Shipbuilding Cybersecurity: Aligning Newbuilding Milestones with IACS UR E26 & E27 Deliverables (Standard)

💡 Insight Newbuilding IACS UR E26 · E27 Shipyard Compliance

Aligning Shipbuilding Schedules with Cybersecurity Deliverables

From Contract Signing to Delivery — What Owners, Shipyards, and Suppliers Must Prepare at Each Milestone

Captain Ethan
Captain Ethan
Maritime 4.0 · AI, Data & Cyber Security
📅April 19, 2026

With the enforcement of IACS Unified Requirements E26 and E27 — mandatory for newbuildings contracted from 1 July 2024 — cybersecurity has become an integral part of the shipbuilding process. Classification societies now require cybersecurity certification, and shipyards must integrate security measures from the earliest design stage. This article maps every key shipbuilding milestone to the cybersecurity deliverables required by classification society guidelines, clarifying who must prepare what, and when.

📖 Key Abbreviations
CBS — Computer-Based System
MoC — Management of Change
SDL — Secure Development Lifecycle
FAT — Factory Acceptance Test
SAT — Site Acceptance Test
IDS — Intrusion Detection System
SIEM — Security Information and Event Management
VPN — Virtual Private Network
MFA — Multi-Factor Authentication
TA — Type Approval
UR E26 — IACS Unified Req.: Cyber Resilience of Ships
UR E27 — IACS Unified Req.: Cyber Resilience of On-Board Systems

Ⅰ. The Intersection of Shipbuilding and Cybersecurity

Shipbuilding follows a structured process of five phases after contract signing:

📐 Design
🔩 Procurement
🏗️ Construction
⚙️ Trials
🚢 Delivery

At each stage, cybersecurity requirements outlined by classification societies must be integrated. This requires close collaboration between shipowners, shipyards, and equipment suppliers — with clear accountability for who prepares each deliverable.

Ⅱ. Shipbuilding Milestones × Cybersecurity Deliverables (Standard)

The table below maps each major shipbuilding event to the cybersecurity deliverables required from owners, shipyards, and suppliers under classification society guidelines (IACS UR E26/E27).

Milestone Duration Owner's Deliverables Shipyard's Deliverables Supplier's Deliverables
C/S
Contract Signing
1–3 mo. Ship Cybersecurity & Resilience Program
B/D
Basic Design
2–6 mo. Management of Change (MoC) Cyber Security Design Description
D/D
Detail Design
2–6 mo. Management of Software Updates
Management of Firewalls
Zones & Conduit Diagram
Security Configuration Guidelines
E/O
Equipment Ordering
5–12 mo. Management of Malware Protection
Risk Assessment for Exclusion of CBS
SDL Documentation
Management of Change Plan
S/C
Steel Cutting
3–6 mo. after C/S Management of Access Control
Ship Asset Inventory
Computer-Based System (CBS) Asset Inventory
B/C
Block Construction
4–12 mo. Management of Remote Access
Description of Compensating Countermeasures
Topology Diagram
H/E
Hull Erection
2–6 mo. Management of Mobile & Portable Devices Description of Security Capabilities
L/A
Launching
2–6 mo. Detection of Security Anomalies Ship Cyber Resilience Test Procedure Test Procedure for Security Capabilities
H/T
Harbor Trial
1–2 mo. Verification of Security Functions Cybersecurity FAT (Factory Acceptance Test) Reports Incident Response & Recovery Plans
S/T
Sea Trial
1–2 mo. Incident Response Plans Cybersecurity SAT (Site Acceptance Test) Reports Test Reports
O/I
Owner's Inspection
1–2 mo. Recovery Plans Final Cybersecurity Audit Plans for Maintenance & Verification
D/L
Delivery
Final Final Cybersecurity Certification Compliance Audit Report Type Approval (TA) Certification
Based on IACS UR E26 / UR E27 requirements (effective July 2024 newbuildings)

Ⅲ. Cybersecurity Deliverables — What Each Document Contains

Ship Cyber Resilience Program

Management framework for IT/OT system protection. Compliance baseline with IMO MSC-FAL.1/Circ.3.

Management of Change (MoC)

Security risk assessment and approval process for all IT/OT system modifications.

Management of Software Updates

Managing OS, firmware, and security patch updates for CBS and IT/OT systems throughout the vessel lifecycle.

Management of Firewalls

Firewall configuration, maintenance policies, and log monitoring procedures between network zones.

Management of Malware Protection

Malware detection and defense measures for IT/OT systems, including update policies for AV/EDR tools.

Management of Access Control

User access rights definition, RBAC policy, and unauthorized access prevention measures.

Management of Remote Access

Secure remote access management using VPN (Virtual Private Network), MFA (Multi-Factor Authentication), and session logging.

Management of Mobile & Portable Devices

Security policies covering USB storage devices, laptops, and other removable media brought onboard.

Zones & Conduit Diagram

Network segmentation design and data flow analysis for cybersecurity zoning, aligned with IEC 62443.

SDL — Secure Development Lifecycle

Security requirements, secure coding practices (aligned with IEC 62443-4-1), and verification processes for IT/OT system development.

CBS Asset Inventory

Recording all Computer-Based System (CBS) inventory items, their security interfaces, and network connections onboard.

Topology Diagram

Visual representation of CBS interconnections, data flows, and external network interfaces across IT/OT systems.

Description of Security Capabilities

Documentation of security features: encryption, IDS (Intrusion Detection System), and access control mechanisms.

Incident Response & Recovery Plans

Detection, response, and recovery procedures for cybersecurity incidents including ransomware and data breaches.

Captain's Take

With IACS UR E26 and E27 now in effect for newbuildings contracted from July 2024, cybersecurity is no longer a post-delivery concern — it must be embedded from the moment the contract is signed. Shipowners, shipyards, and suppliers each carry distinct obligations, and misalignment between them is the most common cause of certification delays.

The deliverable matrix above is a practical starting point for project managers, compliance officers, and class surveyors to align expectations early — and avoid last-minute document scrambles before delivery. 🚢🔐

#URE26 #URE27 #IACS #IMO #Newbuilding #ShipbuildingCyber #TypeApproval #OTSecurity #MaritimeCyberSecurity #IEC62443 #Maritime40

Related Articles & Official Resources

📋
IACS — Unified Requirements E26 & E27 (Official)
UR E26: Cyber resilience of ships · UR E27: Cyber resilience of on-board systems and equipment. Mandatory for newbuildings contracted from 1 July 2024.
IMO — Maritime Cyber Risk Management (MSC-FAL.1/Circ.3)
Guidelines on maritime cyber risk management. MSC.428(98) requires cyber risk to be addressed in Safety Management Systems from January 2021.
🔧
IEC 62443 — Industrial Automation & Control Systems Security
The foundational OT security standard series referenced by IACS UR E27, particularly IEC 62443-4-1 for SDL requirements in equipment development.
🛡️
DNV — Maritime Cyber Security
DNV's guidance on cyber secure class notations, Type Approval for onboard systems, and practical implementation of UR E26/E27 for newbuilding projects.
🇯🇵
ClassNK — Cyber Security for Ships
ClassNK's implementation of IACS UR E26/E27, including Statement of Compliance (SoC), Statement of Fact (SoF), and Type Approval pathways for suppliers.
Captain Ethan
Captain Ethan
Maritime 4.0 · AI, Data & Cyber Security

A market-moving innovation leader connecting data, AI, and cybersecurity with the maritime industry. Expertise spans maritime cyber compliance, business design, investment, project management, AI-based RAG systems, and software development.

Comments