EU Machinery Regulation 2023/1230: What Changes for AGVs

The EU Machinery Regulation applies from 20 January 2027: cybersecurity becomes part of CE conformity and software counts as a safety component.

Reading time: 15 min

The Short Answer

On 20 January 2027, Machinery Regulation (EU) 2023/1230 fully replaces Machinery Directive 2006/42/EC. There is no parallel period: a machine placed on the market on 19 January 2027 falls under the Directive, one placed on the market on 20 January falls under the Regulation.

Three changes matter most for AGV projects:

  1. Cybersecurity becomes part of CE conformity. Remote access, tamper protection, and logging are no longer purely IT topics but essential health and safety requirements.
  2. Software explicitly counts as a safety component. The software version must remain identifiable and interventions must be traceable.
  3. A software update can constitute a substantial modification and therefore require a new conformity assessment.
A hard deadline with no buffer: The Regulation applies directly in all Member States, with no national transposition and no transition year. Vehicles delivered in 2027 are being specified today. If you are writing a specification now, you are effectively writing it for the Machinery Regulation.

Timeline and Legacy Protection

The Regulation was published on 29 June 2023 and entered into force on 19 July 2023. After a 42-month transition period it applies in full. Other legal acts affecting the same vehicles and the same supply chains are phasing in alongside it:

Date What applies
11 September 2026 Reporting obligations under Art. 14 of the Cyber Resilience Act (CRA): actively exploited vulnerabilities and severe security incidents require an early warning within 24 hours, a notification within 72 hours, and a final report within 14 days.
Q4 2026 Expected: citation of the majority of harmonised standards under the Machinery Regulation and publication of the Commission's official application guide.
20 January 2027 Machinery Regulation (EU) 2023/1230 applies in full, Machinery Directive 2006/42/EC is repealed.
11 December 2027 Cyber Resilience Act (EU) 2024/2847 fully applicable.
2 August 2028 Latest date by which the delegated acts transferring the AI requirements into Annex III of the Machinery Regulation must apply.

Legacy protection (Art. 52). Vehicles and installations lawfully placed on the market under the Machinery Directive before 20 January 2027 may continue to be made available and operated. There is no obligation to recertify existing machinery as long as no substantial modification takes place. For series manufacturers who cannot know whether a machine will be placed on the market before or after the cut-off date, the Commission permits a combined EC/EU declaration of conformity.

In Germany, the Machinery Regulation Implementation Act (MaschinenDG) accompanies the change. It replaces the 9th ProdSV and covers language, market surveillance, and penalty provisions.

What Changes Compared to the Machinery Directive

Topic Directive 2006/42/EC Regulation (EU) 2023/1230
Legal form Directive, transposed nationally Regulation, directly applicable
Cybersecurity Not explicitly regulated Annex III 1.1.9 and 1.2.1, part of CE conformity
Software Not explicitly covered as a safety component Safety component covers physical, digital, and mixed components as well as software
High-risk machinery Annex IV Annex I Part A (notified body mandatory) and Part B
Artificial intelligence Not addressed Safety components with self-evolving behaviour listed in Annex I Part A Nos. 5 and 6
Substantial modification Only via interpretation papers Legally defined in Art. 3(16), explicitly including digital modifications
Instructions for use Paper Digital permitted, paper version free of charge on request within one month
Annexes Essential requirements in Annex I Essential requirements in Annex III, high-risk list in Annex I
A common migration mistake: Changing only the title of the declaration of conformity from "Directive 2006/42/EC" to "Regulation (EU) 2023/1230". The whole chain needs updating: product classification, machine boundaries, risk assessment, selection of essential requirements, the Annex I check, and the choice of conformity assessment module.

Cybersecurity Becomes Part of CE Conformity

Two essential health and safety requirements in Annex III are new or extended. Without evidence in the technical documentation, the declaration of conformity remains incomplete.

Annex III 1.1.9: Protection against corruption (new)

  • Connecting another device or using remote access must not create a hazardous situation
  • Safety-related hardware, software, and data must be protected against accidental and intentional corruption (authentication, integrity checks, code signing, interface protection)
  • Safety-related software must remain identifiable
  • The machine must collect evidence of legitimate and illegitimate interventions (logging)

Annex III 1.2.1: Safety and reliability of control systems (extended)

  • Control systems must withstand expected external influences, explicitly including reasonably foreseeable malicious attempts by third parties
  • Safety functions must operate within predefined parameters, including in self-learning systems
  • The limits of the safety functions must be protected against later modification by users, administrators, or attackers

What This Means for an AGV System in Practice

An AGV system is networked by definition. The very properties that make it operable now require documented evidence:

  • Remote maintenance access. Access to a vehicle or to the fleet controller must not be able to trigger a hazardous state. Access rights, the approval process, and the effect of remote commands on safe states belong in the risk assessment.
  • MQTT broker and order channel. The broker is the single shared integration point between IT and OT. Authentication, TLS, and network segmentation have to be demonstrated, not merely recommended. VDA 5050 message flow describes which channels actually need to be open.
  • Software version per vehicle. For every vehicle it must be traceable which safety-related software version is running. A fleet with organically grown, undocumented firmware versions does not meet this.
  • Logging. Log-in and log-out events as well as changes to software and configuration must be recorded, regardless of whether they were authorised. The records must be made available, either stored on the machine or transmitted to a central server.
  • Safety parameters. Protective field geometries, speed limits, and zone configurations must be protected against later modification. A service access that can change protective fields without authentication and without a log entry is a finding.
Practical note: A fleet manager that only dispatches orders and plans routes is usually not a safety component. The protective function sits on the vehicle. As soon as software sets safety-related parameters, such as speed zones or protective field switching, the classification shifts. Clarify this boundary with your supplier early and have it documented in the risk assessment.

The established methodology under EN ISO 12100 remains the starting point but has to be extended with cyber hazard sources: manipulation, remote access, corrupted software. There is one relief: machinery certified under a recognised scheme of the Cybersecurity Act (EU) 2019/881 is presumed to conform with 1.1.9 and 1.2.1 to the extent the certificate covers those requirements.

Software as a Safety Component

The definition of a safety component now explicitly covers physical, digital, and mixed components as well as software performing a safety function. The indicative list of safety components has moved to Annex II and was extended to include software with a safety function and safety components using machine learning.

This has two practical consequences:

  1. Software can be placed on the market on its own. In that case the software manufacturer carries the full set of obligations, including conformity assessment.
  2. The chain of evidence reaches deeper than the application software. According to expert commentary, the Regulation also covers the toolchain, meaning compilers and standard libraries. Qualification is therefore not a one-off certification milestone but must be maintained across the lifecycle.

The ZVEI publication "Safe Software in the EU Machinery Regulation 2023/1230" describes the requirements for safety-related software development, including evidence of independence where safety integrity levels are mixed and secure communication over bus systems such as PROFIsafe, Safety over EtherCAT, and AS-i Safety.

Software Updates and Substantial Modification

Art. 3(16) defines substantial modification in binding terms for the first time: a physical or digital modification after placing on the market that is not foreseen or planned by the manufacturer and that affects safety by creating a new hazard or increasing an existing risk, so that additional protective measures become necessary.

Whoever carries out a substantial modification legally becomes the manufacturer and must run the conformity assessment procedure. For operators who adapt their own fleets, this is the most consequential rule in the entire Regulation.

Usually does not trigger a new assessment

  • Updates foreseen and planned by the manufacturer
  • Parameter changes within the limits released by the manufacturer
  • New transport orders and routes within the assessed operating boundaries

Requires assessment

  • Safety-related software updates outside the foreseen scope
  • Retrofitting or replacing safety sensors
  • Extending operation into zones that were never assessed
  • Higher speeds, heavier loads, new load handling devices
Two thresholds, two assessments: The Machinery Regulation and the Cyber Resilience Act use the same term with different meanings. The Machinery Regulation asks whether functional safety is affected and additional protective measures become necessary. The CRA asks whether cybersecurity conformity or the assessed intended purpose is affected. For networked vehicles, both assessments must be carried out separately.

In practice this means a fleet operator needs a defined process that checks every update against both thresholds before rollout and documents the result. For fleets with over-the-air updates, that step belongs in the release workflow, not in a form filled in afterwards.

AI and Self-Evolving Behaviour

Annex I Part A Nos. 5 and 6 list safety components and embedded systems with fully or partially self-evolving behaviour based on machine learning that ensure safety functions. These are mandatorily subject to conformity assessment by a notified body, with no alternative route.

For AGVs and AMRs this draws a clear line:

  • Not affected: A conventional safety laser scanner with fixed, parameterised protective fields. Navigation and route planning via SLAM are not safety functions either, as long as the protective function is implemented independently in dedicated safety technology.
  • Affected: ML-based person or obstacle detection that itself delivers the safety function and whose behaviour keeps evolving.

For machinery with evolving and autonomous behaviour, the risks that may arise from that behaviour after the machine is placed on the market must explicitly be included in the assessment. Annex III 1.2.1 additionally requires the learning phase to be safeguarded.

The Digital Omnibus shift: Digital Omnibus (EU) 2026/1744, in force since 27 July 2026, moves the AI requirements for machinery out of the direct scope of the AI Act's high-risk rules and into the Machinery Regulation. The Commission must supplement Annex III by delegated act with corresponding requirements, applicable by 2 August 2028 at the latest. Until machinery-specific standards exist, harmonised standards under the AI Act serve as evidence of conformity. The Digital Omnibus does not move the 20 January 2027 cut-off date or the cybersecurity requirements.

What Happens to Existing Fleets

An installation placed on the market before the cut-off date does not need to be recertified. Even so, AGV projects regularly see events that trigger a reassessment:

Plan Classification
Extending the fleet with additional vehicles (from 20 January 2027) The new vehicles are placed on the market under the Regulation. What this means for the conformity of the overall installation needs to be clarified.
Changing the layout, opening up new driving areas Requires assessment as soon as the assessed operating area is left. Triggers a review of the risk assessment in any case.
Retrofitting safety sensors Regularly a substantial modification if the protective function is realised differently as a result.
Adding remote maintenance access Requires assessment under both regimes, because a new attack surface and a new intervention path are created.
Rolling out a safety-related firmware update To be assessed separately against the Machinery Regulation and the CRA thresholds.

Important for operators: whoever carries out the modification becomes the manufacturer, with all the obligations that entails. The decisive question is therefore not whether something is technically feasible, but who is accountable for the conformity of the modified installation. That role belongs in the contract before the first intervention takes place.

Standards You Can Build On

The Commission issued the final standardisation request M/605 to CEN and CENELEC on 20 January 2025. Most of the roughly 800 existing standards are expected to be carried over under the Machinery Regulation, with citation expected largely in the fourth quarter of 2026.

Standard Role in the AGV context
EN ISO 3691-4 The core safety standard for driverless industrial trucks and their systems. Remains the governing product standard.
EN ISO 12100 Type A standard for risk assessment, currently under revision. The August 2026 draft is editorially aligned with cybersecurity and AI topics but does not yet provide concrete cyber hazard lists.
EN ISO 13849-1:2023 Functional safety of control systems, extended with requirements on software, ergonomics, and EMC immunity.
IEC/EN 62061 Functional safety of electrical, electronic, and programmable control systems.
IEC 62443 Industrial cybersecurity. The methodological basis for demonstrating compliance with 1.1.9. The VDMA has published a guideline specifically for mechanical and plant engineering.
prEN 50742 "Protection of machinery against corruption", targeting 1.1.9 and 1.2.1 across the entire lifecycle and defining logging requirements. Publication planned for November 2026. DGUV Test published test principles on this basis in 2026.

What to Do Now

As an operator

  • Inventory the software versions across the fleet and make them verifiable per vehicle
  • Define a process that checks updates against both thresholds before rollout
  • Document remote maintenance access, access rights, and logging
  • Clarify contractually who is accountable for conformity after modifications
  • Extend the risk assessment with cyber hazards rather than rewriting it

As a manufacturer or integrator

  • Check the portfolio against Annex I Parts A and B, and book notified body slots early for high-risk products
  • Migrate declaration of conformity and technical documentation templates
  • Implement security by design: signed firmware, integrity checks at system start, network segmentation, protection of digital interfaces
  • Implement logging and an audit trail, including retention and accessibility for the authorities
  • Set up digital instructions with a QR code, download capability, and at least ten years of availability
  • Build a software bill of materials (SBOM) and adopt IEC 62443 as the methodological basis
For the specification: Explicitly require conformity with (EU) 2023/1230, evidence for Annex III 1.1.9 and 1.2.1, identifiability of the software version, the scope of logging, and a commitment on how the supplier assesses and releases safety-related updates. Whatever is missing there becomes a change order later. See also: What Belongs in an AGV Specification?

What Is Still Open

Not everything is settled today. These points are worth watching, because they can change decisions:

  • The Commission's official guide, expected in the fourth quarter of 2026. The editorial group is working on substantial modification, safety functions, AI safety, and cybersecurity, among other topics.
  • Citation of the harmonised standards under the Regulation, plus publication of prEN 50742 and the revised EN ISO 12100.
  • Aligning the cybersecurity dates with the CRA. Industry associations are calling for the binding application of 1.1.9 and 1.2.1 to be moved to 11 December 2027. This has not been adopted, and expert bodies consider it unlikely. Do not plan around it.
  • The precise meaning of Annex I Part A Nos. 5 and 6. According to industry representatives, it is not yet finally settled when a learning system "ensures" a safety function.

One point of perspective: where a machine has no network connection, no software-based safety functions, and no remote access, the cybersecurity clauses have limited effect. For AGV systems that is almost never the case. A networked fleet with a fleet controller and a remote maintenance portal falls squarely within scope.

Conclusion

The Machinery Regulation moves cybersecurity out of IT and into the regular product development and conformity process. For AGV systems, which do not function without networking at all, this is not a footnote. It touches the architecture: how updates are released, how access is secured, which software version runs on which vehicle, and who can prove it.

The good news is that the methodology does not change. Risk assessment under EN ISO 12100, control system safety under EN ISO 13849-1, and product requirements under EN ISO 3691-4 remain the foundation. The cyber perspective is added on top, and it now requires evidence. If you already document your system's safety architecture properly, you extend it. If you have left this to your supplier so far, now is the time to start asking.

Note: This article reflects the situation as of September 2026 and is intended for orientation, not as legal advice. The authoritative sources are the official text on EUR-Lex (CELEX 32023R1230), national implementing legislation, and the assessment of the competent authorities.

From strategy to vendor selection.
Hands-on guidance from experienced AGV experts.

Free Initial Consultation