Two New EU Regulations Reshaping Machinery Compliance: What You Need to Know About the Machinery Regulation and the Cyber Resilience Act (CRA)

Updated:
September 9, 2026

For more than 15 years, manufacturers and importers selling machinery in the European Union have worked under the Machinery Directive 2006/42/EC(opens in new tab). That familiar framework is now changing.

Two new EU regulations, the Machinery Regulation (EU) 2023/1230(opens in new tab) and the Cyber Resilience Act (EU) 2024/2847(opens in new tab), will affect how machinery, including connected materials testing systems, is designed, placed on the market, and supported.

For laboratories and quality teams in the EU, these changes are worth understanding now. They may influence future equipment purchases, capital planning, software update strategies, and IT/OT security requirements.

What Is Changing Under the Machinery Regulation?

The Machinery Regulation (EU) 2023/1230 replaces the Machinery Directive and becomes fully applicable on January 20, 2027.

Key changes include:

A regulation, not a directive. Unlike a directive, a regulation applies directly across EU Member States without being transposed into national law. This should help reduce variation in how machinery requirements are applied across the EU.

Greater focus on digital and AI-enabled machinery. The new regulation more directly addresses modern machine behavior and connected systems, including:

  • Machinery with safety functions relying on artificial intelligence
  • Cybersecurity risks that could affect safety
  • Software updates and how they impact conformity
  • Autonomous and self-evolving behavior of machinery

Digital documentation is permitted. Manufacturers may provide instructions and declarations of conformity in digital form, while still making paper copies available on request.

New high-risk categories. Certain machinery categories, including some safety components and AI-related applications, will require third-party conformity assessment rather than self-declaration.

What Is the Cyber Resilience Act?

The Cyber Resilience Act (EU) 2024/2847, or CRA, is a broad cybersecurity regulation for products with digital elements placed on the EU market.

In practice, this can include hardware or software products that connect directly or indirectly to another device or network. For materials testing labs, that may include systems running testing software such as Bluehill® Universal or products that support remote services such as Instron Connect.

The CRA introduces several important manufacturer obligations:

  1. Essential cybersecurity requirements: products must be designed with cybersecurity in mind and placed on the market without known exploitable vulnerabilities.
  2. Vulnerability handling: manufacturers must maintain processes for coordinated disclosure, timely security updates, and software bill of materials documentation.
  3. Conformity assessment: CRA compliance becomes part of the evidence supporting CE marking.
  4. Post-market obligations: actively exploited vulnerabilities must be reported to ENISA within 24 hours of awareness.

Important milestones include:

  • September 2026: Vulnerability and incident reporting obligations begin
  • December 2027: Full compliance required for products placed on the EU market

What Does This Mean for Materials Testing Labs?

If you operate a materials testing lab in the EU, the practical impact will depend on the age of your systems, how they are connected, and whether they continue to receive supported software and security updates.

New Instron systems will be delivered with technical documentation aligned to the Machinery Regulation and Cyber Resilience Act as the applicable deadlines approach.

Existing systems already in the field are not automatically brought under the new regulations simply because the rules have changed. However, vulnerabilities found on existing systems are subject to CRA reporting obligations.

Some configurations may change over time. As the Machinery Regulation is phased in, certain optional or advanced features may need to be reviewed or adjusted to maintain compliance. If a proposed configuration is affected, Instron will communicate the impact through the normal quoting and sales process.

What Instron Is Doing

Instron is preparing for these regulatory changes across engineering, quality, compliance, software, and customer support teams.

  • Machinery Regulation readiness: Engineering, quality, and compliance teams are reviewing all system configurations against the new essential health and safety requirements. Updated technical files, user manuals, and CE declarations will be prepared ahead of the January 2027 deadline.
  • Cyber Resilience Act readiness: Instron is continuing to strengthen secure development practices for products with digital components. We are also formalizing our coordinated vulnerability disclosure process, with reporting information available through Instron support channels.
  • Customer communication: As key CRA and Machinery Regulation milestones approach, Instron will provide updated guidance for existing customers.

Next Steps

If you have questions about how these regulations may affect your Instron systems, procurement plans, or software update strategy, please contact your local Instron sales representative.

To report a suspected cybersecurity vulnerability in an Instron product, please use Instron’s Vulnerability Reporting Form.

Instron will continue to share updates as these regulations move toward their full application dates.

About the Author

Dan Caesar

Dan Caesar(opens in new tab) brings extensive expertise in mechanical engineering, materials testing, and software product strategy, grounded in his Mechanical Engineering degree and MBA from Northeastern University. Since joining Instron® in 2014, he has worked closely with testing laboratories around the world to improve the accuracy, efficiency, and reliability of their mechanical testing workflows. In his current role, Dan guides the vision and development of Instron’s static testing software portfolio — including Bluehill® Universal, Bluehill Elements, and Bluehill Central — leveraging his deep technical understanding and customer‑driven approach to deliver solutions that elevate laboratory performance.

(opens in new tab)