overview confirms that the Regulation generally applies mandatorily from 20 January 2027.
Machinery placed on the EU market before that date must comply with Machinery Directive 2006/42/EC.

Existing machinery does not automatically become non-compliant when the application date arrives.
As a general distinction:
Businesses should not assume that a general grace period will allow newly placed products to continue following the old Directive after the application date.
However, specific transitional provisions, existing certificates, product circumstances, and contractual arrangements may require individual assessment.

|
Area |
Machinery Directive 2006/42/EC |
Regulation (EU) 2023/1230 |
|
Legal form |
Implemented through national law |
Directly applicable EU Regulation |
|
Technology |
Developed before widespread connected and AI-enabled machinery |
Addresses safety-related software, self-evolving behaviour, and cyber-safety |
|
Documentation |
Primarily traditional documentation model |
Clarifies digital instructions and declarations |
|
Modifications |
No equally detailed statutory definition |
Defines substantial physical and digital modifications |
|
Higher-risk machinery |
Annex IV categories |
Updated Annex I Part A and Part B categories |
|
Economic operators |
Strong manufacturer focus |
Clearer importer, distributor, and authorised-representative duties |
|
Traceability |
Existing identification obligations |
Strengthened alignment with the EU New Legislative Framework |
|
Conformity assessment |
Directive procedures |
Updated procedures based partly on Annex I classification |
Key takeaway: The Regulation modernises machinery compliance, but it does not remove the need for risk assessment, inherently safe design, safeguarding, technical documentation, conformity assessment, or CE marking.

The Regulation addresses machinery and safety components whose safety functions use fully or partially self-evolving behaviour based on machine-learning approaches.
Organisations may need to consider:
This does not mean that every machine containing AI automatically becomes high-risk machinery or requires notified-body assessment.
The classification depends on the function of the system, the machinery category, and the applicable conformity-assessment provisions.
Cybersecurity becomes a machinery-safety issue when accidental corruption, unauthorised interference, or deliberate manipulation could create a physical hazard.
The Regulation addresses protection against corruption of:
Relevant risks may include:
General information security and machinery cyber-safety overlap, but they are not identical.
Machinery compliance teams should focus particularly on digital failures that could lead to physical injury or undermine an essential health and safety requirement.
The Regulation provides a specific definition of a substantial modification.
A physical or digital change may qualify when it:
A person who carries out a qualifying substantial modification may be treated as the manufacturer of the modified machinery and may assume responsibilities including:
Not every repair, replacement, software patch, upgrade, or change is automatically a substantial modification.
Businesses should assess modifications individually and document:

Annex I replaces the former Annex IV structure and divides listed machinery into Part A and Part B.
For machinery categories listed in Part A, manufacturer-only internal production control is not available as the sole conformity-assessment route.
The manufacturer must use an applicable procedure involving a notified body, such as:
Relevant categories include certain machinery and safety components presenting a higher risk factor.
For Part B machinery, internal production control may be available when:
Where these conditions are not met, a conformity-assessment route involving a notified body may be required.
Businesses should therefore:
Incorrect classification can cause certification delays, redesign, or restricted market access.
The Regulation aligns machinery legislation more closely with the EU New Legislative Framework.
Duties are established for:
Each operator must understand its position in the supply chain.
A company importing machinery from outside the EU cannot assume that all responsibility remains with the overseas manufacturer. Importers must perform specified checks and ensure required identification, documentation, and compliance information are present.
Distributors must exercise due care and identify obvious compliance deficiencies before making machinery available.
The Regulation permits instructions for use to be supplied digitally when the prescribed conditions are satisfied.
Digital instructions should be:
When a purchaser requests paper instructions at the time of purchase, the manufacturer must generally provide them free of charge within the prescribed period.
For machinery intended for non-professional users, essential safety information needed for putting the machinery into service and using it safely must also be supplied in paper form.
The EU declaration of conformity may also be made available digitally, subject to the Regulation’s conditions.
Digital delivery does not reduce the need for information to be:
Businesses should maintain controlled records covering:
A screenshot, uncontrolled cloud folder, or undocumented software version is unlikely to provide adequate evidence of compliance.
Manufacturers are responsible for matters including:
A business producing machinery for its own use may also be treated as a manufacturer when it puts that machinery into service.
An authorised representative may perform tasks specified in a written mandate.
However, the manufacturer cannot transfer every fundamental design and compliance responsibility to the representative.
Importers must verify matters such as:
Importers must also take action when they believe machinery is non-compliant or presents a risk.
Distributors must exercise due care and check visible compliance elements before making machinery available.
They should not distribute machinery when they know—or should reasonably know—that required compliance elements are missing.
A system integrator combining machines into a production line may become the manufacturer of an assembly of machinery.
Responsibilities may include:
The compliance of each individual machine does not automatically establish the compliance of the complete assembly.
A person carrying out a substantial modification may become the manufacturer of the modified machinery.
Modification-management procedures should therefore involve engineering, maintenance, safety, cybersecurity, and compliance personnel before work begins.
Employers are generally responsible for safe workplace use rather than original product conformity.
Their responsibilities may include:
However, an employer may acquire manufacturer responsibilities if it builds machinery, creates an assembly, or substantially modifies equipment.

Train relevant personnel in:
Professionals responsible for machinery inspections, safeguarding, risk assessment, and hazard control can further strengthen their knowledge through structured machinery and equipment safety training.
The EU and US systems may share safety objectives, but they perform different legal functions.
The EU Machinery Regulation primarily addresses:
OSHA primarily addresses employer duties to protect workers in US workplaces.
OSHA 29 CFR 1910.212 requires one or more guarding methods to protect operators and other employees from hazards including:
The standard also requires point-of-operation guarding where machine operation exposes employees to injury.
OSHA 29 CFR 1910.147 addresses servicing and maintenance where unexpected energisation, startup, or release of stored energy could injure employees.
It requires an energy-control programme and procedures for isolating or disabling machines under the circumstances covered by the standard.
A CE-marked machine is not automatically compliant with every OSHA workplace requirement.
Similarly, compliance with OSHA guarding or lockout requirements does not automatically demonstrate conformity with the EU Machinery Regulation.
A business operating across both markets should separately evaluate:
Businesses should avoid:
The EU Machinery Regulation is not simply a documentation update.
It connects machinery product safety more clearly with:
Organisations should begin gap assessments before machinery is designed, ordered, imported, integrated, modified, or placed on the EU market.
Priority actions include:
Early preparation can help businesses avoid late redesign, certification delays, incomplete documentation, and disruptions to EU market access.
Building practical knowledge of machinery hazards, risk assessment, safeguarding, inspections, and control measures can also support safer equipment management and more effective compliance programmes.Organisations and professionals seeking to develop practical machinery and equipment safety knowledge can explore the Machinery & Equipment course as part of a wider occupational safety development programme.
Disclaimer: This article provides general educational information. It does not replace machinery-specific engineering assessment, notified-body advice, conformity-assessment support, or legal advice.
The EU Machinery Regulation 2027 is Regulation (EU) 2023/1230, which updates machinery product-safety requirements and generally replaces Machinery Directive 2006/42/EC from 20 January 2027.
The EU Machinery Regulation generally becomes mandatory from 20 January 2027 for machinery and related products newly placed on the EU market or put into service.
No. Existing machinery does not automatically require new CE marking when the Regulation applies. The compliance position depends on when the machinery was placed on the market and whether it has been substantially modified.
Key changes include requirements for AI-related safety functions, cybersecurity, digital instructions, software traceability, substantial modifications, higher-risk machinery categories and clearer responsibilities for economic operators.
A substantial modification is a physical or digital change made after machinery is placed on the market that was not planned by the manufacturer, creates a new hazard or increases an existing risk affecting machinery safety.
Responsibilities are shared between manufacturers, authorised representatives, importers, distributors, system integrators, modifiers and employers depending on their role in designing, supplying, modifying or using machinery.
Businesses should review machinery portfolios, update risk assessments, evaluate software and cybersecurity risks, confirm conformity-assessment routes, improve technical documentation, manage modifications and train responsible personnel before 2027.