From 20 January 2027, the EU Machinery Regulation generally applies with safety-linked cybersecurity requirements for products within its scope. Manufacturers should build product-specific security evidence into development and conformity work early.
Plan for cybersecurity as part of product safety
For machinery manufacturers, product managers and engineering leaders, cybersecurity can no longer be treated solely as a late-stage technical addition. Regulation (EU) 2023/1230, the Machinery Regulation, generally applies from 20 January 2027 and brings safety-linked cybersecurity requirements into the essential health and safety requirements for products within its scope.
This does not turn the Regulation into a general cybersecurity code for every industrial system or organisation. Its scope covers machinery, certain related products and partly completed machinery, subject to its definitions, exclusions and other scope rules. The starting point is therefore the individual product and its intended conformity route.
The practical consequence is clear: where digital connections, software, data or control systems can contribute to a hazardous situation, those risks need to be considered during product development and documented as part of conformity work.
Protection against corruption
Annex III section 1.1.9 addresses protection against corruption. It requires that connecting another device, using a feature of a connected device, or communicating through a remote device must not lead to a hazardous situation.
The provision also includes separate requirements concerning specified safety-relevant hardware, software and data. These address protection from accidental or intentional corruption, the identification of software installed for the safe operation of machinery or a related product, and evidence of intervention where relevant.
The emphasis matters. The legal requirement is linked to safety and hazardous situations. It is not a blanket statement that every digital element must meet the same control or that a product must withstand every possible attack.
Control systems and foreseeable malicious attempts
Annex III section 1.2.1 covers the safety and reliability of control systems. Control systems must be designed and constructed to prevent hazardous situations. Where appropriate to the circumstances and risks, they must also withstand reasonably foreseeable malicious attempts by third parties that could lead to a hazardous situation.
This calls for a product-specific assessment. A remote maintenance connection, update mechanism, network interface or exchange of data with another system may create a path that deserves attention. The relevant question is how that path could affect safety, rather than whether the product is simply described as connected.
The official text of Regulation (EU) 2023/1230 sets out both requirements in Annex III.
Risk assessment and technical documentation
The Regulation's general principles require manufacturers to carry out a risk assessment to determine the applicable essential health and safety requirements and address the relevant hazards and risks. Digital threats should therefore be connected to the safety hazards they could create for the product concerned.
Technical documentation must then show how conformity has been ensured. Under Annex IV, this includes the risk-assessment procedure, applicable requirements, protective measures and relevant residual risks. One generic cybersecurity document is not a substitute for product-specific technical documentation.
A useful preparation sequence is:
- Define the product and role scope, including interfaces, remote access and relevant connected devices.
- Identify digital paths that could contribute to hazardous situations.
- Integrate appropriate safeguards and supporting evidence into design and development activities.
- Record the applicable requirements, protective measures and residual risks in the technical documentation.
- Verify the applicable conformity-assessment route for the product.
This is a practical planning method, not a determination of conformity for a particular product.
Treat standards status carefully
Standards may help manufacturers structure their work, but their status matters. DIN Media lists DIN EN 50742:2026-03 as a draft based on prEN 50742:2025, with an issue date of 20 February 2026 and publication in March 2026.
A draft is not the same as a harmonised standard. Under Article 20 of the Machinery Regulation, a harmonised standard can support a presumption of conformity only for the Annex III requirements it covers and only once its reference has been published in the Official Journal of the European Union. A standardisation request, draft, enquiry or national publication does not by itself create that presumption.
Manufacturers that use established industrial cybersecurity practices may find them helpful when developing their approach. They should not assume, however, that use of another standard automatically establishes conformity with the Machinery Regulation.
Keep related instruments separate
Products may also fall within the scope of other EU instruments. For products within both the Machinery Regulation and the Cyber Resilience Act, recital 53 of the Cyber Resilience Act indicates that manufacturers should comply with both sets of requirements, demonstrate relevant synergies after a cybersecurity risk assessment, and follow the applicable conformity-assessment procedures.
That does not make conformity with one instrument automatic conformity with the other. Scope, obligations, dates and procedures should be assessed separately.
Start before the deadline
Machinery often has long development cycles. Products now being designed for market placement in 2027 or later may need cybersecurity considerations built in from the outset.
Starting early creates time to establish responsibility, understand the product's digital paths to safety hazards, integrate safeguards into development and collect the evidence needed for the applicable conformity route. The goal is not a last-minute security file, but a development process that can explain how the relevant safety-linked cybersecurity risks were assessed and addressed.