NIS2 and the new Machinery Regulation (EU) 2023/1230

Two EU regulations raising the bar for industry in parallel — and how to prepare your machinery fleet for them.

For industrial companies, 2026-2027 brings together two EU regulations: NIS2, which raises requirements in the area of cybersecurity, and the new Machinery Regulation (EU) 2023/1230, which reorganizes machinery conformity assessment from the ground up. Both concern the same thing — your machines and systems — so it makes sense to approach them together, building on an organized asset record.

What is NIS2

NIS2 (Directive (EU) 2022/2555) is an EU cybersecurity directive that extends obligations to far more sectors than its predecessor — including manufacturing and production. For industrial plants, this means bringing control systems and shop-floor equipment (OT) under supervision as well.

  • Cybersecurity risk management, including OT systems and shop-floor equipment
  • Inventory and oversight of assets and IT systems
  • Reporting significant incidents within defined deadlines
  • Supply chain and supplier security
  • Accountability and involvement of senior management

You can find out more about our approach to ISO and NIS2 compliance on the ISO / NIS2 Portal page.

The new Machinery Regulation (EU) 2023/1230

Regulation (EU) 2023/1230 replaces the previous Machinery Directive 2006/42/EC and applies from 20 January 2027. As a regulation, it applies uniformly across the EU, without the need for transposition into national law. Key changes:

  • An expanded list of high-risk machinery and clarified conformity assessment paths (Annex I).
  • Explicitly stated requirements for cybersecurity and the integrity of machinery software, as well as for machinery with digital and self-learning components.
  • Acceptance of technical documentation in digital form.
  • A clearer definition of a "substantial modification", which may require a new conformity assessment.

It is precisely in these digital and cyber requirements that the new Machinery Regulation meets the spirit of NIS2 — machine safety today also covers its digital layer.

NIS2 vs the Machinery Regulation — a comparison

CriterionNIS2 (2022/2555)Machinery Regulation (2023/1230)
ScopeCybersecurity of networks and systemsMachine safety and conformity (CE marking)
Who it applies toEssential and important entities (including manufacturing)Machine manufacturers and importers
Main obligationCyber risk management, incident reportingRisk assessment, technical documentation, declaration of conformity
Form and applicationDirective — national transposition (deadline 2024)Regulation — applies from 20 Jan 2027
Point of overlapAsset oversight and risk managementCybersecurity of digital machinery

The machine classification module — how it supports compliance

The machine classification module guides the manufacturer and importer through the entire machine compliance cycle — step by step, with references to the relevant sections of the regulation:

  • Machine classification — a questionnaire and rules engine determine whether a machine falls into the high-risk category (Annex I) and which path to follow for the conformity assessment.
  • Risk assessment — a matrix of hazards, control measures and residual risk, with ready-made prompts.
  • Register of substantial modifications — tracking changes that may require a new conformity assessment.
  • Technical documentation — templates and generation of a complete documentation set.
  • Declarations of conformity and incorporation (DoC / DoI) — generated as a PDF file.
  • A gated workflow: classification → risk assessment → documentation → declarations — you always know what remains to be closed.
  • Full audit trail — every change recorded in the history (who, when, what).

A single source of truth about assets and their compliance

An organized, classified and documented machine database is the foundation for both regulations: the Machinery Regulation requires risk assessment and documentation, while NIS2 requires asset oversight and risk management. Combining the machine classification module with a fixed-asset register (CMMS/EAM) and the ISO/NIS2 portal provides a single, auditable source of truth about your assets and their compliance.

This material is for informational purposes only and does not constitute legal advice. The scope of obligations depends on the profile and size of the company — if in doubt, consult an appropriate specialist.

Frequently asked questions

  • Does the Machinery Regulation (EU) 2023/1230 apply already?
  • How does NIS2 differ from the Machinery Regulation?
  • What is a "substantial modification" of a machine?
  • Does the module replace a notified body?