Regulatory deadline

IACS UR E26 and E27: cyber resilience, in class terms

Since 1 July 2024, ships contracted for construction at an IACS member society must be delivered cyber resilient under Unified Requirement E26, with their computer-based systems meeting E27. This page sets out what that means for a technical department of two or three people, what class asks to see, and where the evidence usually goes missing.

1 July 2024

UR E26/E27 apply

Ships contracted for construction on or after this date are in scope at the IACS member societies. Anything you contract now is inside the requirement.

At delivery

Ship cyber resilience package

Asset inventory, zone and conduit diagram, test evidence and recovery plan handed over — and, critically, absorbed into your SMS rather than shelved.

First annual verification

SMS evidence

The ISM auditor tests whether cyber risk is genuinely managed on board: are procedures known, are incidents logged, are changes controlled.

Continuous

Change control

Every software update, remote support session and vendor connection is a change. Unrecorded changes are the most common finding waiting to happen.

The evidence a small technical department has to be able to produce

  • Inventory of computer-based systems per vessel, with maker, version and criticality.
  • Network zones and conduits documented, including any remote-access route.
  • Change record for software updates and vendor remote support sessions.
  • Incident response and recovery plan referenced from the SMS, not only the yard package.
  • Drill records showing the crew has rehearsed loss of a critical system.
  • Backup and restoration evidence for navigation, propulsion-support and cargo systems.

Where this fails in practice

Almost never at the technical control. It fails at the record: a vendor connects remotely to the ECDIS in Singapore, nobody logs it, and eleven months later there is no change trail to show the auditor. Full Ahead Maritime treats each of those events as a job with evidence attached and a tamper-evident history — the same mechanism used for statutory maintenance, applied to cyber change control.

Common questions

Which ships do IACS UR E26 and E27 apply to?

The Unified Requirements apply to ships contracted for construction on or after 1 July 2024, classed by an IACS member society. E26 covers the cyber resilience of the ship as a whole; E27 covers the on-board systems and equipment supplied into it. Existing tonnage is not retro-fitted into the URs, but the same ships still carry the IMO cyber risk obligation in their safety management system.

What is the difference between E26 and E27?

E26 is addressed to the ship: the vessel-level design, integration, testing and documentation that make the ship cyber resilient — the asset inventory, network segregation, recovery plans and the survey evidence. E27 is addressed to the supplier: the security capabilities each computer-based system and its components must provide, so that the ship-level requirement can actually be met.

What does class actually ask to see?

In practice: an inventory of computer-based systems with their zones and conduits, the ship cyber resilience documentation package, evidence of testing at commissioning, the incident response and recovery plan, and evidence that the crew's procedures for it exist in the SMS rather than only in a shipyard folder.

Do the URs replace IMO Resolution MSC.428(98)?

No. MSC.428(98) requires cyber risk to be addressed in the safety management system under the ISM Code, and applies to the whole managed fleet. The IACS URs add prescriptive, classed technical requirements for newbuildings. A manager with one 2025-contracted ship and eight older ones has to satisfy both, in different ways, for different parts of the fleet.

Does a 1–10 vessel manager need a dedicated cyber team?

No, but you do need a repeatable record. The failure mode we see is not the absence of controls; it is that the evidence of them — the inventory, the drills, the patch decisions, the incident log — lives in email and cannot be produced at a survey or an audit twelve months later.

This is a practitioner's summary, not legal or class advice. Always work from the current text of the Unified Requirements as published by IACS and the guidance issued by your own society and flag.

Cyber requirements are still moving

Short briefs when class, IMO or a flag state changes what has to be evidenced.

Maritime AI Digest — regulatory changes and product updates. No spam, unsubscribe any time.