EXPLORATION

Maritime Cyber Resilience Brief ① — IACS UR E26/E27

Part 1 — IACS UR E26/E27: Cyber Resilience Requirements for Newbuild Vessels

Maritime Cyber Resilience Brief ① — IACS UR E26/E27

Part 1 — IACS UR E26/E27: Cyber Resilience Requirements for Newbuild Vessels

The International Association of Classification Societies (IACS) introduced two landmark Unified Requirements in 2022 — UR E26 and UR E27 — to bolster cyber resilience in new ship designs. These requirements establish a baseline for maritime cybersecurity by focusing on reducing the occurrence of cyber incidents and mitigating their effects on vessel safety. UR E26 applies to the ship as a whole (the integrated vessel systems), while UR E27 targets the cyber integrity of individual on-board systems and equipment. Effective for new vessels contracted on or after 1 July 2024, compliance with E26/E27 is now mandatory across IACS member classification societies. Below, we unpack the core objectives, technical controls, and classification implications of these requirements, with examples of how they are transforming newbuild vessel design and approval.

Strategic Objective and Scope of UR E26 & E27

UR E26 (“Cyber Resilience of Ships”) and UR E27 (“Cyber Resilience of On-board Systems and Equipment”) share the strategic goal of ensuring new vessels are operationally resilient to cyber risks from the outset. In practice, this means embedding cybersecurity into the entire ship lifecycle — from initial design and construction through commissioning and into operation. The UR E26 framework applies at the ship level, addressing how all critical systems interconnect and how the vessel as a whole can withstand and recover from cyber incidents. In contrast, UR E27 applies at the component level, focusing on the security capabilities of individual control systems and equipment (including supplier requirements) that form the ship’s Operational Technology (OT) environment. Both URs concentrate on safety-critical and essential systems (navigation, propulsion, power control, emergency systems, etc.), aligning cybersecurity with maritime safety imperatives. Notably, traditional IT systems are not the direct focus of E26/E27 unless they interface with critical OT — a deliberate scoping to prioritize systems whose compromise could jeopardize vessel safety.

To drive a consistent approach, UR E26 explicitly adopts the familiar “Identify, Protect, Detect, Respond, Recover” risk management framework. This mirrors the NIST Cybersecurity Framework and IMO guidelines, providing a logical structure for requirements. E26 identifies four key stakeholder roles — the shipowner, system integrator, equipment supplier, and classification society — and delineates their responsibilities in achieving cyber resilience. It also breaks the ship’s lifecycle into four phases (Design, Construction, Commissioning, Operation), ensuring cybersecurity tasks and documentation are addressed at each phase. By defining who must do what and when, E26 integrates cyber risk controls into the standard vessel development process. Meanwhile, UR E27 sets out technical expectations for system suppliers and integrators, often mapping to established industrial security standards (it aligns closely with IEC 62443–3–3 on system security levels). In short, the scope of these URs spans from high-level governance (policies, risk assessments, plans) down to detailed technical controls in the hardware and software of shipboard systems — all oriented toward newbuilds meeting a minimum cyber safety standard globally.

Key Technical Requirements in UR E26 (Ship-Level)

Under UR E26, newbuild vessels must implement a broad suite of cybersecurity controls covering all five functions of the risk framework. During Design & Construction, emphasis is on the Identify and Protect functions, while ensuring that the vessel will have capabilities to Detect, Respond, and Recover once operational. Below are some of the core technical and procedural requirements of E26, along with examples:

  • Identify — Asset Inventory: Develop a comprehensive vessel asset inventory of all computer-based systems and networks on board. For example, the shipyard and owner must document every control system (e.g. navigation, engine control, steering gear systems, power management, safety monitoring systems) and their network connections. This inventory underpins all subsequent risk assessments and zone definitions.
  • Protect — Network Segmentation and Access Control: E26 requires implementing security zones and segmented networks to isolate groups of systems. Systems supporting different functions or located in different areas should reside in separate zones with controlled conduits (data flows) between them. For instance, the navigation network must be isolated from cargo management or crew welfare networks. Firewalls or data diodes are expected at zone boundaries to enforce access rules. All critical systems must have appropriate access controls — unique user accounts, role-based access, and where feasible, authentication mechanisms to prevent unauthorized use. (Notably, some bridge systems may be exempted from strict login requirements for safety reasons, but then compensating controls like physical locks are needed) Additional protective measures include anti-malware defenses, secure use of wireless and removable media, and managing remote access securely
  • Detect — Monitoring and Anomaly Detection: Even at the newbuild stage, E26 mandates design provisions for cyber incident detection. This could involve installing intrusion detection sensors or enabling logs and diagnostics in control systems. For example, an integrated machinery monitoring system might be required to generate alerts on anomalous engine data traffic. The goal is to ensure the ship can identify a cyber attack or malfunctioning software early, rather than being blind to silent failures. Plans for network monitoring and periodic vulnerability scanning are expected as part of compliance.
  • Respond — Incident Response Preparedness: A documented Incident Response Plan must be prepared for the vessel. This plan outlines how the crew and shore support will handle a cyber incident affecting onboard systems — from immediate containment steps (e.g. isolating affected networks) to switching to manual or backup controls. E26 also insists that critical systems support local, independent operation in case of network loss or cyber disruption. For instance, if the main integrated navigation system is attacked, the ship should be able to fall back to standalone manual navigation aids or emergency controls (a “minimal risk condition”). Designing systems with analog fallbacks or independent manual overrides is a key expectation.
  • Recover — Backup and Restoration: Vessels must have provisions to backup critical data and configurations and to restore systems after an incident. This includes having offline backups of essential software, ship system parameters, and charts, as well as procedures for safe restart or rollback of systems to a known good state. As an example, the ship’s power management system should be able to be rebooted from a clean backup if malware has impaired its functioning. E26 also calls for a formal Recovery Plan detailing how the vessel would be brought back to operational status after a major cyber event.

A foundational concept in E26 is determining which systems are “in scope.” Generally, all safety-critical, essential, and security-related systems on the vessel are included. This encompasses systems required for propulsion, steering, power generation, navigation, firefighting, flooding control, ballast, and communications, among others.

Practically, for a cargo ship, E26 covers nearly all OT systems except perhaps a few truly isolated subsystems (e.g. standalone HVAC units). Any system that is connected to an “untrusted network” (such as the ship’s business IT network, passenger/crew networks, or the public internet) is also drawn into scope due to the increased risk exposure. For example, if the engine monitoring system sends data to shore via satellite or connects to the corporate network in port, it must meet stricter controls as an untrusted interface. E26 allows certain low-risk systems to be excluded only if a rigorous risk assessment justifies it (e.g. truly air-gapped systems with no connectivity and no safety impact can be exempted). However, such exclusions require documentation and Class approval, and in practice most systems on a modern vessel will be included unless clearly out-of-scope.

Finally, UR E26 emphasizes security-by-design. Decisions made in design (such as selecting systems that support logging, or planning network topology) will affect how well the vessel can detect and respond during operations. Classification societies implementing E26 guide owners and yards to make these design choices early. For instance, choosing an ECDIS (Electronic Chart Display) that supports user authentication and has built-in whitelisting will help fulfill later operational security requirements. E26 essentially embeds a cyber risk management process into the ship development cycle, ensuring that by the time the vessel is delivered, it comes with a “hardened” architecture, documented cyber risk controls, and approved procedures for incident response.

UR E27 Requirements for On-board Systems & Equipment

Where E26 takes a top-down view of vessel security, UR E27 takes a bottom-up view, focusing on individual systems. UR E27 requires that onboard OT systems and equipment meet defined security capability benchmarks, often achieved via a Type Approval process through class societies. The goal is to ensure that each piece of critical equipment — be it a radar, main engine control unit, ballast water controller, or navigation system — has certain cybersecurity features built-in by the manufacturer or integrator. This shifts some burden onto equipment suppliers to deliver “secure-by-design” products.

Many class societies have aligned E27 with tiered security levels. For example, DNV (Det Norske Veritas) class has defined “Cyber Secure” class notations in levels: Basic, Essential, and Advanced. A newbuild under DNV must at least meet “Cyber Secure Essential,” which aligns with IACS UR E26/E27 requirements. DNV further defines Security Profiles (SP0 through SP4) that loosely map to IEC 62443 security levels, indicating increasing robustness against more sophisticated threats. Under this scheme, most mandatory E27 controls correspond to roughly Security Profile 1 (SP1) — protection against casual or basic threats. There are around 100 individual security requirements in a typical E27-based checklist, though not all apply to every system; roughly 60 baseline controls might apply to an SP1-classified device. These include measures like: unique user IDs and passwords for operator interfaces, secure boot and firmware integrity checks, removal of default credentials, audit logging capability, port and interface protections, and basic network security functions. Additional requirements kick in if a system connects to an untrusted network, such as encryption for communications, stronger authentication (e.g. MFA), and remote access protections.

For instance, an E27-compliant engine control unit would be expected to have role-based access control (so only authorized engineers can change settings) and perhaps whitelist communication so it only talks to the intended systems. If that engine controller has a remote monitoring link to shore, E27 would require additional controls like VPN encryption or a demilitarized data diode for that link. If a piece of equipment cannot meet a specific requirement due to operational constraints, compensating countermeasures must be put in place. For example, if a steering gear PLC cannot support user login sessions, a compensating measure might be to physically secure it in a locked cabinet to prevent unauthorized access. E27 expects the supplier or integrator to document such exceptions and mitigations, subject to approval by the class society.

In effect, UR E27 pushes cybersecurity down to the vendor and system integrator level. It dovetails with UR E26 because a ship built entirely from E27-approved components greatly eases the effort to achieve E26 compliance at the vessel level. However, IACS recognized that not all suppliers would be immediately ready. Many newbuilds will include some systems that are not yet type-approved to E27, especially if they are custom or from smaller manufacturers. In those cases, the shipyard and owner must work closely with the supplier (and class) to vet the system’s security and possibly apply additional safeguards during integration. It is in the shipowner’s interest, as industry experts note, to minimize the number of non-type-approved systems onboard and to keep IT-type equipment segregated from OT as much as possible. Doing so reduces the compliance burden and strengthens overall security.

Classification and Compliance Implications

The introduction of UR E26/E27 represents a significant shift in the classification regime for new ships. As of mid-2024, virtually all IACS member societies have incorporated E26/E27 into their rules or notations. This means a new vessel cannot receive classification (which is essential for commercial operation and insurance) unless it meets these cyber requirements. Many class societies have published their own guidelines to help stakeholders comply — e.g. ClassNK’s guidelines for cyber resilience, ABS’s advisories, BV’s rules, etc., all of which are aligned with the IACS URs. Some offer class notations (like Cyber Resilient or Cyber Secure) that shipowners can use to demonstrate compliance. Lloyd’s Register similarly reported that while they didn’t issue a stand-alone E26 guideline initially, their existing rules were updated to closely match the UR obligations.

For shipbuilders and owners, these class requirements have concrete implications. Design approvals now include cybersecurity — for example, when submitting electrical and automation schematics for class review, an owner must also submit a cyber risk assessment, network architecture diagrams showing zones/conduits, an asset inventory, and plans for incident response and recovery. There are typically new document submittals such as a “Cybersecurity Management Plan” or similar, which class reviews against UR E26 criteria. Builders must schedule cybersecurity inspections and tests during construction and commissioning. Classification surveyors will verify, for instance, that the network segmentation and access controls in the actual built vessel match the approved design, and that required security functions (like an alarm on unauthorized access attempts) are working. Some aspects carry into operations: E26 calls for verification at the first annual survey and periodic surveys that the cyber controls remain in place and effective. This parallels how class treats other critical systems — ships now get an ongoing cyber health check as part of staying in class.

One tangible example of a classification implication is type approval of equipment under UR E27. Manufacturers can seek class Type Approval for their products certifying that they meet the E27 cyber requirements. ClassNK, for instance, provides an approval service (with forms and published lists for cyber-resilient equipment). Using type-approved components simplifies the newbuild’s documentation since each approved system comes with a “cyber pedigree.” Classification societies also issue Guidance and FAQs to clarify E26/E27 compliance. For instance, they define what counts as an “untrusted network” or how to document an exemption if a system is isolated and proposed to be out-of-scope. They also provide sample templates (e.g. for the asset inventory and risk assessment) to ensure consistency.

In strategic terms, IACS UR E26/E27 is driving a culture change: cybersecurity is now a standard part of naval architecture and marine engineering for new ships. The purpose behind these URs is not just paperwork; it’s to ingrain cyber resilience into the DNA of the vessel. By setting minimum requirements globally, IACS is leveling the playing field — shipowners can no longer take a lax approach to cyber on new tonnage without jeopardizing class approval. The URs provide a uniform benchmark that enhances clarity amid a once-fragmented landscape of guidelines. A shipping company that invests in meeting E26/E27 is effectively future-proofing its fleet against emerging regulations and threats. In the next parts, we will see how this new baseline compares and interoperates with upcoming national regulations, such as the U.S. Coast Guard’s cybersecurity rule, and what it means for maritime stakeholders.

Part of an ongoing personal intellectual exploration. Conclusions may change as the questions do.