📰 Weekly Brief IMO MASS Code Smart Ship OT Security Regulation

Autonomous Ships Enter the Era of International Rules — IMO MASS Code Enters into Force 1 July 2026

Maritime Cyber Weekly · July 2026 · Issue #02-A

Captain Paul
Captain Paul
Maritime 4.0 · Regulatory Intelligence · July 2026

On 1 July 2026, the IMO's MASS Code (International Code of Safety for Maritime Autonomous Surface Ships) officially entered into force. Since the birth of SOLAS in 1914, every international maritime safety regime has been built on one fundamental assumption — a human being is on board. The MASS Code formally dismantles that assumption for the first time. Degree classifications, Remote Operations Centre (ROC) requirements, cybersecurity provisions — the international safety baseline for the smart ship era has been drawn for the first time.

SECTION 1

Ⅰ. What Is the MASS Code — Background and Scope

In May 2026, the IMO Maritime Safety Committee (MSC) adopted the world's first international safety code for Maritime Autonomous Surface Ships (MASS). Entering into force on 1 July 2026, the code applies initially to cargo ships and is structured as a Goal-Based framework covering ship design, navigation, remote control, connectivity, fire protection, cybersecurity, and search and rescue (SAR).

Autonomous Ships and International Cyber Rules: IMO MASS Code


Existing IMO conventions — SOLAS, MARPOL, STCW — all presuppose the presence of humans on board. The MASS Code is the first international framework to address situations where that presence is reduced or absent. In the cybersecurity domain in particular, it formally recognises that shipboard connectivity is not merely a convenience feature, but the infrastructure that constitutes the operation itself.

MASS CODE — KEY FACTS
Adopted May 2026, IMO MSC
Entry into Force 1 July 2026
Status Non-Mandatory — voluntary application at present
Primary Scope Cargo ships
Coverage Design, navigation, remote control, connectivity, fire protection, cybersecurity, SAR
SECTION 2

Ⅱ. Four Degrees of Autonomy — From Degree 1 to Degree 4

The structural core of the MASS Code is a four-tier classification of vessel autonomy. These degrees are not merely technical categories — the applicable cybersecurity requirements and accountability structures differ at each level, making this classification a direct design reference for shipyards, classification societies, and shipowners alike.

MASS CODE — FOUR DEGREES OF AUTONOMY
Degree Vessel Status Cyber Risk Profile
Degree 1 Crew on board, partial automation Similar to conventional vessels; additional attack surface from automation systems
Degree 2 Remotely controlled, crew on board ROC↔vessel communication link becomes a new attack surface
Degree 3 No crew on board, ROC remote operation Entire operation depends on network connectivity — communications disruption = vessel incapacitation
Degree 4 Fully autonomous, no human intervention AI control systems become the primary attack target; no real-time human override possible

Degrees 1 and 2 are extensions of the existing vessel operating paradigm, but from Degree 3 onwards a qualitatively different security model is required. No crew on board also means no personnel available to respond immediately to a cyber incident at sea.

SECTION 3

Ⅲ. Cybersecurity Provisions — ROC Requirements and Connectivity Security

The code's cybersecurity provisions focus primarily on Degree 3 and above. For vessels with no crew on board, a ROC (Remote Operations Centre) provides continuous oversight and must meet the following requirements:

🔋
Backup Power
Minimum 3 hours of independent power supply
📡
Redundant Communications
Dual independent communication systems — single-channel dependency prohibited
🏢
Secondary ROC
Backup ROC capable of immediate takeover in the event of primary centre failure

The Master retains ultimate responsibility for the vessel regardless of whether they are on board. In Degrees 3 and 4, ROC operators effectively become the primary navigation decision-makers, and their qualifications, training, and certification standards also fall within the code's scope.

🔐 CYBERSECURITY IMPLICATION

The ROC↔vessel communication link is both the structural centrepiece of the MASS Code and its largest cyber attack surface. VSAT satellite terminals (including Starlink), onboard routers, firewalls, and VPN gateways must remain continuously open — which means that until a vulnerability is patched, attackers have a permanently accessible entry point into the vessel's operational systems.

ANALYST NOTE

Ⅳ. Roadmap and Industry Implications — Why 2030/2032 Matters Now

📌 ANALYST NOTE — Author's Opinion

The MASS Code is currently non-mandatory. However, the IMO has set out a roadmap targeting mandatory code adoption in July 2030 and entry into force in January 2032. This gives shipyards, classification societies, and equipment suppliers approximately six years to prepare — while making it clear that cybersecurity requirements will become embedded in newbuild contract specifications. In my view, deferring MASS Code compliance planning now is equivalent to accepting a full design review obligation after 2032. — Captain Paul

While IACS UR E26/E27 addresses OT security on existing vessels, the MASS Code defines — for the first time — the cybersecurity baseline for next-generation ships where connectivity is the operation. The two frameworks target different subjects but point in the same direction: a vessel is now cyber infrastructure.

💡 Two Immediate Action Items — For Shipyards, Class, and Owners (Author's Opinion)
  1. 1 Review ROC Communication Channel Security Architecture — For vessels targeting Degree 2 or above, the ROC↔vessel link must not become a Single Point of Failure. Redundancy and encryption design should be reviewed at the earliest design stage.
  2. 2 Identify Vessels Subject to Both IACS UR E26 and MASS Code — Newbuilds contracted from 2024 onward targeting Degree 1–2 must satisfy both E26 compliance and MASS Code requirements simultaneously. A gap analysis at the design stage is essential to ensure no blind spots emerge at the intersection of the two frameworks — particularly around CBS classification and ROC-connected system definitions.
🔗 RELATED ARTICLE

The attack surface expanded by the MASS Code is already being weaponised by AI within 48 hours. The threat that AI-driven autonomous cyberattacks pose to maritime OT environments is examined in a separate article.
AI-Driven Autonomous Cyberattacks — Maritime OT Vulnerability Weaponization Within 48 Hours

SECTION 5

Ⅴ. From the Bridge — A Field Note on What the MASS Code Means in Practice

In the newbuild specification reviews and IACS UR E26 gap-analysis sessions I've sat through over the past year, "autonomous-ready" was often written into the contract long before anyone on the design team had defined what that phrase actually meant for the OT network topology. The MASS Code finally gives that phrase a legal skeleton — but having walked engine control rooms and cargo control stations on vessels being fitted out for Degree 1–2 trials, what strikes me most is how far the cybersecurity conversation still lags behind the automation conversation. Owners and yards ask detailed questions about sensor redundancy, dynamic positioning accuracy, and collision-avoidance logic. Far fewer ask who patches the ROC's VPN gateway, or what happens to the vessel's steering command authority if that gateway is compromised mid-voyage.

There is also a recurring blind spot I keep running into at the intersection of E26 and the MASS Code: E26 was written around the assumption that, in the worst case, a crew member could physically isolate a compromised system — pull a cable, kill a breaker, stand a watch by hand. The MASS Code removes that assumption entirely at Degree 3 and above, yet several of the CBS (Computer-Based System) inventories I've reviewed still quietly list "crew intervention" as a fallback mitigation for cyber incidents — on vessels explicitly designed to sail without a crew to intervene. That gap between paper compliance and operational reality is exactly where the next incident will be found.

⚓ Field Note

On a recent ROC site visit, the operator's own incident-response runbook still listed "contact the bridge team" as step one. For a Degree 3 vessel, there is no bridge team to contact. That single line told me more about the industry's actual readiness than any regulatory text I've read this year.

None of this means the MASS Code is toothless — quite the opposite. It is the first document that forces owners, yards, and class societies to put a name to a risk that automation projects have been quietly absorbing for years. But a code on paper only closes the gap once design teams stop treating "cyber" as a compliance line item and start treating the ROC link the way they already treat the hull: as a single point of failure that has to survive contact with the sea.

Captain's Take

The MASS Code will not be judged by the ships that pass survey in 2026. It will be judged by how many owners still treat cybersecurity as a checkbox when the mandatory deadline actually lands in 2032. Six years sounds long until you remember how long a newbuild's cyber architecture actually locks a vessel in for — most of the ships being keel-laid this year will still be sailing under this code in the 2040s.

My recommendation to anyone specifying a Degree 2 or higher vessel today: write the ROC failover architecture and the CBS boundary into the contract now, not into the retrofit budget after 2032. — Captain Paul

#MASSCode #IMO2026 #AutonomousShipping #RemoteOperationsCentre #MaritimeCyber #IACSE26 #SmartShip
SHIPPAULJOBS.COM

Maritime 4.0 · AI & Cybersecurity Intelligence from Real Shipyard Experience
www.shippauljobs.com

⚓ Join the ShipPaulJobs Community

Join →
Share

Comments