What changes on 20 January 2027
Regulation (EU) 2023/1230 replaces Directive 2006/42/EC. As a regulation, it applies directly in all Member States without transposition.
It updates the essential health and safety requirements to account for connected machinery and software performing safety functions.
Protection against corruption
Machinery must be designed so that connecting another device or remote access does not create a hazardous situation. Safety-critical hardware and software must be protected against accidental or malicious alteration, and interventions must be traceable.
Safety and reliability of control systems
Control systems must withstand external influences, including malicious attempts, and a failure must not lead to a hazardous situation.
Machinery with evolving behaviour
The regulation addresses machinery whose behaviour evolves, notably when it embeds AI: the risk assessment must cover this evolution, and the limits within which the machine may evolve must be defined.
The link with the Cyber Resilience Act
A connected machine is also a product with digital elements under the CRA. The two texts complement each other: CRA compliance can help demonstrate the protection-against-corruption requirements. It is more efficient to address them together.
Checklist
- Identify machines in your range placed on the market after 20 January 2027
- Include cybersecurity threats in the risk assessment
- Protect safety-critical software and parameters against unauthorised changes
- Log interventions and changes on safety functions
- Define the limits of evolution for AI-based functions
- Update the technical file and the declaration of conformity
- Address CRA requirements in parallel
Information current as of 28 September 2026. Laws and timelines change: this guide is not legal advice.
Related servicesCyber Resilience Act compliance for your connected products

