On this page
In shipping, the longest record of regulation creating a market belongs to environmental rules. In the thirty-odd years since the IMO Assembly adopted ballast water guidelines in 1993 (resolution A.774(18)), environmental regulation has shifted its centre of gravity from recommendation to convention, from newbuildings to existing ships, from equipment to data, and from data to money. Along the way it produced, in turn, a ballast water treatment system (BWMS) retrofit market, a scrubber market, an emissions data verification market and an emissions allowance market.
Cyber regulation has just entered its second stage. IACS Unified Requirements UR E26/E27 became mandatory for newbuildings contracted on or after 1 July 2024, and in 2026 the IMO began work on a non-mandatory Maritime Cyber Code. There is no guarantee that regulatory patterns repeat. But if they do, the past thirty years of environmental regulation are a useful map for reading the next ten years of cyber.
Parts 1 and 2 of this article are verified record. Everything from Part 3 onward is forecast and assumption built on that record. Within the forecast, the direction and sequence have reasonable support; the timing must be read broadly and may well be wrong.
Environmental regulation itself mixed steps that took more than twenty years with steps that arrived in two. This article first extracts a five-stage pattern from that record, then places the current position of cyber regulation on it, sets out fast, base and slow scenarios, and names five leading signals to check each quarter.
1. The five-stage pattern of environmental regulation
Divide the progress of environmental regulation into stages and five appear. Each has real cases and dates.
| Stage | What it is | Cases and dates |
|---|---|---|
| 1. Guidelines | Recommendation, voluntary | Ballast water guidelines 1993 (A.774(18)) and 1997 (A.868(20)); GHG policy resolution 2003 (A.963(23)); voluntary EEOI 2009 (MEPC.1/Circ.684) |
| 2. Mandatory for newbuildings | New ships only, by contract or build date | EEDI in force 1 Jan 2013 (MEPC.203(62), adopted July 2011); BWM Convention in force 8 Sep 2017 — keel laid on or after that date meets D-2 at delivery |
| 3. Retroactive to existing ships | Retrofit obligation timed to surveys | BWMS for existing ships from first IOPP renewal after 8 Sep 2019, completed 8 Sep 2024; EEXI 1 Jan 2023; 0.50% sulphur 1 Jan 2020 (the scrubber retrofit wave) |
| 4. Operational reporting and rating | Annual measurement, reporting, verification; ratings with commercial consequences | EU MRV monitoring from 1 Jan 2018; IMO DCS 1 Jan 2019; CII rating from 2023 (first ratings 2024) |
| 5. Economic instruments | Allowances, levies, fuel rules; money directly at stake | EU ETS for shipping 1 Jan 2024 (40% → 70% → 100%); FuelEU Maritime 1 Jan 2025; IMO Net-Zero Framework (approved April 2025, adoption vote postponed to October 2026) |
The time between stages
- 1 → 2 (guidelines to newbuilding mandate): 10–24 years. For GHG, ten years from the 2003 Assembly resolution to EEDI in 2013. For ballast water, eleven years from the 1993 guidelines to convention adoption in 2004, and twenty-four years to entry into force. Whether the route was a new convention or an amendment to an existing annex made the difference.
- 2 → 3 (newbuilding mandate to existing ships): 2–10 years. Ballast water took two years from entry into force in 2017 to application to existing ships in 2019. EEDI (2013) to EEXI (2023) took ten. Sulphur 2020 skipped the newbuilding stage and applied to the whole fleet at once.
- 3 → 4 (existing ships to reporting and rating): almost simultaneous. EEXI and CII were adopted in the same resolution (MEPC.328(76)) and applied on the same day. Data reporting (DCS 2019, MRV 2018) actually arrived before the technical rules for existing ships.
- 4 → 5 (reporting to economic instruments): 5–6 years. Six years from MRV in 2018 to EU ETS for shipping in 2024. From IMO DCS in 2019, the IMO carbon price is still not adopted.
The higher the stage, the bigger the market, and the less it depends on the cycle
More important than the time is the change in the nature of the money.
- Stages 2 and 3 are equipment sales. At the newbuilding stage the shipyard orders and the market is tied to the newbuilding cycle. When retroactivity arrives, a retrofit wave ordered by owners appears. In 2019 DNV GL estimated roughly 30,000 ships would need a BWMS at USD 0.5–3 million each; by March 2020, just before IMO 2020, 4,014 ships had scrubbers installed or on order, 2,960 of them retrofits.
- Stage 4 is data and services. Annual, repeating measurement, reporting and verification. EU MRV and IMO DCS make owners pay verifiers and reporting platforms every year, regardless of the newbuilding cycle.
- Stage 5 is finance and trading. EU ETS requires surrender of allowances for 40% of 2024 emissions, 70% of 2025 and 100% of 2026. Under FuelEU Maritime the penalty for non-compliance is EUR 2,400 per tonne of VLSFO-equivalent energy. Regulation becomes cost.
2. Where maritime cyber regulation stands today: UR E26/E27 is stage 2
Apply the same frame to cyber regulation and its current position becomes clear. One difference must be noted first: for cyber, shipboard technical requirements and shore-side management requirements are at different stages.
Stage 1 — IMO guidelines (2017–)
In 2017, resolution MSC.428(98) encouraged administrations to ensure that cyber risks are addressed within the safety management system under the ISM Code, no later than the first annual verification of the Document of Compliance after 1 January 2021. The companion guidance MSC-FAL.1/Circ.3 was revised through Rev.3 in April 2025. It is a management-system requirement; it contains no technical requirement.
There is a notable new development. In February 2026 the 27 EU member states and the Commission jointly proposed to the IMO Facilitation Committee (FAL 50, March 2026) the development of a non-mandatory, goal-based Maritime Cyber Code, and in May 2026 MSC 111 approved a FAL-led development roadmap targeting completion in 2028 (FAL 52). The proposal keeps the code non-mandatory but states that, after an experience-building phase, member states should reconsider whether to make it mandatory. This is the first step on the same path by which the ballast water guidelines (1993, 1997) became a convention (2004).
Stage 2 — IACS UR E26/E27 (July 2024–): here and now
UR E26 (ship level) and E27 (system and equipment level) apply mandatorily to newbuildings contracted on or after 1 July 2024. For existing ships they are recommendatory, per ClassNK and ABS guidance. This corresponds exactly to the EEDI stage of environmental regulation.
Tools for existing ships are already on sale. DNV issued its Cyber Secure (Basic) notation, aimed mainly at ships in operation, in July 2018; ABS introduced the CR-Ex notation applying UR E26 elements to existing ships in June 2025 and awarded the first one in September of the same year. IACS Recommendation No. 166 (April 2020) addressed cyber resilience across the ship’s life, including existing ships. Products arriving before the rule is the same pattern as the sixty-odd type-approved BWMS systems that were ready before the convention entered into force.
Partly ahead — shore and management systems are entering stages 3–4
- The US Coast Guard cybersecurity rule (33 CFR Part 101 Subpart F, published 17 January 2025, effective 16 July 2025) requires US-flagged vessels, MTSA-regulated port facilities and outer continental shelf facilities to designate a Cybersecurity Officer, conduct assessments and prepare plans, train personnel and report incidents. Training was due by 12 January 2026 and plan submission by 16 July 2027. Foreign-flagged vessels are excluded; the USCG has instead checked ISM cyber implementation through port state control since January 2021. A 2–5 year implementation delay for US-flagged vessels drew majority support in the March 2025 comment period, but as of September 2026 no follow-up publication confirming it could be found.
- EU NIS2 classifies shipping companies (water transport) as essential entities but explicitly excludes the individual vessels they operate. It requires shore-side risk management, 24-hour / 72-hour / one-month incident reporting and management accountability, but no shipboard technical requirement.
- Insurer and charterer vetting: the OCIMF SIRE 2.0 question library (v1.0, January 2022) already contains a chapter 7.5 Cyber Security, and question 7.5.1 asks whether the master and officers are familiar with, and have implemented, the company’s cyber risk management procedures. It checks procedure rather than technology, but the fact that cyber is already in charterer vetting is the seed of stage 4.
3. Forecast: how the cyber regulation market may progress (base scenario)
The years below are a base scenario produced by applying the stage-to-stage intervals of environmental regulation directly to cyber. Faster and slower cases are treated separately in section 4.
2026–2028: stage 2 settles in — bottlenecks and disputes over interpretation
Newbuildings contracted after July 2024 begin delivering in earnest from 2026–2027. This period looks likely to accumulate differences in interpretation between class societies, suppliers unprepared for E27, and delayed sea trials. Industry material already notes that most suppliers have yet to obtain type approval and that the burden at the design, construction and commissioning stages concentrates on system integrators and shipyards. IACS has acknowledged the need to standardise survey requirements. The picture will probably resemble the first three or four years of EEDI.
The expected nature of the market is one tied to the newbuilding cycle, where passing the compliance gate is itself the product. In parallel, the draft IMO Maritime Cyber Code is scheduled to take shape (2027 correspondence and working groups, FAL 52 in 2028). How its goals and functional requirements are written will, in our view, strongly shape stages 3 and 4.
2028–2032: stage 3, retroactivity to existing ships — why we think it is likely
There are three reasons to expect that retroactivity to existing ships will come at some point. None of them is a document that confirms it.
- The ISM Code already places a management requirement on existing ships (MSC.428(98)). Adding a technical requirement where a management requirement exists should be easier than creating a new regulation.
- The USCG has issued a rule that covers existing US-flagged ships and checks foreign-flagged ships through PSC. The port-state route has generally been faster than an IMO convention.
- Class societies are already selling existing-ship notations (DNV Cyber Secure Basic, ABS CR-Ex), and the IMO code proposal itself writes in a “reconsider mandatory status after experience-building” step.
We assume political resistance would be smaller than for environmental rules, because a BWMS cost USD 0.5–3 million per ship while network segmentation, access control and monitoring cost less and carry a security rationale. This is an estimate; how owners’ associations respond will only be known when an actual proposal appears.
We think the form is more likely to be specific ship types, specific ports of call or specific flags than blanket retroactivity. The most plausible assumption is a USCG-style port-state requirement first, followed by the EU through an extension of NIS2 or a separate regulation. In ballast water, too, the USCG final rule (published March 2012, effective June 2012) preceded entry into force of the IMO convention (September 2017) by five years.
If that assumption holds, the market becomes a retrofit wave. As BWMS retrofits did in 2019–2024, demand to install network segmentation, access control, logging and remote-access controls on tens of thousands of existing ships could arrive on the survey cycle. Newbuildings are led by shipyards, but retrofits are ordered by owners and managers. For cyber system integrators this phase could be the largest market. Whether it reaches BWMS scale depends on the level of the requirement and cannot be known today.
2030–2035: stage 4, operational monitoring, reporting and rating
Four forms are expected: cyber incident reporting obligations (already in USCG and NIS2), log retention, reporting of vulnerability management status, and a cyber rating. The first three already partly exist; the rating does not yet. Just as CII’s A–E ratings affected the charter market — BIMCO issued its CII Operations Clause in November 2022, and low-rated ships face worse financing terms and second-hand values — a cyber maturity score demanded by insurers, class and charterers could emerge. Unlike CII, however, there is no agreed standard of what to measure, and that is a major variable.
We think the drivers are more likely to be insurers and charterers than the IMO. The clues already exist.
- The cyber exclusion clause CL380 (2003) is standard in hull insurance, and in November 2019 the Lloyd’s Market Association issued model clauses separating exclusion (LMA5402) from non-malicious cyber cover (LMA5403), encouraging application from January 2020. The structure that would let insurers demand a ship’s cyber posture as a condition of cover is in place. Whether they use it depends on loss experience.
- According to press reports, in August 2026 Sompo Japan launched a product covering losses from port refusal, detention and departure delay caused by GNSS interference, with completion of ClassNK Academy cybersecurity training by crew as a condition of cover. It can be read as an early case of insurance commercially requiring a cyber measure. It is still a single product, and too early to call a market-wide trend.
- SIRE 2.0 already contains question 7.5.1. If that question deepens from procedure check to technical verification and is converted into a rating, it could become a de facto cyber CII. Whether it does depends on the charterers’ choices.
If this stage arrives, the market becomes annual recurring services: monitoring, verification and reporting platforms. The structure would resemble the DCS/MRV verification market, and post-delivery operating contracts could be formed here.
2035 and beyond: stage 5, economic instruments — the most uncertain
Environmental regulation had a measurable quantity — emissions — which made allowances possible. Cyber has no “cyber emissions.” We therefore think an allowance-type market is unlikely to form. Instead, differentiated insurance premiums, financing terms and charter rates could play the role of the economic instrument: a ship with a poor cyber rating pays more for insurance and finds it harder to charter. Because this is made by the market rather than by regulation, it may also never form. The only reference is that CII’s commercial effect appeared in charter contracts and bank loan conditions before it appeared in IMO rules.
Geopolitics could pull the timing forward. In May 2025 MSC Antonia grounded off Jeddah after GNSS spoofing (per Pole Star and Windward analysis), and threat-intelligence vendor CYTUR counted, on its own platform, a doubling of maritime cyber incidents in 2025 (408 → 828) — a single-vendor tally best read as a trend only. If sanctions, blockades, GPS interference and ship hacking increase, states could attach cyber requirements to port entry and bring stage 5 forward. Unlike environmental regulation, this is a field where a single incident could pull the schedule forward considerably. Conversely, without incidents this stage may never come.
4. Widening the timing: fast, base and slow scenarios
The years in section 3 are the base scenario. Split each stage into fast, base and slow cases and set the accelerators and brakes beside them, and the table looks like this.
| Stage | Fast | Base | Slow | Accelerators | Brakes |
|---|---|---|---|---|---|
| 3. Existing-ship retroactivity | 2027–2029 | 2029–2032 | 2033–2036 | A major cyber incident involving a ship; tighter port state control amid US–China tension; insurers making cyber a condition of cover | Owner-association pushback; IMO consensus delays; cost-versus-benefit disputes over retrofits |
| 4. Operational monitoring and rating | 2029–2031 | 2032–2035 | 2036–2040 | Technical verification entering charterer vetting (SIRE, RISQ); insurer rating demands; expanded USCG and EU incident reporting | Failure to standardise metrics; fatigue from fragmentation |
| 5. Economic differentiation | 2031–2034 | 2035–2040 | After 2040, or never | Accumulated insured losses; banks reflecting cyber in collateral assessment | If incidents stay rare, the market has no reason to differentiate |
How to read it
The fast scenario is most likely to be made by a single incident. Environmental regulation offers such cases. After Exxon Valdez grounded in March 1989, the United States mandated double hulls the following year under OPA 90 and began phasing out single hulls from 1995, and the IMO internationalised double hulls for new tankers through MARPOL regulation 13F in 1992. After Erika sank in December 1999, the April 2001 amendment to MARPOL regulation 13G accelerated the single-hull phase-out; after Prestige in November 2002, proposals from the fifteen EU member states led to the December 2003 amendment banning heavy grades of oil in single-hull tankers (from April 2005) and bringing the phase-out deadline forward to 2010. In these three cases, incident to regulatory amendment took one to two years. Not every incident changed regulation, of course.
Events that might play that role in cyber include a large container ship or LNG carrier taken out of service, a port paralysed, or a ship hacked with a military background. The MSC Antonia GNSS spoofing grounding in May 2025 did not change regulation. The same type of incident combined with loss of life or environmental damage could change the situation, but when such an incident might happen, and whether it would lead to regulation even then, cannot be known.
The slow scenario is when incidents keep not happening. Unlike the environment, ships keep sailing perfectly well without cyber regulation. So the question “why must we do this?” will keep being asked. In that case the IMO code stays non-mandatory for a long time and the market may find no reason to build a rating. The probability of this scenario is by no means low. It is the same picture as the ballast water convention waiting thirteen years between adoption (2004) and entry into force (2017).
The base scenario assumes the United States and the EU push first through port state control and the IMO follows. It borrows the 2010s pattern in which the USCG final rule on ballast water (2012) preceded the IMO convention (2017) by five years and EU MRV (2018) preceded IMO DCS (2019) by a year. In cyber, the USCG rule (2025) and the EU’s IMO code proposal (2026) have so far moved in that order, but whether they continue to do so remains to be seen.
5. Where cyber differs from environmental regulation
There are at least three points where copying the frame directly is likely to be wrong. If the forecast misses, it will probably miss here.
- The nature of the political driver. Environmental regulation had a sustained and predictable driver: climate. Cyber has none; it has a security driver instead, and security drivers react to events irregularly. Political drivers can also retreat, as the IMO carbon price did when its October 2025 vote was postponed; a security driver may accelerate sharply after one incident, or stay quiet for a long time if none occurs. This is the biggest reason timing is hard to forecast.
- The difficulty of inspection. Environmental equipment is visible and easy to survey: a scrubber is either there or it is not. Cyber is hard for a surveyor to confirm. We therefore think a third-party verification and certification market could grow larger than for the environment. The IMO code proposal’s own admission that there is no structured framework for addressing the human element points to the same problem.
- Fragmentation. Environmental regulation was a single IMO-centred system (the EU ran ahead, but MARPOL was the backbone). Cyber has the United States (USCG), the EU (NIS2, CRA), flag states, class (IACS), insurers (LMA) and charterers (OCIMF) each moving on their own. Fragmentation raises compliance cost and may create demand for advisory and integration work to sort it out. Because the IMO code will be non-mandatory even when it arrives in 2028, we expect fragmentation to persist for some time.
6. What this changes: do not try to time it
If the forecast is this uncertain, how should it be used? Reading the timing broadly does not mean giving up on forecasting; it means preferring choices that do not lose badly in any scenario. Sorted into three groups, the choices look like this.
- Valid in every scenario — deepening newbuilding system-integration capability; designing an existing-ship retrofit product and piloting it at small scale with one or two owners; piloting a post-delivery monitoring service; building networks on the insurer and charterer side. These are investments that can be recovered in the newbuilding market even in the slow scenario. If a retrofit wave comes it is likely to be the biggest opportunity, so preparing to repackage newbuilding experience as a retrofit product early is the safer course.
- Valid only in the fast scenario — mass hiring of retrofit staff; large-scale investment in a monitoring platform. Deferring these until the timing is confirmed is the rational choice. One option is to prepare only the partners and the blueprint, so that scaling can happen relatively quickly once the signals move.
- Hedging the slow scenario — broadening into OT integration and regulatory data. Even if cyber regulation is late, carbon regulation is already at stage 5 and its demand is comparatively certain. Capability in EU ETS, FuelEU and CII data would, if cyber stage 4 arrives, overlap substantially with its infrastructure.
7. A cyber regulation clock: five leading signals to check each quarter
Timing cannot be known in advance, but signals that suggest it is approaching can be chosen. We chose five, and record each one’s current reading. These are indicators of the author’s choosing; other indicators may serve better.
| # | Signal | Reading as of September 2026 | What counts as “moved” |
|---|---|---|---|
| 1 | USCG enforcement cases and EU follow-on legislation | USCG rule in force (July 2025), plan submission due July 2027. IMO Maritime Cyber Code at draft stage, targeting 2028 | PSC detentions of foreign-flagged ships begin to cite cyber deficiencies; debate on amending NIS2’s vessel exclusion; technical requirements enter the draft code |
| 2 | Cyber items in charterer and vessel vetting schemes | Already present — OCIMF TMSA3 Element 13 (April 2017), SIRE 2.0 chapter 7.5 (January 2022), RightShip RISQ 3.2 Section 12 Q12.7 (November 2025) — but all at the level of procedure and management-system checks | Questions deepen into technical verification (evidence of segmentation and access control) or class certification requirements, and carry weight in scoring |
| 3 | P&I club and H&M insurer cyber cover conditions | P&I: the International Group pooling agreement does not exclude cyber (war and terrorism excepted). H&M: CL380/LMA5402 exclusion or LMA5403 cover. Sompo Japan attached a training condition to its GNSS-interference product (August 2026) | Multiple cases in P&I and H&M of cyber posture reflected in cover conditions or premium rating |
| 4 | Number of existing ships holding class cyber notations | No published fleet statistics. Only individual cases confirmed: DNV Cyber Secure (2018–), first ABS CR-Ex award (September 2025), TEN shuttle tanker series (2025–2026) | Class societies begin publishing counts, or owners voluntarily obtaining notations for charter or insurance purposes becomes a recurring news item. This can be read as the pre-retroactivity stage |
| 5 | Publicly disclosed ship and port cyber incidents | NHL Stenden MCAD: more than 295 cumulative incidents. CYTUR tally: 828 in 2025 (single vendor) | Official statistics appear from incident reporting obligations (USCG, NIS2); cases of ships taken out of service or casualties are disclosed |
Closing thought
Lay thirty years of environmental regulation over cyber regulation and two kinds of claim separate: those with relative support, and those that are close to guesswork.
The claims with relative support concern direction and sequence. The shift of weight from guidelines to newbuilding mandates, to existing-ship retroactivity, to operational reporting and rating, and to economic differentiation repeated across ballast water, EEDI, CII and the EU ETS, and cyber regulation has so far moved in the same order. The tendency for markets to grow and to detach from the newbuilding cycle as the stage rises was the same too. That does not mean cyber must take the same road. One industry’s past does not guarantee another subject’s future.
The claims close to guesswork concern timing. Environmental regulation mixed steps that took twenty-four years with steps that took two, and cyber leans on an irregular security driver rather than climate, so the variance may be larger still. One incident could pull the schedule forward sharply; without incidents it could stall for a long time, and some stages might never arrive.
The years and scenarios in this article are therefore not there to be right. They are there to organise what to watch. The five-stage frame and the five leading signals are useful when used for that purpose, and if the signals move differently, this forecast should be rewritten.
Sources
- IMO, “Ballast Water Management” and “Implementing the BWM Convention” (A.774(18) 1993, A.868(20) 1997; convention adopted 2004, in force 8 Sep 2017; existing ships 2019–2024)
- IMO, “Historic Background GHG” (A.963(23) 2003, EEOI 2009, EEDI 2013, EEXI/CII 2023, DCS 2019)
- IMO, “Maritime cyber risk” (MSC.428(98) 2017, MSC-FAL.1/Circ.3 Rev.3 2025)
- IMO, “Tanker safety — preventing accidental pollution” (MARPOL 13F 1992, 13G amendments 2001 and 2003)
- EUR-Lex, Regulation (EU) 2015/757 (MRV); Directive 2023/959 (ETS); Regulation (EU) 2023/1805 (FuelEU Maritime); Directive (EU) 2022/2555 (NIS2) Annex I
- Federal Register, 90 FR 6298, “Cybersecurity in the Marine Transportation System,” 17 Jan 2025; 77 FR 17254, USCG Ballast Water Discharge Standard, 23 Mar 2012
- IACS, UR E26/E27 press release; Rec. No. 166 (Apr 2020). ABS Regulatory News; ABS/Offshore Magazine, first CR-Ex award (Sep 2025). ClassNK UR E26/27 guidance
- DNV, Cyber Secure class notation (2018); DNV GL ballast water expert story (Sep 2019); DNV FAL 50 and MSC 111 summaries; Riviera Maritime Media, TEN shuttle tankers (2025)
- OCIMF, TMSA3 Fast Facts (Apr 2017) — Element 13 Maritime Security; DNV, “Cyber security given priority in TMSA3”; OCIMF SIRE 2.0 Question Library Part 1 (Jan 2022), 7.5.1
- Safety4Sea, “RightShip revises questionnaire RISQ 3.2: What you should know” (Nov 2025) — Section 12, Q12.7
- UK P&I Club, “Cyber Risk Management”; West P&I, “P&I Cover and Cyber risk”; International Group of P&I Clubs, 2026/27 Pooling and GXL structure; Britannia P&I on PSC cyber checks
- LMA, Property and Marine Cyber Clauses LMA5402/5403 (Nov 2019); Lexology/IUA on CL380 (2003); Splash247, (Re)in Asia and IndexBox on Sompo Japan’s GNSS-interference product (Aug 2026)
- Steamship Mutual, “Post-Prestige — Single-Hull Phase-Out and Fines” and “Single Hull Tanker Phase Out — Developments at IMO”
- NOAA Office of Response and Restoration, “A Final Farewell to Oil Tankers with Single Hulls”; US House Transportation Committee hearing record, “The Requirement for Double Hulls Under OPA 90”
- NHL Stenden, Maritime Cyber Attack Database (MCAD); Maritime Executive / Cyprus Mail on the CYTUR 2026 Maritime Cyber Threat White Paper; gCaptain / Inside GNSS on the MSC Antonia grounding (May 2025); Offshore Energy citing DNV GL AFI on scrubbers (Mar 2020)
This article is analysis and forecast based on public sources as of September 2026. Dates and figures for future stages are the author’s assumptions, not regulatory facts. It does not constitute legal, compliance or investment advice.