IACS UR E26, officially titled Cyber Resilience of Ships, is a mandatory unified requirement issued by the International Association of Classification Societies (IACS). It defines cyber resilience requirements for all ships contracted for construction on or after 1 July 2024.
It covers the entire newbuilding lifecycle — from design and construction through delivery and operation — and requires shipyards, equipment suppliers, and shipowners to systematically manage cyber risks across all Computer Based Systems (CBS) on board.
① What Is IACS UR E26?
IACS UR E26, officially titled Cyber Resilience of Ships, was adopted by the International Association of Classification Societies (IACS) and entered into force for ships contracted for construction on or after 1 July 2024. It is one of two companion requirements — alongside IACS UR E27, which governs Cyber Resilience of On-board Systems and Equipment — that together define the new mandatory framework for maritime cybersecurity.
선박 사이버 보안 규정
IACS UR E26 요구사항
Unlike IMO MSC-FAL.1/Circ.3, which provided guidance for existing ships, IACS UR E26 is a binding requirement for newbuildings. Every classification society that is a member of IACS — including DNV, Lloyd's Register, Bureau Veritas, ABS, ClassNK, RINA, and others — must implement UR E26 in their rules for new ship contracts from July 2024.
Captain Paul's Practitioner Note
IACS UR E26 is not simply a documentation requirement — it is a system engineering obligation. From my experience working across shipyards, owners, and suppliers, the most common misunderstanding is treating E26 as a checklist to submit at delivery. In reality, it must be embedded from the Basic Design phase onwards. The three key deliverables — CBS Inventory, ZCD, and CRSI — are not forms to fill out; they are engineering artefacts that must reflect the actual architecture of the ship.
② Why IACS UR E26 Matters
Modern ships are no longer isolated mechanical systems. Today's vessels are floating data centres — connected to satellite networks, remote vendor systems, fleet management platforms, and port information systems. This connectivity creates attack surfaces that did not exist a decade ago.
The MSC Antonia grounding (2026) illustrated what happens when shipboard systems fail in ways that are not anticipated by the crew. Cyber incidents on ships are no longer theoretical — from GPS spoofing to ransomware affecting navigation systems, the maritime sector has experienced real incidents that demonstrate the urgency of IACS UR E26 implementation.
⚡ Key Insight
IACS UR E26 is not just a compliance exercise. It is the industry's collective answer to the question: "How do we build ships that can survive a cyber attack and continue to operate safely?" The answer requires engineering, not paperwork.
③ Core Requirements of IACS UR E26
IACS UR E26 structures its requirements around five functional areas that map to the NIST Cybersecurity Framework: Identify, Protect, Detect, Respond, and Recover. These five functions must be addressed across all CBS on board, from navigation systems and propulsion controls to cargo management and ballast water treatment systems.
④ CBS — Computer Based Systems Inventory
The Computer Based System (CBS) is the fundamental unit of IACS UR E26 analysis. Every hardware and software system on board that uses digital computing — from the navigation radar to the engine control system — must be identified, catalogued, and categorised in the CBS Inventory.
→ Deeper Dive: CBS Category Classification — The Core Framework of IACS UR E26/E27
→ System Classification Guide: Efficient Way to Classify CBS Types
⑤ ZCD — Zone and Conduit Diagram
The Zone and Conduit Diagram (ZCD) is the primary architecture document required by IACS UR E26. It graphically and textually defines how all CBS on board are grouped into security Zones and how data flows between zones through Conduits — each with defined security controls.
→ Deep Dive Series:
- Anatomy of a Ship ZCD — Building Blocks of IACS UR E26 Zone and Conduit Diagram
- From Networks to ZCD — Translating Physical and Logical Networks into E26 Documentation
- Why Most Ship ZCDs Fail — Seven Common Mistakes in IACS UR E26/E27 Projects
- Zone Before VLAN — Designing Logical Networks Using the Purdue Model
⑥ CRSI — Cyber Resilience System Integrator
The Cyber Resilience System Integrator (CRSI) is the entity responsible for coordinating the overall cyber resilience architecture of a newbuilding. IACS UR E26 implicitly requires that someone takes ownership of the whole-ship cyber resilience design — and in practice, this role has become known as the CRSI.
→ The Cyber Resilience System Integrator and the Six Core Ship-Level Deliverables
→ The Missing Role in IACS UR E26/E27 — Why a Cyber Resilience Integrator Is No Longer Optional
⑦ Shipyard Implementation
Shipyards bear the greatest operational burden under IACS UR E26. They are responsible for coordinating cyber resilience across potentially hundreds of suppliers, integrating E26 requirements into newbuilding contract specifications, and delivering the complete documentation package to the classification society at delivery.
⚠️ Critical Warning: CSDD Completeness at Delivery
The CSDD (Cyber Security Design Documentation) handed over at delivery is the foundation for the ship's entire operational cyber resilience lifecycle. If it is rushed or incomplete during construction, the SCARP and all post-delivery maintenance activities will be built on an unstable foundation. This is one of the most critical failure points seen in current E26 projects.
→ The Shipyard's View: Implementing IACS UR E26 on the Drydock
→ [IACS UR E26] Belongs in Basic Design — Cyber by Design from Day One
⑧ Classification Society Perspective
Classification societies verify E26 compliance at three key stages: design approval, delivery survey, and annual surveys thereafter. Each stage has distinct requirements, and classification societies are increasingly developing specialised teams and digital tools to handle the volume of E26 projects entering the pipeline.
→ Through the Eyes of the Classification Society — The Surveyor's View of IACS UR E26
→ What Classification Societies Actually Verify — And Why Projects Fail at Audit
⑨ IACS UR E26 vs E27 — Key Differences
- Applies to the Ship as a whole
- Shipyard is the primary responsible party
- Requires CBS Inventory, ZCD, CRSI, SCARP
- Governs the overall cyber resilience architecture
- Korean: 선박 사이버 복원력 규정
- Applies to individual CBS equipment and systems
- Equipment Suppliers are primary responsible party
- Requires 41 Security Capabilities to be demonstrated
- Type Approval and supplier documentation required
- Korean: 선내 시스템 및 장비의 사이버 복원력
Think of it this way: E26 is the ship's cyber resilience blueprint, while E27 is the individual building block certification. A ship cannot be E26 compliant if its E27-applicable components have not received the necessary supplier documentation — the two standards are inseparable in practice.
→ For a complete treatment of E26 vs E27: IACS UR E27 — 41 Security Capabilities You Must Prove
⑩ IACS UR E26 Compliance Structure
Compliance with IACS UR E26 is not a single event — it is a lifecycle commitment. The compliance structure spans three phases: design-phase documentation, delivery verification, and operational maintenance through annual surveys.
→ IACS UR E26/E27 Compliance Matrix: Cybersecurity Solutions for Maritime OT
⑪ Common Mistakes in IACS UR E26 Projects
❌ Starting E26 at Detail Design (Too Late)
Zone architecture decisions made at Basic Design affect structural routing, cable trays, and fire protection boundaries. Starting E26 at Detail Design means redesign costs and schedule overruns.
❌ Treating IT Systems as Out of Scope
If IT systems connect to OT networks — even indirectly through crew internet or admin systems — they must be included in the CBS Inventory and ZCD. IT/OT boundary management is a core E26 requirement.
❌ Collecting E27 Documents Without Verification
Many projects collect supplier E27 documentation without verifying its completeness or accuracy. A document that looks complete on a checklist may be missing critical technical detail. The CRSI must review, not just collect.
❌ Delivering a Static ZCD That Is Never Updated
ZCD must reflect the as-built state of the ship at all times. Software updates, new sensors, or network changes that are not reflected in the ZCD are a compliance gap and a security risk. Owners must maintain it post-delivery.
❌ SCARP Delivered Without Crew Training
A SCARP that sits in a binder is not a functioning cyber resilience plan. Crew must be trained in incident identification and response procedures before the ship departs on its first voyage.
⑫ ShipPaulJobs IACS UR E26 Knowledge Hub
⑬ FAQ — IACS UR E26
Q. Does IACS UR E26 apply to existing ships?
No. IACS UR E26 applies to ships contracted for construction on or after 1 July 2024. Existing ships (in-service vessels) are not covered by E26 but are subject to IMO MSC-FAL.1/Circ.3 guidance and flag state requirements, which vary by jurisdiction. Some flag states are now developing mandatory requirements for existing ships.
Q. Who is responsible for IACS UR E26 compliance — shipyard or shipowner?
The shipyard is primarily responsible for E26 compliance during construction and at delivery. However, the shipowner becomes responsible for maintaining compliance post-delivery — keeping the ZCD and CBS Inventory updated, conducting annual surveys, and maintaining the SCARP. Both parties have defined obligations.
Q. What is the difference between IACS UR E26 and the IMO Maritime Cyber Risk Management guidelines?
IMO MSC-FAL.1/Circ.3 provides non-mandatory guidance applicable to all ships (primarily existing vessels), while IACS UR E26 is a mandatory binding requirement for newbuildings contracted from July 2024. E26 is aligned with IMO principles but goes significantly further in specifying deliverables, categorisation, and verification requirements.
Q. IACS UR E26와 IACS UR E27의 차이는?
IACS UR E26은 선박 전체의 사이버 복원력 구조를 다루며 조선소가 주로 책임집니다. IACS UR E27은 개별 선내 시스템 및 장비의 사이버 복원력 요건을 다루며, 장비 공급업체가 41개 보안 기능을 증명해야 합니다. 두 규정은 함께 적용되며, E26 준수는 E27 장비 문서 없이는 완성될 수 없습니다.
Q. What does 'Cyber Resilience of Ships' mean in the context of IACS UR E26?
'Cyber Resilience of Ships' is the official title of IACS UR E26 and describes the core intent: not just preventing cyber attacks, but ensuring that a ship can withstand, adapt to, and recover from cyber incidents without loss of essential safety and operational functions. This is broader than cybersecurity — it encompasses both prevention and recovery.
This guide reflects hands-on experience working across shipyards, shipowners, classification societies, and suppliers on IACS UR E26 implementation projects. The views expressed are practitioner observations, not official IACS guidance. Always refer to the official IACS UR E26 document and your classification society for authoritative requirements.
⚓ Join the ShipPaulJobs Community
Join →
Comments
Post a Comment