Machinery Regulation, Protection Against Corruption and Safety and Reliability of Control Systems (Software and Cybersecurity Requirements)
Regulation (EU) 2023/1230, Annex III, sections 1.1.9 and 1.2.1
A product security requirements rule binding public and private bodies.
- Obligation class
- Security
As of .
What it requires
- This duty takes effect on (Article 54 of Regulation (EU) 2023/1230), when Directive 2006/42/EC is repealed (Article 51(2)).
- It reaches you if you are a manufacturer, meaning a person that makes machinery or a related product and markets it under its name or trademark, or puts it into service for its own use, and you place that product on the EU market or put it into service; a safety component can be a digital component, including software, that is independently placed on the market to fulfil a safety function: design and construct the product in accordance with the essential health and safety requirements of Annex III (Articles 2(1), 3, point (3), and 10(1)); sections 1.1.9 and 1.2.1 hold its provisions on protection against corruption of software and data and on malicious third-party influence on control systems.
- Design and construct the product so that connecting another device, through a feature of that device or a remote device that communicates with it, does not lead to a hazardous situation (section 1.1.9).
- Design a hardware component that transmits signal or data relevant for connection or access to software critical for compliance so that it is adequately protected against accidental or intentional corruption, and identify software and data critical for compliance as such and protect them adequately against accidental or intentional corruption (section 1.1.9).
- Make the product identify the software installed on it that is necessary for it to operate safely and provide that information at all times in an easily accessible form, and collect evidence of a legitimate or illegitimate intervention in that hardware component, in the software, or in a modification of the software or its configuration (section 1.1.9).
- Design and construct control systems so that they can withstand, where appropriate to the circumstances and the risks, the intended operating stresses and intended and unintended external influences, including reasonably foreseeable malicious attempts from third parties leading to a hazardous situation (section 1.2.1, point (a)).
- Enable a tracing log of the data generated in relation to an intervention, and of the versions of safety software uploaded after the product is placed on the market or put into service, for five years after each upload, exclusively to demonstrate conformity further to a reasoned request from a competent national authority (section 1.2.1, point (f)).
- For control systems with fully or partially self-evolving behavior or logic designed to operate with varying levels of autonomy, enable the recording of data on the safety related decision-making process of software based safety systems, retain it for one year after its collection, and make it possible at all times to correct the product to maintain its inherent safety (section 1.2.1).
- The Regulation does not apply to, among others, motor vehicles within the scope of Regulation (EU) 2018/858, except for machinery mounted on them, or to household appliances, audio and video equipment and information technology equipment insofar as they fall within Directive 2014/35/EU or Directive 2014/53/EU (Article 2(2), points (g) and (p)).
Who enforces it
Enforcement body
The market surveillance authorities of each Member State, which evaluate a product within the scope of the Regulation under Article 43.
What this law does
Article 2(1) applies the Machinery Regulation to machinery and to the related products interchangeable equipment, safety components, lifting accessories, chains, ropes and webbing, and removable mechanical transmission devices, and to partly completed machinery.
Article 3, point (3), defines a safety component as a physical or digital component, including software, of a product within the scope of the Regulation that is designed or intended to fulfil a safety function and is independently placed on the market.
Article 3, point (18), defines a manufacturer as any natural or legal person who manufactures products within the scope of the Regulation, or has them designed or manufactured, and markets them under its name or trademark, or who manufactures such products and puts them into service for its own use.
Article 10(1) requires a manufacturer placing machinery or a related product on the market or putting it into service to ensure that it has been designed and constructed in accordance with the essential health and safety requirements of Annex III.
Section 1.1.9 of Annex III requires the product to be designed and constructed so that the connection to it of another device, via any feature of the connected device itself or via any remote device that communicates with it, does not lead to a hazardous situation.
A hardware component transmitting signal or data, relevant for connection or access to software that is critical for the compliance of the product with the relevant essential health and safety requirements, must be designed so that it is adequately protected against accidental or intentional corruption. Software and data that are critical for that compliance must be identified as such and adequately protected against accidental or intentional corruption.
The product must identify the software installed on it that is necessary for it to operate safely and be able to provide that information at all times in an easily accessible form. It must collect evidence of a legitimate or illegitimate intervention in the software or a modification of the software installed on it or its configuration.
Section 1.2.1 requires control systems to be designed and constructed so that they can withstand, where appropriate to the circumstances and the risks, the intended operating stresses and intended and unintended external influences, including reasonably foreseeable malicious attempts from third parties leading to a hazardous situation.
It requires the tracing log of the data generated in relation to an intervention, and of the versions of safety software uploaded after the product has been placed on the market or put into service, to be enabled for five years after each upload, exclusively to demonstrate conformity further to a reasoned request from a competent national authority.
For control systems with fully or partially self-evolving behavior or logic that are designed to operate with varying levels of autonomy, it requires recording of data on the safety related decision-making process for software based safety systems to be enabled after the product is placed on the market or put into service, and that data to be retained for one year after its collection.
It also requires that it be possible at all times to correct such a product in order to maintain its inherent safety. Under Article 20(9), machinery and related products certified, or covered by a statement of conformity, under a cybersecurity certification scheme adopted under Regulation (EU) 2019/881 whose references are published in the Official Journal are presumed to conform to sections 1.1.9 and 1.2.1 insofar as the certificate or statement covers those requirements.
Article 2(2) leaves out motor vehicles and their trailers, and the systems, components, separate technical units, parts and equipment designed and constructed for them, that fall within the scope of Regulation (EU) 2018/858, except for machinery mounted on those vehicles.
It also leaves out household appliances, audio and video equipment, information technology equipment and certain other electrical and electronic products insofar as they fall within the scope of Directive 2014/35/EU or of Directive 2014/53/EU. Article 54 provides that the Regulation applies from . Article 51(2) repeals Directive 2006/42/EC with effect from .
Article 50(1) leaves the rules on penalties to the Member States, requires them to be effective, proportionate and dissuasive, and provides that they may include criminal penalties for serious infringements.
When LexLint raises it
When your app profile says your app distributes a software product or ships a mobile app.