IACS UR E26 governs cyber resilience at the ship level — the overall architecture, documentation, and compliance programme for the entire vessel. IACS UR E27 governs cyber resilience at the equipment level — the 41 security capabilities each individual Computer Based System (CBS) must demonstrate.
The two standards are inseparable: E26 compliance cannot be achieved without E27-compliant equipment documentation. Think of E26 as the ship's cyber resilience blueprint and E27 as the individual component certification — both mandatory for ships contracted from July 2024.
① Side-by-Side Overview — IACS UR E26 vs E27
| DIMENSION | IACS UR E26 | IACS UR E27 |
|---|---|---|
| Official Title | Cyber Resilience of Ships | Cyber Resilience of On-board Systems and Equipment |
| Scope Level | Ship Level (whole vessel architecture) | Equipment Level (individual CBS) |
| Primary Responsible Party | Shipyard (+ Shipowner post-delivery) | CBS Equipment Supplier |
| Key Deliverables | CBS Inventory, ZCD, CRSI Report, SCARP, Pen Test | 41 Security Capabilities documentation, Type Approval |
| Class Verification | Design approval, Delivery survey, Annual survey | Type approval / Product certification per equipment |
| Applies To | All CBS categories (A, B, C) at the ship level | Individual CBS with network interfaces (OT focus) |
| Korean Terms | 선박 사이버 복원력 | 선내 시스템 및 장비의 사이버 복원력 |
| Effective Date | Ships contracted ≥ 1 Jul 2024 | Ships contracted ≥ 1 Jul 2024 |
⚠️ Critical Point
E26 and E27 are not interchangeable or alternatives — they are complementary. You cannot achieve E26 compliance without E27 equipment documentation, and E27 documentation alone does not constitute ship-level compliance. Both must be addressed simultaneously from the Basic Design phase.
② IACS UR E26 — Ship Level in Detail
IACS UR E26 addresses cyber resilience at the ship as a system. It requires the shipyard to treat the vessel as an integrated cyber-physical system and document its security architecture comprehensively. The ship-level view is what E27 equipment-level certification cannot provide on its own.
→ The Cyber Resilience System Integrator and the Six Core Ship-Level Deliverables
③ IACS UR E27 — Equipment Level in Detail
IACS UR E27 (Cyber Resilience of On-board Systems and Equipment) addresses cyber resilience at the level of individual Computer Based Systems. Where E26 defines the ship's security architecture, E27 defines what each component within that architecture must be capable of doing from a security perspective.
E27 requires CBS equipment suppliers to demonstrate that their products implement 41 defined security capabilities across five categories: Software Design, Access Control, System Integrity, Detection Capabilities, and System Restoration. The level of capability required depends on the CBS category (A, B, or C) as defined in E26.
The E27 compliance process requires each supplier to produce a Security Capability Statement (SCS) — a documented assessment of which of the 41 capabilities their product implements and at what level. This is then reviewed by the classification society as part of type approval or product certification.
④ IACS UR E27's 41 Security Capabilities — Overview
The 41 security capabilities defined in IACS UR E27 are organised into five functional categories. Each capability is numbered (SC-1 through SC-41) and carries specific requirements that CBS manufacturers must document and demonstrate. The capability set draws from IEC 62443 security requirements, adapted for the maritime OT context.
⑤ How IACS UR E26 and E27 Interact
The relationship between E26 and E27 is hierarchical but interdependent. E26 defines what the ship needs to achieve; E27 defines what each component of the ship must provide to make that achievement possible. Neither standard can be satisfied without addressing the other.
- ZCD to show zone segmentation
- CBS Inventory to list all equipment
- Security controls per CBS category
- OT monitoring coverage of all zones
- CRSI to coordinate compliance
- Security capabilities enabling zone controls
- Asset documentation for CBS Inventory
- Capability levels mapped to CBS categories
- Log output compatible with OT monitoring
- Supplier docs verified by CRSI
For example: E26 requires that a ship's ECDIS be in Zone A with appropriate access controls. E27 requires the ECDIS manufacturer to demonstrate capability SC-15 (Authentication) and SC-10 (Least Privilege) — which are the technical mechanisms that enable the zone control E26 requires. Without the E27 documentation, the E26 zone control cannot be verified by class.
Captain Paul's Practitioner Note
In practice, the E26/E27 interaction creates the most complex documentation management challenge in the project. A single newbuilding may have 200+ CBS, each needing E27 documentation from their respective supplier. I have seen projects where the CRSI is collecting 300+ supplier documents and trying to reconcile them against the ZCD — at the same time as the shipyard is still finalising the network design. Start early, track rigorously, and never assume a supplier's E27 documentation is complete until you have reviewed it yourself.
⑥ Who Is Responsible? — Stakeholder Roles in E26 vs E27
→ The Shipyard's View: Implementing IACS UR E26 on the Drydock
⑦ E26 + E27 Compliance Strategy
Achieving compliance with both IACS UR E26 and E27 simultaneously requires a carefully sequenced project strategy. The most common failure mode is addressing them sequentially (E26 first, then E27 documents later) — which leads to gaps between the ship-level design and the available equipment capabilities.
⑧ Common Points of Confusion — E26 vs E27
❌ MYTH: "If all CBS are E27 compliant, the ship automatically meets E26."
FALSE. E27 compliance of individual systems does not produce the ship-level ZCD, CBS Inventory, CRSI Report, or SCARP that E26 requires. These are whole-ship deliverables that require integration across all systems — not a sum of individual equipment certifications.
❌ MYTH: "E27 type approval from a classification society means no further action is needed."
FALSE. E27 type approval certifies the product in isolation. The CRSI must still verify that the E27 capability level matches the CBS category assigned in the E26 CBS Inventory, and that the equipment's security features are correctly configured in the actual ship installation.
❌ MYTH: "E26 only applies to OT systems — IT systems are not in scope."
FALSE. E26 applies to all Computer Based Systems on board, including IT systems — particularly those that interface with OT networks or operate as part of the ship's operational technology ecosystem. IT/OT boundary management is a core E26 requirement.
✓ CORRECT: "E26 and E27 must be addressed in parallel from Basic Design."
TRUE. The CBS category assigned in the E26 CBS Inventory determines the E27 capability level required for each system. This assignment must happen at Basic Design so that procurement specifications can include the correct E27 requirements for each CBS supplier.
⑨ Related Articles — IACS UR E26 & E27
⑩ FAQ — IACS UR E26 vs E27
Q. What is the main difference between IACS UR E26 and IACS UR E27?
IACS UR E26 governs the ship as a whole — the overall cyber resilience architecture, CBS Inventory, Zone & Conduit Diagram, SCARP, and system integrator coordination. IACS UR E27 governs individual equipment — the 41 specific security capabilities each Computer Based System must demonstrate. E26 is the ship-level framework; E27 is the equipment-level standard.
Q. IACS UR E26과 E27 중 어느 것이 더 어려운가?
두 규정 모두 어렵지만 다른 이유에서입니다. E26은 전체 선박 시스템 통합의 복잡성 — 수백 개의 CBS를 일관된 보안 아키텍처로 통합하는 것 — 이 도전입니다. E27은 공급업체 공급망 관리의 복잡성 — 각기 다른 수십~수백 개 공급업체로부터 기술적으로 완전한 문서를 수집하고 검증하는 것 — 이 도전입니다. 현장 경험상 E27 공급업체 문서 수집이 가장 많은 지연을 유발합니다.
Q. Can a ship have E26 compliance without E27 compliance?
No. IACS UR E26 requires the collection and verification of E27 documentation from all applicable CBS suppliers as part of the ship-level compliance package. A classification society will not issue the E26 notation if the E27 supplier documentation is incomplete or absent. The two standards are structurally dependent.
Q. What happens if a CBS supplier cannot provide E27 documentation?
This is a real and frequent challenge. If a supplier cannot meet E27 requirements, the options are: (1) replace the equipment with an E27-compliant alternative, (2) implement compensating controls at the ship level (via ZCD architecture) to address the gaps, documented and approved by class, or (3) seek a class exemption with appropriate risk acceptance justification. Option 3 is rarely granted for Category A systems.
This guide is based on practitioner experience navigating IACS UR E26 and E27 implementation across shipyards, equipment suppliers, owners, and classification societies. Content reflects the regulatory and industry state as of August 2026. Always refer to official IACS documents and your classification society for binding guidance.
⚓ Join the ShipPaulJobs Community
Join →

Comments
Post a Comment