Editorial note

This article provides general information, not legal, regulatory or financial advice. Requirements depend on the applicable contract, authority and jurisdiction.

Bow view of a bulk carrier at anchor

What E26 and E27 cover

Maritime cyber security moved from advisory to mandatory in two steps. First, IMO required cyber risks to be addressed in safety management systems under the ISM Code. Second, the International Association of Classification Societies made cyber resilience a class requirement for new construction through Unified Requirements E26 and E27, applicable to ships contracted for construction on or after 1 July 2024.

UR E26UR E27
ScopeCyber resilience of the shipCyber resilience of on-board systems and equipment
Applies toThe vessel as an integrated systemIndividual computer-based systems
Responsible partyYard and owner, with class verificationSystem suppliers
Key outputsInventory of CBS, network topology, security zones, recovery planSupplier security capability, hardening, documentation

Between them they establish five expectations: know what computer-based systems are on board; segregate networks; control access; detect and respond to incidents; and be able to recover.

Why operational technology is the hard part

IT is email, crew wifi and business systems. Operational technology (OT) is the machinery: engine control, integrated bridge and navigation, cargo control, ballast, power management, dynamic positioning. The differences are fundamental:

ITOT
PriorityConfidentialityAvailability and safety
Patch cycleWeeksYears, if at all
Lifespan3–5 years20–25 years
Downtime toleranceMinutesSometimes zero
Vendor accessControlledFrequently remote and poorly logged
Change controlStandardClass approval may be required

You cannot simply apply corporate IT security to a ship. Patching an engine control system may invalidate a class approval or a maker's warranty; taking a bridge system offline for a security update is not an option at sea.

Remote vendor access is consistently identified as the largest practical exposure: engine makers, ECDIS suppliers and automation vendors connect to ships for diagnostics, often through arrangements nobody in the shipowner's organisation has documented.

The connectivity change

Shipboard bandwidth transformed with the arrival of LEO satellite services. A ship that once had a metered, narrow link now has a broadband connection used by crew and systems simultaneously. That is a substantial quality-of-life improvement and a substantially larger attack surface.

Two controls matter more than anything else in that environment: segregation of crew networks from OT networks, and monitoring of what crosses between zones.

A practical programme for a fleet

Phase 1 — Know what you have (months 1–3)

  • Inventory every computer-based system, by vessel
  • Map network topology including all external connections
  • Identify every remote access path, including vendor connections
  • Classify systems by consequence of compromise

Phase 2 — Reduce exposure (months 3–9)

  • Segregate OT from IT and from crew networks
  • Control removable media with a documented, enforced policy
  • Bring vendor remote access under managed, logged, time-limited control
  • Harden accounts: no shared credentials, no default passwords
  • Physically secure bridge and engine control room network points

Phase 3 — Detect and respond (months 6–12)

  • Logging and monitoring where practical without affecting OT availability
  • An incident response plan that works with the ship at sea and offline
  • Contact routes for class, flag, insurers and vendors
  • Tabletop exercises including the master and chief engineer

Phase 4 — Recover (months 9–15)

  • Backups of critical system configurations, held offline
  • Tested restoration procedures — untested backups are assumptions
  • Manual fallback procedures for navigation, propulsion and cargo systems
  • Crew trained on those fallbacks

Existing tonnage

E26/E27 apply to ships contracted for construction on or after 1 July 2024. Existing ships are not covered by the URs, but they remain covered by the ISM Code requirement to address cyber risk in the safety management system — and by charterers, insurers and increasingly by financiers.

Practical position: apply the same five principles to existing ships, proportionately, prioritising vendor remote access and network segregation as the highest-value interventions.

The human layer

Most maritime cyber incidents start with a person: a USB drive used to transfer a chart update, a phishing email opened on the ship's business PC, a crew member connecting a personal device to the wrong network. Training that treats crew as the last line of defence rather than the primary risk works better, because it produces reporting rather than concealment.

IACS UR E26 and E27 apply to ships contracted for construction on or after 1 July 2024; consult IACS and your class society for authoritative requirements. Exposure chart is an indicative model. Reviewed by the Zeaclub Editorial Team, 24 August 2026.

Frequently asked questions

Do IACS UR E26 and E27 apply to my existing ship?

They apply to ships contracted for construction on or after 1 July 2024. Existing ships remain subject to the ISM Code requirement to manage cyber risk.

What is the difference between E26 and E27?

E26 addresses the cyber resilience of the ship as a whole; E27 addresses the cyber resilience of individual on-board systems and equipment, placing obligations on suppliers.

Is crew internet a security risk?

Any network connection is. The answer is segregation and monitoring, not restricting crew connectivity — which is now a central welfare and retention factor.

What is the highest-value single control?

Bringing vendor remote access under managed, logged, time-limited control. It is consistently the largest undocumented exposure on ships.