What actually changes for machine builders and retrofit projects?
Author: Christophe Huyghe - Safety Expert
From 20 January 2027, the Machinery Regulation (EU) 2023/1230 replaces the Machinery Directive 2006/42/EC. That sounds like an administrative change. A new reference number on your EU declaration of conformity. The reality is different.
In short
- From 20 January 2027, the Machinery Regulation (EU) 2023/1230 applies.
- The basis of machine safety doesn't change, but software, cybersecurity, and self-learning behaviour get an explicit place in the legislation.
- For many companies, the biggest impact lies with retrofit projects and the assessment of substantial modifications.
- As a result, conformity strategy is increasingly decided during the design phase, rather than only at the point of CE marking.
The new regulation aligns better with the technology found in machines today. Software plays a bigger role. Machines are connected to networks. And existing installations are modernised more often than fully replaced. We see that same shift in the engineering projects we guide at SPARQ: extensions, modernisations, and integrations increasingly outweigh full new-builds.
The fundamentals of machine safety remain in place. Risk assessment according to ISO 12100, harmonised standards, a solid technical file. Still, several changes directly affect the design and modification of machines.
From directive to regulation
A directive is transposed by each member state into its own national law. A regulation applies directly, in every member state. From 20 January 2027, you therefore refer directly to the Machinery Regulation, not to the national transposition of the Machinery Directive.
No need to panic about what you already have on the market. The Machinery Directive remains in force up to and including 19 January 2027. Machines lawfully placed on the market before 20 January 2027 do not need to retroactively comply with the new regulation.
For most high-risk machines, little changes
The list of high-risk machinery has been reworked. The former Annex IV is now Annex I, split into two parts.
Part A covers six machine categories for which involvement of a notified body is mandatory. Two categories are new, covering safety components with fully or partially self-learning behaviour based on machine learning that ensures safety functions.
Part B covers nineteen categories for which the existing procedure remains in place. If you fully apply the harmonised standards, self-certification stays possible.
For most machines, the conformity route therefore changes little. The stricter procedure mainly affects the specific categories under Part A, with self-learning behaviour within a safety function as the main novelty.
Software and cybersecurity get a fully-fledged place
When the Machinery Directive was drafted in 2006, network connections, remote diagnostics, and software updates were still the exception. Today they're the norm.
The Machinery Regulation accounts for that. Safety-related hardware, software, and data must be protected against corruption when this could lead to a hazardous situation. An unauthorised firmware update, an unsecured USB port, an external network connection: none of these may simply disable or alter your safety function.
Software itself can also be explicitly considered a safety component, when it independently fulfils a safety function. Even when it's placed on the market separately from the machine.
Additional requirements apply to systems with self-learning behaviour. If machine learning is part of a safety function, the system must keep operating safely within its intended limits, even as its behaviour evolves over its lifetime.
The Machinery Regulation doesn't stand alone here. For machines and systems connected to networks or digital products, other European cybersecurity rules also come into play, such as the Cyber Resilience Act (CRA) and, depending on your sector and organisation, NIS2. You need to consider these obligations together.
Retrofit: when does a modification become substantial?
For many companies, the biggest impact of the Machinery Regulation isn't on new machines, but on existing installations.
Production lines get modernised. Controls get replaced. Machines get extended to prolong their service life. The question then isn't only whether the new components are safe, but also what the modification means for the safety of the existing machine.
Under the Machinery Directive, the concept of substantial modification existed mainly as an interpretation, taken from the European Blue Guide. The Machinery Regulation now explicitly incorporates this concept into the legislation.
A modification may be substantial when it:
- occurs after the machine was placed on the market or put into service,
- was not foreseen or planned by the original manufacturer,
- creates a new hazard or increases an existing risk, requiring additional protective measures.
That doesn't automatically mean the entire machine needs to become CE-compliant again. However, for the modified part, you do need to demonstrate again that you meet the applicable essential health and safety requirements. Think of an updated risk assessment, the necessary technical documentation, and, depending on the situation, a new conformity assessment.
Practical example. An older packaging machine gets a new safety PLC. If the original safety philosophy is preserved and no new functions are added, this is usually not a substantial modification.
Add new automatic functions at the same time, adjust the safety logic, or integrate extra servo axes, and that same retrofit can legally receive a completely different assessment. The technical intervention may look limited. The impact on your conformity obligations is not.
In the retrofit projects we guide at SPARQ, this is one of the first questions we investigate. A correct assessment during the concept phase prevents you from having to reopen fundamental design choices only once commissioning is underway.
Digital documentation
The administrative side is evolving too. You may now provide instructions for use and the EU declaration of conformity digitally. If the user still wants a paper version, you must make one available free of charge.
For machine builders, this makes it easier to keep documentation up to date, especially when machines receive software updates or functional extensions during their service life.
What doesn't change?
The basis of machine safety remains in place. Risk assessment according to ISO 12100, harmonised standards, and a solid technical file remain the foundations of every safe machine design.
The biggest change isn't in the methodology, but in how you assess software, cybersecurity, and modifications to existing machines.
What SPARQ does
The Machinery Regulation brings legislation in line with the technology found in machines today. For most machine builders, day-to-day design practice changes only modestly. The biggest impact lies with retrofit projects, where the assessment of substantial modifications is now more clearly anchored in law. Software and cybersecurity also get an explicit place within machine safety.
For engineering teams, this mainly means one thing: you decide your conformity strategy increasingly early, during the concept phase. Anyone who only thinks about CE once the machine is built risks having to revisit important design choices afterwards.
That's why, at SPARQ, we make conformity assessment part of the engineering process, not of the handover. By determining early on what impact a modification has on machine safety, and which conformity route applies, you design, validate, and deliver retrofit and machine-building projects with far more focus.
Facing a retrofit or an ongoing project and want to know where you stand under the new regulation? Get in touch with our safety team.