Machinery Safety in 2027: Is Your Equipment Ready?
Cybersecurity. Software. Major upgrades. Ten-year records. The new EU Machinery Regulation puts them all firmly in the compliance picture.
Machinery can be mechanically sound, production-ready and still present a compliance problem at handover. The next major change is closer than many businesses realise.

From January 2027, the EU Machinery Regulation (EU) 2023/1230 replaces the existing Machinery Directive. It brings connected machinery, safety-related software, cybersecurity and document control more firmly into the machinery-safety picture.
For manufacturers, integrators and end users, this is not simply a paperwork update. It is a prompt to build traceability, security and safety into projects from the start.
Why the destination market matters
The Regulation applies when machinery is placed on the EU market, and it is also relevant to Northern Ireland. Great Britain continues to operate under the Supply of Machinery (Safety) Regulations 2008, while recognition and marking arrangements continue to evolve.
The practical message is straightforward: confirm the intended market and compliance route before the design is locked in. A project supplied to Great Britain, Northern Ireland and the EU may need different considerations for marking, documentation and conformity assessment.
Five Key Changes to Watch Out For
1. A cyber risk can become a physical riskIf unauthorised access, a remote connection or an uncontrolled software change can affect a safety function, it becomes a machinery-safety issue. Risk assessments should consider network interfaces, remote access, software integrity and the protection of safety-related parameters.
2. Software is part of the machineModern control systems are not an add-on. PLC, HMI, drive and safety-program versions need to be controlled, documented and validated. Clear change management helps prevent a minor software alteration becoming a hidden safety risk.
3. Major modifications may shift responsibilityA substantial modification can mean the organisation carrying out the work takes on manufacturer responsibilities for the modified machine. This can be relevant to new operating modes, major control-system replacement, safety-circuit changes, increased speed or the integration of separate machines.
Assess the proposed work before it begins and record the decision. It is far easier to establish responsibilities at the planning stage than at commissioning.
4. Your technical file must remain retrievableThe Regulation permits digital instructions and declarations in defined circumstances. It also requires manufacturers to retain the technical documentation and EU declaration of conformity for at least ten years after machinery is placed on the market or put into service.
That makes disciplined document control essential. Risk assessments, drawings, test evidence, manuals, component information and software records need to be complete, controlled and easy to retrieve.
5. Higher-risk machinery needs early attentionSome categories of machinery and related products are subject to specific conformity-assessment routes. Where third-party involvement may be needed, the right route should be established early in the project—not when the machine is ready to leave the factory.

Six practical steps to take now
Projects being quoted, designed or built now may be supplied after the January 2027 changeover. Practical preparation should include:
• Confirm the destination market and compliance route for every new project.
• Expand risk assessments to cover connectivity, remote access, software integrity and foreseeable misuse.
• Introduce version control for PLC, HMI, drive and safety-program software.
• Review planned upgrades to identify whether they could amount to a substantial modification.
• Audit technical-file records, including drawings, calculations, test results, instructions and declarations.
• Plan cybersecurity alongside functional safety, using a risk-based approach and recognised industrial principles such as IEC 62443 where appropriate.
And PUWER? It still matters every day
CE or UKCA marking is about machinery being placed on the market or put into service. PUWER applies throughout equipment’s working life. A PUWER assessment can uncover gaps in guarding, isolation, emergency stops, control reliability, maintenance access and safe use—particularly on older or modified equipment.
How UK ICS turns the rules into a workable plan
UK Industrial Control Systems designs and manufactures control panels and provides PLC, HMI, drive software, commissioning and machine integration. We can also support customers with:
Machinery safety and PUWER assessments for existing equipment and production lines.
Control-system and panel upgrades including obsolete PLC, HMI, drive and safety-system replacement.
Functional-safety engineering including safety-function design, verification, validation and supporting documentation.
Industrial cybersecurity readiness with risk-based controls and IEC 62443 principles incorporated where appropriate.
Technical-file support including electrical drawings, test evidence, software records and conformity documentation inputs.
Secure cloud document storage for controlled, versioned and retrievable compliance records, retained for the required period—including at least 10 years for relevant EU machinery documentation.
Do not let compliance become the final commissioning snag. If a machine is being designed, upgraded or supplied into 2027, speak to UK Industrial Control Systems about a compliance review, PUWER assessment or upgrade plan. Early decisions are usually simpler—and far less expensive—than a redesign at handover. |
Sources: Regulation (EU) 2023/1230 on machinery (EUR-Lex); UK Government and HSE guidance on machinery safety.



Comments