EXPLORATION
What the USCG’s Performance-Driven COC Regime and IACS UR E26 Are Telling Us
This isn’t the dawn of “fewer inspections.” It’s the dawn of “you have to prove it.”
This isn’t the dawn of “fewer inspections.” It’s the dawn of “you have to prove it.”

In March 2026, the United States Coast Guard (USCG) introduced a new performance-driven Certificate of Compliance (COC) examination framework for foreign tank vessels, launched as a pilot program.
Grounded in the National Defense Authorization Act for Fiscal Year 2026 (NDAA FY2026), the program is being run on a limited basis — initially for vessels calling at ports under the Sector Corpus Christi and Port Arthur captain-of-the-port zones — as a step to validate the effectiveness of a data-driven model before any full rollout. The key mechanism is this: for high-performing vessels only, the annual (intermediate) examination that falls between the two-year COC renewal exams is replaced by a USCG comprehensive review in place of a physical onboard inspection. The comprehensive onboard examination required for the two-year renewal itself remains unchanged. The specifics may change depending on the pilot’s results.
At first glance, the policy can look like nothing more than a way to reduce the number of inspections.
But look a little closer, and it becomes clear this is not a simple change in inspection procedure.
It is a shift toward risk-based oversight — a model that evaluates a vessel’s safety and regulatory compliance using data, and then applies inspection intensity in proportion to the result.
And that direction maps closely onto what IACS UR E26 asks of vessels in the name of cyber resilience.
Where IACS UR E26 and the USCG Policy Converge
Regulation used to work mainly like this:
- “Do you have the required documents?”
- “Did you complete the checklist?”
- “Did you declare that the requirements were met?”
More recent regulation is shifting toward a different set of questions:
- “Is the vessel actually being operated safely?”
- “Do the controls described on paper actually work?”
- “When an incident occurs, can you recover?”
The preliminary details USCG has released describe the assessment as a “comprehensive review of the vessel’s safety and performance profile.”
The agency has not spelled out the specific evaluation criteria. But judging by how USCG has long assessed vessel performance under its existing PSC targeting matrix and the QUALSHIP 21 program, the core factors are likely to include:
- Port State Control (PSC) detention history
- Violation history
- Marine casualty history
- The safety-management maturity of the operator and the owner
In other words, the direction is not simply “Did you pass the inspection?” but
“Are you actually operating safely?”
IACS UR E26 is built on the same philosophy.
The purpose of E26 is not to produce documents. It is to design the vessel so that its essential functions can survive a cyber attack or a system failure.
In the end, both regulations reduce to a single question:
In a real operating environment, can the vessel continue to function safely?
The Real Risk Owners and Yards Should Be Watching
On many projects, cyber security is still understood as a certification exercise:
- Requirements mapped
- Cyber Security Plan written
- Asset Inventory compiled
- Class approval obtained
Once those boxes are ticked, the project is considered finished.
From an operational standpoint, however, this is much closer to the starting line.
What the USCG made plain with this policy is unambiguous:
A vessel’s real-world performance determines how closely it is supervised.
Cyber security is no different. After an incident, the questions that surface are:
- Did the network segmentation actually hold?
- Were the remote-access controls actually enforced?
- Was the backup actually in a recoverable state?
- Were the logs usable for incident analysis?
- Is the system change history traceable?
If you cannot answer these questions, then no matter how many documents were produced, real resilience was never achieved.
What the Shipowner Needs to Consider
Owners often think, “As long as the yard satisfies E26, we’re fine — aren’t we?”
But E26 is not a regulation that applies only up to delivery.
Responsibility for maintaining resilience in actual operation ultimately rests with the owner.
So the owner should be demanding the following.
1. A security architecture that can actually be operated
Is it a structure that can be maintained after delivery?
- Can accounts be managed?
- Can patches be managed?
- Can remote access be controlled?
- Can logs be collected?
A security regime the operating organization cannot manage will eventually be neutralized.
2. A backup scheme that can actually be recovered
Many projects confirm only whether a backup exists.
But what matters is this:
“Can you actually restore from it?”
When ransomware hits, far more important are:
- how quickly you can recover,
- which functions come back first,
- whether the recovery was ever validated.
3. Supply-chain management
A vessel’s OT environment involves dozens of suppliers.
A single vendor’s weak remote-access setup can become a risk to the entire vessel.
Security requirements for suppliers therefore have to be defined from the contracting stage.
What the Shipyard Needs to Consider
Yards typically run projects with one goal: “obtain class approval.”
Going forward, that is unlikely to be enough.
The yard should be considering the following.
1. Design consistency
- Network diagrams
- Firewall policies
- Data flow diagrams
- System function descriptions
These documents have to connect to one another without contradiction.
One of the most common findings in an actual review is inconsistency between documents.
2. Operability
A technically flawless design is not the same as a design that can actually be run.
For example:
- overly complex VLAN structures
- unmanageable firewall policies
- excessive access controls
end up being bypassed or disabled during operation.
3. The ability to generate evidence
When an incident is later investigated, you need to be able to explain
- who
- when
- what
- and why
something was changed.
This kind of traceability is becoming steadily more important.
What Goes Wrong When You Only Do the Basics
Problem 1: “We have the documents, but they can’t be explained.”
The deliverables on many projects are adequate at the level of class approval.
From an operational perspective, though, they often fall short.
An Asset Inventory, for example, lists the equipment.
But it leaves undefined:
- the relationship to essential functions
- the network path
- who owns security responsibility
- the recovery priority
So when an incident occurs, its practical value drops.
Problem 2: “We have the network diagram, but we don’t know the data flow.”
In real breach response, more important than how the boxes are connected is
which data moves where.
Yet on a great many projects, data-flow analysis is thin.
As a result,
- unnecessary communication
- excessive privileges
- hidden remote-access paths
are discovered only once the vessel is in operation.
Problem 3: “We have backups, but we don’t know the recovery time.”
The existence of a backup does not mean resilience.
The real questions are:
- What is the recovery time for ECDIS?
- For the IAS server?
- For the Cargo Control System?
- For propulsion-related systems?
If you cannot answer these, your resilience has not been verified.
The difference between “documents for approval” and “documents for operation”
Many projects are run approval-first.
But the operating organization wants something else:
- What do I do when a problem occurs?
- Who do I contact?
- In what order do I recover?
In other words, documents you can actually operate with.
Going forward, approval documents and operational documents need to be managed as distinct things.
Conclusion
The USCG’s performance-driven COC policy is not a mere reshuffling of an inspection scheme.
It shows that the maritime industry as a whole is moving away from evaluating whether requirements are met and toward evaluating actual performance and resilience.
IACS UR E26 sits on the same current.
What matters now is not the number of documents.
What matters is whether you can answer these questions:
- What happens when you’re attacked?
- What happens when something fails?
- Can you recover?
- Can you prove it?
Future competitiveness will not be decided by obtaining E26 certification itself, but by the ability to continuously prove cyber resilience in a real operating environment.