Rapid technological changes in digital transformation and Industry 4.0 are creating new industrial challenges and opportunities. In line with this, the European Parliament recently approved the new Regulation on machinery well, and this causes existing regulations to have to be adapted to meet the requirements of a modern factory. The ‘Regulation (EU) 2023/1230 on machinery’ will come into force in 2027. What do companies need to know to prepare for the successor to the Machinery Directive?
The most notable change in these health and safety regulations is the focus on the technological development of machinery. This pays special attention to the risks associated with new technologies such as the Internet of Things and artificial intelligence. Machinery manufacturers must ensure that all products they place on the EU market after 19 January 2027 comply with the new ‘Machinery Regulation on Machinery’. In view of the long lead times of manufacturing processes, it is wise to start compliance planning soon.
The ‘Machinery Regulation on Machinery’ provides new definitions, roles and responsibilities for all economic players in the supply chain (such as importers and distributors). Each of these parties is assigned specific responsibilities for ensuring conformity with the Machinery Directive. This emphasises and reinforces the current focus on the supply chain and verification of correct identification and documentation for equipment.
Another central concern is cybersecurity. It is necessary to design machines and related products that minimise security risks caused by connections to the outside world. The Fortinet OT Security Platform offers a solution to these challenges with network connections specifically designed for operational technology (OT), support for zero trust security and SecOps solutions.
The new machinery regulation is part of a broader framework of cybersecurity directives and highlights the need to consider security during all stages of production.
For organisations, it is crucial to consider security risks within the workflow for assessing risks around machine safety, keep track of all software used and choose parts with care. Another important aspect is managing alignment with third-party ecosystems. Care must be taken to ensure that these meet the requirements of the latest cyber security guidelines. The Cyber Security Resilience Act (CRA) regulation, enacted on 23 October 2024, specifically addresses aspects of security throughout the lifecycle of products with digital components.
The following recommendations can help machine builders deal effectively with this new regulatory landscape: