IT Law · 2026-09-11 · 14 min read
The Machinery Regulation from 20 January 2027: When a Software Update Makes You the Manufacturer

Michael Kaiser
Co-Founder & Head of Systems, Vincency
On 20 January 2027 the Machinery Directive disappears and Regulation (EU) 2023/1230 takes its place, without a transition period. Most accounts stop there. The sentence that matters for a mid-market manufacturer sits in the definitions: a safety component is now expressly a physical or digital component, including software. And anyone who makes a substantial modification to a machine is treated as its manufacturer.
Read quickly, that reads like a threat to every service technician who installs an update. Read properly, it does not. Article 3(16) contains two sub-paragraphs that most summaries skip, and they exclude the great majority of updates from the rule. This article follows both directions: where the regulation reaches further than it appears to, and where it is considerably narrower than the alarm suggests.
What exactly happens on 20 January 2027
Two provisions carry the date. Article 54 states that the regulation applies from 20 January 2027. Article 51(2) repeals Directive 2006/42/EC with effect from the same day. There is no overlap and no grace period: until 19 January the directive governs, from 20 January the regulation does.
The regulation has in fact been in force since 2023, and parts of it have applied for some time. Article 54 staggers them: Articles 26 to 42, which govern notified bodies, have applied since 20 January 2024. Article 6(7) and Articles 48 and 52 have applied since 19 July 2023. Article 50(1) on penalties applies from 20 October 2026, and Article 50(2) obliges Member States to notify the Commission of their penalty rules by that same date. That last date is a deadline for the Member States, not for your company, but it is worth noting: from late October 2026 it will be visible what a breach actually costs in Germany.
| Date | What applies | Who it binds |
|---|---|---|
| 19 July 2023 | Art. 6(7), Art. 48, Art. 52 | Member States, Commission |
| 20 January 2024 | Art. 26 to 42 (notified bodies) | Conformity assessment bodies |
| 20 October 2026 | Art. 50(1), notification under Art. 50(2) | Member States |
| 20 January 2027 | The regulation in full; Directive 2006/42/EC repealed | Manufacturers, importers, distributors, and anyone modifying machinery |
The cut-off attaches to the individual machine, at the point it is placed on the market. A machine lawfully placed on the market on 15 January 2027 stays under the directive for its whole life. It does not have to be re-assessed later. That single distinction removes most of the panic from the topic, and it is the same logic that governs the product liability reform taking effect six weeks earlier.
Why software is now a safety component
Article 3(3) defines a safety component as a physical or digital component, including software, of a product falling within the scope of the regulation, which is designed or intended to ensure a safety function, is placed on the market separately, and whose failure or malfunction endangers the safety of persons. The old directive spoke of components in a way that made standalone safety software a matter of argument. That argument is over.
Two qualifiers in the same sentence decide how far this actually reaches, and they are usually dropped from the summaries. The component must be placed on the market separately, and it must not be required for the product itself to function. Control software that ships as an inseparable part of your machine is therefore not a standalone safety component under this definition. A safety module that you sell on its own, to be integrated into third-party machinery, is.
For a mid-market manufacturer the practical question is not philosophical but commercial: do you sell any software separately? A licence for a safety PLC program, a retrofit package for older machines, a configurable safety layer. Whatever appears on an invoice as its own line item deserves the check.
When a modification transfers the manufacturer role
Article 18 is the provision with the sharpest consequence. A natural or legal person who makes a substantial modification to a machine is considered the manufacturer for the purposes of the regulation and is subject to the manufacturer obligations under Article 10. The article goes further: that person must ensure and declare on their sole responsibility that the machine concerned complies with the applicable requirements, and must apply the conformity assessment procedure under Article 25(2), (3) and (4).
There is one relief built in. If the risk assessment shows that the modification affects only the safety of one machine within an assembly, the obligations attach to that machine, not to the entire assembly. For anyone who links production lines, that is the difference between a manageable task and an unmanageable one.
The two sub-paragraphs that most accounts skip
Everything above depends on what counts as a substantial modification, and here the regulation is far narrower than the headlines. Article 3(16) requires three elements, and they are cumulative:
- The change is a physical or digital modification not foreseen or planned by the manufacturer, made after the machine was placed on the market or put into service.
- It affects safety, by creating a new hazard or increasing an existing risk.
- It thereby makes it necessary either to add guards or protective devices whose integration requires adapting the existing safety control system, or to take additional protective measures to ensure stability or mechanical strength.
The third element is the filter, and it is the one that goes missing in practice. A software update can create a new hazard and still not be a substantial modification, provided it does not require new guards or new stability measures. And an update that the manufacturer foresaw, a released patch, a documented parameter change, a firmware version from the manufacturer's own catalogue, fails the first element before the others are even reached.
Put plainly: the regulation does not turn your maintenance department into a machinery manufacturer. It catches the case where someone rebuilds a machine into something its maker never intended, and it now says clearly that this rebuilding can be done in software alone.
What the regulation asks on cybersecurity, and what it does not
Recital 25 places risks caused by malicious third parties among the new digital risks and obliges manufacturers to take proportionate measures, expressly limited to protecting the safety of the product. Annex III carries this into the requirement of protection against corruption. The regulation is therefore a safety instrument that has grown a security edge, not a cybersecurity regime.
The same recital states that other Union legislation dealing specifically with cybersecurity remains applicable alongside it. In practice that means the Cyber Resilience Act, whose reporting duty has applied since September 2026, and which asks quite different questions of the same product.
What to do before January 2027
Three steps hold regardless of how your exposure assessment turns out.
List what you will place on the market after the cut-off. Only those products fall under the new rules. For machines with long lead times the boundary runs straight through your current order book, which makes this a commercial question, not just a legal one.
Decide who rules on substantial modifications. The three criteria in Article 3(16) form a workable test, but only if someone applies them before the conversion rather than after. Write down who that is. The question almost always arises under time pressure, in the middle of a line rebuild, which is the worst moment to start reading the regulation.
Identify software placed on the market separately. Anything invoiced as its own item, licensed on its own, or delivered as a retrofit package deserves the Article 3(3) check. This is usually a short list, and knowing it is short is itself worth having.
None of this requires a project. It requires an afternoon, a list and a named decision-maker, and it is considerably cheaper than the alternative, which is discovering during a line rebuild in 2028 that your own team signed a declaration of conformity nobody knew they were signing.
Frequently asked questions about the Machinery Regulation
When does the new Machinery Regulation apply?
From 20 January 2027. Regulation (EU) 2023/1230 entered into force back in 2023, but its application was deferred. Article 54 names 20 January 2027 as the general date of application and staggers individual provisions ahead of it: Articles 26 to 42 have applied since 20 January 2024, and Article 6(7) together with Articles 48 and 52 since 19 July 2023. The distinction between entry into force and date of application is not pedantry; it is why reports of the regulation entering into force in 2027 are misleading.
Is there a transition period for machinery under the old rules?
No, there is no general transition period. The regulation uses a cut-off date: Article 51(2) repeals Machinery Directive 2006/42/EC with effect from 20 January 2027. Until then the directive applies, afterwards the regulation. What matters is when the individual machine is placed on the market, not the order date and not the state of your company. A machine lawfully placed on the market before that date does not have to be brought into conformity retrospectively.
Is software now a safety component?
Yes, where it is placed on the market separately and performs a safety function. Article 3(3) defines a safety component as a physical or digital component, including software, designed or intended to ensure a safety function, whose failure endangers the safety of persons. Two features are routinely overlooked: the component must be placed on the market separately, and it must not be required for the product itself to function. Control software that is inseparable from the machine is therefore not a standalone safety component.
When does a software update make me the manufacturer?
When it amounts to a substantial modification within the meaning of Article 3(16). Article 18 then provides that whoever makes that modification is considered the manufacturer for the purposes of the regulation and is subject to the manufacturer obligations in Article 10. They must additionally declare on their sole responsibility that the machine meets the requirements and apply the conformity assessment procedure under Article 25(2), (3) and (4). This is not a formality but the transfer of the manufacturer role to the operator or the service provider.
Is every software update a substantial modification?
No, and this is the practically most important point. Article 3(16) requires three things cumulatively: the modification is not foreseen or planned by the manufacturer, it affects safety by creating a new hazard or increasing an existing risk, and it thereby makes it necessary either to add guards or protective devices whose integration requires adapting the existing safety control system, or to take additional measures to ensure stability or mechanical strength. Without the third element there is no substantial modification. An update foreseen by the manufacturer fails at the first hurdle already.
What does the regulation mean for cybersecurity?
It requires proportionate measures, but only with regard to the safety of the product. Recital 25 expressly assigns risks caused by malicious third parties to the new digital risks and obliges manufacturers to take measures limited to protecting the safety of the product. Annex III adds the requirement of protection against corruption. The regulation does not replace general cybersecurity legislation, and the recital makes clear that other Union rules remain applicable alongside it, such as the Cyber Resilience Act.
We buy machines, we do not build them. Does this still concern us?
Possibly, by way of retrofitting. As long as you operate machines as intended and install updates foreseen by the manufacturer, little changes for you. But as soon as you intervene yourself, for instance by linking two machines into one assembly, replacing a controller or adding automation the manufacturer did not foresee, the questions under Article 3(16) and Article 18 arise. That assessment belongs before the conversion, not after it.
What should we actually do before January 2027?
Three things that hold regardless of how the exposure assessment turns out. First, a list of the products you will place on the market after 20 January 2027, because only those fall under the new rules. Second, a written decision on who in the company determines whether a planned conversion or update is a substantial modification, using the three criteria in Article 3(16) as the test. Third, clarity on which of your software components are placed on the market separately, because precisely those can be standalone safety components.
Sources, status and note: All article references are taken from Regulation (EU) 2023/1230 and were checked against the consolidated text on 11 September 2026, in both the German and the English language version. The repeal of Directive 2006/42/EC follows from Article 51(2). This article is an engineering perspective on a legal instrument, not legal advice; whether a specific conversion constitutes a substantial modification is a question for a risk assessment in the individual case.
Related service
Turning obligations into systems
This article clarifies the legal position. It gets implemented in software and processes: product inventory, reporting channel, data access, invoice format, update documentation. We take the inventory off mid-sized companies, order the obligations by deadline and effort and, if you wish, implement them.
IT strategy consultingRelated insights