Risk assessment from 20 January 2027: what the EU Machinery Regulation changes

· Dipl.-Ing. Wojciech Protasiewicz

On 20 January 2027, Regulation (EU) 2023/1230 on machinery becomes generally applicable and replaces Machinery Directive 2006/42/EC. For manufacturers this does not mean that risk assessment has to be reinvented. On the contrary: the familiar iterative process remains. The new regulation does, however, make it clearer that modern machinery no longer consists of mechanics and electrics alone. Software, connectivity, changing behaviour and later digital modifications can also affect machinery safety.

For design engineers and those responsible for CE marking, the decisive question is therefore not whether a risk assessment will be required from 2027. It already was. What matters more is what has to be considered and documented in addition.

The methodology of risk assessment stays the same at its core

Anyone who already carries out risk assessments in a methodically sound way does not have to rebuild the process from scratch. The general principles in Annex III of the Machinery Regulation still describe an iterative procedure in five steps:

  1. establish the limits of the machinery, including intended use and reasonably foreseeable misuse,
  2. identify the hazards and the associated hazardous situations,
  3. estimate the risks, taking into account the severity of harm and the probability of occurrence,
  4. evaluate whether further risk reduction is necessary,
  5. eliminate hazards or reduce risks through protective measures.

The design is then developed further on the basis of these results. Risk assessment therefore remains part of the design process, not a document written up at the end of a project.

The familiar hierarchy of risk reduction remains as well: hazards should first be eliminated or reduced through inherently safe design. Only then come technical protective measures and, finally, user information about remaining residual risks.

Methodologically, this is familiar ground. What is new is above all what has to be considered within this process.

1. Software becomes a subject of the risk assessment

With classical machinery, a hazard can usually be traced directly back to a physical cause: a rotating shaft, a crushing point, a hot surface or stored pneumatic energy. With modern machinery, the cause of a dangerous state can just as well lie in software or parameterisation.

An example: a guard door is opened. The machine’s safe reaction depends on sensors, the safety controller, parameterisation and drive functions interacting correctly. An unintended change to a safety-related parameter can therefore ultimately lead to the same hazard as a mechanical defect.

The Machinery Regulation expressly takes account of this development. Safety-related software and data have to be identified and adequately protected against unintended or intentional modification. The machine must also be able to identify the software needed for its safe operation. Interventions in software or configuration should be traceable.

For the risk assessment, this leads to a practical question: which software, parameters and digital interfaces can influence a dangerous machine state?

This does not necessarily affect every software component of a machine. A visualisation showing production figures has a different safety significance from a parameter that determines the permissible range of movement or the reaction of a safety function. What remains decisive is the possible effect on safety.

2. Cybersecurity can become part of machinery safety

The Machinery Regulation therefore also creates a much closer link between safety and security. This does not mean that every IT threat has to become part of a machine’s risk assessment in future. The decisive connection exists where a digital attack or manipulation can lead to a hazard to persons.

On this subject, Annex III contains requirements for protection against corruption in section 1.1.9. For example, connecting another or a remote device to the machine must not lead to a hazardous situation. Safety-related hardware, software and data have to be adequately protected against unintentional and intentional manipulation. Foreseeable malicious interference by third parties with control systems is also expressly addressed, insofar as it can lead to a hazardous situation.

PLC rack with input and output modules, field terminals and wiring in a control cabinet

Safety functions now sit in the controller, in parameters and in software. Protection against manipulation therefore belongs in the risk assessment.
Image: "BMA Automation Allen Bradley PLC 3" by Elmschrat, CC BY-SA 3.0, edited.

For a connected machine, the following relationships can therefore become relevant, for example: remote access enables the modification of safety-related parameters. An insufficiently protected interface allows the manipulation of a control function. A software update changes the behaviour of a safety function. Or a changed configuration means that an originally limited range of movement is exceeded.

The risk assessment does not have to become a full cybersecurity audit in the process. Its task is rather to examine the safety-related chain of effects: digital interference → change in machine behaviour → hazardous situation → possible harm. Machinery design, functional safety and industrial security thereby move closer together.

3. Self-changing and autonomous behaviour has to be thought through in advance

The Machinery Regulation widens the view most clearly for machinery whose behaviour can continue to develop after placing on the market, within foreseen limits.

Risk assessment and risk reduction have to include hazards that can foreseeably arise during the life cycle from an intended development of fully or partially self-evolving behaviour or the corresponding logic. This concerns machinery designed for operation with varying degrees of autonomy.

In the risk assessment, the manufacturer may therefore not look exclusively at the state the machine is in on the day it is placed on the market, if it is already foreseen that its behaviour will change later. With a classical machine, the intended state can be described in comparatively static terms. With a machine whose behaviour can change, it additionally has to be established within which limits this change may take place.

The regulation accordingly requires that the control systems of such machinery must not lead to actions outside the defined task and the foreseen space of movement. In addition, the limits of safety functions have to be established as part of the risk assessment. For the risk assessment this means: the machinery limits become even more important.

4. Interactions between machinery count as well

A hazard does not always arise within a single assembly. With linked machinery, individually safe machines can jointly create a new hazard. Examples are material handovers, mutual start enables, overarching emergency stop concepts or movements that only become dangerous through the interplay of several machines.

The Machinery Regulation expressly requires that risks arising from interactions between machinery be taken into account where the machines are arranged and controlled so that they function as a whole. For plant builders and integrators this point is particularly important. It is not enough to simply file the risk assessments of the individual machines built in. In addition, it has to be considered which hazards arise from the components interacting within the plant as a whole.

It is precisely at the interfaces that the advantage of a risk assessment structured by assemblies and functions becomes apparent. A hazard needs more than a name: it has to be traceable where it arises, which function is affected and which protective measure controls it.

5. Changes to existing machinery gain in importance

Another important point of the new regulation is the European definition of substantial modification.

It can arise from physical as well as digital changes. One precondition is, among other things, that the change was not foreseen or planned by the original manufacturer, that it affects safety and that it creates a new hazard or increases an existing risk. In addition, the additional protective measures named in the definition must be present, such as a modification of the existing safety-related control system as a result of additional protective devices, or additional measures to ensure stability or mechanical strength.

This makes clear: not every software update, every conversion and every parameter change is automatically a substantial modification. But every safety-related change demands the question of what effects it has on existing hazards and risks.

Anyone carrying out a substantial modification can, under Article 18 of the Machinery Regulation, themselves become the manufacturer of the machinery or product concerned. In the case of a machinery plant, this responsibility can also be limited to the part concretely affected by the modification, if this is demonstrated by the risk assessment.

This increases the importance of another capability: being able to pick up an existing risk assessment again later and continue it in a targeted way. A risk assessment whose connections are no longer traceable years later makes exactly this task harder.

6. The risk assessment has to document the line of reasoning

A risk assessment is more than the longest possible list of identified hazards. What matters is that the technical documentation makes the process actually carried out traceable.

Within the technical documentation, Annex IV of the Machinery Regulation expressly requires documentation on the risk assessment from which the procedure followed is apparent. This includes the applicable essential health and safety requirements as well as the protective measures with which the identified hazards were eliminated or the associated risks reduced. Where necessary, remaining residual risks also have to be stated.

Laptop on a workbench showing a dimensioned technical drawing

Technical documentation has to make it traceable how the decision was reached, from the requirement through the hazard to the protective measure.

A quality criterion follows from this: a good risk assessment documents the connection between requirement, hazard, evaluation, protective measure and residual risk, not merely the result.

That is exactly where grown Excel and Word solutions often run into difficulties. A value is changed, a protective measure added or an assembly carried over from an earlier project, but later it is barely recognisable which entries belong together in technical terms. As software versions, changes and variants gain in importance, this traceability becomes even more important.

7. The essential safety requirements move from Annex I to Annex III

With the new regulation, a familiar designation in the CE process changes as well. Under the Machinery Directive, the essential health and safety requirements are located in Annex I. In the Machinery Regulation they are found in Annex III.

That initially sounds like a purely editorial change. For existing processes it is relevant all the same. Templates, work instructions, CE checklists, software catalogues and report structures that refer to “Annex I of the Machinery Directive” have to be reviewed. At the same time, the opportunity should be taken to assess the new and amended requirements on their merits, alongside the numbering.

The Machinery Regulation makes one thing expressly clear here: which essential health and safety requirements apply to a concrete machine follows from the risk assessment. The list of requirements and the hazard analysis are therefore not documents independent of each other.

What does this mean for existing risk assessments?

20 January 2027 does not mean that all machinery already in existence has to be assessed again and CE-marked afresh. Products placed on the market before this date in accordance with Machinery Directive 2006/42/EC may continue to be made available on the market. The Machinery Directive is repealed with effect from 20 January 2027 and the Machinery Regulation becomes generally applicable from that date.

For ongoing development projects the situation is different. If a machine is to be placed on the market or put into service for the first time only from 20 January 2027, the requirements of the Machinery Regulation should already be taken into account during design. “Switching” the risk assessment to a new legal basis shortly before delivery falls short. A risk assessment is meant to influence design decisions.

What companies should check now

For many machinery manufacturers, no revolution of the CE process is therefore necessary. A targeted gap analysis is the sensible approach.

First, it should be checked whether the existing method actually maps the complete iterative process, from the machinery limits through hazard identification and risk estimation to risk reduction. Then it has to be examined how the new topics are integrated into the existing process.

Particular attention is due to safety-related software and parameters, connectivity and remote access, possibilities of manipulation, planned software changes, machinery with changing or autonomous behaviour, and interfaces within linked plants. It should equally be clarified how changes after placing on the market are documented and assessed in safety terms.

Finally, a look at the documentation structure itself is worthwhile: years later, can the hazard, its original evaluation, the associated protective measures, the standards applied, the essential safety requirements and the remaining residual risk still be related to one another? With variants and special-purpose machinery in particular, this question is often more decisive than the sheer number of filled-in table fields.

Risk assessment with Probavis

Probavis is designed to map the individual steps of the risk assessment in a common project structure. Machinery limits, functions, hazards, risk evaluations, protective measures, standards and essential health and safety requirements remain linked to one another. Hazards can be evaluated with the parameters Se, Fr, Pr and Av; protective measures and residual risks are documented directly at the respective hazard. Recurring assemblies, including their evaluations and protective measures, can be carried over into further projects. From the information maintained in the project, the risk assessment report can then be generated.

Detail view of a hazard in Probavis with the fields designation, location, group, origin, consequences and causes, below them the risk evaluation with Se, Fr, Pr and Av including the risk level, the assigned essential requirements, the life phases concerned and the residual risk

A hazard in Probavis: description, risk evaluation according to ISO/TR 14121-2 with Se, Fr, Pr and Av, assigned essential health and safety requirements, life phases concerned and residual risk are held in one place (German user interface).

This allows the risk assessment to be continued during development, instead of being assembled at the end of the project from different tables, documents and earlier templates. With the Machinery Regulation, this does not become more important because the basic method of risk assessment changes completely. It becomes more important because more technical connections have to remain cleanly traceable.

The central task remains the same as before: identify hazards systematically, evaluate risks traceably and document the technical decisions made in a lasting way. Anyone who has already organised this process soundly today does not have to reinvent it for 2027. They have to extend it in the right places.

As of August 2026. Legal basis: Regulation (EU) 2023/1230 on machinery. Following the official corrigendum of 4 July 2023, the relevant general date of application is 20 January 2027. This article provides technical information and does not replace a legal assessment of the individual case.