EU Machinery Regulation 2023/1230: Do You Need an Authorised Representative?
Authorised Representative
Profile picture of Sarath Kumar S

Sarath Kumar S

Regulatory Compliance Analyst | EU/UK Product Compliance & Risk Mitigation Regulatory Compliance Analyst at Euverify with experience in EU and UK product safety requirements. Focused on risk assessments, technical file preparation, and regulatory mapping across diverse products. Brings a creative edge to compliance work, supported by a background in AI-driven research and analysis.

EU Machinery Regulation 2023/1230: Do You Need an Authorised Representative?

Direct answer: The Machinery Regulation (EU) 2023/1230 replaces the Machinery Directive 2006/42/EC on 20 January 2027. It covers machines, partly completed machinery, and related products like interchangeable equipment, safety components, lifting accessories, chains, ropes, webbing, and load-bearing transmission devices. Most of the old rules carry over, about 90% of the requirements stay the same. But there are real additions: cybersecurity requirements, a new high-risk category for machinery with AI-based safety functions, and permission, for the first time, to use digital instructions instead of paper. If you manufacture outside the EU, you still need an EU-based Authorised Representative. That part hasn’t changed. It’s just been extended to cover the new cybersecurity paperwork too. 

Who Needs to Comply with the EU Machinery Regulation (2023/1230)? 


The Regulation applies to manufacturers, importers, and authorised representatives of machinery and the related products listed above. Because it’s a Regulation and not a Directive, it takes effect the same way in every member state at once. No country writes its own version, and no small inconsistencies creep in between markets the way they sometimes did under the old Directive, which each country had to fold into its own national law.

There’s a 42-month transition period between the Regulation entering into force and it fully applying. During that window, manufacturers can follow either the old Directive or the new Regulation. From 20 January 2027, only the Regulation applies, and the Directive is gone. A few administrative rules, mostly around how notified bodies get authorised, kicked in earlier, from 20 January 2024.

If you already sell machinery into the EU, you’re affected by this transition whether or not you change a single thing about your product. And if you’re a manufacturer outside the EU with no entity there, you still [need to appoint an Authorised Representative. That obligation doesn’t go away under the new rules, it just picks up a new job: speaking to the cybersecurity side of your documentation, not only the mechanical safety file.

Machinery Directive 2006/42/EC vs. Machinery Regulation 2023/1230: What Changes 

Machinery Directive 2006/42/EC vs. Machinery Regulation 2023/1230: What Changes

Most of the compliance work stays the same. Here’s what’s actually new or expanded:

  • Cybersecurity requirements. The current Directive says nothing about this. The Regulation now requires protection against unauthorised digital access and safeguards for software integrity. Assessors will run what’s described as a “plausibility check” on the cybersecurity documentation you submit.
  • AI and autonomous systems move into high-risk. If a machine uses AI to perform a safety function, or has a safety component that can change its own behaviour through machine learning, it’s now automatically classified as high-risk under Annex I. A notified body has to assess it. Self-certification isn’t an option for these categories anymore, and they weren’t even a distinct category under the old Directive.
  • The Annex I high-risk list has grown, and it’s now split into Part A (notified body required) and Part B (existing procedures still apply). There’s also a new “unit verification” module, which lets a single complex machine get certified on its own instead of as part of a wider product line.
  • Digital instructions are allowed now. Technical files, instructions for use, and the Declaration of Conformity can all be delivered digitally instead of on paper. One thing worth watching: a separate proposal called Omnibus IV would make digital format mandatory for machinery, with no transition period. Industry groups are pushing back on it, so treat this as unsettled rather than final.
  • Software updates can reopen the compliance question. If you push an update after the machine is already sold, and it touches safety-relevant functioning, that counts as a new placing on the market. You might need a fresh conformity assessment and a new CE mark.
  • “Substantial modification” now has teeth. If someone changes a machine in a way the manufacturer never intended, and that change creates new hazards or raises existing risk, that person becomes the new manufacturer of record. They then have to run a full conformity assessment and put their own CE mark on it. This reaches well beyond original manufacturers, to anyone modifying, refurbishing, or reselling machinery already in service.
  • Market surveillance got stricter, and the responsibility now runs through importers, distributors, and authorised representatives too, not just whoever originally built the machine.

Machinery Regulation 2023/1230 Compliance Checklist 

  • Work out which Annex I category applies to you, if any. Most machinery still isn’t high-risk, and self-certification works the same way it always has. But if your machine has an AI-based safety function or a self-evolving safety component, it’s high-risk now, automatically, and that pulls in mandatory notified body assessment.
  • Put cybersecurity into your technical file from the start, not bolted on later. It needs to cover protection against unauthorised digital access and software integrity, and it needs to hold up under the “plausibility check” during assessment.
  • Decide now whether you’re going digital or staying on paper, and keep an eye on the Omnibus IV proposal in case digital becomes mandatory before you’re ready.
  • Keep track of software updates after sale. If one touches safety functioning, it may trigger a fresh conformity assessment.
  • Appoint an EU Authorised Representative if you’re outside the EU. They hold your technical documentation, deal with market surveillance authorities, and now need to be able to speak to your cybersecurity documentation too.
  • Plan out your transition, not just your deadline. You’ve got 42 months where either the Directive or the Regulation applies. Decide early whether to move new product lines onto the Regulation now or wait, rather than leaving it to the last minute.

How to Choose a Machinery Regulation Authorised Representative 

Your situationWhat to look for
Standard machinery, no AI safety functionsCheck that your existing self-certification process still holds. Most machinery doesn’t move into the high-risk category under the new Regulation.
Machinery with AI-based safety functions or self-evolving componentsAsk the provider directly how they handle the new Annex I reclassification and the notified body requirement that comes with it. This is a genuinely new obligation, not something carried over.
Non-EU manufacturerYou need an EU Authorised Representative either way. Confirm their mandate actually covers cybersecurity documentation, not just the traditional mechanical safety file.
Selling machinery alongside other CE-marked products (electronics, toys, PPE)Ask whether machinery is priced separately or bundled into a general AR subscription. Pricing models differ a lot between providers here.

Euverify’s Machinery Regulation Authorised Representative Service 

Euverify’s Authorised Representative service covers the Machinery Regulation (EU 2023/1230), alongside GPSR, RED, EMC, LVD, RoHS, and Toy Safety. It isn’t sold as a standalone machinery product. It’s part of the general AR platform: a UK/EU representative address, authority communication handled on your behalf, 10-year secure document storage, EC/UKCA Declaration generators, and a dashboard that automatically detects which directives apply to your product.  

Red Flags When Choosing a Machinery Regulation Compliance Provider 

  • A provider telling you all machinery now needs a notified body. It doesn’t. Most machinery is still self-certified. Only the expanded high-risk categories, including the new AI-safety classification, need third-party assessment.
  • A provider with nothing to say about cybersecurity documentation. This is genuinely new, and an old technical file won’t cover it automatically.
  • A provider who’s completely certain about digital instructions, either way. The Omnibus IV proposal is still up in the air, so total confidence in either direction is a red flag, not reassurance.
  • A provider who can’t explain what “substantial modification” means, or who it makes the new manufacturer of record. That has real consequences for anyone refurbishing or reselling used machinery.
  • No mention of the 42-month transition window at all, just the final deadline. You need to decide when in that window to move, not just that you eventually have to.

Frequently Asked Questions

20 January 2027, when it fully replaces the Machinery Directive 2006/42/EC. A few administrative rules around notified bodies kicked in earlier, from 20 January 2024. Between now and the 2027 deadline, a 42-month transition period lets manufacturers follow either the old Directive or the new Regulation.

No. About 90% of the requirements haven’t changed. What’s new is cybersecurity, the AI-safety-function high-risk category, the option to go digital with your documentation, and clearer rules around software updates and substantial modification. If none of those apply to you, most of your existing work still stands.

Only if it falls into the Annex I high-risk categories, which now include machinery with AI-based safety functions or self-evolving safety components. Everything else still runs on manufacturer self-certification, same as before.

A Directive needs each country to write it into national law, which can create small gaps or inconsistencies. A Regulation applies the same way everywhere in the EU the moment it’s in force, no national step needed.

Yes, if you manufacture outside the EU. It’s the same obligation you already have under the current Directive, just extended to cover the new cybersecurity documentation.

If the update touches safety-relevant functioning, it counts as a new placing on the market. That can mean a fresh conformity assessment and a new CE mark, not just a quiet patch.

It’s a change the manufacturer never intended, one that creates new hazards or increases existing risk. Whoever makes that change becomes the new manufacturer of record, and has to run a full conformity assessment and apply their own CE mark. That matters for anyone refurbishing or reselling machinery already in use, not just the original builder.

Yes. Technical files, instructions, and the Declaration of Conformity can all be digital instead of paper. A separate proposal, Omnibus IV, would make digital mandatory for machinery specifically, with no transition period. That proposal is still contested, so check its status closer to the deadline rather than assuming either version is settled.