Entering the EU Machinery Regulation Era: Rethinking Manufacturing Safety Through Machine Safety, Functional Safety and Cybersecurity-

2026 / 08 / 20 Views:2949
Writer: Chen-Chi Chi, Manager, Product Certification Department, TÜV NORD Taiwan Co., Ltd.

Preface: Machine Safety Is Entering a New Era

In the past, when discussing the “safety” of machinery and equipment, most engineers first thought of traditional machine safety measures such as guards, emergency stops, two-hand controls, photoelectric safety devices, door interlock switches and safety relays. With advances in control technology, functional safety has gradually become a key element of machine safety design, and standards such as EN ISO 13849-1 and IEC/EN 62061 have become important tools familiar to machinery engineers. However, with the rapid development of Industry 4.0, smart manufacturing and the Industrial Internet of Things, machinery is no longer an isolated mechanical system.

Modern machinery may include PLCs, HMIs, servo drives, industrial Ethernet, remote maintenance functions, USB interfaces, cloud connectivity, MES/SCADA interfaces, and even AI or autonomous decision-making capabilities. Once equipment is connected to a network, what was originally a straightforward safety issue may evolve into a safety issue caused by a cybersecurity incident.

For example, if a hacker gains control of a PLC, safety-related parameters may be modified. Malware may alter control logic and cause hazardous motion. Unauthorized firmware updates may affect safety functions. Communication interference or data tampering may turn originally correct control commands into dangerous outcomes. As a result, the machinery industry is facing a significant transformation: machine safety, functional safety and cybersecurity will no longer be three independent areas of expertise, but three major pillars that together define the safety of modern machinery. This marks the beginning of a new “three-pillar” era for the machinery industry.

 

 

1. From the Machinery Directive to the Machinery Regulation: The Concept of Safety Is Expanding

The EU Machinery Regulation (EU) 2023/1230, hereinafter referred to as the MR, will replace the Machinery Directive 2006/42/EC. The MR will apply from January 20, 2027, replacing the current directive. This is not merely a change in regulatory name; it reflects a shift in the EU’s safety concept for modern machinery. Traditional machine safety mainly focused on whether the mechanical structure is safe, whether personnel may access hazardous areas, whether protective devices are effective, whether emergency stops are reliable, and whether control system failures may create hazards.

Modern machinery, however, must further address whether control systems may be modified without authorization, whether software may be tampered with, whether firmware updates are controlled, whether machinery can maintain a safe state during network attacks, whether remote maintenance may become an attack entry point, whether USB, Ethernet or wireless communication interfaces may create hazards, and whether software versions and safety parameters can be traced.

MR Annex III has incorporated requirements for protection against corruption, as well as the safety and reliability of control systems. It also introduces corresponding requirements for certain control systems with self-evolving behavior or autonomous logic. This represents an important trend: cybersecurity in machinery is beginning to directly intersect with machine safety.

 

 

2. The Three Pillars: The Core Safety Foundations of Modern Machinery

Source : TUV NORD (2026)

 

If modern machinery is compared to a building, the three major safety domains can be viewed as three essential pillars.

The first pillar is machine safety, which addresses the fundamental question: “Can the machine itself harm people?” Its core is risk assessment and risk reduction based on machine hazards, including mechanical, electrical, thermal, ergonomic and pressure hazards, accidental start-up, access to hazardous areas, and hazards during maintenance and servicing. The risk assessment and risk reduction methodology established by EN ISO 12100 remains the foundation of machine safety design: hazard identification, risk assessment, risk reduction and verification.

The second pillar is functional safety, which addresses another question: “When a control system fails, can the machine enter a safe state?” Examples include stopping hazardous motion when a guard door is opened, cutting off hazardous energy when an emergency stop is activated, stopping machinery when a photoelectric safety device detects personnel entering the area, or allowing a servo drive to execute STO. Functional safety is therefore not simply about whether safety devices exist, but about proving that the safety function remains sufficiently reliable under reasonably foreseeable fault conditions. This is why EN ISO 13849-1 and IEC/EN 62061 are so important.

The third pillar is cybersecurity, which is becoming part of machine safety. Traditional cybersecurity usually focuses on confidentiality, integrity and availability, commonly known as the CIA triad. For machinery, however, one additional concept is essential: safety impact. In an IT environment, modified data may simply cause incorrect information. In an OT environment, the same data manipulation may directly lead to injury. Cybersecurity risk can ultimately become machine safety risk, which is one of the key differences between IT and OT cybersecurity.

 

 

3. Why Functional Safety and Cybersecurity Can No Longer Be Separated

Consider a simple example: an automated processing machine equipped with a safety door, Safety PLC, servo drive, STO, Ethernet and remote maintenance functions. Engineers may complete the safety function design according to EN ISO 13849-1 and verify that the required Performance Level has been achieved. From a traditional functional safety perspective, the design may appear completely valid. However, if an attacker can gain engineering access to the PLC via Ethernet and modify the Safety PLC program or safety parameters, the question becomes critical: Can the originally verified safety function still be considered to retain its original safety integrity?

This question is crucial. Functional safety usually assumes that safety-related control functions operate as designed. Cybersecurity, on the other hand, must ask: “What happens if someone maliciously changes these control functions?”

 

 

4. The Real Change Brought by the MR: Safety Must Extend from the Product to the Lifecycle

One of the important implications of the MR is that machine safety is no longer only a matter of design and testing before a product leaves the factory. Risks in modern machinery may emerge after the product has entered the market. A machine may have no known vulnerabilities when shipped, but three years later a new CVE may be discovered in its operating system. Equipment may originally use secure communication settings, but a customer may later enable new network services for remote maintenance. A manufacturer may release new firmware that changes safety-related behavior. This means machinery manufacturers must begin establishing a cybersecurity lifecycle, which differs significantly from traditional CE technical documentation management.

 

 

5. The Cyber Resilience Act Further Institutionalizes Machinery Cybersecurity

In addition to the MR, the EU Cyber Resilience Act, or CRA, Regulation (EU) 2024/2847, is establishing new cybersecurity requirements for products with digital elements. The CRA covers product design, development, production and vulnerability handling processes. Its general application date is December 11, 2027, while reporting obligations for actively exploited vulnerabilities and severe incidents will apply from September 11, 2026. For machinery manufacturers, the broader trend is the emergence of an interdisciplinary product safety engineering system combining safety engineering, functional safety and cybersecurity engineering.

 

 

6. Manufacturers Should Establish an Integrated Safety Engineering Process

For machinery manufacturers, the real challenge is not to create three separate sets of documents, but to establish one engineering process that integrates the three safety domains. A recommended structure begins with machine risk assessment based on EN ISO 12100, followed by safety function specification, functional safety analysis, cybersecurity threat analysis and the establishment of a safety–security interface. The key task is to link cybersecurity threats to safety impact and safety mitigation.

Manufacturers’ organizational capabilities must also change. In the past, machinery manufacturers often assigned machine safety, electrical safety, functional safety and cybersecurity to separate departments. In the future, however, hazards will often arise at the interfaces between these domains. A cybersecurity engineer may believe that account permissions are controlled, a functional safety engineer may believe that the Safety PLC has achieved PL d, and a machine safety engineer may believe that the guard door meets requirements. Yet if the three do not jointly analyze whether an attacker with engineering privileges could modify the Safety PLC, each design may meet its own requirements while the overall system still contains a safety gap. Future manufacturers will therefore need integrated machine safety, functional safety and cybersecurity reviews rather than three unrelated review processes.

 

 

7. From Compliance to Security by Design

For machinery manufacturers, the most important conceptual shift is not to wait until a product is completed before addressing cybersecurity. If issues such as the absence of Secure Boot, unsigned firmware, overly broad user permissions, unauthenticated remote maintenance, directly modifiable safety parameters or unprotected network communication are discovered only at the final development stage, the required corrections may involve hardware, PLCs, firmware, HMIs, network architecture, safety validation and technical documentation, resulting in significant development costs.

Future machinery products should therefore gradually introduce Security by Design alongside the traditional concept of Safety by Design, eventually integrating both into Safety & Security by Design. This does not mean every machine safety engineer must become a cybersecurity expert, nor that every cybersecurity engineer must become a mechanical design engineer. What truly needs to change is cross-disciplinary understanding. Future machine safety engineers must at least understand machine safety, functional safety and cybersecurity, and more importantly, know how cybersecurity incidents can be transformed into safety risks.

 

 

8. What Should Machinery Manufacturers Do Now?

In response to the MR, the CRA and the rapid development of smart manufacturing, manufacturers do not need to wait until the regulations formally apply before preparing. They can begin immediately by reviewing product network architecture, establishing cybersecurity threat assessments, building a safety–security interface, incorporating cybersecurity into the early stages of product design, creating software and firmware lifecycle management, and cultivating cross-disciplinary talent. The most valuable engineering talent of the future may not be the specialist in only one domain, but the person who can understand the full relationship among machine, control, safety, network and cybersecurity.

 

 

Conclusion: Future Safe Machinery Must Be Both Safe and Trustworthy

The machinery industry is moving from automation toward intelligence. Machinery is no longer merely a combination of motors, gears, hydraulics, pneumatics and electrical controls; it is becoming a cyber-physical system with sensing, control, communication, software, data and intelligent decision-making capabilities. As a result, the boundaries of traditional machine safety are disappearing.

In the past, we asked: “If a component fails, will the machine create a hazard?” Functional safety led us to ask: “If the control system fails, can the safety function still operate correctly?” Now we must ask: “If someone maliciously attacks the control system, can the safety function still be trusted?” These three questions represent three stages in the development of machine safety.

Machine Safety ensures that the machine itself does not create unacceptable hazards. Functional Safety ensures that the control system can still perform safety functions under fault conditions. Cybersecurity ensures that control systems do not compromise safety functions due to malicious attacks, unauthorized access or data tampering.

These three domains do not replace one another; they reinforce one another. Therefore, the real challenge of the new CE MR era is not simply to add another cybersecurity standard, but to establish a new engineering mindset: safety is not achieved by mechanical, control and cybersecurity departments completing their own work independently, but by all three sharing responsibility for the same ultimate goal—ensuring that machinery can maintain an acceptable safe state throughout its entire lifecycle, even in the face of failures, misuse and cyberattacks. This means that future machine safety will evolve from machine safety alone toward a three-pillar era of Machine Safety × Functional Safety × Cybersecurity. For machinery manufacturers, beginning to consider this transformation now is not merely about responding to a new regulation; it is about building a truly reliable safety foundation for the next generation of smart machinery.

 

 


References

  1. TÜV NORD Taiwan. “Cyber Resilience Act (CRA).” TÜV NORD Taiwan. Available at: https://www.tuv-nord.com/tw/zh/%E9%A6%96%E9%A0%81/%E7%94%A2%E5%93%81%E8%88%87%E6%9C%8D%E5%8B%99/%E5%8A%9F%E8%83%BD%E5%AE%89%E5%85%A8/cyber-resilience-act-cra-%E7%B6%B2%E8%B7%AF%E9%9F%8C%E6%80%A7%E6%B3%95%E6%A1%88/

  2. David Lin. “EU CRA Regulation and Harmonized Standards.” David Lin Consultant Notes, June 18, 2026. Available at: https://linchew.com/eu-cra-regulation-and-harmonized-standards/