EXPLORATION
IACS Cybersecurity Framework: E22, E26, and E27 Unified Requirements
IACS UR E22, E26, and E27 are cybersecurity and computer-based systems requirements, forming a comprehensive three-tier cybersecurity…

IACS UR E22, E26, and E27 are cybersecurity and computer-based systems requirements, forming a comprehensive three-tier cybersecurity framework for maritime vessels.
Foundation established by IACS UR E22
UR E22 “On Board Use and Application of Computer Based Systems” serves as the foundational framework for all maritime computer-based systems and cybersecurity requirements. Originally published in 2006 and most recently revised in June 2023 (Rev.3), E22 establishes several critical foundations:
System categorization framework that classifies computer-based systems into Categories I, II, and III based on the consequences of system failure to human safety, vessel safety, and environmental protection. This categorization becomes the backbone for risk-based cybersecurity implementation in E26 and E27.
Lifecycle management structure covering design, construction, commissioning, and maintenance phases. This framework provides the temporal structure within which cybersecurity requirements from E26 and E27 are implemented throughout a vessel’s operational life.
Stakeholder responsibility allocation defining roles for suppliers, system integrators, shipyards, and shipowners. This governance structure is essential for implementing the distributed cybersecurity responsibilities required by E26 and E27.
Quality management system requirements including software development lifecycle standards, factory acceptance testing (FAT), and system acceptance testing (SAT) procedures. These quality frameworks are enhanced with cybersecurity-specific requirements in the later unified requirements.
How UR E26 builds upon E22
UR E26 “Cyber Resilience of Ships” represents a ship-level cybersecurity framework that directly depends on and extends E22’s foundational structure. Implemented July 1, 2024, E26 creates comprehensive vessel-wide cyber resilience capabilities.
Technical integration with E22 shows E26 explicitly references E22’s system categorization in Section 1.3.1, using Categories I, II, and III to scale cybersecurity requirements appropriately. More critical systems receive stronger security controls, creating a risk-based implementation approach.
NIST Cybersecurity Framework implementation organizes E26 around five functional elements: Identify, Protect, Detect, Respond, and Recover. The “Identify” function builds upon E22’s asset management requirements by creating comprehensive inventories of hardware and software for all computer-based systems.
Security zone architecture represents E26’s major technical contribution, implementing network segmentation based on E22’s system categories. Critical Category III systems receive stronger isolation and protection, while lower-category systems can share security zones with appropriate controls.
Lifecycle enhancement integrates cybersecurity activities into E22’s established design, construction, commissioning, and operational phases, rather than creating parallel processes. This ensures cybersecurity considerations are embedded throughout the vessel’s lifecycle rather than bolted on afterward.
How UR E27 relates to both E22 and E26
UR E27 “Cyber resilience of on-board systems and equipment” creates individual system-level cybersecurity capabilities that support both E22’s foundational requirements and E26’s vessel-wide objectives. This creates a comprehensive three-tier architecture addressing cybersecurity from individual components to entire vessels.
Foundation dependency on E22 shows E27 explicitly references E22 as a normative standard in Section 1.3.1. E27 leverages E22’s system categorization to determine which systems require cybersecurity capabilities, uses E22’s change management procedures for security modifications, and builds upon E22’s quality system requirements for secure development lifecycle implementation.
Complementary relationship with E26 demonstrates how E27 focuses on individual systems supplied by third parties while E26 addresses vessel-wide integration. E27 systems must fit within E26’s security zone architecture, with E27’s 41 specific security capabilities designed to support E26’s vessel-level cyber resilience objectives.
Technical specifications include 30 required security capabilities for all applicable systems, plus 11 additional capabilities for systems communicating with untrusted networks. These capabilities address authentication, access control, data integrity, audit logging, and secure communications — all essential building blocks for E26’s ship-level security framework.
Technical relationships and dependencies between E26 and E27
The relationship between E26 and E27 represents a systems integration approach where vessel-wide cybersecurity (E26) depends on individual system capabilities (E27) while providing the architectural framework within which those systems operate.
Scope division shows E26 targeting the vessel as a collective entity using performance-based objectives, while E27 provides prescriptive technical standards for individual systems. This division enables flexible implementation approaches while ensuring consistent baseline security capabilities.
Security zone integration requires E27 systems to be designed for deployment within E26’s security zone architecture. Systems crossing zone boundaries must meet specific conduit protection requirements, while zone boundary protection components may be provided by E27-compliant systems.
Asset inventory coordination demonstrates how E27’s individual system inventories feed into E26’s comprehensive vessel asset inventory, creating a hierarchical information structure supporting both system-level and vessel-level cybersecurity management.
Incident response coordination shows E27’s audit and monitoring capabilities supporting E26’s detection and response functions, creating an integrated threat monitoring and incident management framework across the entire vessel.
Chronological development and evolution
The evolutionary development from E22 to E26/E27 reflects the maritime industry’s response to rapid technological change and emerging cyber threats.
E22 development (2006–2024) began with basic software quality requirements in 2006, evolved through Rev.2 in 2016 addressing increased onboard digitalization, and culminated in Rev.3 (2023) specifically aligned with cybersecurity requirements E26/E27.
Cybersecurity recognition (2018–2022) emerged from industry understanding that cyber incidents could directly impact life, property, and marine environment. IACS published 12 cyber safety recommendations in 2018, later consolidated into IACS Recommendation 166 on Cyber Resilience, which formed the technical foundation for E26/E27 development.
Implementation refinement (2022–2024) shows how industry feedback led to significant revisions between original publication (April 2022) and final implementation (July 2024). Key changes included clearer applicability criteria, refined security capabilities, and standardized survey procedures across classification societies.
Current status indicates successful implementation with type approval processes established by major classification societies, though industry adaptation continues as suppliers develop E27-compliant systems and shipowners integrate comprehensive cybersecurity management into their operations.
Practical applications and scope differences
The three unified requirements create distinct but complementary implementation domains serving different stakeholder needs while maintaining technical coherence.
E22 applications focus on system suppliers and integrators implementing quality management systems, software development lifecycle procedures, and factory/system acceptance testing. These foundational requirements ensure reliable, maintainable computer-based systems capable of supporting cybersecurity enhancements.
E26 applications target shipowners, system integrators, and classification societies implementing vessel-wide cybersecurity management. This includes network architecture design, security zone implementation, incident response planning, and ongoing cybersecurity risk management throughout vessel operations.
E27 applications address equipment suppliers developing individual systems with specific cybersecurity capabilities. Type approval processes enable standardized security verification, while vessel-specific integration ensures systems support overall vessel cybersecurity objectives.
Conclusion
The IACS cybersecurity framework demonstrates sophisticated technical architecture where UR E22 provides foundational computer-based systems management, UR E26 creates comprehensive vessel-wide cyber resilience, and UR E27 ensures individual systems possess necessary security capabilities. This three-tier approach addresses cybersecurity challenges from component level through system integration to vessel operations, creating robust maritime cybersecurity standards appropriate for the increasingly connected and digitalized maritime environment.
The evolutionary development from basic software quality (E22, 2006) to comprehensive cybersecurity (E26/E27, 2024) reflects industry recognition that maritime cybersecurity requires coordinated technical standards, stakeholder responsibilities, and lifecycle management approaches Iacs — establishing a foundation for future maritime digitalization and autonomous vessel development.