Products in Scope

The Machinery Regulation cybersecurity question starts with the product. Regulation (EU) 2023/1230 applies to machinery, listed related products, and partly completed machinery. Cybersecurity evidence is then relevant only when software, data, interfaces, or digital components affect the safety requirements for that in-scope product.

Products in scope

This Regulation applies to machinery and the following related products: (a) interchangeable equipment; (b) safety components; (c) lifting accessories; (d) chains, ropes and webbing; (e) removable mechanical transmission devices. This Regulation also applies to partly completed machinery.

Regulation (EU) 2023/1230, Article 2(1)

The listed related products are interchangeable equipment, safety components, lifting accessories, chains, ropes and webbing, and removable mechanical transmission devices. The Regulation also applies to partly completed machinery. Together, those are the products within the scope of the Regulation.

Machinery

The definition covers assemblies with linked parts or components, at least one moving part, and a specific application. It also covers machinery missing only the upload of application software foreseen by the manufacturer.

Related products

The listed related products are not optional examples. They are source-defined product categories in Article 2.

Partly completed machinery

Partly completed machinery is within scope, but it has a specific incorporation route because it cannot itself perform its specific application.

Safety components

A safety component can be physical or digital, including software, if it fulfils the Article 3 definition and is independently placed on the market.

Software can change the product boundary

Regulation (EU) 2023/1230 treats software in two important ways. First, an assembly can still be machinery when it is missing only the upload of software intended for the specific application foreseen by the manufacturer. Second, software that performs a safety function and is independently placed on the market can be a safety component.

These rules stop the cybersecurity analysis from being limited to physical hardware. A robot controller image, safety PLC application, drive safety configuration, or separate safety-function software can be central to the machinery-safety conclusion when it fits the source definition.

Market and use terms

The Regulation uses different trigger terms. They should not be merged into one general idea.

Explicit exclusions

Article 2 also excludes specific products. The exclusions matter because an item can look like machinery in engineering terms and still fall outside the Regulation for that category or risk.

  • identical spare safety components supplied by the original manufacturer;
  • specific equipment for fairgrounds or amusement parks;
  • weapons, including firearms;
  • means of transport by air, water, and rail networks, except for machinery mounted on those means of transport;
  • motor vehicles, trailers, systems, components, separate technical units, and agricultural or forestry vehicles to the extent listed Union legislation covers the relevant risks;
  • seagoing vessels, mobile offshore units, and machinery installed on board them;
  • machinery or related products specially designed and constructed for military or police purposes.

Cybersecurity relevance

Once the product is in scope, the cybersecurity question is not whether the product is connected in a general sense. The relevant question is whether a connection, software item, data item, configuration, safety component, or intervention path can affect the applicable essential health and safety requirements.

Sources