
Cyber compliance, without the scaremongering.
IACS UR E26 and E27 are real, and they have teeth. They also do not apply to most of the ships already in your fleet. We will tell you which of your vessels are actually in scope before we sell you anything.
First, some things other vendors will not tell you.
E26 and E27 apply to newbuilds. Specifically, ships contracted for construction on or after 1 July 2024. They are not retroactive. If your fleet was contracted before that date, these requirements do not automatically apply to it.
But you are not off the hook. Every vessel has been subject to IMO cyber risk management under the ISM Code since January 2021. That obligation is already live, it already applies to your whole fleet, and it is already being looked at by Port State Control.
And the direction of travel is one way. Class societies are increasingly treating E26-aligned practice as the standard for existing tonnage, and it is showing up in charterers' questionnaires and vetting long before it shows up in a rule.
So the honest position is this. If you are taking delivery of a newbuild, you have a hard requirement and a date. If you are not, you have a softer obligation that is quietly hardening, and you have time to do it properly rather than in a panic.
We would rather tell you that than sell you a compliance package you do not need.
What the requirements actually are.
Cyber Resilience of Ships
The ship as a whole. Owners and yards. It covers how OT and IT systems are integrated into the vessel's network across design, construction, commissioning and the operational life of the ship. Built around five functions: Identify, Protect, Detect, Respond, Recover.
In practice, you must be able to show:
- A documented inventory of every computer-based system essential to safe operation, with manufacturer, model, firmware version and network connectivity
- A process for identifying and responding to known vulnerabilities in those systems
- Network architecture that segregates what needs segregating, documented and approved
- Access control, malware protection and recovery capability
- A Cyber Resilience Test Procedure, exercised at construction and at annual surveys
- A Ship Cyber Security and Resilience Program, maintained for the life of the vessel and verified by class
Cyber Resilience of On-board Systems and Equipment
Individual systems and equipment. Aimed at third-party suppliers. It requires makers to harden their products before installation, and to provide secure update mechanisms and vulnerability disclosure.
If you are an owner: E27 is what your suppliers owe you, and what your handover documentation must prove.
If you are a supplier: E27 is now being written into procurement contracts. If you cannot demonstrate a secure update mechanism and a vulnerability disclosure policy, you will start losing bids.
Who is in scope
Passenger ships on international voyages. Cargo ships of 500 GT and above on international voyages. High-speed craft of 500 GT and above. Mobile offshore drilling units of 500 GT and above. Self-propelled mobile offshore units.
For other vessel types, the requirements are non-mandatory guidance, which does not mean irrelevant, only that nobody will detain you over them yet.
Nobody fails on cyber because they are careless.
They fail because nobody has ever written down what is connected to the vessel network.
That sounds trivial. It is not. On a working vessel there is a bridge system nobody can name the supplier of, a laptop connected to an engine system by a contractor in 2019, a routing table three people have edited and nobody has documented, and a piece of equipment that phones home to a maker's server through a link the owner does not know exists.
You cannot protect, detect, respond or recover without that inventory. Every one of the five functions depends on the first one. And the first one is dull, unglamorous, boots-on-deck work that nobody wants to do.
We will do it.
From scoping to survey, held current.
Scoping. Start here
We tell you which vessels are actually in scope, what you are obliged to do today, and what is coming. Fixed fee, and deliberately small. If the answer is "less than you feared", that is what we will tell you.
Asset inventory
Every connected device on board, documented: manufacturer, model, firmware, what it talks to and how. Boots on deck, not a spreadsheet emailed to the master.
Network segmentation
OT separated from IT, crew separated from operations, with an architecture your class surveyor will accept and the evidence to demonstrate it. This is our core engineering competence. It is what we do on every network we build.
Vulnerability management
A working process for tracking vendor advisories across every maker in your inventory, so that a published vulnerability in a system on your ships does not sit unnoticed for eight months.
Access control and hardening
Accounts, credentials, remote access paths: under control, and documented as being under control.
Incident response plan
What the crew actually does at 03:00, written in language a chief engineer will follow under pressure. Not a forty-page document nobody has read.
Cyber Resilience Test Procedure
Prepared, and exercised at survey.
Class evidence pack
The documentation your surveyor asks for, ready before they ask for it.
Retainer
Compliance is not a certificate you frame. Fleets change, contractors plug things in, firmware ages. We hold it current and prepare you for each survey.
E27 is now a procurement condition, not a nice-to-have.
If you make equipment that goes on vessels, owners are starting to ask you for things you may not have: a secure software update mechanism, a vulnerability disclosure policy, evidence of hardening, and the ability to prove which firmware version is running on which vessel. Suppliers who cannot answer are being excluded from bids. Quietly, and without being told why.
We help equipment makers get there: the security capabilities, the update mechanism, and the evidence trail that survives a surveyor's question.
We are network engineers, not a compliance consultancy.
The difference matters more than it sounds.
A compliance consultancy will produce you a gap analysis and a document set. Someone else then has to actually re-segment the network, reconfigure the firewalls, harden the access controls and make the vessel match the document.
We do both. We write the evidence and we build the thing the evidence describes, because we are the people who install vessel networks in the first place. That means the architecture on the page is the architecture on the ship, which is not always true when those two jobs are done by two companies.
22 years in maritime and industrial IT, including the legacy equipment that makes compliance hard. Riding technicians who sail with the vessel when an inventory needs doing properly. And honest scoping: we tell you what does not apply to you.
Find out what actually applies to your fleet.
A scoping call, no cost. Tell us your fleet: vessel types, tonnage, contract dates. We will tell you which requirements bite, which do not, and what we would do first.
Questions we get asked
Do E26 and E27 apply to my existing fleet?
Probably not. They apply to ships contracted for construction on or after 1 July 2024, and they are not retroactive. But IMO cyber risk management under the ISM Code has applied to every vessel since January 2021, and Port State Control is increasingly looking at it. So the honest answer is: E26 likely does not apply, and you have work to do anyway.
We are taking delivery of a newbuild. When should we start?
Before delivery, not after. The handover documentation is where compliance either exists or does not, and unpicking it afterwards is far more expensive than getting the yard to do it right.
Can you certify us?
No. Class certifies. We prepare you, produce the evidence, and build the architecture that evidence describes. Be suspicious of anyone who tells you they can certify you.
What does it cost?
Scoping is a fixed fee and small. Everything after that depends on what the scoping finds, and we will not quote it blind.
Our vessels are under 500 GT, or not on international voyages.
Then E26 is likely non-mandatory guidance for you rather than a requirement. Worth doing some of it anyway, but we will not pretend you are obliged to.
