If We Already Have an E27 Certificate, Why Is Cyber Security Verification During FAT Still Required?
An E27 Certificate Is Not a FAT Exemption: Why Cyber Security Verification Still Matters
Why systems that already hold an IACS UR E27 Type Approval Certificate still require Cyber Security Verification during FAT under IACS UR E26
Technical Advisor: shippauljobs.com — Crew Behind ShipJobs
As the implementation of IACS UR E26 and E27 becomes increasingly mandatory across newbuilding projects, we frequently encounter a specific pattern of response during technical discussions with system suppliers regarding their preparation for FAT cyber security testing.
Question: "Are you preparing to perform the Cyber Security Verification during the FAT?"
System Supplier's Response: "Since our product has already achieved E27 certification, we believe Cyber Security Verification during FAT is no longer necessary. Therefore, we are not making any separate test preparations."
It is a response we can understand to some extent. Obtaining an E27 Certificate requires significant effort, time, and investment from system suppliers. Security functions must be implemented, secure development processes established, vulnerability management procedures maintained, and extensive documentation prepared to demonstrate compliance with the applicable requirements. Given this effort, system suppliers naturally assume that the certificate serves as a universal pass. But is Cyber Security Verification during FAT really no longer necessary?
Yes. Cyber Security Verification during FAT is still required.
However, certain verification items may be replaced by evidence already demonstrated during the E27 certification process, which can reduce the overall verification scope during FAT. In other words, an E27 Certificate is not an exemption from Cyber Security Verification — it is objective evidence that allows certain verification items already demonstrated during E27 certification to be omitted, thereby reducing the verification scope during FAT.
Ⅰ. E27 and E26 Have Fundamentally Different Objectives
The reason Cyber Security Verification remains necessary is simple. E26 and E27 are fundamentally designed for different purposes. Many people view E26 and E27 as similar requirements, but they differ significantly in both their primary purpose and scope of application.
Defines the Security Capability Requirements for a Computer-Based System (CBS).
"Does this equipment provide the required cyber security capabilities?"
Requires demonstrating that systems installed onboard a vessel can continue to operate safely, respond appropriately, and recover effectively in the event of a cyber incident.
"Can the integrated system demonstrate Cyber Resilience?"
E27 defines what capabilities a product must possess, whereas E26 requires the integrated system to demonstrate Cyber Resilience using those very capabilities.
For this reason, certain verification items that overlap with the Security Capabilities already proven during E27 certification can be replaced or omitted during FAT. However, the requirement for the Cyber Resilience Demonstration under E26 is not waived. This distinction is the core reason why Cyber Security Verification remains mandatory during FAT, even for products that already hold an E27 Certificate.
Ⅱ. Why Is Cyber Security Verification During FAT Still Necessary?
Although duplicate verification items already proven during E27 certification can be omitted, verifying the actual state of the delivered equipment remains necessary. For instance, each specific project must still verify the following project-specific configurations:
"This equipment possesses the required Cyber Security Capabilities."
"The equipment delivered for this specific project is actually configured and implemented in that secure state."
Having the capability and actually applying the configuration are not the same thing.
Ⅲ. "Can't We Just Verify It After Installation Onboard?"
This is another question frequently raised by system suppliers: "The equipment will eventually be installed onboard the vessel — why can't we verify it during onboard commissioning or sea trial?" At first glance, this may seem like a practical alternative. In reality, however, this is one of the most dangerous assumptions one can make in a shipbuilding project.
The Yard Is Not a Testing Ground to Discover Basic Problems
A shipyard quay or a vessel at sea is not a controlled laboratory environment. During onboard commissioning and sea trials, Shipowners, Classification Societies, Builders, system integrators, and dozens of system suppliers are all working simultaneously under tight schedules. If cyber security issues that should have been caught during FAT are discovered only at this final stage, the consequences can be severe — for example:
- Critical security configuration errors or improper account privilege setups.
- Remote access malfunctions or unexpected network interface vulnerabilities.
- Software version mismatches or incomplete, non-functional recovery procedures.
⚠️ If such issues emerge onboard, simply patching a single piece of equipment is rarely enough. It often triggers a chain reaction: adjacent systems must undergo re-verification, previously completed integration tests must be repeated from scratch, and both Owners and Class Surveyors must be rescheduled for re-attendance and formal re-approval.
What initially appeared to be a minor technical glitch instantly escalates into a critical project schedule delay. At that point, the Builder and Owner will inevitably ask: "Shouldn't this have been verified and fixed during FAT?" When the ship's schedule is impacted, discussions quickly shift from technical troubleshooting to contractual liabilities — including rework costs, surveyor re-attendance fees, and penalties for delivery delays.
A cyber security problem discovered onboard is no longer just a technical issue; it becomes a major project risk.
Ⅳ. Then Why Is an E27 Certificate Still Valuable?
At this stage, another question naturally arises: "If Cyber Security Verification during FAT is still required and E26 requirements must still be satisfied, why should suppliers invest in obtaining an E27 Certificate?" The true value of E27 is not exemption. The true value is credibility and efficiency.
When an E27 Certificate is available, system suppliers do not need to repeatedly demonstrate the same capabilities on every project. Furthermore, Builders, Owners, and Classification Societies gain confidence that the equipment has already been independently assessed against internationally recognized cyber security requirements. As a result, system suppliers benefit from:
Therefore, an E27 Certificate is not an exemption from Cyber Security Verification — it is objective engineering evidence that allows already-proven capabilities to be recognized, sparing system suppliers from repeatedly justifying their product's baseline security on every new project.
Obtaining an E27 Certificate does not eliminate the need for Cyber Security Verification during FAT. However, verification items already demonstrated during the certification process may be omitted, reducing the overall verification scope and effort required during FAT. More importantly, the real value of E27 lies not in avoiding verification, but in providing objective evidence of an equipment's cyber security capabilities and reducing repetitive project-by-project justification.
Ultimately, completing Cyber Security Verification during FAT and obtaining acceptance from the Owner and Classification Society is one of the most effective ways for system suppliers to eliminate potential cyber-related issues before onboard commissioning and protect themselves from project schedule risks.
Regulatory Basis & References
Related Articles on ShipPaulJobs
About the Author
Iris is a maritime engineering specialist with deep expertise in detailed ship design and engineering drawing analysis. She brings strong capability in mechanical, electrical & electronics, and cybersecurity system onboard specification review — together with experience spanning pre-design and post-design stages, quality inspection, and cross-functional communication for large-scale vessel and offshore construction projects.
⚓ Join the ShipPaulJobs Community
Join →

This is an insightful perspective and provides a solid foundation for shipowners and shipbuilders when establishing cybersecurity policies.
ReplyDeleteI also believe that an E27 certificate demonstrates compliance with design requirements—it does not, by itself, guarantee cyber resilience in operational environments.
Ultimately, cyber resilience must be demonstrated through rigorous verification in real-world conditions, supported by objective evidence rather than certification alone.