36 n MACHINERY REGULATION July/August 2026 www.drivesncontrols.com The European manufacturing industry is on the cusp of a regulatory shift that promises to reshape how machines are designed and operated. UK machinebuilders will also feel its impact. The new Machinery Regulation (EU 2023/1230) comes into effect in January next year, replacing the old Machinery Directive (2006/42/EC). Any UK machinebuilder selling into the European market will need to comply with the legislation to achieve CE marking. The most significant change in the regulation relates to cybersecurity. Specifically, every machine – whether newly built or retrofitted – must now be assessed for cybersecurity vulnerabilities. As systems become more digital-enabled, safety and cybersecurity are becoming increasingly entwined. Including cybersecurity as a core part of the regulation’s scope is a logical progression, and can arguably be seen as an extension of the historical focus on machine safety. What it means for the UK While the regulation will be implemented in Europe, the UK has been watching developments closely. The government has already issued calls for comment on future product safety and cybersecurity frameworks. Crucially, it is highly unlikely that the UK will water down its own requirements. One of the biggest changes in the regulation relates to accountability. Responsibility for addressing and mitigating cybersecurity risks now lies firmly with the machine-builder. As well as safety assessments, OEMs must also demonstrate that cybersecurity risks have been identified, assessed and mitigated. This isn’t necessarily as onerous as it sounds. It is unrealistic to expect every possible threat to be eliminated before a product reaches the market. However, manufacturers must be able to show that they have considered the threats, mitigated risks where appropriate, and documented the decision-making process clearly. While undoubtedly a welcome step forward for end-users, for machine-builders this arguably creates an extra layer of bureaucracy most would say they could do without. Some OEM companies may not have ready access to in-house cybersecurity expertise, and so may have to hire and train additional personnel, or enlist third-party expertise. Both take time and have inherent costs, particularly if left to the last minute. High stakes This growing focus on cybersecurity reflects the new digital reality in which we live. Recent high-profile attacks have made headlines over the past couple of years. A major attack on Jaguar Land Rover in August 2025 caused significant disruption to production, and cost the wider economy an estimated £1.9bn. It was, at the time, the most costly cyber-event in UK history. Cybersecurity is therefore no longer just an IT concern. If a compromised system affects how a machine can operate safely, then it becomes a safety issue as well. The The new Machinery Regulation may be an EU law, but its reach is global, with implications for any UK machine-builders who are selling into Europe. Matthew Hallas, ABB’s OEM business development manager for drives in the UK, discusses some of the key takeaways for UK OEMs. UK OEMs can’t ignore the new Machinery Regulation
RkJQdWJsaXNoZXIy MjQ0NzM=