In recent years, digital transformation has revolutionized the way we work and live. Our daily lives are increasingly interconnected thanks to the expansion of Internet connectivity, smart devices, and the digitalization of services. All of this creates extraordinary opportunities for growth and innovation, even if these changes have sometimes occurred almost invisibly. However, this evolution also brings new challenges. One of these is cybersecurity, which has become essential for protecting data, processes, and infrastructures. To address this challenge, companies must identify their vulnerabilities and adopt effective strategies to prevent cyberattacks and mitigate their impact.
Machinery Regulation (EU) 2023/1230 and Cybersecurity
The Machinery Regulation (EU) 2023/1230 recognizes that a machine can be attacked remotely through a network connection or a software update. For this reason, it introduces explicit requirements for protecting machinery against unauthorized cyber access and alterations that could compromise the safety of people.
The Regulation explicitly acknowledges this scenario in Recital 25, which highlights that malicious actors may affect product safety through cyberattacks and that manufacturers must implement proportionate measures to safeguard the safety of machinery.
Within the context of the Machinery Regulation, cybersecurity requirements are not intended to protect corporate data or user privacy. Their purpose is to ensure product safety. The objective is to prevent cyberattacks from creating hazardous situations for people, animals, or property.
The new cybersecurity-related requirements are primarily contained in Section 1.1.9 of Annex III. According to this Essential Health and Safety Requirement (EHSR), machinery must be designed so that:
Cybersecurity requirements are also introduced under Section 1.2.1 of Annex III. Control systems are required not only to withstand faults, errors, and disturbances, but also to maintain their safety functions, which must be designed to counter manipulation attempts and malicious attacks.
It is easy to see how this affects an increasing number of machines. Consider their connection to the Internet, the use of remote support systems, wireless technologies, and integration into Industry 4.0 architectures. As a result, functionalities such as remote software updates and cloud-based monitoring must be evaluated not only from a functional perspective but also in terms of cybersecurity and regulatory compliance.
What Should Manufacturers Do and Which Standards Should They Use?
Although the Machinery Regulation will apply from 20 January 2027, the necessary activities should begin today.
In practice, machine manufacturers should ask themselves: "Could a cyberattack create a hazardous situation or compromise a safety function?" If the answer is yes, a series of actions should be planned and implemented as soon as possible.
The first step is undoubtedly to analyze machinery in order to identify potential attack surfaces. This assessment will require a review of the risk assessment process to include cyber-related risks. Based on this evaluation, manufacturers can define the cybersecurity requirements that hardware and software must meet. These requirements will then lead to the implementation of appropriate protection measures already during the design phase, following a security-by-design approach.
Naturally, all these requirements must be documented and demonstrated through technical documentation and company procedures.
Fortunately, manufacturers can rely on established standards. In the field of industrial cybersecurity, the primary international reference is currently the IEC 62443 series.
At the European level, the forthcoming EN 50742 – Safety of machinery – Protection against corruption standard is expected to be published soon. This standard is intended to fill the gap created by the Machinery Regulation regarding Sections 1.2.1(a), 1.2.1(f), and 1.1.9. It will provide specific guidance on meeting the requirements related to protection against manipulation and cyberattacks. Once harmonized, it is expected to become a key reference for the design and assessment of machinery cybersecurity.
Does Everything Change?
In conclusion, cybersecurity is no longer a topic confined to the IT domain. It is becoming a genuine machinery safety requirement.
The objective of the Regulation is to ensure that machinery remains safe, reliable, and competitive, even when interconnected. The challenge for manufacturers is to achieve this in a simple, structured, and compliant manner.
The challenge has already begun...