⚖️ E26 vs E27 🚢 Major Pillar 04 Complete Guide Practitioner Insight

IACS UR E26 vs E27:
The Complete Comparison Guide

IACS UR E26 vs E27 완벽 비교 가이드 — Ship Level vs Equipment Level Cyber Resilience
Understanding the Difference, the Overlap, and How Both Standards Work in Practice

Captain Paul — Maritime Cybersecurity Expert
Captain Paul ✓ Verified
Maritime Cybersecurity Practitioner · IACS UR E26/E27 Specialist · August 2026
📌 Quick Answer — E26 vs E27 in One Paragraph

IACS UR E26 governs cyber resilience at the ship level — the overall architecture, documentation, and compliance programme for the entire vessel. IACS UR E27 governs cyber resilience at the equipment level — the 41 security capabilities each individual Computer Based System (CBS) must demonstrate.

The two standards are inseparable: E26 compliance cannot be achieved without E27-compliant equipment documentation. Think of E26 as the ship's cyber resilience blueprint and E27 as the individual component certification — both mandatory for ships contracted from July 2024.

① Side-by-Side Overview — IACS UR E26 vs E27



E26 vs E27 — Comparison Table
DIMENSION IACS UR E26 IACS UR E27
Official Title Cyber Resilience of Ships Cyber Resilience of On-board Systems and Equipment
Scope Level Ship Level (whole vessel architecture) Equipment Level (individual CBS)
Primary Responsible Party Shipyard (+ Shipowner post-delivery) CBS Equipment Supplier
Key Deliverables CBS Inventory, ZCD, CRSI Report, SCARP, Pen Test 41 Security Capabilities documentation, Type Approval
Class Verification Design approval, Delivery survey, Annual survey Type approval / Product certification per equipment
Applies To All CBS categories (A, B, C) at the ship level Individual CBS with network interfaces (OT focus)
Korean Terms 선박 사이버 복원력 선내 시스템 및 장비의 사이버 복원력
Effective Date Ships contracted ≥ 1 Jul 2024 Ships contracted ≥ 1 Jul 2024

⚠️ Critical Point

E26 and E27 are not interchangeable or alternatives — they are complementary. You cannot achieve E26 compliance without E27 equipment documentation, and E27 documentation alone does not constitute ship-level compliance. Both must be addressed simultaneously from the Basic Design phase.

② IACS UR E26 — Ship Level in Detail

IACS UR E26 addresses cyber resilience at the ship as a system. It requires the shipyard to treat the vessel as an integrated cyber-physical system and document its security architecture comprehensively. The ship-level view is what E27 equipment-level certification cannot provide on its own.

IACS UR E26 — What Must Be Produced
CBS INVENTORY
Complete list of all Computer Based Systems, their categories (A/B/C), descriptions, vendor information, network interfaces, and operational criticality. The master asset register for E26.
ZONE & CONDUIT DIAGRAM (ZCD)
Graphical and textual representation of the ship's security architecture — all zones, conduit controls, data flows, and security boundaries. Must be approved by class.
CRSI REPORT
The Cyber Resilience System Integrator's consolidated assessment confirming the ship's cyber resilience architecture integrates correctly across all CBS and suppliers.
SCARP
Ship Cyber Awareness and Resilience Plan — the crew-facing operational document for cyber incident response, training, and recovery procedures.
PENETRATION TEST
Pre-delivery security testing to verify that the implemented controls function as documented in the ZCD and CBS Inventory. Results must be disclosed to class.
SUPPLIER DOC PACKAGE
The collection and verification of E27 documentation from all applicable CBS suppliers — coordinated by the CRSI and presented to class as part of delivery documentation.

The Cyber Resilience System Integrator and the Six Core Ship-Level Deliverables

IACS UR E26/E27 Compliance Matrix

③ IACS UR E27 — Equipment Level in Detail

IACS UR E27 (Cyber Resilience of On-board Systems and Equipment) addresses cyber resilience at the level of individual Computer Based Systems. Where E26 defines the ship's security architecture, E27 defines what each component within that architecture must be capable of doing from a security perspective.

IACS UR E27 — Core Concept

E27 requires CBS equipment suppliers to demonstrate that their products implement 41 defined security capabilities across five categories: Software Design, Access Control, System Integrity, Detection Capabilities, and System Restoration. The level of capability required depends on the CBS category (A, B, or C) as defined in E26.

KEY PRINCIPLE: E27 IS SCALABLE
Not all 41 capabilities apply to every CBS at the same level. Category A (safety-critical) systems face stricter requirements than Category B or C. This scaling is intentional — applying maximum security controls to crew entertainment systems (Category C) would be disproportionate.

The E27 compliance process requires each supplier to produce a Security Capability Statement (SCS) — a documented assessment of which of the 41 capabilities their product implements and at what level. This is then reviewed by the classification society as part of type approval or product certification.

④ IACS UR E27's 41 Security Capabilities — Overview

The 41 security capabilities defined in IACS UR E27 are organised into five functional categories. Each capability is numbered (SC-1 through SC-41) and carries specific requirements that CBS manufacturers must document and demonstrate. The capability set draws from IEC 62443 security requirements, adapted for the maritime OT context.

The Five E27 Security Capability Categories
CATEGORY 1 — Software Design SC-1 to SC-9
Secure software development lifecycle, patch management, vulnerability disclosure procedures, and documentation of software components. Requires suppliers to maintain a software bill of materials (SBOM) and have a defined process for distributing security updates to deployed systems.
SC-1: Secure SW development SC-2: Patch management SC-4: Vulnerability disclosure SC-9: SW component inventory
CATEGORY 2 — Access Control SC-10 to SC-18
User account management, role-based access control (RBAC), authentication mechanisms, and session management. For OT systems, this includes documented procedures for vendor/maintenance access and physical port control.
SC-10: Least privilege SC-12: Account management SC-15: Authentication SC-18: Session lock
CATEGORY 3 — System Integrity SC-19 to SC-28
Malware protection, input validation, communication integrity, and protection of cryptographic keys. For OT systems, also covers physical port security (USB, serial, network) and configuration hardening. One of the most challenging categories for legacy OT equipment.
SC-19: Malware protection SC-22: Communication integrity SC-25: Physical port control SC-28: Config hardening
CATEGORY 4 — Detection Capabilities SC-29 to SC-35
Audit logging, security event generation, clock synchronisation, and anomaly detection. Equipment must generate security-relevant logs in a standard format that can be collected by the ship's OT monitoring system. Critical interface between E27 equipment and E26 ship-level detection.
SC-29: Audit logging SC-31: Security events SC-33: Clock sync SC-35: Anomaly detection
CATEGORY 5 — System Restoration SC-36 to SC-41
Backup and recovery procedures, configuration restoration, and documented recovery time objectives (RTO). Equipment must support restoration to a known-good state without requiring internet connectivity. Critical for ensuring the ship can recover from an incident at sea.
SC-36: Backup procedures SC-38: Config restoration SC-40: Incident reporting SC-41: RTO documentation

⑤ How IACS UR E26 and E27 Interact

The relationship between E26 and E27 is hierarchical but interdependent. E26 defines what the ship needs to achieve; E27 defines what each component of the ship must provide to make that achievement possible. Neither standard can be satisfied without addressing the other.

The E26 ↔ E27 Interaction Model
E26 (SHIP LEVEL) REQUIRES:
  • ZCD to show zone segmentation
  • CBS Inventory to list all equipment
  • Security controls per CBS category
  • OT monitoring coverage of all zones
  • CRSI to coordinate compliance
E27 (EQUIPMENT LEVEL) PROVIDES:
  • Security capabilities enabling zone controls
  • Asset documentation for CBS Inventory
  • Capability levels mapped to CBS categories
  • Log output compatible with OT monitoring
  • Supplier docs verified by CRSI

For example: E26 requires that a ship's ECDIS be in Zone A with appropriate access controls. E27 requires the ECDIS manufacturer to demonstrate capability SC-15 (Authentication) and SC-10 (Least Privilege) — which are the technical mechanisms that enable the zone control E26 requires. Without the E27 documentation, the E26 zone control cannot be verified by class.

Captain Paul's Practitioner Note

In practice, the E26/E27 interaction creates the most complex documentation management challenge in the project. A single newbuilding may have 200+ CBS, each needing E27 documentation from their respective supplier. I have seen projects where the CRSI is collecting 300+ supplier documents and trying to reconcile them against the ZCD — at the same time as the shipyard is still finalising the network design. Start early, track rigorously, and never assume a supplier's E27 documentation is complete until you have reviewed it yourself.

⑥ Who Is Responsible? — Stakeholder Roles in E26 vs E27

IACS UR E26 — Responsible Parties
SHIPYARD
Lead E26 compliance during construction. Coordinate CRSI. Deliver CBS Inventory, ZCD, CRSI Report, and SCARP at delivery.
CRSI
Coordinate the whole-ship cyber resilience architecture. Collect and verify E27 supplier documents. Produce the CRSI Report.
SHIPOWNER (POST-DELIVERY)
Maintain ZCD and CBS Inventory current. Implement SCARP. Conduct crew training and drills. Prepare for annual surveys.
CLASSIFICATION SOCIETY
Verify E26 compliance at design, delivery, and annual surveys. Issue E26 notation.
IACS UR E27 — Responsible Parties
CBS SUPPLIER / MANUFACTURER
Primary responsible party. Must demonstrate 41 security capabilities for their product. Produce Security Capability Statement (SCS). Manage patch and vulnerability disclosure.
CRSI (VERIFICATION ROLE)
Collect and review E27 documentation from all applicable suppliers. Identify gaps and manage supplier remediation. Consolidate into supplier documentation package for class.
SHIPYARD (CONTRACT ROLE)
Include E27 requirements in procurement specifications. Follow up with suppliers to obtain documentation. Cannot delegate responsibility to suppliers without oversight.
CLASSIFICATION SOCIETY
Type approval or product certification for individual CBS based on E27 capability statements. Review supplier documentation during newbuilding project approval.

The Shipyard's View: Implementing IACS UR E26 on the Drydock

The Vendor's View: The Economics of E27 Certification

⑦ E26 + E27 Compliance Strategy

Achieving compliance with both IACS UR E26 and E27 simultaneously requires a carefully sequenced project strategy. The most common failure mode is addressing them sequentially (E26 first, then E27 documents later) — which leads to gaps between the ship-level design and the available equipment capabilities.


BASIC DESIGN
Establish E27 requirements in procurement specs. CBS categories must be decided at this stage so suppliers know what E27 level applies. Start CBS scoping and Zone architecture. Designate CRSI.
DETAIL DESIGN
Collect E27 documentation from suppliers — NOW, not later. CRSI reviews capability statements. Gaps identified here can still be resolved. ZCD submitted to class for design approval incorporating E27 findings.
CONSTRUCTION
Verify as-installed compliance. FAT includes E27 capability verification. OT monitoring deployed. ZCD updated as-built. Any supplier documentation gaps must be resolved before delivery.
DELIVERY
Complete E26 package delivery to class and owner. All E27 supplier documentation consolidated. CRSI Report finalised. SCARP delivered to owner. Class issues E26 notation.

E26 Deliverable Quality — The Low, Medium, and High Tiers

⑧ Common Points of Confusion — E26 vs E27

❌ MYTH: "If all CBS are E27 compliant, the ship automatically meets E26."

FALSE. E27 compliance of individual systems does not produce the ship-level ZCD, CBS Inventory, CRSI Report, or SCARP that E26 requires. These are whole-ship deliverables that require integration across all systems — not a sum of individual equipment certifications.

❌ MYTH: "E27 type approval from a classification society means no further action is needed."

FALSE. E27 type approval certifies the product in isolation. The CRSI must still verify that the E27 capability level matches the CBS category assigned in the E26 CBS Inventory, and that the equipment's security features are correctly configured in the actual ship installation.

❌ MYTH: "E26 only applies to OT systems — IT systems are not in scope."

FALSE. E26 applies to all Computer Based Systems on board, including IT systems — particularly those that interface with OT networks or operate as part of the ship's operational technology ecosystem. IT/OT boundary management is a core E26 requirement.

✓ CORRECT: "E26 and E27 must be addressed in parallel from Basic Design."

TRUE. The CBS category assigned in the E26 CBS Inventory determines the E27 capability level required for each system. This assignment must happen at Basic Design so that procurement specifications can include the correct E27 requirements for each CBS supplier.

⑩ FAQ — IACS UR E26 vs E27

Q. What is the main difference between IACS UR E26 and IACS UR E27?

IACS UR E26 governs the ship as a whole — the overall cyber resilience architecture, CBS Inventory, Zone & Conduit Diagram, SCARP, and system integrator coordination. IACS UR E27 governs individual equipment — the 41 specific security capabilities each Computer Based System must demonstrate. E26 is the ship-level framework; E27 is the equipment-level standard.

Q. IACS UR E26과 E27 중 어느 것이 더 어려운가?

두 규정 모두 어렵지만 다른 이유에서입니다. E26은 전체 선박 시스템 통합의 복잡성 — 수백 개의 CBS를 일관된 보안 아키텍처로 통합하는 것 — 이 도전입니다. E27은 공급업체 공급망 관리의 복잡성 — 각기 다른 수십~수백 개 공급업체로부터 기술적으로 완전한 문서를 수집하고 검증하는 것 — 이 도전입니다. 현장 경험상 E27 공급업체 문서 수집이 가장 많은 지연을 유발합니다.

Q. Can a ship have E26 compliance without E27 compliance?

No. IACS UR E26 requires the collection and verification of E27 documentation from all applicable CBS suppliers as part of the ship-level compliance package. A classification society will not issue the E26 notation if the E27 supplier documentation is incomplete or absent. The two standards are structurally dependent.

Q. What happens if a CBS supplier cannot provide E27 documentation?

This is a real and frequent challenge. If a supplier cannot meet E27 requirements, the options are: (1) replace the equipment with an E27-compliant alternative, (2) implement compensating controls at the ship level (via ZCD architecture) to address the gaps, documented and approved by class, or (3) seek a class exemption with appropriate risk acceptance justification. Option 3 is rarely granted for Category A systems.

Captain Paul
Captain Paul 
Maritime Cybersecurity Practitioner · IACS UR E26/E27 Specialist

This guide is based on practitioner experience navigating IACS UR E26 and E27 implementation across shipyards, equipment suppliers, owners, and classification societies. Content reflects the regulatory and industry state as of August 2026. Always refer to official IACS documents and your classification society for binding guidance.

⚓ Join the ShipPaulJobs Community

Join →
Share

Comments

Top Ranked · All Posts

Popular Posts