Published:
New EU regulations are approaching – is your organization ready?
The EU Machinery Regulation (EU) 2023/1230 and Cyber Resilience Act introduce new requirements from 2027. Learn what they mean for your organization—and how NodeCE helps you meet them.

The EU is fundamentally modernizing its regulatory framework. During 2027, two regulations will begin to apply and affect a wide range of companies—whether they manufacture industrial machines, smart products, or software-integrated systems. The earlier you understand the requirements, the better prepared you will be to meet them without disrupting your operations.
Machinery Regulation (EU) 2023/1230
Modernized safety requirements for machinery
Applies from: 20 January 2027
The Machinery Regulation (EU) 2023/1230 replaces the current Machinery Directive 2006/42/EC and thoroughly modernizes how machine safety is regulated in the EU. It reflects the technological developments since the directive was adopted—particularly digitalization, increased connectivity, and the use of AI in machinery and systems.
What does this mean in practice?
- Clearer responsibilities throughout the supply chain—from manufacturers and importers to distributors
- Updated essential health and safety requirements that reflect modern technology
- Stronger handling of risks associated with connected and AI-controlled machinery
- The option to use digital instructions under defined conditions
- Stricter technical-documentation and traceability requirements
Unlike the old directive, the regulation applies directly in every EU member state without implementation in national law. This creates one common framework across the Union, but it also leaves no room for national adaptation.
Cyber Resilience Act (CRA)
EU-wide cybersecurity requirements for digital products
Partly in force since December 2024 · Fully applicable: 11 December 2027
The Cyber Resilience Act is the first EU regulation to impose binding cybersecurity requirements on products with digital elements—from industrial hardware with embedded software to consumer products such as smart-home devices and IoT sensors.
The regulation entered into force in December 2024 and is being phased in. Some provisions, including incident-reporting requirements, apply from September 2026, while all requirements become fully applicable on 11 December 2027.
Its purpose is to raise digital security throughout the product lifecycle: from design and development to deployment, updates, and decommissioning.
Core CRA requirements
- Security must be built into the product from the design phase (security by design)
- Vulnerabilities must be managed throughout the product lifecycle
- Security updates must be provided for a defined support period
- Serious cyber incidents must be reported to ENISA and national authorities
- Products with digital elements require documentation and CE marking
The CRA affects a broad range of actors: manufacturers, importers, and distributors of hardware, software, and combined products placed on the EU market.
Timeline—important dates
- December 2024—CRA enters into force. The regulation is adopted and published, and its first provisions take effect.
- September 2026—CRA reporting requirements apply. Incident-reporting and vulnerability-information requirements begin before the remaining provisions.
- January 2027—Machinery Regulation applies. EU 2023/1230 applies in full and Machinery Directive 2006/42/EC ceases to apply.
- December 2027—CRA applies in full. All Cyber Resilience Act requirements are binding for products with digital elements on the EU market.
What should you do now?
Adapting to two new regulations takes time, especially when reviewing technical documentation, risk assessments, design solutions, and internal processes. It is wise to start mapping your current position now:
- Inventory the products and machines covered by each regulation
- Analyze the gap between current processes and the new requirements
- Update technical documentation and risk assessments
- Create an action plan with clear milestones through 2027
NodeCE is prepared for CE marking and machine risk assessments under the Machinery Regulation.
Would you like to know how NodeCE can help?
We guide you through the Machinery Regulation and CRA requirements step by step. Contact NodeCE to learn how we can support your organization ahead of 2027.