Anyone who substantially modifies or retrofits a machine is quickly considered the manufacturer, with CE marking and conformity obligations. This explains when that applies and how software changes matter.
The new EU machinery regulation (Regulation (EU) 2023/1230, MVR) explicitly codifies this principle for the first time. It applies from 20 January 2027 and will, on that date, replace the previous Machinery Directive 2006/42/EC (https://eur-lex.europa.eu/legal-content/DE/TXT/?uri=CELEX:32006L0042). Anyone who modifies or retrofits in-service machines should therefore know the term “significant change” before taking the first wrench.
The machinery regulation defines a significant change as a physical or digital modification of a machine after it has been placed on the market or put into service that was not foreseen or planned by the manufacturer and that affects safety by creating a new hazard or increasing an existing risk.
The decisive consequence is this: under the regulation a change becomes significant only if it makes it necessary to add additional separating or non-separating protective devices (whose integration requires an adaptation of the existing safety control system) or to take additional measures for the stability or strength of the machine. In other words, it is not every change but those that demand new safety-related responses.
Two points are important. First, digital changes count explicitly, not only mechanical alterations. Second, the assessment is tied to your risk assessment: what the original manufacturer already anticipated and planned is not a significant change.
Repair maintenance or significant change — where is the boundary?
Not every intervention makes you the manufacturer. The EU guide to the implementation of product legislation (Blue Guide 2022) (https://eur-lex.europa.eu/legal-content/DE/TXT/?uri=OJ:C:2022:247:TOC) describes the test that underlies the machinery regulation. A modified product can be considered a new product if three conditions coincide: its original performance, intended use or construction has been changed without this being foreseen in the original risk assessment; the nature of the hazard has changed or the risk level has increased; and the product is placed on the market or put into service. Whether this threshold is reached must always be decided case by case.
Pure maintenance is not covered. If a defective or worn part is replaced by an identical or at least a substantially similar spare part, the machine remains, according to the Blue Guide, not a new product even if the new part performs somewhat better for technical reasons. For such repaired machines no renewed conformity assessment is required.
The following overview indicates the boundary for typical retrofit situations. It does not replace a case-by-case assessment but makes the logic tangible.
| Does not usually trigger manufacturer duties | Generally counts as a significant change |
|---|---|
| Replacement of a sensor or motor with a component identical in design and performance | Retrofitting a robot cell or handling system that creates new hazards |
| Repair after a defect without changing the function | Increasing power, speed or cycle rate beyond the intended range |
| Software security update that only closes a vulnerability | Removing or bypassing a separating protective device so the safety control system must be adapted |
| Cosmetic or purely operator-facing adjustments | Modification that introduces a new type of hazard (for example, first-time remote controllability) |
When do you become the manufacturer through modification and what does that mean?
The machinery regulation is clear at this point: a natural or legal person who makes a significant change to a machine is considered the manufacturer for the purposes of the regulation. That person is then subject to the manufacturer’s obligations for that machine. If the change, as the risk assessment shows, affects only a single machine within a group of machines, the obligations are limited to the affected machine.
This role assumption does not only affect classic remodellers. An importer or distributor also becomes the manufacturer if they modify a product already placed on the market in a way that can affect conformity. An exception applies only to non-professional users who modify their own machine for personal use: they are not considered manufacturers.
Which obligations apply in concrete terms?
Whoever becomes the manufacturer must declare on their own responsibility that the affected machine complies with the applicable requirements of the regulation and must undergo the relevant conformity assessment procedure. In practice this means taking the same steps as an original manufacturer:
- Renew the risk assessment and apply the essential health and safety requirements from Annex III of the regulation to the modified machine.
- Create or update the technical documentation. The Blue Guide makes clear: you only need to reassess and document the aspects affected by the change, not the entire machine from scratch.
- Carry out the conformity assessment according to the procedure appropriate for the machine.
- Issue an EU declaration of conformity and affix the CE marking for the modified machine.
The limited scope is the good news: tests and documentation not affected by the modification do not have to be repeated. However, the responsibility for the conformity of the modified result lies with you.
Why are software changes assessed differently from hardware?
Once a machine is networked and controlled by software, a second level is added. For products with digital elements the Cyber Resilience Act (Regulation (EU) 2024/2847, CRA) applies. It defines its own concept of significant change and evaluates software specifically.
Under the CRA a significant change is a change to a product with digital elements after it has been placed on the market that affects conformity with cybersecurity requirements or changes the intended purpose. Here too: whoever makes such a significant change and makes the product available is considered the manufacturer — for the part affected by the change or, if the cybersecurity of the whole product is affected, for the entire product.
The obligations of the original manufacturer do not end as a result. For the parts your modification does not touch, the original manufacturer remains responsible according to the Commission’s guidance, in particular for vulnerability handling. Responsibility is therefore shared, not transferred. That is also the difference to integration: someone who assembles components into a new product and places it on the market under their own name does not modify someone else’s product but is the manufacturer of the new product as a whole.
The decisive difference lies in the assessment of updates. A pure security update that only reduces the cybersecurity risk and does not change the intended purpose is, according to the recitals of the CRA, generally not a significant change. This typically covers closing a known vulnerability. Minor functional adjustments such as a new language or a visual update are also usually unproblematic. Conversely, a functional update that changes originally intended functions or performance can very well be a significant change: new functions generally enlarge the attack surface and thus increase cybersecurity risk.
The Commission’s guidance sharpens this line at a point often overlooked in practice. A security update remains unproblematic even if it intervenes significantly at the technical level, as long as it does not change the intended purpose and does not introduce new risks. This explicitly covers cases in which functions are restricted or reworked solely to close a vulnerability. Conversely, a security-driven update can tip over: if it relocates a previously local function to a remote service, materially changes data flows or creates new externally reachable interfaces that were not foreseen in the risk assessment, it is a significant change even though it was carried out for security reasons.
The Blue Guide draws the same line for classic product safety: software updates are equivalent to maintenance as long as they do not impair conformity. Only when an update changes the intended functions, construction or performance, shifts the nature of the hazard or raises the risk level does the product become significantly changed.
| Change to the machine | Assessment logic | Is a new assessment required? |
|---|---|---|
| Hardware modification that creates a new hazard (machinery regulation) | Significant change if additional protective devices or stability measures are required | Yes, manufacturer duties for the affected machine |
| Security update without change of purpose and without new risks (CRA) | Fixes a vulnerability, only reduces risk; applies even with substantial technical intervention | No, generally not a significant change |
| Security update that shifts data flows or creates new external interfaces (CRA) | Despite security purpose, new or increased risks outside the risk assessment | Yes, manufacturer duties for the affected part |
| Functional update that changes purpose or performance (CRA) | Enlarges attack surface, increases cybersecurity risk | Yes, manufacturer duties for the affected part |
| Minor adjustment (new language, interface) | No impact on purpose or safety | No |
Both realms interact. Annex III of the machinery regulation contains its own requirements for protection against corruption and for the safety and reliability of control systems. How these cyber requirements of the machinery regulation and the obligations of the CRA interplay is discussed in the contribution on the interaction of the Cyber Resilience Act and the machinery regulation. For more on protection against manipulation see EN 50742: protection of machines against corruption.
Does your next update create new attack surfaces?
The CRA readiness check shows in a few minutes how well your products and processes are currently secured — including where an update or retrofit starts.
What applies to in-service machines and older installations?
A common misconception is that older machines are not affected. For continued operation alone that is often true. But as soon as they are significantly modified, the new obligations apply.
Legally this is a real advance. The old Machinery Directive 2006/42/EC did not explicitly include the concept of significant change; until now it was derived mainly through guidance and national interpretation. The MVR now codifies it directly in the regulation text for the first time. It takes effect on 20 January 2027 and the Directive 2006/42/EC will be repealed on the same date.
For the cyber side the CRA provides a clear transitional rule: products with digital elements that were placed on the market before 11 December 2027 are subject to the CRA’s requirements only if they undergo a significant change after that date. The obligation to report actively exploited vulnerabilities and serious incidents, which already applies to all affected in-service products, remains an exception. A retrofit can therefore pull an in-service product that was initially outside the full scope into full application.
What does a retrofit mean for the support period?
If a retrofit becomes a significant change and you make the result available, the Commission’s guidance considers that a new placing on the market. That raises the question of the support period.
It is not automatically extended or reset. The decisive factor remains the expected service life of the modified product, which you must reassess according to the CRA criteria. What matters is whether the change touches the factors that determined the original service life.
In many retrofits that is not the case. If the expected service life previously depended mainly on the machine’s physical durability and you only change software or a back-end service, the original framework remains: the support period for the modified product is then based on the remaining expected service life. If, however, the modification shifts the service life itself, for example because major assemblies are renewed, the period must be set anew accordingly.
How do you check in practice whether your retrofit is affected?
Before implementing a modification, a short structured check is worthwhile. Three questions usually lead to the correct classification:
- Does the modification create a new hazard or increase an existing risk? Was the change foreseen in the original risk assessment? If not, and if protective devices or stability measures become necessary, everything points to a significant change.
- Are you changing hardware or software? For software the decisive factor is whether you are only closing a vulnerability (usually uncritical) or changing purpose, function or performance (then generally significant).
- Do you make the result available or put it into service? Manufacturer duties only apply with availability or commissioning.
For software changes, the Commission’s guidance specifies the second question with four checkpoints. Does the update introduce new threat vectors, such as additional interfaces, communication channels or external dependencies? Does it enable new attack scenarios? Does it change the likelihood of already known scenarios because, for example, less effort or knowledge is required to exploit them? And does it change their possible impact, i.e. the scope of affected data and functions or your ability to detect and contain an incident? If the answer is No to all four and the assumptions of your risk assessment remain unchanged, that speaks against a significant change.
Document this check. Keep the risk assessment up to date and, in case of doubt, treat the machine like a new machine. That is the safer route because the responsibility for the conformity of the modified result lies with you.
Regardless of the final classification, the risk assessment and technical documentation must be kept continuously up to date. This obligation does not depend on whether a change is deemed significant.
Decision tree: when a retrofit makes you the manufacturer. Pure maintenance and pure security updates usually remain outside; function- or risk-changing modifications lead into manufacturer duties.
Conclusion the modification decides your role
A retrofit is rarely just technical. It can legally shift your role from operator to manufacturer, with conformity assessment, technical documentation, a declaration of conformity and CE marking. The machinery regulation makes this transition visible in law from 2027, and for networked machines the CRA additionally checks whether a software change alters the cybersecurity risk. Those who consider both levels early plan modifications robustly instead of having to supplement them afterwards.
Is your retrofit in the gray area?
A conversation clarifies whether your planned modification crosses the threshold to a significant change and which tests, documents and declarations will then be required.