The new EU Machinery Regulation comes into force in January 2027. For manufacturing companies, this means preparing for stricter requirements—especially when it comes to protection against cyber attacks.
Only one year to go: the new EU Machinery Regulation makes cybersecurity mandatory. Companies should act now.
The urgency is real: cyberattacks on production facilities can not only cause expensive downtime, but also jeopardize the existence of entire companies. The new regulation responds to this threat and makes cybersecurity mandatory. For machine manufacturers, this means that they must incorporate protective measures right from the design stage. Industrial companies, on the other hand, must operate and maintain their devices carefully.
But where to start? The automation experts at Omron have put together five practical tips that companies can use to prepare themselves optimally for the new requirements.
1. Understand And Strategically Implement New Regulations
Regardless of whether you are a machine manufacturer or a user company: If you want to implement and comply with the new regulations properly, you first need to understand them. The overarching aim of the new regulation is the same as before: to ensure the safe design, manufacture and use of machinery. However, gaps in the original directive are now also to be closed, particularly in view of advances in digital technology and the complexity of modern manufacturing. In addition to a more structured approach to conformity assessments, the new regulation also includes specific provisions on digitalization and cybersecurity. A sound understanding of these provisions is essential.
2. Introduce New Standards at An Early Stage
There is no transitional period between the two pieces of legislation. This means that companies must achieve full compliance by January 20, 2027. By this date, all machines on the EU market must be designed to withstand unauthorized access or tampering that could compromise safety-critical functions. This includes protective measures against malicious tampering via physical connections such as USB ports and digital channels such as networked systems. The regulation also explicitly requires safety-critical AI systems to undergo rigorous risk assessments and, in many cases, third-party conformity assessments to verify compliance. Setting up and testing processes and protocols to ensure compliance can take some time. The sooner companies start implementing the required new standards, the easier the transition will be.
3. Check Existing Machines And Systems
The next step is to check all existing machines and systems against the new standards. A comprehensive audit helps to determine which machines are networked, which contain AI or adaptive systems and which safety-critical components could be vulnerable to cyberattacks. For machine builders, this may mean evaluating design plans, software architecture and network integration points. For end users, it means reviewing how machines are actually operated on the shop floor. This includes any ad hoc modifications or legacy connections. The aim is to identify gaps, prioritize high-risk systems and plan upgrades or additional security measures in good time before the deadline in January 2027.
4. Develop And Conduct Training Courses
Even the safest machines are only as safe as the people who operate them. Machine manufacturers should therefore provide clear instructions and documentation on cybersecurity measures. End users, in turn, must ensure that operators, maintenance staff and supervisors are fully trained in safe use, reliable operation and incident response. A note: The new regulation allows manufacturers to provide online user manuals. This can help reduce environmental impact and operating costs. To ensure compliance, digital resources must remain accessible for at least ten years after a product is launched on the market.
5. Rely on Reliable And Experienced Partners
The cybersecurity requirements of the new Machinery Directive can be complex. That's why it pays to work with experienced suppliers and integrators to ease the transition. Companies with a proven track record in areas such as secure design, automation and compliance offer comprehensive industrial automation solutions that integrate cybersecurity best practices from the ground up. Working with trusted partners like Omron helps ensure secure and compliant machines that can stand up to new cyber threats.
Date: 08.12.2025
Naturally, we always handle your personal data responsibly. Any personal data we receive from you is processed in accordance with applicable data protection legislation. For detailed information please see our privacy policy.
Consent to the use of data for promotional purposes
I hereby consent to Vogel Communications Group GmbH & Co. KG, Max-Planck-Str. 7-9, 97082 Würzburg including any affiliated companies according to §§ 15 et seq. AktG (hereafter: Vogel Communications Group) using my e-mail address to send editorial newsletters. A list of all affiliated companies can be found here
Newsletter content may include all products and services of any companies mentioned above, including for example specialist journals and books, events and fairs as well as event-related products and services, print and digital media offers and services such as additional (editorial) newsletters, raffles, lead campaigns, market research both online and offline, specialist webportals and e-learning offers. In case my personal telephone number has also been collected, it may be used for offers of aforementioned products, for services of the companies mentioned above, and market research purposes.
Additionally, my consent also includes the processing of my email address and telephone number for data matching for marketing purposes with select advertising partners such as LinkedIn, Google, and Meta. For this, Vogel Communications Group may transmit said data in hashed form to the advertising partners who then use said data to determine whether I am also a member of the mentioned advertising partner portals. Vogel Communications Group uses this feature for the purposes of re-targeting (up-selling, cross-selling, and customer loyalty), generating so-called look-alike audiences for acquisition of new customers, and as basis for exclusion for on-going advertising campaigns. Further information can be found in section “data matching for marketing purposes”.
In case I access protected data on Internet portals of Vogel Communications Group including any affiliated companies according to §§ 15 et seq. AktG, I need to provide further data in order to register for the access to such content. In return for this free access to editorial content, my data may be used in accordance with this consent for the purposes stated here. This does not apply to data matching for marketing purposes.
Right of revocation
I understand that I can revoke my consent at will. My revocation does not change the lawfulness of data processing that was conducted based on my consent leading up to my revocation. One option to declare my revocation is to use the contact form found at https://contact.vogel.de. In case I no longer wish to receive certain newsletters, I have subscribed to, I can also click on the unsubscribe link included at the end of a newsletter. Further information regarding my right of revocation and the implementation of it as well as the consequences of my revocation can be found in the data protection declaration, section editorial newsletter.