If We Already Have an E27 Certificate, Why Is Cyber Security Verification During FAT Still Required?

📋 Compliance IACS UR E26 & E27 FAT & Commissioning

An E27 Certificate Is Not a FAT Exemption: Why Cyber Security Verification Still Matters

Why systems that already hold an IACS UR E27 Type Approval Certificate still require Cyber Security Verification during FAT under IACS UR E26

Iris
Iris
Maritime Engineering Specialist · Detailed Design & Engineering Review
Technical Advisor: shippauljobs.com — Crew Behind ShipJobs

As the implementation of IACS UR E26 and E27 becomes increasingly mandatory across newbuilding projects, we frequently encounter a specific pattern of response during technical discussions with system suppliers regarding their preparation for FAT cyber security testing.

Question: "Are you preparing to perform the Cyber Security Verification during the FAT?"

System Supplier's Response: "Since our product has already achieved E27 certification, we believe Cyber Security Verification during FAT is no longer necessary. Therefore, we are not making any separate test preparations."

It is a response we can understand to some extent. Obtaining an E27 Certificate requires significant effort, time, and investment from system suppliers. Security functions must be implemented, secure development processes established, vulnerability management procedures maintained, and extensive documentation prepared to demonstrate compliance with the applicable requirements. Given this effort, system suppliers naturally assume that the certificate serves as a universal pass. But is Cyber Security Verification during FAT really no longer necessary?


The Short Answer

Yes. Cyber Security Verification during FAT is still required.

However, certain verification items may be replaced by evidence already demonstrated during the E27 certification process, which can reduce the overall verification scope during FAT. In other words, an E27 Certificate is not an exemption from Cyber Security Verification — it is objective evidence that allows certain verification items already demonstrated during E27 certification to be omitted, thereby reducing the verification scope during FAT.

Ⅰ. E27 and E26 Have Fundamentally Different Objectives

The reason Cyber Security Verification remains necessary is simple. E26 and E27 are fundamentally designed for different purposes. Many people view E26 and E27 as similar requirements, but they differ significantly in both their primary purpose and scope of application.

IACS UR E27

Defines the Security Capability Requirements for a Computer-Based System (CBS).

"Does this equipment provide the required cyber security capabilities?"

IACS UR E26

Requires demonstrating that systems installed onboard a vessel can continue to operate safely, respond appropriately, and recover effectively in the event of a cyber incident.

"Can the integrated system demonstrate Cyber Resilience?"

E27 defines what capabilities a product must possess, whereas E26 requires the integrated system to demonstrate Cyber Resilience using those very capabilities.

For this reason, certain verification items that overlap with the Security Capabilities already proven during E27 certification can be replaced or omitted during FAT. However, the requirement for the Cyber Resilience Demonstration under E26 is not waived. This distinction is the core reason why Cyber Security Verification remains mandatory during FAT, even for products that already hold an E27 Certificate.

Ⅱ. Why Is Cyber Security Verification During FAT Still Necessary?

Although duplicate verification items already proven during E27 certification can be omitted, verifying the actual state of the delivered equipment remains necessary. For instance, each specific project must still verify the following project-specific configurations:

01
Software Version
Whether the delivered software version aligns with the certified scope of the E27 certificate.
02
Account Management
Whether user accounts and access privilege levels are properly configured according to the vessel's specific operational requirements.
03
Remote Access Control
Whether remote access functions are strictly controlled and configured in accordance with the project specification, ensuring no unauthorized backdoors exist.
04
Security Baseline
Whether essential security settings and hardening features are correctly enabled and active.
05
Backup & Recovery
Whether backup and recovery procedures are properly prepared, functional, and ready for use on the actual hardware.
E27 Certificate Demonstrates

"This equipment possesses the required Cyber Security Capabilities."

FAT Verification Confirms

"The equipment delivered for this specific project is actually configured and implemented in that secure state."

Having the capability and actually applying the configuration are not the same thing.

Ⅲ. "Can't We Just Verify It After Installation Onboard?"

This is another question frequently raised by system suppliers: "The equipment will eventually be installed onboard the vessel — why can't we verify it during onboard commissioning or sea trial?" At first glance, this may seem like a practical alternative. In reality, however, this is one of the most dangerous assumptions one can make in a shipbuilding project.

The Yard Is Not a Testing Ground to Discover Basic Problems

A shipyard quay or a vessel at sea is not a controlled laboratory environment. During onboard commissioning and sea trials, Shipowners, Classification Societies, Builders, system integrators, and dozens of system suppliers are all working simultaneously under tight schedules. If cyber security issues that should have been caught during FAT are discovered only at this final stage, the consequences can be severe — for example:

  • Critical security configuration errors or improper account privilege setups.
  • Remote access malfunctions or unexpected network interface vulnerabilities.
  • Software version mismatches or incomplete, non-functional recovery procedures.

⚠️ If such issues emerge onboard, simply patching a single piece of equipment is rarely enough. It often triggers a chain reaction: adjacent systems must undergo re-verification, previously completed integration tests must be repeated from scratch, and both Owners and Class Surveyors must be rescheduled for re-attendance and formal re-approval.

What initially appeared to be a minor technical glitch instantly escalates into a critical project schedule delay. At that point, the Builder and Owner will inevitably ask: "Shouldn't this have been verified and fixed during FAT?" When the ship's schedule is impacted, discussions quickly shift from technical troubleshooting to contractual liabilities — including rework costs, surveyor re-attendance fees, and penalties for delivery delays.

A cyber security problem discovered onboard is no longer just a technical issue; it becomes a major project risk.

Ⅳ. Then Why Is an E27 Certificate Still Valuable?

At this stage, another question naturally arises: "If Cyber Security Verification during FAT is still required and E26 requirements must still be satisfied, why should suppliers invest in obtaining an E27 Certificate?" The true value of E27 is not exemption. The true value is credibility and efficiency.

When an E27 Certificate is available, system suppliers do not need to repeatedly demonstrate the same capabilities on every project. Furthermore, Builders, Owners, and Classification Societies gain confidence that the equipment has already been independently assessed against internationally recognized cyber security requirements. As a result, system suppliers benefit from:

Reduced verification scope Lower FAT preparation effort Minimized project risk

Therefore, an E27 Certificate is not an exemption from Cyber Security Verification — it is objective engineering evidence that allows already-proven capabilities to be recognized, sparing system suppliers from repeatedly justifying their product's baseline security on every new project.

Closing Thoughts

Obtaining an E27 Certificate does not eliminate the need for Cyber Security Verification during FAT. However, verification items already demonstrated during the certification process may be omitted, reducing the overall verification scope and effort required during FAT. More importantly, the real value of E27 lies not in avoiding verification, but in providing objective evidence of an equipment's cyber security capabilities and reducing repetitive project-by-project justification.

Ultimately, completing Cyber Security Verification during FAT and obtaining acceptance from the Owner and Classification Society is one of the most effective ways for system suppliers to eliminate potential cyber-related issues before onboard commissioning and protect themselves from project schedule risks.

Finding a vulnerability during onboard commissioning is a cost.
Finding it during FAT is an opportunity.

Regulatory Basis & References

IACS UR E26 — Cyber Resilience of Ships, including the Ship Cyber Resilience Test Procedure and Commissioning-phase demonstration requirements.
IACS UR E27 — Cyber Resilience of On-board Systems and Equipment, defining the Security Capability Requirements and Type Approval pathway for Computer-Based Systems (CBS).
ClassNK — IACS UR E26/E27 overview: classnk.or.jp — IACS UR E26/27

About the Author

Iris
Iris
Maritime Engineering Specialist · Detailed Design & Engineering Review

Iris is a maritime engineering specialist with deep expertise in detailed ship design and engineering drawing analysis. She brings strong capability in mechanical, electrical & electronics, and cybersecurity system onboard specification review — together with experience spanning pre-design and post-design stages, quality inspection, and cross-functional communication for large-scale vessel and offshore construction projects.

⚓ Join the ShipPaulJobs Community

Join →
Share

Comments

  1. This is an insightful perspective and provides a solid foundation for shipowners and shipbuilders when establishing cybersecurity policies.

    I also believe that an E27 certificate demonstrates compliance with design requirements—it does not, by itself, guarantee cyber resilience in operational environments.

    Ultimately, cyber resilience must be demonstrated through rigorous verification in real-world conditions, supported by objective evidence rather than certification alone.

    ReplyDelete

Post a Comment

Top Ranked · All Posts

Popular Posts