Regulation (EU) 2023/1230 · Article 10(2) and Annex IV · applies January 20, 2027
The machinery technical file, for one machine. €5,000 once.
The Machinery Regulation replaces the Machinery Directive on January 20, 2027, and it is not a renumbering. Six categories lose self-assessment outright, self-assessment for nineteen more now depends on applying standards in full, and Annex III has picked up cybersecurity requirements that did not exist before. The file you built under the Directive does not answer them.
What this pack does not do
It does not perform your safety assessment. Annex III runs to several hundred clauses of guards, stability, ejected parts, noise, vibration and lifting, and that work belongs to a safety engineer with ISO 12100 and ISO 13849 open. Anyone selling you software that claims to do it is selling you a liability.
What the pack does is the file: the Annex IV structure, the applicability list Annex IV(b)(i) explicitly requires, the standards and evidence index, the production and retention record, and the declaration. Plus the digital requirements, clause by clause, because those are new and your safety consultant probably did not cover them.
What changed in 2023/1230
Six categories lost self-assessment entirely
Annex I, Part A lists removable mechanical transmission devices and their guards, vehicle servicing lifts, portable cartridge-operated fixing machinery, and safety components or embedded systems with self-evolving machine-learning behaviour. For these, Article 25(2) allows only type-examination with conformity to type, full quality assurance, or unit verification. A notified body is involved whatever standards you applied.
Part B self-assessment now depends on applying standards in full
For the nineteen Annex I Part B categories, internal production control is available only where harmonised standards specific to that category, covering all the relevant essential requirements, were applied in full. Applied in part, the route closes. The standards index in the file is what that claim rests on, and it is the claim a market surveillance authority tests first.
The Regulation became a cybersecurity regulation
Section 1.1.9 requires protection against corruption of safety-critical hardware, software and data, evidence collection when either is interfered with, and the machine being able to state at any time what safety software it is running. Section 1.2.1 requires control systems to withstand reasonably foreseeable malicious attempts by third parties, and a five-year tracing log of interventions and safety software versions. None of this exists in Directive 2006/42/EC.
What you get
7 controlled documents, drafted from the record you fill in. Each is versioned, approved and hash-chained in your organization, and exports as a PDF with the sha256 of the approved text in the footer. Article 10(3) asks you to keep the file at least ten years from placing on the market or putting into service; this is a file that can still be verified then.
The documents are drafted in English, under the titles below, as are the twelve clause summaries further down; the product presents them the same way. Article 10(6) requires the file in a language the requesting authority can easily understand, which makes translation a task for when an authority asks.
- 1
Scope, category and conformity route determination · Article 25, Annex I
- 2
Description, intended use and limits · Annex IV(a), Annex III Part B
- 3
Applicable essential health and safety requirements · Annex IV(b)(i), Annex III
- 4
Protection against corruption and control-system safety · Annex III 1.1.9, 1.2.1, 1.2.6
- 5
Standards applied and test evidence index · Annex IV(e), (f), (g)
- 6
Production conformity, traceability and retention · Annex IV(h), (l), (m), (n), Article 10(3)
- 7
Draft EU declaration of conformity · Annex V
The digital requirements, in full
Twelve clauses, each answered separately in the record and written out in the file. This is the part that has no equivalent in the Directive you have been working to.
- 1.1.9(a)Connecting another device does not create a hazard
- 1.1.9(b)Safety-critical hardware is protected against corruption
- 1.1.9(c)Intervention in that hardware is evidenced
- 1.1.9(d)Safety-critical software and data are identified and protected
- 1.1.9(e)The machine can state what safety software it is running
- 1.1.9(f)Software intervention and modification are evidenced
- 1.2.1(a)Control systems withstand foreseeable malicious attempts
- 1.2.1(d)Safety-function limits are fixed, including in a learning phase
- 1.2.1(f)Five-year tracing log of interventions and safety software
- 1.2.1(g)Self-evolving behaviour stays inside its defined task
- 1.2.1(h)Wireless control fails safe
- 1.2.6Loss of power or of the network connection is not hazardous
If your machine also has digital elements
The Cyber Resilience Act reaches products with digital elements placed on the market, and its own deadline is December 11, 2027, nine days after the AI Act's high-risk obligations and eleven months after this one. A connected machine can owe both files. The evidence overlaps; the obligations do not merge.
The CRA technical fileBuy it
Create your organization, record the machine and its category, answer the applicability list and the digital clauses, pay. The file is drafted the moment the payment confirms.
Buy the technical file, €5,000Article 10, Article 25 and Annexes I, III, IV and V are worth reading yourself: Regulation (EU) 2023/1230. Keeping the file current afterwards is what the €249/mo product is for. This page is not legal advice.