Essential requirements (ch. 1)New requirement
1.1.9 · Protection against corruption
Annex III, 1.1.9 · Regulation (EU) 2023/1230 ·
What it requires
1.1.9 of Regulation (EU) 2023/1230 requires: protection against corruption: connections to other devices must not create hazardous situations; safety-critical hardware, software and data must be protected against accidental or intentional corruption and identified, and legitimate or illegitimate interventions must be recorded. It is a new requirement compared with Directive 2006/42/EC and applies to machinery placed on the market from 20 January 2027.
What changes compared with Directive 2006/42/EC
New requirement (functional cybersecurity). Presumption of conformity possible through certification under Regulation (EU) 2019/881 (Art. 20(9)).
What the instruction manual must reflect
Connectivity architecture, installed safety software and its version, how to check it, cybersecurity measures, log of interventions and modifications.
If your manual was written for Directive 2006/42/EC, it probably doesn't cover this requirement. Upload it and we'll check it for free alongside the other 108.
Check my manual for free →Official text
The machinery or related product shall be designed and constructed so that the connection to it of another device, via any feature of the connected device itself or via any remote device that communicates with the machinery or related product does not lead to a hazardous situation. A hardware component transmitting signal or data, relevant for connection or access to software that is critical for the compliance of the machinery or related product with the relevant essential health and safety requirements shall be designed so that it is adequately protected against accidental or intentional corruption. The machinery or related product shall collect evidence of a legitimate or illegitimate intervention in that hardware component, when relevant for connection or access to software that is critical for the compliance of the machinery or related product. Software and data that are critical for the compliance of the machinery or related product with the relevant essential health and safety requirements shall be identified as such and shall be adequately protected against accidental or intentional corruption. The machinery or related product shall identify the software installed on it that is necessary for it to operate safely, and shall be able to provide that information at all times in an easily accessible form. The machinery or related product shall collect evidence of a legitimate or illegitimate intervention in the software or a modification of the software installed on the machinery or related product or its configuration.
Source: Regulation (EU) 2023/1230, OJ L 165, 29.6.2023, Annex III, 1.1.9. The sections ‘What it requires’ and ‘What the instruction manual must reflect’ are our own summary and do not replace the official text.