Knowledge base / Security / Machine Safety

Machine Regulation 2027.
Safe remote working.

A connection makes your control system accessible. Whether a remote action is safe depends on the machine, the situation, and the agreements made.

What changes on January 20, 2027?

From January 20, 2027, the Machine Regulation (EU) 2023/1230 will become mandatory and replace the Machinery Directive 2006/42/EC. The new rules pay explicit attention to digital influence on safety-relevant software, data, and control systems.

According to the European Commission, machines placed on the EU market before that date must comply with the current Machinery Directive. The transition point does not mean that every existing machine must automatically be recertified. However, assess which rules apply to a specific delivery or modification. View the official explanation on machinery legislation.

Safety and security meet in the control system

Safety is about managing the machine’s safety risks. Security includes preventing and limiting unauthorized access or influence. If an unauthorized change can cause a dangerous movement, these subjects overlap directly.

Consider changing a motion parameter, replacing software, or changing an operating mode. The question is not just whether the connection is encrypted. The question is also who is allowed to perform this action, what can happen physically, and how you verify that the machine remains safe.

A VPN is not a safety function

A standard remote access connection does not replace an emergency stop, safety control, shielding, or other measures from the risk assessment. Even in the event of connection loss, safety must be assessed based on the machine and its local facilities.

Distinguish between viewing, modifying, and operating

  • Viewing: request status or measured values. Also assess accessibility and the influence of data traffic on the installation.
  • Modifying: adjust parameters, configuration, or software. Arrange permission, a suitable machine state, version control, and post-check.
  • Operating: give commands that influence the process. Assess visibility of the situation, coordination with people on-site, and the necessary safety measures.

This distinction helps to set up access appropriately. It is not a general release of a specific action: the machine risk assessment and the responsible parties determine the conditions.

A practical modification procedure

  1. Beforehand: describe the purpose, the control system involved, and possible consequences. Record approval and contact with the site.
  2. Prepare: check the initial version, create a restorable backup where appropriate, and determine what happens in case of connection loss.
  3. Execute: use the agreed access, monitor the state of the installation, and record the modification performed.
  4. Release: test the agreed functions, have the responsible person evaluate the results, and revoke temporary access.

For modifications, have it assessed whether the consequences for safety or compliance go beyond regular maintenance. Not every software update is the same, and remote execution does not change the responsibility.

What can you expect from Remote?

Remote provides the means for access, asset and rights management, and data logging/monitoring. With our team, you discuss the connection, network boundaries, users involved, and any custom apps or protocol links. The machine builder, integrator, and user remain involved in the safety of the entire application.

We agree in advance who sets up access, who approves modifications, and what information is needed to keep management and maintenance feasible. Installing a router is not a CE assessment of the machine.

Practical points of attention for remote access, not a machine risk assessment, safety design, or declaration of conformity. Have legal applicability and significant changes assessed on a project-specific basis.