This article provides general information, not legal, regulatory or financial advice. Requirements depend on the applicable contract, authority and jurisdiction.

What E26 and E27 cover
Maritime cyber security moved from advisory to mandatory in two steps. First, IMO required cyber risks to be addressed in safety management systems under the ISM Code. Second, the International Association of Classification Societies made cyber resilience a class requirement for new construction through Unified Requirements E26 and E27, applicable to ships contracted for construction on or after 1 July 2024.
| UR E26 | UR E27 | |
|---|---|---|
| Scope | Cyber resilience of the ship | Cyber resilience of on-board systems and equipment |
| Applies to | The vessel as an integrated system | Individual computer-based systems |
| Responsible party | Yard and owner, with class verification | System suppliers |
| Key outputs | Inventory of CBS, network topology, security zones, recovery plan | Supplier security capability, hardening, documentation |
Between them they establish five expectations: know what computer-based systems are on board; segregate networks; control access; detect and respond to incidents; and be able to recover.
Why operational technology is the hard part
IT is email, crew wifi and business systems. Operational technology (OT) is the machinery: engine control, integrated bridge and navigation, cargo control, ballast, power management, dynamic positioning. The differences are fundamental:
| IT | OT | |
|---|---|---|
| Priority | Confidentiality | Availability and safety |
| Patch cycle | Weeks | Years, if at all |
| Lifespan | 3–5 years | 20–25 years |
| Downtime tolerance | Minutes | Sometimes zero |
| Vendor access | Controlled | Frequently remote and poorly logged |
| Change control | Standard | Class approval may be required |
You cannot simply apply corporate IT security to a ship. Patching an engine control system may invalidate a class approval or a maker's warranty; taking a bridge system offline for a security update is not an option at sea.
Remote vendor access is consistently identified as the largest practical exposure: engine makers, ECDIS suppliers and automation vendors connect to ships for diagnostics, often through arrangements nobody in the shipowner's organisation has documented.
The connectivity change
Shipboard bandwidth transformed with the arrival of LEO satellite services. A ship that once had a metered, narrow link now has a broadband connection used by crew and systems simultaneously. That is a substantial quality-of-life improvement and a substantially larger attack surface.
Two controls matter more than anything else in that environment: segregation of crew networks from OT networks, and monitoring of what crosses between zones.
A practical programme for a fleet
Phase 1 — Know what you have (months 1–3)
- Inventory every computer-based system, by vessel
- Map network topology including all external connections
- Identify every remote access path, including vendor connections
- Classify systems by consequence of compromise
Phase 2 — Reduce exposure (months 3–9)
- Segregate OT from IT and from crew networks
- Control removable media with a documented, enforced policy
- Bring vendor remote access under managed, logged, time-limited control
- Harden accounts: no shared credentials, no default passwords
- Physically secure bridge and engine control room network points
Phase 3 — Detect and respond (months 6–12)
- Logging and monitoring where practical without affecting OT availability
- An incident response plan that works with the ship at sea and offline
- Contact routes for class, flag, insurers and vendors
- Tabletop exercises including the master and chief engineer
Phase 4 — Recover (months 9–15)
- Backups of critical system configurations, held offline
- Tested restoration procedures — untested backups are assumptions
- Manual fallback procedures for navigation, propulsion and cargo systems
- Crew trained on those fallbacks
Existing tonnage
E26/E27 apply to ships contracted for construction on or after 1 July 2024. Existing ships are not covered by the URs, but they remain covered by the ISM Code requirement to address cyber risk in the safety management system — and by charterers, insurers and increasingly by financiers.
Practical position: apply the same five principles to existing ships, proportionately, prioritising vendor remote access and network segregation as the highest-value interventions.
The human layer
Most maritime cyber incidents start with a person: a USB drive used to transfer a chart update, a phishing email opened on the ship's business PC, a crew member connecting a personal device to the wrong network. Training that treats crew as the last line of defence rather than the primary risk works better, because it produces reporting rather than concealment.
IACS UR E26 and E27 apply to ships contracted for construction on or after 1 July 2024; consult IACS and your class society for authoritative requirements. Exposure chart is an indicative model. Reviewed by the Zeaclub Editorial Team, 24 August 2026.
Frequently asked questions
Do IACS UR E26 and E27 apply to my existing ship?
They apply to ships contracted for construction on or after 1 July 2024. Existing ships remain subject to the ISM Code requirement to manage cyber risk.
What is the difference between E26 and E27?
E26 addresses the cyber resilience of the ship as a whole; E27 addresses the cyber resilience of individual on-board systems and equipment, placing obligations on suppliers.
Is crew internet a security risk?
Any network connection is. The answer is segregation and monitoring, not restricting crew connectivity — which is now a central welfare and retention factor.
What is the highest-value single control?
Bringing vendor remote access under managed, logged, time-limited control. It is consistently the largest undocumented exposure on ships.