← ← Back to BlogNews Cybersecurity and CNC machines: what changes with Regulation (EU) 2023/1230

Cybersecurity and CNC machines: what changes with Regulation (EU) 2023/1230

22/08/2026
If you ask a CNC machine manufacturer what is new about Regulation (EU) 2023/1230, they will probably talk about substantial modification, the supply chain of economic operators, the new annexes. Cybersecurity almost always comes last — yet it is perhaps the most significant change for anyone who produces networked machines.
For the first time in the history of European machinery legislation, cybersecurity is not a recommendation, not a best practice: it is a mandatory legal requirement, from 20 January 2027 onwards.

Why now?
The Machinery Directive 2006/42/EC was written at a time when a milling machine was a milling machine: a mechanical object, possibly equipped with a numerical controller, but fundamentally isolated from the outside world. There was no internet, no remote access, no firmware updates over the network.
Today the situation is completely different. Modern CNC machines are connected to the company network, receive software updates remotely, transmit production data to ERP and MES systems, and are accessible by the manufacturer's service team through VPN or cloud connections. They are, in every practical sense, computers that control physical processes.
And connected computers get attacked. An attack on a CNC machine is not like a virus on an office PC: it can cause uncontrolled axis movements, disable safety functions, and bring an entire production line to a halt. The European legislator recognised this risk and decided to put it into law.

What the Regulation actually says
The core of the cybersecurity change is in Annex III, point 1.1.9, titled "Protection against corruption". This is a completely new paragraph, with no equivalent in the old directive.
The underlying concept is straightforward: if a machine can be connected to a network — wired or wireless — it must be designed to resist both unintentional unauthorised connections and deliberate attacks. The Regulation translates this concept into four concrete obligations for the manufacturer.
Obligation 1 — Protect hardware, software and data (point 1.1.9 a)
The machine must have protection mechanisms on three levels: physical (who can open the control panel?), software (who can change the configuration?), and data (who can alter the safety parameters?).
In practice for a CNC machine: authentication to access configuration functions, encrypted communications between the CNC and supervision systems, controlled or locked USB ports, restriction of active network protocols.
Obligation 2 — Identify and protect safety software (point 1.1.9 b)
Every software component that manages safety functions — the PLC that controls interlocks, the drive firmware, the software supervising axis protection systems — must be identified with a precise version number. And the manufacturer must prevent that software from being modified without authorisation.
In practice: digital signing of firmware, secure update procedures, documented version management.
Obligation 3 — Log access to safety functions (point 1.1.9 c)
The machine must keep a record (log) of all intentional interventions affecting safety functions: who had access, when, and what was changed. Like a safe that records every opening.
This also applies to SCADA and supervision systems that communicate with the machine: external interfaces must also record and retain logs of access to safety functions. The updated point 1.2.1 states that these logs must be retained for at least 5 years and protected against unauthorised deletion.
Obligation 4 — Maintain an inventory of installed software (point 1.1.9 d)
Throughout the machine's lifetime, an up-to-date list of all installed software must be available: operating system, firmware, libraries, drivers, applications. In technical terms this is called an SBOM — Software Bill of Materials.
Why does this matter? Because when a vulnerability is discovered in a software library (it happened with Log4j, with OpenSSL, and it will happen again), whoever manages the machine needs to know within minutes whether that library is installed and in which version. Without an up-to-date inventory, this question cannot be answered.

The 5-year log retention rule
It is worth pausing on this point, because it has concrete practical implications. The updated point 1.2.1 of Annex III states that logs relating to safety functions must be retained for at least 5 years. This is not an aspirational goal: it is a design requirement.
The logging system must have adequate storage capacity, logs cannot be overwritten or deleted without authorisation, and must be accessible to market surveillance authorities in the event of an incident. For a CNC machine manufacturer, this means the logging system cannot be an afterthought: it must be designed from the start.

What does not change: the user's responsibility
The Regulation imposes these requirements on the manufacturer, not the user. The company that buys a CNC machine does not need to certify anything regarding cybersecurity.
However, this does not mean the user has no responsibilities. The machine's instructions for use will need to include a section on secure configuration: how to change default passwords, how to configure remote access, how to manage updates. And the employer has an obligation to follow those instructions under occupational health and safety legislation.
In practice: the manufacturer is responsible for delivering a machine that is secure by design. The user is responsible for keeping it secure during operation.

The link with the Cybersecurity Act
Regulation 2023/1230 provides (Art. 20(9)) an interesting shortcut for manufacturers. If a machine component has been certified under Regulation (EU) 2019/881 (the Cybersecurity Act) — the European regulation on cybersecurity certification for ICT products — that certification creates a presumption of conformity with the cybersecurity requirements of the Machinery Regulation.
In practical terms: if the CNC system or one of its components already holds a European cybersecurity certification, the manufacturer can use it as a basis for demonstrating compliance with points 1.1.9 and 1.2.1, without duplicating all the work.

What to do now, if you manufacture CNC machines
20 January 2027 is approaching, and cybersecurity requirements cannot be satisfied with a document or a declaration: they require design choices. There are four areas to work on.
Secure design from the start. Cybersecurity cannot be added at the end of the project as an afterthought. It must be incorporated into the machine's risk assessment, documented in the technical file, with the same importance as mechanical or electrical risks.
Control system architecture. The CNC must have a clear separation between the internal control network and external networks (internet, company network). Remote access for maintenance — essential in modern systems — must be authenticated and encrypted.
Software management. Every software component with safety functions must have a version number, a secure update procedure, and an up-to-date inventory (SBOM). The manufacturer must be able to answer the question "which firmware version is installed on that machine?" at any time.
Logging system. The CNC must log access to safety functions, retain logs for 5 years, and protect them against unauthorised deletion.

What to do now, if you purchase CNC machines
If you are a company that buys CNC machines, the Regulation does not impose direct obligations on you regarding the machine's cybersecurity. But you can — and should — start asking your suppliers questions.
Ask whether the machine you are buying will comply with the requirements of point 1.1.9 by 20 January 2027. Ask how remote access is managed. Ask whether there is a documented firmware update procedure. Ask whether an SBOM will be available.
A supplier who cannot answer these questions in 2026 is probably not going to be compliant in 2027.

This article is intended for informational purposes. For a specific assessment of your company's compliance with Regulation 2023/1230, contact us for a personalised consultation.