EXPLORATION
UR E26, After the Mandate ① — One Mandatory Rule, Five Perspectives (Series Notification)
What UR E26 actually changed in maritime cybersecurity — and the single variable that decides whether the market works or grinds
What UR E26 actually changed in maritime cybersecurity — and the single variable that decides whether the market works or grinds
Series: “UR E26, After the Mandate” — Part 1 of 6. This is the market overview; five stakeholder deep-dives follow. It is not a critique of any classification society or of the class system itself, but an attempt to map — as factually and neutrally as possible — the market that took shape once the rule became mandatory.

- On 1 July 2024, cyber resilience became a condition of class for newbuildings — comply with IACS UR E26/E27 or no class certificate.
- The rule “unified” cybersecurity, yet the field still shows class-by-class differences in guidelines, notation names, and survey deliverables.
- That isn’t necessarily a defect. A UR is a floor, not a ceiling — and IACS explicitly lets each society build above it.
- Everything turns on one variable: the clarity of the boundary between the mandatory floor and the voluntary layer on top.
What 1 July 2024 actually changed
For every newbuilding contracted on or after that date, cyber resilience became a mandatory class condition. IACS Unified Requirements UR E26 — Cyber Resilience of Ships and UR E27 — Cyber Resilience of On-Board Systems and Equipment entered into force. (Adopted in their original form in April 2022 for January 2024 application, they were withdrawn and replaced by revised texts — E26 in September 2023, E27 in November 2023 — moving the date to July 2024.) The mechanism is blunt: fail to comply, and no class certificate is issued.
First, a misconception worth clearing. Cybersecurity was not absent before this. It already existed in layers. Classification societies ran their own voluntary notations — DNV’s Cyber Secure (2018), Bureau Veritas’ NR659, ABS’ CyberSafety, ClassNK’s guidelines. And outside class there were IMO Res. MSC.428(98) and MSC-FAL.1/Circ.3 (2017), BIMCO’s guidelines, and IACS Recommendation 166 (2020).
So what was actually missing was not security itself, but a mandatory, unified newbuilding baseline at the technical class level. The old notations were optional. MSC.428(98), though mandatory, governed risk management inside the safety management system — not the technical design of a newbuilding.
What UR E26/E27 did was neither invent something new nor merely tidy up what was disparate. It converted a dispersed, voluntary set of approaches into a single technical baseline — a condition of class — mandated for every newbuilding.
The technology was largely already there. The contribution was the shift along two axes: voluntary → mandatory, and dispersed → unified.
And yet — in its second year — the “unified” rule still produces class-by-class variation: separate guidelines, differently named notations, different depth and format of deliverables at survey. Which raises this series’ question:
A class-by-class differentiation layer is being stacked atop a mandatory baseline that was meant to unify. What does that dual structure mean for the market — and where does its boundary get tested?
This piece doesn’t answer that. It does something more useful first: it takes the question apart.
The question actually contains two questions
The confusion is that the question bundles two different strata together:
- The mandatory baseline (the UR text) is itself interpreted differently by different societies.
- The voluntary notation layer stacked on top is a separate thing with a separate nature.
These behave in completely different ways. Most debates run on parallel tracks precisely because they mix the two.
One clarification up front: nothing here is an attack on any society or on class itself. A society building a differentiated layer above the mandatory floor is — as long as the boundary stays clear — not a deviation but a function the IACS system explicitly permits. The tension is about what happens when that boundary blurs. That boundary is the whole subject.
Anatomy of the floor: what E26/E27 are, and where they stop
The foundation: UR E22. Beneath E26/E27 sits E22 — On Board Use and Application of Computer Based Systems(2006, Rev.3 in June 2023). It sorts computer-based systems (CBS) into Categories I/II/III by the consequence of their failure to people, ship, and environment. That classification is the skeleton of risk-based application. E22 supplies the vocabulary; E26/E27 run on top of it.
E26 is ship-level. It treats the ship as one integrated object and requires a cyber risk management framework, built on the five NIST CSF functions — Identify, Protect, Detect, Respond, Recover — across 17 requirements in the revised text. In practice it demands deliverables at three life-cycle stages:
- Design / build — the systems integrator (usually the shipyard) submits the Zones and Conduit Diagram (ZCD), the asset inventory, and the cyber security design description.
- Commissioning — the ship cyber resilience test procedure is submitted and verified.
- Operation — the owner maintains the ship cyber security and resilience programme.
E27 is system-level. It sets the minimum security capabilities each CBS and piece of equipment must have, aimed mainly at third-party vendors — 30 core capabilities, plus 11 more for systems on an untrusted network. A vendor’s type approval sharply cuts the evidentiary burden downstream. Early on, though, very few systems were approved — roughly 4 at ClassNK and 20 at DNV by November 2024 — a bottleneck where certification lagged demand.
Scope. Both rest on IEC 62443, generally apply to ships ≥ 500 GT on international voyages (mandatory vs non-mandatory by type and size; small fishing vessels and yachts among the exclusions), and interlock with the SMS-level cyber risk management required by MSC.428(98) and MSC-FAL.1/Circ.3.
And the one fact that runs through this entire series:
A UR is, by definition, a minimum. IACS expressly lets each member society set stricter requirements. E26/E27 mandate a floor, not a ceiling — and the space above it was left open by design.
Why one rule produces different outcomes — three structural reasons
“If it’s unified, why does it differ?” is the natural question, but blaming a single actor’s intent misreads it. Divergence comes from structure:
- E26 is substantially goal-based. Much of it says “meet this goal,” not “do exactly this.” The method is left open — and a society’s guideline becomes an interpretation service filling that gap. The abstraction is deliberate. It’s a design feature.
- It’s a new rule, and we’re in the transition. Binding only since July 2024, it is still converging through Unified Interpretations, FAQs, and panels. The first year was friction and ad-hoc coordination; only from late 2025 — type approvals surging, the first cyber-notated ships delivered — did it start maturing into execution, with DNV, ClassNK and others issuing more granular guidance. Some of today’s divergence may be a converging transitional phenomenon, not a permanent flaw.
- The floor is explicitly exceedable — which legitimizes divergence. Building a stricter standard on top is a rightthe IACS system guarantees. Different higher standards across societies aren’t evidence of a violation; they can be a sign the rule is working as intended.
All three are structural, not intentional. All three also imply a degree of ambiguity in the floor itself — and that ambiguity is the soil for everything below.
Two strata, and the key called scope
Split the market in two.
Lower stratum — the mandatory floor: the minimum the UR text requires. Non-negotiable; the price of a class certificate.
Upper stratum — voluntary notations: the products societies sell on top. DNV Cyber Secure (entry-level, Essential, and other qualifiers), ABS Cyber Resilience (CR) and fleet-facing CR-Ex, BV’s NR659 line, ClassNK’s guideline system. (LR issued no separate E26/E27 documents, aligning existing rules instead.) Names and grades differ; all are a choice, not a mandate.
The pointed question — does the upper stratum sell the lower one twice? — has one deciding criterion: scope. And the answer isn’t uniform, because notations aren’t monolithic.
- Some tiers are effectively the baseline. DNV presents Cyber Secure (Essential) as a path to UR E26 compliance. That isn’t double-selling — it’s a means of discharging a mandatory obligation. Compliance needs class verification anyway; the notation just packages it.
- Higher tiers go beyond. Higher IEC 62443 security levels (SL); the IT domain E26 doesn’t directly cover (E26 is OT-centric); operational / fleet-level governance; and in-service / “In-Operation” notations for existing shipsoutside mandatory scope. In late 2025 DNV split its notation into Design and In-Operation; ABS extended CR-Exto existing fleets — driven by demand to prove the cyber hygiene of ships the mandate doesn’t touch.
So “does it sell twice?” depends on the tier. Baseline-equivalent = a means to comply; baseline-exceeding = different scope. And the latter has real demand. The clearest case is chartering / vetting — DNV explicitly markets the notation as lifting charterer and oil-major vetting scores. Insurance and flag-state interest is rising too, but how much reaches pricevaries so much by market, type, and timing that it’s too early to be categorical.
Where the tension actually lives
None of this means it’s seamless. When the two strata don’t separate cleanly, you get friction — and it reads better as boundary management than as a flaw in the products:
- Divergence in the mandatory layer fights the UR’s whole purpose. Unification was meant to end dispersion; if interpretation, survey criteria, and pass criteria diverge at the floor, you partly recreate the pre-unification mess. Differentiation up top is normal; divergence at the floor carries a different weight.
- The rule-maker and the compliance-seller are the same body. IACS writes the rule; its members sell the service. Whatever the intent, that structure creates a latent pull for floor-ambiguity and notation-appeal to line up — a variable a consultant has to track.
- Multi-class owners pay asymmetrically. Different cost, criteria, and deliverables for the same E26 compliance isn’t a product problem — it’s governance: the floor isn’t uniform enough.
- Floor and upsell can blur. When a voluntary requirement is presented as “mandatory E26,” scope quietly creeps, and an owner perceives as mandatory something they needn’t buy.
The point bears repeating: as long as the two strata stay separated — floor surveyed clearly and uniformly, voluntary layer genuinely additional — structural friction is near zero. It appears only where the separation breaks.
The provisional verdict: the boundary decides everything
Back to the opening question. Part 1’s answer compresses to a single variable — the clarity of the boundary.
When the floor is clear and uniform and the layer above is genuinely additional, the dual structure is coherent. That’s how class has always worked, it’s the differentiation the market actually pays for, and it’s the design IACS permits. Friction shows up only when (a) the baseline is interpreted differently, enabling forum shopping; (b) a voluntary requirement is packaged as mandatory and scope expands; © a dispersed-fleet owner eats asymmetric cost for identical compliance. All three are boundary problems, not product problems.
Is the tension permanent, or transitional? Too early to say. Three structural fixes exist: IACS issuing stronger Unified Interpretations to shrink the interpretive room; more prescriptive UR revisions; or IMO elevating the baseline into a mandatory instrument, moving the source of binding force outside the class–customer relationship. Right now, both E26’s force and the notation products grow from the same root — a contract with the society — which is exactly why they’re hard to separate. Only the third path touches that root. Until then, divergence is a market fact; the work is reading and managing it precisely.
Five perspectives — the road ahead
The same structure is a different landscape from each seat (order may shift):
- ② Owner — cost vs risk vs commercial reward; separating mandatory floor from optional upsell, so you buy what you must and skip what you needn’t.
- ③ Class — guaranteeing a uniform floor, creating value through differentiation, balancing liability against reputation. Conservative interpretation has its own sound logic.
- ④ Shipyard — the integrator’s design and evidence burden, and the reality of satisfying multiple societies’ expectations at once.
- ⑤ Vendor — the economics of E27 type approval, the cost of multiple class profiles, and the integration-compatibility problem of wiring certified systems together safely.
- ⑥ Consultant — owner-side, reading and policing the floor/upsell boundary: not taking a guideline as the pass mark, but anchoring on the UR text and treating the society’s reading as one claim.
Closing
The mandate was a comma, not a full stop. Cyber resilience is finally a condition of class — but how much more gets stacked on top is still the market’s call, and the boundary between mandate and differentiation is tested continuously. Arguing about that boundary is easy; reading it precisely is hard. And that hard part is the one thing all five stakeholders can actually control.
Next: the same structure through the owner’s eyes — where the first question is surprisingly plain. How far is mandatory, and where does choice begin?
Sources: IACS UR E26 / E27 (revised, in force 1 Jul 2024), UR E22 Rev.3 (2023); IACS Recommendation №166 (2020); IEC 62443; IMO Res. MSC.428(98), MSC-FAL.1/Circ.3 (2017); class notation systems — DNV Cyber Secure (2018–), BV NR659, ABS CyberSafety / CR · CR-Ex, ClassNK guidelines, LR aligned rules.
General analysis of the IACS UR E26/E27 market structure — not advice on any specific project, society, or client. Concrete application follows the relevant society’s current UR and guideline texts.