New Machinery Regulation enters into force
Machinery Regulation facts you should know
The new EU Machinery Regulation will become legally binding across Europe in just a few months. Yet, a number of suppliers in the automation industry are still not fully aware about its finer details. The machine and robot safety expert Jens Müller, CMSE®, has a deep understanding of the MR. The ISO/IEC 17024 Certified Expert answers frequently asked questions here.
Mr. Müller, the new EU Machinery Regulation 2023/1230 will enter into force in January 2027. You are an expert who gets around in the automation industry. Do you feel that manufacturers and system integrators are prepared for the MR?
Müller: My impression varies widely. Major manufacturers and integrators have carefully considered the new requirements, but I see a significant knowledge gap in many small and medium-sized enterprises. They don’t have much time left until January 20, 2027.
What is your advice to those who haven’t considered the new MR with the necessary care yet?
Müller: They should jump into action now and follow a structured approach: define responsibilities, review existing processes and risk assessments, and systematically address any discrepancies with the Machinery Directive. Software, cybersecurity, digital documentation, and, where applicable, new conformity assessment procedures are of particular importance in this context and should be looked at as soon as possible.
The MR will enter into force on January 20, 2027. What happens to machines ordered and scheduled for delivery well before this date if they can only be put into operation shortly after this date due to delays?
Müller: It doesn’t matter when a machine was ordered or what delivery date was contractually agreed upon. The most important factor is when it is placed on the market. If it was placed on the market in compliance with the Machinery Directive before January 20, 2027, continued marketing is permissible after that date, too. However, if it is initially placed on the market on or after January 20, 2027, the new Machinery Regulation applies without any transition or grace period.
What happens to stocks—such as robots—currently stored in a manufacturer or system integrator warehouse if it doesn’t get sold or integrated before the MR enters into force?
Müller: The same principle applies. It depends on the legal status and not just on the robot’s physical location. If a product is already properly placed on the market before the MR enters into force, continued marketing is generally permissible. However, the mere fact that a manufacturer has the product in stock does not automatically mean that the product has been placed on the market.
What needs to be considered with regard to retrofitting machines and systems? What can system owners do to make sure upgrades are not considered substantial modifications, which will cause them to be considered manufacturers?
Müller: Every modification should be evaluated for safety and transparently documented before implementation. A modification that gives rise to new hazards or exacerbates existing risks to an extent that requires additional protective measures may constitute a “substantial modification” within the meaning of the MR. In such cases, the party implementing the modification generally assumes the manufacturer’s obligations for the machine or component in question.
Robots using artificial intelligence will be considered high-risk machines in the future. What real-world implications does that entail?
Müller: I think we have to differentiate: Not every AI-enabled robot is a high-risk machine by default. According to Annex I of the MR, safety components and machines with fully or partially self-evolving behavior using machine learning approaches are particularly relevant when they ensure safety functions. These categories have stricter applicable conformity assessment procedures.
How do we secure machines and software against cyber risks and unauthorized external access in order to meet the new requirements of the MR and the supplementary EU Cyber Resilience Act?
Müller: Cybersecurity will explicitly be a machine safety matter: Security-related hardware, software, and data must be protected against unintentional and intentional tampering, and any necessary security-related interventions must be fully transparent. In products with digital elements, the Cyber Resilience Act goes even further as it requires systematic vulnerability management and other safeguards. However, its main requirements will not take effect until December 11, 2027, while certain reporting requirements have already been applicable since September 11, 2026.
Unlike the existing Machinery Directive 2006/42/EC, the new Machinery Regulation is legally binding and not just a recommendation. How does that impact manufacturers and system integrators specifically?
Müller: I'd like to set the record straight on this one: The existing Machinery Directive is not just a recommendation, but a binding piece of EU legislation. It just had to be transposed into national law by the member states. As opposed to that, the new MR is an EU regulation, which is directly applicable in all member states—meaning there will no longer be any differences between national implementations.
Last but not least: Who monitors compliance with the MR in practice, and what penalties can be imposed in case of violations?
Müller: In Germany, compliance is monitored primarily by the relevant market surveillance authorities of the individual federal states. For example, they can demand corrective actions and keep noncompliant or dangerous products off the market. The MR requires member states to impose effective, proportionate, and dissuasive sanctions while expressly permitting criminal penalties in cases of serious violations.
More on the Machinery Regulation
conflicting priorities of regulation and dynamic innovation: Walter Reithmaier, CEO Division Industry & Infrastructure, TÜV SÜD
