EU Regulation & Compliance · 2026-09-30 · 13 min read

Machinery Regulation meets Cyber Resilience Act: two regulations, one interface, and why the cyber duty has applied since September

Michael Kaiser

Michael Kaiser

Co-Founder & Head of Systems, Vincency

The short answer first: if you build or retrofit a machine with digital elements, two EU regulations now read the same product, and they started on different dates. The Machinery Regulation (EU) 2023/1230 becomes mandatory on 20 January 2027 and brings explicit cyber-safety requirements for conformity-relevant software for the first time. The Cyber Resilience Act (EU) 2024/2847 has already obliged manufacturers to report incidents and exploitable vulnerabilities since 11 September 2026. Whoever treats them as two separate projects will build the same documentation twice.

This guide is written for the machine builder and its software supplier, not for the certifier. It covers what each regulation demands, where they overlap, and the one trigger both share: the substantial modification that turns an update into a re-certification.

The two timelines, side by side

DateRegulationWhat changes
11 Sep 2026Cyber Resilience Act, Art. 14Active reporting obligations for incidents and exploitable vulnerabilities begin, for products already on the market.
20 Jan 2027Machinery Regulation (EU) 2023/1230Replaces Directive 2006/42/EC; software counts as a safety component, cyber-safety and AI-powered safety functions become conformity requirements.
11 Dec 2027Cyber Resilience Act, main obligationsFull cybersecurity requirements for products with digital elements over their whole lifecycle become binding.

The dates matter because they refuse to queue politely. The CRA's reporting duty is already live while the Machinery Regulation is still eleven months away, and the CRA's main obligations land eleven months after it. Between them sits the product lifecycle of every machine that ships in between, and each one will have to answer to both.

What the Machinery Regulation adds that the directive never had

The Commission's machinery page lists the changes plainly: the regulation integrates provisions for cyber-safety of conformity-relevant software data and safety control systems, provisions for machinery with AI-powered safety functions, and it clarifies that instructions and the declaration of conformity can be provided digitally. Under Directive 2006/42/EC none of this was explicit; the machine's software lived in a footnote. Under the regulation it is a named requirement, which means the auditor can now fail it.

The same page confirms the trigger that decides whether an old machine becomes a new obligation: a substantial modification. Our earlier piece on the software-update side walked through Article 18 and the two-letter carve-out in Article 3(16) that keeps most routine updates out of scope; the short version is that a change to a safety function can requalify you as the manufacturer, and from January 2027 that assessment runs against the new requirements, not the old directive.

Where the Cyber Resilience Act picks up the same product

The Commission's CRA summary sets the second clock: in force since 10 December 2024, reporting obligations under Article 14 since 11 September 2026, main provisions from 11 December 2027. And it shares the MVO's trigger logic: products placed on the market before 11 December 2027 only fall fully under the CRA if they undergo a substantial modification afterwards. The reporting duty, however, applies to everything already on the market, no grandfather clause for incidents.

The overlap is the product that is both: a machine whose safety or function depends on software with digital elements. That covers the embedded controller in a press, the HMI on a packaging line, the networked drive in a conveyor. For that product the MVO asks whether the software keeps the machine safe, and the CRA asks whether the software keeps itself safe. Both answers live in the same engineering file.

What a mid-market manufacturer should do before January

Four steps, in order. First, inventory the software-bearing safety functions: which products have controllers, firmware or connected components whose failure could hurt someone. Second, map each one against both requirement lists, because the MVO conformity file and the CRA technical documentation reference the same versions. Third, fix the reporting channel now, since the CRA's duty is already live: whoever learns of an actively exploited vulnerability today owes a notification, whether or not the rest of the file is ready. Fourth, decide the update policy, because every future software change is a potential substantial modification and should be triaged, not improvised.

The regulatory stack keeps growing sideways: the CRA reporting piece covers the September deadline in detail, and the NIS2 incident duty applies to the same events at company level if you sit in a covered sector. One incident can owe three reports.

The honest remainder

Two qualifications keep this honest. First, the detailed conformity mechanics depend on the harmonised standards; the Commission notes the first MVO list is expected before year-end, and until it lands, some questions sit in interim. Second, this is orientation, not legal advice: whether a specific update crosses the substantial-modification line is an engineering and legal judgment on the actual change, not a rule of thumb.

Whoever takes one sentence from this piece: the two regulations do not ask two different questions; they ask the same question about the same software from two directions, and the company that builds one lifecycle file answering both will be done while competitors are still explaining to two auditors why the folders disagree.

Related service

IT strategy as a guided service

The analysis described here can be done in house. If you lack the time or the distance from your own systems, we take it on: inventory, a prioritised order and, if you wish, the implementation.

IT strategy consulting

Frequently asked questions about the Machinery Regulation and the Cyber Resilience Act

Does the new Machinery Regulation already apply?

Not yet, but nearly. Regulation (EU) 2023/1230 applies on a mandatory basis from 20 January 2027; until then Directive 2006/42/EC remains the binding norm. The Commission already permits voluntary declaration under the new regulation, and the Cyber Resilience Act has required active reporting of incidents and exploitable vulnerabilities since 11 September 2026.

What does cyber-safety in the Machinery Regulation mean concretely?

The Commission puts it this way: the regulation brings explicit cybersecurity requirements for conformity-relevant software data and safety control systems for the first time, plus rules for machinery with AI-powered safety functions. Concretely: whoever sells a machine whose safety depends on software must show that software is protected against manipulation and that the safety logic cannot be corrupted remotely.

When am I affected by both regulations at once?

Exactly when your product is a machine with digital elements, which today describes nearly every machine with its own control. The Machinery Regulation governs the safety of the product, the Cyber Resilience Act the cybersecurity of the digital element across its whole lifecycle. An embedded controller, an HMI or a networked drive sits in both books.

What does substantial modification mean here?

Both regulations share the same trigger: whoever substantially modifies a product already on the market becomes legally the manufacturer and must reassess conformity. Under the old directive this was a grey zone; under the regulation it is codified. A software update that changes a safety function can trigger it; an update that only recolors a display does not.

Do I have to keep both documentations separately?

No, but you have to read both. The MVO requires technical documentation proving the essential safety requirements, the CRA requires it for the cybersecurity of the digital element, and both allow digital formats. The practical advice: one lifecycle document mapping both requirement lists against the same software version, rather than two parallel folders drifting apart.

Sources, status and note: Both regulations were read at the Commission's own pages, retrieved on 30 September 2026: the Commission machinery page for the 20 January 2027 application date and the cyber-safety and AI provisions, and the Commission CRA summary for the reporting duty since 11 September 2026 and the full application on 11 December 2027, plus the regulation text on EUR-Lex. This is orientation, not legal advice; whether a specific change crosses the substantial-modification line is an individual assessment.