Cyber compliance for CE marking
Verification of cybersecurity requirements for the new Machinery Regulation (EU) 2023/1230
Algorithms and functions
must be governed
When a machine integrates software, communication networks or remote connections, cyber events can directly affect the safety of people and the reliability of command systems.
The new Machinery Regulation (EU) 2023/1230 makes these aspects an integral part of the essential safety requirements, linking them explicitly to CE marking. The Cyber Compliance for CE Marking service supports the manufacturer in verifying and implementing the cybersecurity measures required for the machine or related product to be placed on the market or put into service in compliance with the Regulation.
The new Machinery Regulation (EU) 2023/1230 makes these aspects an integral part of the essential safety requirements, linking them explicitly to CE marking. The Cyber Compliance for CE Marking service supports the manufacturer in verifying and implementing the cybersecurity measures required for the machine or related product to be placed on the market or put into service in compliance with the Regulation.
When is it needed
The service is particularly indicated when:
- A machine integrates software, programmable command systems or connections to external or remote devices;
- CE marking is required pursuant to Regulation (EU) 2023/1230;
- It is necessary to demonstrate compliance with the requirements for protection against tampering and the security of command systems;
- Software and critical data contribute to the safe operation of the machine.
How the assessment is carried out
The activity consists of a technical and documentary verification focused on the cybersecurity requirements relevant for CE marking.
- Verification that connections to external or remote devices do not create hazardous situations, including in the presence of unauthorised access or foreseeable misuse;
- Verification of the design and configuration of command systems with respect to intentional or unintentional external influences;
- Analysis of software and safety-critical data, verifying identification, protection against tampering, and management of access and updates;
- Verification of the protection of hardware relevant to access to safety-critical software;
- Verification of evidence-collection mechanisms relating to software interventions, configuration changes and interventions on safety-relevant hardware components;
- Verification of the traceability of safety software versions for the period provided for in the Regulation.
What we deliver
At the end of the activity, we provide:
- Technical verification report on the cybersecurity requirements relevant for CE marking;
- Evidence of gaps with respect to the requirements of Annex III of Regulation (EU) 2023/1230;
- Technical recommendations for remediation;
- Support for updating the technical documentation of the machine.