📋 IACS UR E26 🚢 Major Pillar 01 Complete Guide Practitioner Insight

IACS UR E26: Complete Guide to
Cyber Resilience of Ships

IACS UR E26 선박 사이버 복원력 완벽 가이드 — Requirements, Compliance and Implementation
from Requirements to CBS Inventory, ZCD, CRSI, and Classification Society Verification

Captain Paul — Maritime Cybersecurity Expert
Captain Paul ✓ Verified
Maritime Cybersecurity Practitioner · IACS UR E26/E27 Specialist · August 2026
📌 Quick Answer — What Is IACS UR E26?

IACS UR E26, officially titled Cyber Resilience of Ships, is a mandatory unified requirement issued by the International Association of Classification Societies (IACS). It defines cyber resilience requirements for all ships contracted for construction on or after 1 July 2024.

It covers the entire newbuilding lifecycle — from design and construction through delivery and operation — and requires shipyards, equipment suppliers, and shipowners to systematically manage cyber risks across all Computer Based Systems (CBS) on board.

① What Is IACS UR E26?

IACS UR E26, officially titled Cyber Resilience of Ships, was adopted by the International Association of Classification Societies (IACS) and entered into force for ships contracted for construction on or after 1 July 2024. It is one of two companion requirements — alongside IACS UR E27, which governs Cyber Resilience of On-board Systems and Equipment — that together define the new mandatory framework for maritime cybersecurity.



IACS UR E26 — Key Facts
Official Title
Cyber Resilience of Ships
Issuing Authority
IACS (International Association of Classification Societies)
Effective Date
Ships contracted on or after 1 July 2024
Scope
All Computer Based Systems (CBS) on board — OT, IT, and interfaces
Companion Rule
IACS UR E27 (On-board Systems and Equipment)
Key Korean Terms
IACS UR E26 선박 사이버 복원력
선박 사이버 보안 규정
IACS UR E26 요구사항

Unlike IMO MSC-FAL.1/Circ.3, which provided guidance for existing ships, IACS UR E26 is a binding requirement for newbuildings. Every classification society that is a member of IACS — including DNV, Lloyd's Register, Bureau Veritas, ABS, ClassNK, RINA, and others — must implement UR E26 in their rules for new ship contracts from July 2024.

Captain Paul's Practitioner Note

IACS UR E26 is not simply a documentation requirement — it is a system engineering obligation. From my experience working across shipyards, owners, and suppliers, the most common misunderstanding is treating E26 as a checklist to submit at delivery. In reality, it must be embedded from the Basic Design phase onwards. The three key deliverables — CBS Inventory, ZCD, and CRSI — are not forms to fill out; they are engineering artefacts that must reflect the actual architecture of the ship.

② Why IACS UR E26 Matters

Modern ships are no longer isolated mechanical systems. Today's vessels are floating data centres — connected to satellite networks, remote vendor systems, fleet management platforms, and port information systems. This connectivity creates attack surfaces that did not exist a decade ago.

⚠️
Connectivity Risk
Ships now connect to VSAT, 4G/5G, Starlink, and vendor remote access — all potential attack vectors
🏗️
Newbuilding Gap
Without E26, cybersecurity requirements were fragmented across different class rules with no unified standard
📋
Legal Mandate
Flag state acceptance of IACS URs means E26 is effectively binding for all major classification society classed ships

The MSC Antonia grounding (2026) illustrated what happens when shipboard systems fail in ways that are not anticipated by the crew. Cyber incidents on ships are no longer theoretical — from GPS spoofing to ransomware affecting navigation systems, the maritime sector has experienced real incidents that demonstrate the urgency of IACS UR E26 implementation.

⚡ Key Insight

IACS UR E26 is not just a compliance exercise. It is the industry's collective answer to the question: "How do we build ships that can survive a cyber attack and continue to operate safely?" The answer requires engineering, not paperwork.

③ Core Requirements of IACS UR E26

IACS UR E26 structures its requirements around five functional areas that map to the NIST Cybersecurity Framework: Identify, Protect, Detect, Respond, and Recover. These five functions must be addressed across all CBS on board, from navigation systems and propulsion controls to cargo management and ballast water treatment systems.

IACS UR E26 — Five Functional Requirements
IDENTIFY
Enumerate all Computer Based Systems (CBS) on board, classify them by category, document their network interfaces, and produce a CBS Inventory. This is the foundational deliverable — without accurate identification, all subsequent requirements cannot be properly applied.
PROTECT
Implement security controls commensurate with each CBS category. Define Zones and Conduits to segregate systems by security level. Establish access control, authentication, and network segmentation. The Zone & Conduit Diagram (ZCD) documents this architecture.
DETECT
Deploy monitoring capabilities capable of detecting anomalies, unauthorised access, and potential intrusions across OT and IT networks. OT network monitoring must be configured to detect events without disrupting operational systems.
RESPOND
Establish incident response procedures, define roles and responsibilities, and ensure crew can contain and manage cyber incidents at sea without relying solely on shore-side support. Backup and fallback modes must be documented and tested.
RECOVER
Define recovery procedures, backup configurations, and restoration processes for all CBS. SCARP (Ship Cyber Resilience Plan) must document how the ship will recover from a cyber incident and restore operational capability within defined timeframes.

④ CBS — Computer Based Systems Inventory

The Computer Based System (CBS) is the fundamental unit of IACS UR E26 analysis. Every hardware and software system on board that uses digital computing — from the navigation radar to the engine control system — must be identified, catalogued, and categorised in the CBS Inventory.

CBS Categories Under IACS UR E26
CATEGORY A — Safety Functions
Systems directly responsible for the safety of the ship, crew, and cargo. Failure or compromise could cause loss of life or environmental damage. Highest security requirements apply. Examples: Navigation systems (ECDIS, AIS), Alarm Monitoring System, Fire Detection.
CATEGORY B — Operational Functions
Systems supporting ship operations but not directly safety-critical. Compromise would affect operations significantly but not immediately endanger the ship. Examples: Cargo Management, Ballast Water Treatment, Engine Room Automation.
CATEGORY C — Management Functions
Administrative, crew welfare, and business systems. Lower security classification — but still must be inventoried and segregated from Category A/B systems via proper zone design. Examples: Crew Internet, CCTV, Administration Systems.
⚠️ Common Mistake
Many projects undercount CBS by focusing only on dedicated OT systems. In practice, any laptop, server, or network device connected to shipboard networks must be assessed. IT systems used for operational purposes (e.g., cargo planning software) must be classified and included.

Deeper Dive: CBS Category Classification — The Core Framework of IACS UR E26/E27

System Classification Guide: Efficient Way to Classify CBS Types

⑤ ZCD — Zone and Conduit Diagram

The Zone and Conduit Diagram (ZCD) is the primary architecture document required by IACS UR E26. It graphically and textually defines how all CBS on board are grouped into security Zones and how data flows between zones through Conduits — each with defined security controls.

ZCD Key Concepts
ZONE
A logical grouping of CBS with the same security level and trust requirements. A zone boundary prevents unauthorised lateral movement between systems of different security classifications.
CONDUIT
A defined communication path between zones, secured by specific controls (firewalls, data diodes, VPN). Every conduit must document what data flows, which protocols are used, and what security controls are in place.
PURDUE MODEL
ZCD design should follow the Purdue Reference Model hierarchy — separating Level 0 (sensors/actuators), Level 1 (basic control), Level 2 (supervisory), Level 3 (operations), and higher levels of IT connectivity.
MAINTENANCE
ZCD is a living document. It must be updated whenever the ship's systems change — software upgrades, new equipment installation, or network reconfiguration. An outdated ZCD is a compliance risk during annual surveys.

Deep Dive Series:

⑥ CRSI — Cyber Resilience System Integrator

The Cyber Resilience System Integrator (CRSI) is the entity responsible for coordinating the overall cyber resilience architecture of a newbuilding. IACS UR E26 implicitly requires that someone takes ownership of the whole-ship cyber resilience design — and in practice, this role has become known as the CRSI.

Six Core Ship-Level Deliverables — CRSI Responsibility
1
CBS Inventory — Complete catalogue of all Computer Based Systems, their categories, and network interfaces
2
ZCD (Zone & Conduit Diagram) — Graphical and textual architecture showing all zones, conduits, and security controls
3
CRSI Report — System integrator's consolidated assessment of the ship's cyber resilience posture
4
SCARP (Ship Cyber Awareness and Resilience Plan) — Operational plan for incident response, crew training, and recovery
5
Penetration Test / Vulnerability Assessment — Pre-delivery testing to verify security controls are effective
6
Supplier Documentation Package — E27 compliance documents from each CBS supplier, coordinated and verified by the CRSI

The Cyber Resilience System Integrator and the Six Core Ship-Level Deliverables

The Missing Role in IACS UR E26/E27 — Why a Cyber Resilience Integrator Is No Longer Optional

⑦ Shipyard Implementation

Shipyards bear the greatest operational burden under IACS UR E26. They are responsible for coordinating cyber resilience across potentially hundreds of suppliers, integrating E26 requirements into newbuilding contract specifications, and delivering the complete documentation package to the classification society at delivery.

E26 Implementation Timeline — Newbuilding Phases
BASIC DESIGN
Define cyber resilience requirements in contract spec · Identify CRSI · Conduct initial CBS scoping · Establish Zone architecture concept
DETAIL DESIGN
Complete CBS Inventory · Produce detailed ZCD · Collect E27 documents from suppliers · Submit to class for design approval
CONSTRUCTION
Install systems per approved design · Implement OT network monitoring · Conduct Factory Acceptance Tests (FAT) with cyber requirements · Update ZCD as-built
DELIVERY
Complete penetration testing · Deliver SCARP to owner · Final class verification · Transfer CSDD (Cyber Security Design Documentation) to owner

⚠️ Critical Warning: CSDD Completeness at Delivery

The CSDD (Cyber Security Design Documentation) handed over at delivery is the foundation for the ship's entire operational cyber resilience lifecycle. If it is rushed or incomplete during construction, the SCARP and all post-delivery maintenance activities will be built on an unstable foundation. This is one of the most critical failure points seen in current E26 projects.

The Shipyard's View: Implementing IACS UR E26 on the Drydock

[IACS UR E26] Belongs in Basic Design — Cyber by Design from Day One

⑧ Classification Society Perspective

Classification societies verify E26 compliance at three key stages: design approval, delivery survey, and annual surveys thereafter. Each stage has distinct requirements, and classification societies are increasingly developing specialised teams and digital tools to handle the volume of E26 projects entering the pipeline.

DESIGN APPROVAL
Review of CBS Inventory, ZCD, and security architecture against E26 requirements. Approval granted before construction commences. Missing documentation at this stage causes schedule delays.
DELIVERY SURVEY
Verification that installed systems match approved design, FAT results are acceptable, SCARP is delivered, and penetration testing is complete. Class issues the E26 notation at delivery.
ANNUAL SURVEY
Ongoing verification that the ZCD and CBS Inventory remain accurate as-built. OT monitoring logs may be reviewed. Updates required whenever systems change. Not a one-time compliance event.

Through the Eyes of the Classification Society — The Surveyor's View of IACS UR E26

What Classification Societies Actually Verify — And Why Projects Fail at Audit

⑨ IACS UR E26 vs E27 — Key Differences

E26 vs E27 — At a Glance
IACS UR E26 — Ship Level
  • Applies to the Ship as a whole
  • Shipyard is the primary responsible party
  • Requires CBS Inventory, ZCD, CRSI, SCARP
  • Governs the overall cyber resilience architecture
  • Korean: 선박 사이버 복원력 규정
IACS UR E27 — Equipment Level
  • Applies to individual CBS equipment and systems
  • Equipment Suppliers are primary responsible party
  • Requires 41 Security Capabilities to be demonstrated
  • Type Approval and supplier documentation required
  • Korean: 선내 시스템 및 장비의 사이버 복원력

Think of it this way: E26 is the ship's cyber resilience blueprint, while E27 is the individual building block certification. A ship cannot be E26 compliant if its E27-applicable components have not received the necessary supplier documentation — the two standards are inseparable in practice.

→ For a complete treatment of E26 vs E27: IACS UR E27 — 41 Security Capabilities You Must Prove

⑩ IACS UR E26 Compliance Structure

Compliance with IACS UR E26 is not a single event — it is a lifecycle commitment. The compliance structure spans three phases: design-phase documentation, delivery verification, and operational maintenance through annual surveys.

E26 Compliance Checklist — Key Deliverables
CBS Inventory — complete, categorised (A/B/C), with network interface documentation
Zone & Conduit Diagram (ZCD) — approved by classification society at design stage
CRSI designation — entity identified and accountable for system integration
E27 supplier documentation — collected and verified for all applicable CBS
OT network monitoring — deployed and operational at delivery
SCARP — delivered to shipowner at delivery, covering incident response and crew training
Penetration test / vulnerability assessment — completed pre-delivery
Annual survey readiness — ZCD updated as-built, monitoring logs available

IACS UR E26/E27 Compliance Matrix: Cybersecurity Solutions for Maritime OT

E26 Deliverable Quality — The Low, Medium, and High Tiers

⑪ Common Mistakes in IACS UR E26 Projects

❌ Starting E26 at Detail Design (Too Late)

Zone architecture decisions made at Basic Design affect structural routing, cable trays, and fire protection boundaries. Starting E26 at Detail Design means redesign costs and schedule overruns.

❌ Treating IT Systems as Out of Scope

If IT systems connect to OT networks — even indirectly through crew internet or admin systems — they must be included in the CBS Inventory and ZCD. IT/OT boundary management is a core E26 requirement.

❌ Collecting E27 Documents Without Verification

Many projects collect supplier E27 documentation without verifying its completeness or accuracy. A document that looks complete on a checklist may be missing critical technical detail. The CRSI must review, not just collect.

❌ Delivering a Static ZCD That Is Never Updated

ZCD must reflect the as-built state of the ship at all times. Software updates, new sensors, or network changes that are not reflected in the ZCD are a compliance gap and a security risk. Owners must maintain it post-delivery.

❌ SCARP Delivered Without Crew Training

A SCARP that sits in a binder is not a functioning cyber resilience plan. Crew must be trained in incident identification and response procedures before the ship departs on its first voyage.

⑬ FAQ — IACS UR E26

Q. Does IACS UR E26 apply to existing ships?

No. IACS UR E26 applies to ships contracted for construction on or after 1 July 2024. Existing ships (in-service vessels) are not covered by E26 but are subject to IMO MSC-FAL.1/Circ.3 guidance and flag state requirements, which vary by jurisdiction. Some flag states are now developing mandatory requirements for existing ships.

Q. Who is responsible for IACS UR E26 compliance — shipyard or shipowner?

The shipyard is primarily responsible for E26 compliance during construction and at delivery. However, the shipowner becomes responsible for maintaining compliance post-delivery — keeping the ZCD and CBS Inventory updated, conducting annual surveys, and maintaining the SCARP. Both parties have defined obligations.

Q. What is the difference between IACS UR E26 and the IMO Maritime Cyber Risk Management guidelines?

IMO MSC-FAL.1/Circ.3 provides non-mandatory guidance applicable to all ships (primarily existing vessels), while IACS UR E26 is a mandatory binding requirement for newbuildings contracted from July 2024. E26 is aligned with IMO principles but goes significantly further in specifying deliverables, categorisation, and verification requirements.

Q. IACS UR E26와 IACS UR E27의 차이는?

IACS UR E26은 선박 전체의 사이버 복원력 구조를 다루며 조선소가 주로 책임집니다. IACS UR E27은 개별 선내 시스템 및 장비의 사이버 복원력 요건을 다루며, 장비 공급업체가 41개 보안 기능을 증명해야 합니다. 두 규정은 함께 적용되며, E26 준수는 E27 장비 문서 없이는 완성될 수 없습니다.

Q. What does 'Cyber Resilience of Ships' mean in the context of IACS UR E26?

'Cyber Resilience of Ships' is the official title of IACS UR E26 and describes the core intent: not just preventing cyber attacks, but ensuring that a ship can withstand, adapt to, and recover from cyber incidents without loss of essential safety and operational functions. This is broader than cybersecurity — it encompasses both prevention and recovery.

Captain Paul
Captain Paul (In Sung Lee)
Maritime Cybersecurity Practitioner · IACS UR E26/E27 Specialist

This guide reflects hands-on experience working across shipyards, shipowners, classification societies, and suppliers on IACS UR E26 implementation projects. The views expressed are practitioner observations, not official IACS guidance. Always refer to the official IACS UR E26 document and your classification society for authoritative requirements.

⚓ Join the ShipPaulJobs Community

Join →
Share

Comments

Top Ranked · All Posts

Popular Posts