Machine and automation cybersecurity – getting ready for Regulation (EU) 2023/1230
REGULATION (EU) 2023/1230 • OT • SIEMENS • KUKA / ABB
The EU Machinery Regulation 2023/1230 applies from 20 January 2027. Automation audit, PLC and robot hardening, OT segmentation, backups, remote service.
From 20 January 2027 the Machinery Regulation (EU) 2023/1230 replaces the Machinery Directive 2006/42/EC. Protection against interference with software, parameters and industrial communication becomes an explicit safety requirement. The machine builder has to document that those risks were taken into account.
This is not a job for the IT department. Cybersecurity becomes part of functional safety the moment an unauthorised change to a program, a drive parameter or robot access can change how the machine moves, disable a safety function or leave the operator unprotected.
We work on the machine, not on a security policy: Siemens S7-1500 and S7-1200, TIA Portal, WinCC, SINAMICS drives, SCALANCE switches, KUKA and ABB controllers. The scope follows the project: one machine, a robot cell, a line or a chosen part of the OT network.
Scope of services
- Automation audit: inventory of PLCs, HMIs, robots, drives and network devices
- Review of local and remote access to the control systems
- Access protection for the CPU and the TIA Portal project, order in accounts, roles and passwords
- Separation of the standard program, the safety program and safety-critical data
- Verified backups of PLC, HMI, robot and drive parameters, with a restore procedure
- OT network segmentation: VLANs, industrial firewalls, controlled VPN access
- KUKA and ABB robot cells: access, critical parameters, safety configuration, PLC handshake
- Change register and technical documentation feeding the manufacturer risk assessment
- A list of devices and access points in the OT network instead of guesswork
- Backups a machine can actually be restored from - verified, not left on somebody USB stick
- Every program change has an author, a date, a purpose and a test after the change
- Remote service keeps working, on named accounts and only for the duration of the job
- Technical input the machine builder can use to update the risk assessment and the CE file
- Time until 2027: the work fits into a planned shutdown instead of a rush
What changes on 20 January 2027
Regulation (EU) 2023/1230 replaces the Machinery Directive 2006/42/EC and applies from 20 January 2027. It entered into force back in 2023, but that date ends the transition period. Machinery placed on the EU market from then on has to meet the new essential requirements of Annex III.
Two threads matter for automation. Hardware and software components carrying safety-related signals have to be protected against corruption and change, accidental as well as intentional, and the control system has to record intervention in safety-related software. The second thread requires the software and data critical to the compliance of the machine to be identified as such and protected against unauthorised modification.
In practice it comes down to questions nobody in the plant can answer on the spot. Who holds the CPU password today. How do you know the controller runs exactly the program version that was accepted. What happens when an external service laptop plugs straight into the machine network.
Three things to do before you look for a contractor
None of them needs an automation engineer and all three fit into one afternoon.
First: write down who has remote access to your machines today. The builder, the integrator, the robot supplier, the vision company, your own maintenance team, an intern from two years ago. That list is usually longer than anyone expects, and a good part of it is shared accounts with no expiry date.
Second: check whether you hold copies of the PLC, HMI and robot programs, and when somebody last tried to restore anything from them. A copy nobody has ever restored is a declaration, not a backup.
Third: ask the builder of the machine you are ordering right now how they intend to meet the requirements of the Regulation after 2027. That question costs least before the contract is signed.
Scope and price depend mostly on the number of devices and on whether any network documentation exists. Do not hand this to your own automation engineer next to running production: an inventory gets interrupted by every breakdown, and an interrupted inventory is worth about as much as none.
What this service does not cover
We do not issue certificates or EU declarations of conformity. Formal responsibility for the conformity assessment and the CE marking stays with the machine builder, or with whoever takes over those duties – including you, once you substantially modify a machine.
This is also not a company-wide cybersecurity programme or an IEC 62443 implementation. The Machinery Regulation deals with cyber threats only as far as they can affect the safety of the machine, and that is exactly the scope we work in. Office mail, accounting and the server room stay untouched.
If you already run an OT team that keeps an inventory, segments the network and controls versions, you probably do not need us for anything beyond an outside look at one machine. We will say so rather than sell an audit of the whole hall.
Frequently asked questions
When does the EU Machinery Regulation 2023/1230 start to apply?
On 20 January 2027. The Regulation entered into force in 2023 but applies only from that date, when it replaces the Machinery Directive 2006/42/EC. Machinery placed on the EU market from then on must meet the new essential requirements, including those on protecting software and data against unauthorised interference.
Does this apply to machines already running in the plant?
A machine already in use does not have to be brought up to the new rules retroactively. That changes with a substantial modification: whoever makes it takes over the duties of the manufacturer and answers for the conformity of the machine in its new form. Users also have their own obligations for work equipment, so order in access rights and program copies pays off regardless.
Is machine cybersecurity a job for the IT department?
Only in part. IT owns the office network, the accounts and the mail. On the machine the point is that a change to the PLC program, a drive parameter, a robot safety zone or the safety configuration cannot happen unnoticed. Those risks are assessed together with the mechanical ones, as part of functional safety, not in an IT policy.
What exactly do you check in a Siemens controller?
Access protection for the CPU and the TIA Portal project, service accounts and roles, separation of the standard program from the safety program, versions of the hardware configuration, firmware and libraries, and whether the project copy matches what actually runs in the controller. SINAMICS drive parameters and the configuration of network devices, SCALANCE switches included, come with it.
Will securing the machine cost us remote service?
No, as long as remote access is put in order rather than switched off. Instead of one password circulating between companies you get named accounts, access enabled for the duration of the job and limited to specific devices, and a session log where the solution supports one. Service response time does not suffer.
Do you issue a declaration of conformity or the CE marking?
No. We leave the machine builder, or whoever took over those duties, with the full input package: a list of devices and access points, a register of accounts and permissions, verified copies of the PLC, HMI and robot programs, a change register and a description of the risks with recommendations. With that in hand they update the risk assessment and the technical file. The EU declaration of conformity and the CE marking come from them.
How is this different from IEC 62443?
By example: IEC 62443 asks you to define zones and conduits for the whole plant network, roles, policies and the life cycle of the system. The Machinery Regulation asks one thing: can somebody change a program, a parameter or an access right so that the machine hurts someone. We answer that second question, device by device, and borrow practices from 62443 where they help, for example in segmentation.
What drives the scope and the price of an automation audit?
Which of three situations we start in. A single cell: one controller, one robot, a panel, one document at the end. A line with several cabinets and a network drawing: a longer inventory and a prioritised to-do list. A line with no network documentation at all: the inventory first, and only then a quote for the rest. We set the scope after a call with the device list in hand, or after an inspection.
Free engineering consultation
+48 505 603 607 · contact@ledniowski.com
We reply within 24 hours.
This page is also available in other languages: Polski · Deutsch