Blog | IES

Machinery Directive vs Regulation: What's the Difference? | IES

Written by Admin | Oct 6, 2026, 2:02:20 PM

From 20 January 2027, the Machinery Regulation (EU) 2023/1230 fully replaces the Machinery Directive 2006/42/EC.

That means it becomes the legal standard for machinery safety across the EU, introducing direct EU-wide application and new requirements for AI, cybersecurity, autonomous machinery and digital documentation that the old Directive never addressed.

If you manufacture, import, modify, or place equipment on the EU market, this will impact your business.

Here are the key differences between the Directive and the Regulation, including whether you need to act to remain compliant in 2027.

What's the difference between the Machinery Directive and the Machinery Regulation?

The biggest structural difference between the Machinery Directive and the Machinery Regulation is legal form.

Under the old Directive, each Member State had to transpose the rules into its own national law. That meant it could end up as 27 (or more) separate pieces of national legislation, each written, worded, and interpreted slightly differently, introducing small inconsistencies between countries.

The Machinery Regulation, on the other hand, applies directly and identically across the whole EU the moment it takes effect. No transposition, no local variation, and every Member State working from the exact same wording, applied in the exact same way.

That also changes how quickly the EU can react to new risks. Amending a Directive means that every Member State must update its own national transposition, which can take time. Amending a Regulation is a single legislative act, which means new changes apply immediately.

But beyond legal form, the Machinery Regulation introduces many new rules and requirements that aren’t currently included in the Directive.

What's new in the Machinery Regulation?

Written twenty years after its predecessor, the Machinery Regulation introduces entirely new technical requirements that the Directive was never designed to accommodate.

That’s because, back in 2006, machinery didn't connect to the internet, teach itself, or run on code that could be hacked. The Regulation introduces new rules for cybersecurity, AI, and autonomous machinery, among others:

  • AI and self-evolving machinery now sit in Annex I's highest-risk tier, alongside a handful of other categories, including removable mechanical transmission devices, vehicle servicing lifts, and portable cartridge-operated fixing tools. This tier always requires a notified body, regardless of the standards to which the equipment is built.
  • A further 23 categories sit in a second tier, largely carried over from the old Directive's high-risk list. Here, self-certification is still possible, but only if the equipment is built entirely in accordance with the relevant harmonised standards. Otherwise, the same notified body routes apply as for the highest-risk tier.
  • Where a notified body is required, manufacturers choose from three routes: EU type-examination followed by internal production control, full quality assurance, or unit verification (typically used for complex, one-off, customer-specific machines).
  • New cybersecurity obligations require machinery to resist corruption and log any tampering with safety-critical software.
  • Autonomous machinery needs control systems that stay within a defined task and movement space, with safety-related decisions logged for at least a year.
  • "Substantial modification" is formally defined for the first time. If a change creates a new hazard or increases risk, whoever makes it takes on full manufacturer obligations.

We’ve outlined some of the key changes in the table below:

Feature

Machinery Directive 2006/42/EC

Machinery Regulation (EU) 2023/1230

AI/self-evolving machinery

Not addressed

New Annex I categories where the strictest conformity assessment route applies

Cybersecurity

Not addressed

"Protection against corruption" required; safety-critical software must be identifiable and tamper-logged

Autonomous control systems

Not addressed

Must stay within defined task/movement space, with safety decisions logged for 1+ year

Documentation

Paper-based by default

Digital by default, and must stay accessible online for 10+ years

Software traceability

Not addressed

Tracing log for safety software updates, retained for 5 years

"Substantial modification"

Not formally defined

Formally defined: whoever makes the modification is treated as the manufacturer

Importers & distributors

Limited explicit obligations

Explicit obligations set out directly in the Regulation

Does the Machinery Regulation apply in the UK and Northern Ireland?

Northern Ireland applies the Machinery Regulation directly from 20 January 2027, under the Windsor Framework.

Great Britain is different. UKCA marking is unaffected and continues to be governed by the UK's Supply of Machinery (Safety) Regulations 2008.

CE marking is a separate question. Great Britain continues to recognise it, meaning CE-marked equipment will need to meet the new Regulation to keep the mark valid.

Do you need to do anything before 2027?

Yes, don't wait until the deadline.

If you manufacture, develop, modify or import machinery for the EU market, review your technical documentation against the new requirements now.

Please be aware that technical files built to satisfy the 2006 Directive aren't guaranteed to meet the Regulation, particularly around cybersecurity, AI/self-evolving behaviour and digital documentation accessibility. You will need sufficient time to retest your equipment and compile the relevant documentation to achieve the CE mark.

Our free guide walks through who's responsible, how conformity assessment works under the new Regulation, and the practical steps to take before January 2027.

Download it here.

Get ahead of the new Regulation

Whether you're working from the old Machinery Directive or preparing for the new Regulation, our compliance team can help you understand exactly where you stand and the steps you may need to take.

Speak to our compliance team.