Machinery Safety for Equipment Manufacturers: A Practical Guide
Safety is a design constraint for whoever builds the machine. What the new EU Machinery Regulation changes, and where small builders lose the most time.
Written by Eduardo Fuentevilla Blanco
Robotics Engineer at Maedcore · Robotics Engineer LinkedIn ↗
Safety Is a Design Constraint, Not a Plant Problem
Most writing about industrial safety is addressed to the company that runs the machine — risk assessments, PPE, training, accident rates. If you build machines, almost none of it is your problem.
Yours arrives earlier and is harder to undo. By the time a machine reaches a customer’s floor, its safety characteristics are already fixed: the guarding is welded, the safety functions are specified, the control architecture is chosen, and the declaration of conformity carries your name. Safety is not something you add to a machine at the end. It is a set of constraints that shape the design from the first layout drawing, and a documentation obligation that follows you for the life of the product.
That distinction matters more than usual over the next eighteen months, because the rules are changing.
What Changes in January 2027
Regulation (EU) 2023/1230 replaces the Machinery Directive 2006/42/EC and applies from 20 January 2027. It is a regulation rather than a directive, so it applies directly across member states without national transposition.
Four changes matter most if you place machines on the EU market:
Digital instructions become permissible. Under the old regime, instructions had to be supplied on paper. The new Regulation allows them to be supplied in digital format, with a paper version on request. For a builder shipping variants across several languages, this is the single most useful change in the text — and the one that most directly rewards having your documentation generated rather than assembled.
Software corruption is treated as a safety concern. The Regulation brings cybersecurity into the essential health and safety requirements: a machine must be designed so that corruption of software — accidental or malicious — does not create a hazardous situation. If your machine has a network connection, this is now part of your risk assessment.
Self-evolving behaviour gets explicit treatment. Machines whose behaviour changes through machine learning after they are placed on the market are addressed directly, including safety functions that rely on it. If you are adding adaptive control or vision-based decisions, expect this to shape both your design and your technical file.
Substantial modification can transfer the obligations. A machine changed significantly after being placed on the market can trigger a new conformity assessment — and whoever made the modification may become the manufacturer for the modified machine. This bites on retrofits, upgrades and second-life sales, which is exactly the aftermarket work many builders are trying to grow.
Work from the current consolidated text of the Regulation and confirm the detail with a notified body or a competent safety consultancy before you rely on any of it. This section is orientation, not legal advice, and the transition arrangements deserve a closer read than a blog post can give them.
The Standards That Do the Actual Work
The Regulation tells you what to achieve. The harmonised standards tell you how, and using them gives a presumption of conformity — which in practice is the cheapest route to demonstrating you did the work.
| Standard | What it covers | When you need it |
|---|---|---|
| ISO 12100 | Risk assessment and risk reduction — the general methodology | Every machine, always. This is the foundation |
| ISO 13849-1 | Performance Level (PL) of safety-related control systems | Whenever a control system implements a safety function |
| IEC 62061 | Functional safety expressed as SIL | Complex or highly electronic safety architectures |
| ISO 10218 | Industrial robots and robot systems | Any robot cell you design or integrate |
| ISO/TS 15066 | Collaborative operation, force and pressure limits | Any application without full physical separation |
The one worth pausing on is ISO/TS 15066, because the most expensive misunderstanding in robot cell design is treating “collaborative” as a property of the robot.
It is a property of the application. A robot sold as collaborative is not automatically safe in your cell — the end effector, the workpiece, the speeds, the layout and the human body regions that could be contacted all determine whether collaborative operation is achievable. A cobot carrying a sharp part at speed may need precisely the same guarding as a conventional six-axis arm. Designing the cell around the robot’s marketing category rather than around a risk assessment is how a project ends up re-guarded after FAT.
Where Small Builders Actually Lose the Time
Here is the part that rarely gets written about, because it isn’t technically interesting.
The engineering work of safety — assessing risk, specifying safety functions, calculating a performance level, validating it — is real, but it is proportionate to the machine and it is work your engineers are qualified to do. It scales with complexity, which is fair.
The documentation does not scale fairly. For every machine you ship you need a technical file, instructions, a declaration of conformity, and the residual-risk information that belongs with them. Then you ship a variant of that machine, and much of it is rebuilt by hand. Then a third variant, in another language, for another customer. Then someone asks for the file on a machine you delivered in 2019 and the engineer who compiled it has left.
For a builder with a handful of engineers, this is where safety compliance actually consumes the week — and none of it is engineering. It is retrieval, reassembly and reformatting of information you already own, repeated on every delivery, and it gets worse as your installed base grows rather than better.
That is the part worth attacking, and the new Regulation’s acceptance of digital instructions makes it materially easier. When the technical documentation is generated from the machine’s configuration instead of assembled from the last similar project, a variant costs minutes rather than days, translations stop being a separate project, and the file for a machine from 2019 is still there when the customer asks.
A Practical Sequence for a Small Builder
- Start the risk assessment at concept, not at FAT. ISO 12100 is cheapest when it can still change the layout. Late risk assessment is how you end up bolting guarding onto a machine that was designed without space for it.
- Decide the required performance level before you choose components. PL follows from the risk assessment. Choosing safety relays and then reverse-engineering a justification is slower and less defensible.
- Treat the network connection as a hazard path. If the machine can be reached remotely, corruption of its software is now within scope. Decide who can update what, and write it down.
- Audit your documentation flow before your next variant. Count the hours between “we’ve sold it” and “the file is complete”. That number, multiplied by machines per year, is the real compliance cost.
- Write down the aftermarket rules. Decide now what your position is when a customer or a third party modifies a machine you built — because substantial modification can move the manufacturer’s obligations, and you want that answered before it happens, not after.
- Keep the residual-risk information with the machine, not with the person. The commissioning engineer’s knowledge of why a guard is where it is belongs in the file.
How Maedcore Fits
We are not a safety consultancy and we do not issue conformity assessments — for that, use a notified body or a specialist safety engineer.
What we build is the layer around it: technical documentation that is generated from a machine’s configuration rather than reassembled by hand, project and drawing archives your engineers can actually search years later, and the instrumentation that lets a machine you built report what it is doing once it is on a customer’s floor. In practice this is the difference between compliance being an engineering task and compliance being an administrative one.
Related reading
See a machine we designed with inspection and safeguarding built into the head itself in our automated welding head case study, and explore our mechatronics services for the sensing and firmware side.
About the Author
Robotics Engineer
For over a decade, I have been driven by a single mission: leveraging AI and robotics to build a world of automated production. I believe that by creating self-sufficient systems, we can empower people to refocus on what truly matters—their families and their passions. My expertise spans from winning prestigious European startup competitions to architecting complex, integrated hardware and software projects. I specialize in bridging the gap between today's industrial challenges and tomorrow's autonomous solutions.
Frequently Asked Questions
Who is responsible for machinery safety — the builder or the operator?
What is changing with the new EU Machinery Regulation?
Which standards actually do the work?
Does a cobot need guarding?
What does compliance cost a small machine builder?
Ready to transform your company?
Book a free 30-minute meeting with an engineer.