NIS2 and the new Machinery Regulation (EU) 2023/1230
Two EU regulations raising the bar for industry in parallel — and how to prepare your machinery fleet for them.
For industrial companies, 2026-2027 brings together two EU regulations: NIS2, which raises requirements in the area of cybersecurity, and the new Machinery Regulation (EU) 2023/1230, which reorganizes machinery conformity assessment from the ground up. Both concern the same thing — your machines and systems — so it makes sense to approach them together, building on an organized asset record.
What is NIS2
NIS2 (Directive (EU) 2022/2555) is an EU cybersecurity directive that extends obligations to far more sectors than its predecessor — including manufacturing and production. For industrial plants, this means bringing control systems and shop-floor equipment (OT) under supervision as well.
- Cybersecurity risk management, including OT systems and shop-floor equipment
- Inventory and oversight of assets and IT systems
- Reporting significant incidents within defined deadlines
- Supply chain and supplier security
- Accountability and involvement of senior management
You can find out more about our approach to ISO and NIS2 compliance on the ISO / NIS2 Portal page.
The new Machinery Regulation (EU) 2023/1230
Regulation (EU) 2023/1230 replaces the previous Machinery Directive 2006/42/EC and applies from 20 January 2027. As a regulation, it applies uniformly across the EU, without the need for transposition into national law. Key changes:
- An expanded list of high-risk machinery and clarified conformity assessment paths (Annex I).
- Explicitly stated requirements for cybersecurity and the integrity of machinery software, as well as for machinery with digital and self-learning components.
- Acceptance of technical documentation in digital form.
- A clearer definition of a "substantial modification", which may require a new conformity assessment.
It is precisely in these digital and cyber requirements that the new Machinery Regulation meets the spirit of NIS2 — machine safety today also covers its digital layer.
NIS2 vs the Machinery Regulation — a comparison
| Criterion | NIS2 (2022/2555) | Machinery Regulation (2023/1230) |
|---|---|---|
| Scope | Cybersecurity of networks and systems | Machine safety and conformity (CE marking) |
| Who it applies to | Essential and important entities (including manufacturing) | Machine manufacturers and importers |
| Main obligation | Cyber risk management, incident reporting | Risk assessment, technical documentation, declaration of conformity |
| Form and application | Directive — national transposition (deadline 2024) | Regulation — applies from 20 Jan 2027 |
| Point of overlap | Asset oversight and risk management | Cybersecurity of digital machinery |
The machine classification module — how it supports compliance
The machine classification module guides the manufacturer and importer through the entire machine compliance cycle — step by step, with references to the relevant sections of the regulation:
- Machine classification — a questionnaire and rules engine determine whether a machine falls into the high-risk category (Annex I) and which path to follow for the conformity assessment.
- Risk assessment — a matrix of hazards, control measures and residual risk, with ready-made prompts.
- Register of substantial modifications — tracking changes that may require a new conformity assessment.
- Technical documentation — templates and generation of a complete documentation set.
- Declarations of conformity and incorporation (DoC / DoI) — generated as a PDF file.
- A gated workflow: classification → risk assessment → documentation → declarations — you always know what remains to be closed.
- Full audit trail — every change recorded in the history (who, when, what).
A single source of truth about assets and their compliance
An organized, classified and documented machine database is the foundation for both regulations: the Machinery Regulation requires risk assessment and documentation, while NIS2 requires asset oversight and risk management. Combining the machine classification module with a fixed-asset register (CMMS/EAM) and the ISO/NIS2 portal provides a single, auditable source of truth about your assets and their compliance.
This material is for informational purposes only and does not constitute legal advice. The scope of obligations depends on the profile and size of the company — if in doubt, consult an appropriate specialist.
Frequently asked questions
- Does the Machinery Regulation (EU) 2023/1230 apply already?
The regulation was adopted in 2023 but applies from 20 January 2027. Until then, Directive 2006/42/EC remains in force. It is worth preparing early, however, because adapting documentation and processes takes time.
- How does NIS2 differ from the Machinery Regulation?
NIS2 concerns the cybersecurity of networks and IT systems, while the Machinery Regulation concerns the safety and conformity of machines (CE marking). These are two separate regulations, although both apply to industrial companies, and the new Machinery Regulation also includes requirements for the cybersecurity of machinery.
- What is a "substantial modification" of a machine?
It is a change made to a machine after it has been placed on the market that affects its safety in a way not foreseen by the manufacturer. Such a modification may require a new conformity assessment. The machine classification module keeps a register of such changes.
- Does the module replace a notified body?
No. The module organizes the process, documentation and decisions and makes them easier to demonstrate, but it does not replace the involvement of a notified body where this is required by law.