For Japanese manufacturers, machine builders and engineering teams designing or modifying equipment in Thailand and ASEAN for Europe, the EU Machinery Regulation 2027 is not merely a legal-reading exercise. Regulation (EU) 2023/1230 becomes mandatorily applicable on 20 January 2027. The practical task is to connect applicability, machinery risk assessment, safety-related controls, technical documentation, instructions, conformity assessment and CE marking to real project gates: design review, procurement, FAT, shipment and SAT.
This guide is written for production engineering, controls engineering, equipment purchasing and project leaders. It translates EU Machinery Regulation 2023/1230 into a 90-day execution plan: who owns each decision, what evidence must exist, when it must be reviewed, and how it should be specified in an RFP and FAT/SAT protocol. It is general technical and project-management information, not legal advice. Confirm the formal scope, conformity route and standards against the latest EU legislation and Official Journal, with an EU-recognised body, notified body where applicable, or qualified specialist.
EU Machinery Regulation 2027: start with the correct date and scope
Mandatory application starts on 20 January 2027
The current consolidated Regulation (EU) 2023/1230 and the European Commission machinery page state that the Regulation applies mandatorily from 20 January 2027. Plans should use the corrected date, not 14 January shown in the original publication before the corrigendum. Machinery placed on the EU market before 20 January 2027 is generally assessed under the current Machinery Directive 2006/42/EC; products placed on the market or put into service from that date require an assessment under the new Regulation.
Do not treat a shipment date from Thailand as the only legal milestone. Factory release, vessel departure, arrival in Europe, transfer to an importer, installation and first use can occur on different dates. Record Incoterms, importer, contractual acceptance, installer and commissioning responsibility. Then determine which event constitutes placing on the EU market or putting into service for that specific transaction.
A machine used only in Thailand is not automatically in scope
The Regulation focuses on machinery and related products placed on the EU market or put into service in the EU. A machine installed only in a Thai factory is not automatically subject to the Regulation solely because the owner is European or the finished goods are exported. Early applicability review is nevertheless important for:
- a dedicated machine completed in Thailand and shipped to an EU customer or affiliate;
- a line partly assembled in ASEAN and completed or integrated in Europe;
- an existing machine substantially modified and brought back into use in Europe;
- a product whose status as machinery, a related product, partly completed machinery, a safety component or interchangeable equipment is unclear;
- machinery with AI-powered safety functions, remote updates or network-connected safety controls.
The product category affects the declaration, assembly instructions, technical documentation, marking and conformity procedure. Define the machine boundary and intended use before relying on past practice.
Use the legal test for a “substantial modification”
Under the Regulation, a substantial modification is not simply any commercially “major” change. It is a physical or digital alteration made after machinery or a related product has been placed on the market or put into service, which was not foreseen or planned by the manufacturer and affects safety by creating a new hazard or increasing an existing risk. The definition then requires either the addition of guards or protective devices whose processing necessitates modification of the existing safety control system, or additional protective measures to ensure stability or mechanical strength.
As the general rule, the person carrying out a substantial modification is considered the manufacturer for the purposes of the Regulation and assumes the relevant manufacturer obligations and conformity assessment for the affected machinery or related product. Article 18, third paragraph, provides an exception: a non-professional user who substantially modifies machinery or a related product that they own, for their own use, is not considered a manufacturer. Record the change specification, what the original manufacturer foresaw, the new or increased risk, its effect on safety controls, stability and strength, and the modifier’s status and purpose before reaching a conclusion. This article focuses on building EU market-access evidence for that decision; our existing equipment-modification guidance covers the wider operational change process.
Fix the roles across Thailand, Japan and Europe
Commercial labels do not always match the roles defined by EU product legislation. A Thai machine builder, Japanese headquarters, EU importer, end user and system integrator may all participate. At the first gate, create a responsibility matrix covering at least the following.
| Topic | Typical owner | Required evidence |
|---|---|---|
| Intended use and reasonably foreseeable misuse | Manufacturer and user | User requirement, operating envelope, exclusions |
| Product classification and legislation | Manufacturer with EU specialist | Applicability memo, legislation register |
| Risk assessment | Mechanical, electrical and controls design | Hazard log, risk-reduction record |
| Safety-related controls | Controls engineer | PLr rationale, architecture, calculation and test |
| Technical file | Document owner | Drawings, calculations, tests and revision history |
| Conformity assessment and declaration | Legal manufacturer | Route decision, EU declaration of conformity |
| EU contact and retention | Manufacturer/importer | Contract, contact and record-retention duty |

Turn Regulation (EU) 2023/1230 changes into design evidence
Technical documentation is built during design, not collected at delivery
Manufacturers must design against applicable essential health and safety requirements, perform the relevant conformity assessment and compile and retain technical documentation. A common failure is asking a documentation coordinator to collect drawings and tests after the design is complete. The reason a safeguard was selected, and the condition before a later modification, may then be impossible to reconstruct.
Treat the technical file as the controlled history of the design decision. Its index should cover a general description, assembly drawings, control circuits, risk assessment, applied standards, design calculations, test results, instructions, draft declaration and supplier evidence. Every file needs the machine ID, revision, approver and approval date. The BOM, software, drawings and physical machine inspected at FAT must share a traceable baseline.
Digital instructions require more than uploading a PDF
As legal requirements under Article 10(7), digital instructions must be printable, downloadable and saveable, and remain available online for the expected lifetime of the product and for at least ten years after it is placed on the market. When the purchaser requests paper instructions at the time of purchase, the manufacturer must provide them free of charge within one month of that request. For machinery or related products intended for non-professional users, the essential safety information needed to put the product into service and use it safely must be provided on paper when the product is placed on the market or put into service.
The following are implementation recommendations, not extra wording imposed verbatim by the Regulation: test URL persistence, permissions, server-outage fallback, revision history, serial-number applicability, language, and the one-month paper-request workflow before FAT. Avoid a QR code that leads to an expired link or inaccessible portal, and keep the printed essential safety information aligned with the controlled digital revision. These controls help sustain the Article 10(7) outcome over the product life.
Protection against corruption of safety controls and compliance data
The Regulation adds emphasis on protection of compliance-relevant software and data, and safety control systems, from accidental or intentional corruption. This cannot be closed with a generic IT cybersecurity questionnaire. Identify the parameters, safety PLC program, robot safety zones, speed limits, accounts and update procedures that could change a safety function. Verify that unauthorised or erroneous modification cannot create a hazardous condition unnoticed.
Possible controls include role-based access, change logs, approved backups, signature or hash checks, managed maintenance laptops, restricted remote access, recovery procedures and revalidation after an update. The chosen measures depend on the machine risk and architecture. ISO 13849-1:2023 provides a methodology for designing and integrating safety-related parts of control systems (SRP/CS); it does not itself provide detailed cybersecurity measures. Functional safety and cyber protection should meet in one change-control process.
AI safety functions and source code or programming logic
As legal requirements, Annex III contains essential health and safety requirements (EHSRs) relevant to control systems with fully or partially self-evolving behaviour or logic; affected machinery must demonstrate conformity through design and risk reduction. Separately, Annex IV Part A(n) specifies technical-documentation content, where applicable, for sensor-fed, remotely driven or autonomous machinery, including relevant characteristics, performance and tests. The Regulation’s source-code or programming-logic provision should be read narrowly: it concerns safety-related software, and information is required when a competent national authority makes a reasoned request because it is necessary to verify conformity with Annex III. It is not a general duty to disclose all source code to customers.
The consolidated text of 27 July 2026 also requires two AI timelines to be kept separate. Annex I contains specified categories involving safety components with fully or partially self-evolving behaviour using machine-learning approaches to ensure safety functions; the delegated requirement connected to high-risk AI systems in this safety-component context is to apply by 2 August 2028. Separately, the Machinery Regulation applies from 20 January 2027. Assess the Annex III EHSRs and Annex IV Part A(n) technical-documentation content as distinct requirements. Do not use the 2028 date to postpone the risk assessment and technical file for a 2027 machinery project.
Performance limits, data assumptions, fallback behaviour and post-change regression evidence should not be presented as mandatory statutory fields in every case. This article recommends defining them, where relevant to the function and risk, as additional RFP, design-review and FAT/SAT evidence that makes the applicable Annex III and Annex IV obligations easier to demonstrate and verify. That is a project-control recommendation, distinct from the legal requirements themselves.
Machinery risk assessment using ISO 12100
ISO 12100:2010 remains current, while revision work is underway
ISO 12100:2010 describes the terminology, principles and methodology for machinery risk assessment and risk reduction. The ISO page states that the 2010 edition was reviewed and confirmed in 2022 and remains current, while a revision is under development. For a project designed in 2026 and placed on the EU market in 2027, check both the latest edition and its harmonised-standard citation status at contract award and again at design freeze.
A risk assessment is not just a hazard list. It establishes machine limits, identifies tasks and human intervention over the life cycle, identifies hazards, estimates and evaluates risk, applies risk reduction, verifies the result, and communicates residual risk.
Include non-routine tasks common in Thailand-to-EU projects
Serious omissions often occur outside normal automatic operation. Review actual work with assemblers, maintenance personnel, commissioning engineers and EU site representatives:
- assembly, wiring, teaching and debugging in Thailand;
- lifting, packing, sea transport, unpacking and installation in Europe;
- production, changeover, manual operation and jam clearing;
- access inside guards for adjustment, sensor alignment and tooling;
- cleaning, lubrication, preventive maintenance, troubleshooting and recovery;
- recipe changes, software updates and backup restoration;
- isolation, dismantling and disposal.
Map the people, machine, workpiece, energy and environment for each task. For a robot cell, the boundary includes conveyors, fixtures, access doors, light curtains, upstream PLCs and neighbouring equipment—not just the robot. See our guide to industrial robot implementation and ISO 10218 in Thailand for related integration issues.
Apply the three-step risk-reduction method at design reviews
Consider inherently safe design first, safeguards and protective devices second, and information for use last. Do not begin with warning labels. Explore removing a hazardous movement, reducing force or speed, eliminating the need for access, or separating people from the hazard.
For every measure, record the pre-control risk, selected design measure, drawing/circuit/software reference, verification method, result, residual risk and communication route. Check whether the measure introduces a new hazard. For example, a guard that makes cleaning impractical may motivate bypassing an interlock.
ISO 13849-1:2023 and evidence for safety-related controls
Maintain traceability from PLr to validation
ISO 13849-1:2023 provides a methodology for the design and integration of SRP/CS. In a project file, connect each hazard to a safety function, the required performance level (PLr) rationale, Category, MTTFD, DCavg, CCF, software, diagnostics, achieved PL and validation result.
| Field | Example record |
|---|---|
| Safety Function ID | SF-01 Guard Door Stop |
| Hazard | Crushing, cutting or collision |
| Input | Dual-channel guard-lock switch |
| Logic | Safety PLC and approved function block |
| Output | STO, contactor and pneumatic dump valve |
| PLr rationale | Link to risk-assessment row |
| Response time | Detection to end of hazardous motion |
| Fault response | Open circuit, short circuit or welded output |
| Evidence | Calculation, test sheet and log |
Certificates for individual components do not prove the complete safety function. Confirm the boundary from sensor to actuator, stopping time, safety distance, wiring diagnostics, prevention of unexpected restart and behaviour under fault on the actual machine. A safety PLC change requires regression testing of affected safety functions.

Put CE marking machinery deliverables into the RFP
“CE compliant” is not a measurable purchasing requirement
An RFP that only says “CE compliant” leaves unclear whether the supplier owes a parts list, electrical drawings, risk assessment, test evidence, declaration or the entire technical documentation package. State who makes the final legislative decision, then define deliverables, revision, due date, review and correction duty, language, file format and FAT acceptance criteria.
RFP deliverables checklist
- Proposed product category and machine boundary.
- Applicable legislation and standards register, including editions.
- ISO 12100 machinery risk assessment.
- Essential health and safety requirements matrix.
- Mechanical, electrical, pneumatic, hydraulic and control drawings.
- Safety-function list, PLr basis, calculations and validation evidence.
- Safety software version, approved backup and change history.
- Supplier declarations and evidence for incorporated products.
- Test plan, FAT records and open-item register.
- Instructions and maintenance information in required languages.
- Draft EU declaration of conformity, marking and nameplate.
- Post-shipment technical-file retention, updates and authority-response process.
Evaluate whether a supplier can explain risk-reduction decisions through drawings and tests, not merely produce a certificate. The European Commission warns that voluntary certificates issued outside a body’s notified capacity are not a recognised means of proving conformity under EU harmonisation law. Where third-party involvement is required, verify the body’s notified scope in NANDO.
Define design-freeze gates before FAT
Finding an incomplete safety circuit on FAT day may leave no time to change the machine structure. Put these gates in the procurement schedule:
- G0 Requirements: use, capacity, materials, interventions and EU destination agreed.
- G1 Applicability: legislation, product category, economic operators and provisional conformity route reviewed.
- G2 Safety concept: boundary, principal hazards, safeguards and PLr approved.
- G3 Detailed design: guards, circuits, stopping distance, software and instruction structure approved.
- G4 FAT Ready: technical-file index and test procedures available; revisions match.
- G5 FAT: safety functions, faults and residual risks verified on the machine.
- G6 Shipment: open items closed; declaration, marking and instructions approved.
- G7 SAT: post-installation changes, interfaces and acceptance conditions revalidated.
Our articles on electrical design outsourcing for Thai factories and factory equipment modification explain drawing handover and modification control. For EU projects, connect those controls to the safety-evidence structure.
FAT/SAT tests that show—not merely state—compliance
FAT is a requirements-to-evidence review, not a production demo
Every FAT line should identify a requirement ID, safety-function ID, drawing, software version, test condition, expected result, measured result, pass/fail decision and owner of any correction. A video or a tick without the test condition is weak evidence.
Useful tests include:
- individual and combined operation of emergency stops, guard doors, light curtains and two-hand controls;
- fault response under loss of power or air, communication interruption, broken sensor wiring and welded contactors;
- stopping-time measurement and consistency with safety-distance calculations;
- speed, hold-to-run behaviour and access control in manual, maintenance and teaching modes;
- prevention of automatic restart after a safety function is triggered;
- resistance to unauthorised parameter changes from the network or maintenance laptop;
- restoration of an approved backup and retention of the associated log;
- agreement between the machine and instructions on hazard zones, residual risks and inspection intervals.
SAT closes the installation differences
Shipping, installation, utilities, upstream systems and adjacent machines can change the risk after FAT. SAT should start with a delta list rather than blindly repeat FAT. Check altered guards, cabling, PLC interfaces, floor level, lighting, walking routes, materials and recipes. Update the risk assessment and safety-function validation where the delta affects them.
If an EU line integrator changes controls on site, agree before shipment who owns the technical documentation and declaration for the final configuration. Even where the Thai supplier’s responsibility ends at a standalone machine, missing interface data can prevent the final conformity assessment.

A 90-day EU Machinery Regulation 2023/1230 plan
Days 1–15: establish applicability and ownership
Create a project register of machinery likely to be placed on the EU market or put into service around 20 January 2027. Record model, destination, contract, key dates, manufacturer, importer, integrator and current design phase.
Prepare a provisional classification—machinery, related product, partly completed machinery or other relevant category—plus applicable legislation, possible Annex I status and conformity route. Do not force uncertain cases into an internal yes/no answer. Define escalation criteria to an EU specialist. Deliverables are an applicability memo, responsibility matrix, legislation and standards register, and project RACI.
Days 16–30: gap analysis and safety concept
Collect the existing risk assessment, drawings, BOM, software, instructions and declarations. Map requirements to evidence. Check not only whether a file exists, but whether it matches the machine revision, provides a rationale and contains verification results.
Group critical gaps under mechanical design, safety-related controls, digital instructions, software/data protection, AI safety functions and technical documentation. Prioritise items requiring physical redesign. Approve the safety concept and issue a first safety-function list.
Days 31–60: synchronise design, documentation and verification
Implement guards, access control, stopping functions, modes, energy isolation, safety PLC logic and diagnostics. Update the risk assessment, essential-requirements matrix, drawings, calculations and instructions in parallel. Documentation must track the design, not follow it weeks later.
Create a validation plan for every safety function. Specify instruments, fault insertion, test pieces, witnesses and acceptance limits. Ask suppliers for missing evidence with owners and due dates. Deliver a design-freeze package, technical-file index, FAT procedure and draft instructions.
Days 61–75: pre-FAT and evidence consistency
Run a document-based pre-FAT. Align the revisions of BOM, drawings, program, nameplate, instructions and test procedure. Compare calculated values with settings in the physical machine. Every open point needs an owner, action, due date and closure evidence.
Test the digital-instruction operation: URL, print/save functions, access period, outage fallback and paper-request process. Store the approved software release, restore it from backup and verify the change log.
Days 76–90: FAT, shipment decision and SAT handover
Record normal and fault behaviour at FAT and close nonconformities. At shipment review, ensure that the declaration and CE marking are controlled until the required conformity assessment has actually been completed.
Handover the FAT baseline, post-transport checks, site interface conditions, change-control method, SAT tests and technical-file update ownership to the EU team. Ninety days may not complete every complex conformity project, but it creates a controlled flow of decisions, evidence and gates that exposes major rework early.
Role-based readiness checklist
Production engineering and project management
- Is the EU placing-on-market or put-into-service milestone recorded?
- Is the machine boundary and contractual responsibility approved?
- Are safety measures compatible with production and maintainability?
- Do design changes have owners, deadlines and FAT impact?
- Is responsibility for the final EU-integrated configuration agreed?
Mechanical and controls engineering
- Does the ISO 12100 assessment include non-routine tasks?
- Does every safety function link to a hazard and PLr rationale?
- Is ISO 13849-1:2023 used within its actual scope?
- Are stopping time, diagnostics, faults and restart prevention tested?
- Are safety software, data and settings under change control?
Equipment purchasing
- Does the RFP define evidence, revision, date and acceptance condition?
- Are voluntary certificates distinguished from the required conformity route?
- Are the importer, EU specialist and notified body roles clear?
- Does the contract cover correction, retest and document update after FAT?
- Is the digital/paper instruction process specified?
Quality, legal and document control
- Is the edition and citation basis of each law and standard recorded?
- Do the declaration, nameplate and technical file identify the same machine?
- Can requested records be found and supplied under controlled conditions?
- Are retention, access, backup and confidentiality defined?
- Are the latest legislation, Official Journal and harmonised references rechecked before the decision?
Common mistakes to prevent
Adding CE-marked components and assuming the machine is compliant
Component evidence is useful, but it does not prove the integrated machine. Evaluate architecture, interfaces, fault response and safety distance as a system.
Writing the risk assessment after the machine is built
Late assessment makes inherently safe design difficult and can force expensive guards or capacity compromises. Start at requirements and layout, then approve updates at G2 and G3.
Treating ISO 13849-1:2023 as a complete cybersecurity solution
The standard addresses SRP/CS design and integration, not detailed cybersecurity controls. Link machinery hazards to network, update and privilege risks, and select additional measures with competent specialists.
Starting instructions and declarations after FAT
Instructions contain residual risks, maintenance and setting conditions. Draft them at G3 and compare them with the physical machine during FAT.
Freezing an old harmonised-standards list
References change. The Commission’s summary is useful but says it is for information and does not itself create legal effects. Recheck the Official Journal and latest implementing decisions at design freeze and declaration issue.
FAQ: EU Machinery Regulation 2027 and CE marking for machinery
1. When does the EU Machinery Regulation 2027 apply?
The current consolidated text and European Commission page state that Regulation (EU) 2023/1230 applies mandatorily from 20 January 2027. Assess the relevant placing-on-market or putting-into-service event, not shipment date alone.
2. Does a machine used only in Thailand need Regulation (EU) 2023/1230 compliance?
Not automatically because of its location or ownership. If it is not placed on the EU market or put into service there, the Regulation may not apply directly. Reassess if the machine will later be moved, sold or integrated in the EU.
3. What should an ISO 12100 machinery risk assessment retain?
Retain the machine limits, life-cycle tasks, hazards, risk estimates and evaluation, selected reductions, verification and residual-risk communication. Link each decision to controlled drawings, safety functions and tests.
4. Does ISO 13849-1:2023 complete cybersecurity compliance?
No. It provides a methodology for SRP/CS design and integration, but not the complete set of specific cybersecurity measures. Identify safety-relevant software and data and separately control access, change, update, recovery and revalidation.
5. Is a notified body mandatory for every CE-marked machine?
Not every machine follows the same route. The product category, Annex I status and chosen conformity procedure matter. Confirm the current legal requirements and, when necessary, consult a body with the relevant notified scope in NANDO.
6. Can instructions be supplied only in digital form?
The Regulation permits digital instructions subject to conditions. They must be printable and saveable and remain online for the product’s expected lifetime and at least ten years after placing on the market. Paper instructions requested at purchase must be supplied free within one month. For non-professional-user machinery, essential safety information must be supplied on paper when the product is placed on the market or put into service. Keep those legal duties distinct from recommended URL monitoring and outage controls.
7. Can modification of an existing machine trigger a new assessment?
Yes, if the legal test is met. An unplanned or unforeseen physical or digital post-market change that creates a new hazard or increases risk, and requires either guards/protective devices that change the existing safety control system or additional stability/mechanical-strength measures, can be a substantial modification. As a rule, the modifier is considered the manufacturer and assumes the relevant obligations and conformity assessment. The Article 18 third-paragraph exception applies when a non-professional user modifies machinery or a related product they own for their own use. Confirm the modifier and purpose in the case-specific review.
8. What support should a 90-day programme procure first?
Prioritise applicability and responsibility review, evidence-based gap analysis, risk-assessment restructuring, and RFP/FAT/SAT specification. Look for support that can integrate compliance evidence into engineering gates, not simply issue an additional certificate.
Conclusion: manage the flow of evidence, not only the deadline
EU Machinery Regulation 2027 readiness means connecting the 20 January 2027 milestone to applicability, ISO 12100 risk reduction, ISO 13849-1:2023 safety controls, digital instructions, software and data protection, technical documentation and conformity assessment. Thailand-to-EU projects especially need early agreement on ownership across companies and countries.
TOMAS TECH can support machine inventories, 90-day gap analysis, RFP deliverable definitions and FAT/SAT evidence planning from the early study stage. Formal legal decisions remain with appropriate EU-recognised bodies and specialists; our focus is converting requirements into practical engineering controls for Thai and ASEAN projects. Contact us to discuss an early-stage project.
Primary sources
Checked on 15 September 2026. Reconfirm the latest versions before a project decision.
- Regulation (EU) 2023/1230 — current consolidated text
- Regulation (EU) 2023/1230 — consolidated PDF dated 27 July 2026
- European Commission: Machinery
- European Commission: Harmonised standards for machinery
- ISO 12100:2010 official standard page
- ISO 13849-1:2023 official standard page
*This article is general technical and project-management information, not legal advice. Confirm formal applicability, conformity routes and harmonised standards against the latest EU law and Official Journal with an EU-recognised body, notified body where applicable, or qualified specialist.*