Under UR E27, Unprepared Marine Equipment Is Less Likely to Be Selected
Introducing a 12-Part Series on UR E27 Strategies for Marine Equipment Suppliers
Since the International Association of Classification Societies (IACS) introduced UR E27, shipyards and classification societies have begun assessing whether onboard systems and equipment meet the applicable cyber resilience requirements. UR E27 applies to relevant ships contracted for construction on or after 1 July 2024. Judging solely by the contract date, the requirements may appear to have been in effect for some time. Yet many equipment suppliers do not seem to feel their full impact on the ground.
Some suppliers are already consulting with classification societies and preparing for Type Approval. Others are considering approaches such as a Statement of Compliance or Statement of Fact for specific projects. Many suppliers, however, continue to postpone preparations because they have not yet received specific requirements from their shipyard customers.
These are understandable questions. They also reflect one of the most concerning assumptions surrounding UR E27. By the time a shipyard formally requests certification evidence, it may already be too late for the supplier to analyze the product architecture, address missing security functions, and establish the necessary development and change-management processes.
UR E27 Risks Will Not Appear Overnight
UR E27-related problems are unlikely to emerge only in the form of a sudden notice from a shipyard stating, "You cannot deliver this product because you do not have a certificate." In actual projects, the consequences are likely to be more complex.
A supplier may be unable to explain whether UR E27 applies to its product during the quotation or technical negotiation stage. Approval drawings and technical documents may be submitted, only for the classification society to issue repeated comments because the product's security functions and external interfaces have not been adequately defined. Shortly before the Factory Acceptance Test (FAT), the supplier may discover that functions such as account management, logging, backup and recovery, and remote-access control do not meet the applicable requirements.
Once these issues are discovered at this stage, adding a few documents will not be enough. The supplier may need to modify the product's software or network architecture, rewrite test procedures, and adjust an already committed delivery date or FAT schedule. In the worst case, the shipyard may consider another, better-prepared supplier to reduce project risk.
The sense of urgency for equipment suppliers should therefore not begin with the message that "every product must obtain TA." A more accurate message is this:
In the future, products whose UR E27 conformity cannot be clearly explained and demonstrated may find it increasingly difficult to be selected through the shipyard's design, procurement, and class approval processes.
Should Every Supplier Follow the Same Approach?
No. A supplier that repeatedly delivers the same standardized product to multiple shipyards and vessels does not necessarily need the same certification strategy as a supplier that provides a customized system for each vessel or project.
For some suppliers, Type Approval, or TA, may be the most appropriate option. For others prioritizing a specific product version or project, a Statement of Compliance (SoC) or Statement of Fact (SoF) may offer a more practical starting point. In some cases, the most suitable approach may be to focus on the design approval and product inspection processes for an individual ship project.
This raises several important questions.
- Is our product subject to UR E27?
- Which option — TA, SoC, or SoF — is best suited to our business model?
- If we begin with an SoC or SoF, must we eventually transition to TA?
- When should certification preparations begin, and how long will the overall process take?
- What should the product design, software development, testing, quality, and sales teams each prepare?
- What should we discuss with the shipyard, classification society, and CRSI — and at what stage?
- How should the deliverables required by UR E27 be generated through our existing engineering processes?
This 12-part series has been designed to answer these questions in sequence.
A 12-Part Series on Supplier Implementation — Not Clause-by-Clause Interpretation
The purpose of this series is not to explain every clause of UR E27 in sequence. Reading a requirement and applying it to an actual product are two entirely different challenges. Equipment suppliers need more than a translation of the requirements. They need a practical method for integrating those requirements into product design, development, testing, production, and delivery.
The series is organized into four parts.
The first part examines the risks facing equipment suppliers that have not yet begun preparing for UR E27.
Examines how requirements may become more stringent as shipyards and classification societies accumulate implementation experience, and why the current quiet period does not mean there will be no problems in the future.
Follows a hypothetical project scenario showing how inadequate UR E27 preparation can develop into commercial, technical, project, and management risks.
Explains how to assess applicability — Computer-Based System status, relation to Essential/Important Functions, network connectivity, and system integration — with a self-assessment checklist.
The second part addresses the certification and conformity-demonstration strategies that equipment suppliers ask about most frequently.
Compares the three in terms of purpose, scope of use, initial preparation burden, potential for reuse, implications of product changes, and use in class and shipyard projects.
A checklist and decision tree covering repeat delivery, standardization, customization, version management, test environment, and international market plans.
Compares four strategies, from continuing project-specific approval to pursuing TA from the outset, and when the shift to TA becomes worthwhile.
Perhaps the most important part of the series — most suppliers struggle with UR E27 because they try to create certification documents separately, after development is already complete.
Explains how engineering information generated through a single product-development process can be connected to multiple items of approval evidence, instead of being treated as separate documents.
Covers incorporating UR E27 activities into requirements definition, architecture, network design, development, and configuration management, with CRSI connecting the resulting evidence to class.
Covers items to verify during production and FAT — versions, default accounts, ports, logging, time sync, remote access, backup — with a checklist for expanding FAT into a cybersecurity verification activity.
The final part explains how to connect a prepared product and its supporting evidence to the actual approval and delivery process.
Clarifies each stakeholder's responsibilities — product security evidence, vessel-level integration, independent verification, and CRSI's supporting role — and what falls outside each role.
Identifies what to confirm at each stage — quotation, pre-contract, basic and detailed design, approval, FAT, delivery, integration — to reduce differences in interpretation.
Brings the overall process into a single master plan using a RACI framework across product, engineering, quality, sales, CRSI, and class roles.
What We Aim to Build Through This Series
After reading all 12 articles, readers should have more than an interpretation of the requirements. They should have four practical tools:
- ✓ UR E27 Applicability Checklist
- ✓ TA–SoC–SoF Decision Tree
- ✓ Engineering Lifecycle–Evidence Mapping
- ✓ UR E27 Master Schedule and RACI
Each tool can be used independently. When connected, however, the four tools form a Supplier UR E27 Readiness Kit that can help a company assess the current state of its product and establish both a certification strategy and an implementation plan.
This series will not answer only the question, "Which documents must we submit?" It will explain which product personnel should generate which source information, what should be added to existing processes, when to engage with the classification society, what to confirm with the shipyard, and how CRSI can contribute at each stage of the product lifecycle.
The Gap Between Prepared and Unprepared Products Will Continue to Grow
The application of UR E27 does not mean that every unprepared item of equipment will immediately disappear from the market. During the early stages, projects may accommodate various forms of corrective action, additional documentation, or conditional approval.
As the number of applicable projects increases and shipyards and classification societies accumulate experience, however, the requirements are likely to be incorporated more explicitly into contracts and purchasing specifications. At that point, supplier evaluations may increasingly consider not only product price and delivery time, but also cybersecurity functions, approval status, development processes, and change-management capabilities.
Suppliers that prepare early will be able to reuse certification evidence, respond quickly to shipyard queries, and systematically manage the impact of product changes on the approval scope. Suppliers that wait until after winning a project will need to address product deficiencies, produce documents, conduct testing, and respond to class — all within a constrained project schedule. Even under the same UR E27 requirements, the cost and project risk can vary significantly depending on when preparation begins.
The right starting point for UR E27 is not the day a certification application is submitted. It is the moment a supplier determines how its product relates to UR E27 and identifies the gaps in its current design and development system.
UR E27 is already being applied — so why have many equipment suppliers still not felt its impact?
IT/OT Integrated Cybersecurity specialist with expertise in IACS UR E26/E27 compliance, N2SF, Cybersecurity Strategy & Governance, BPR, and Digital Transformation. Former IT Consultant at KPMG (2019–2022). M.S. Information Systems, University of Maryland, Robert H. Smith School of Business.
⚓ Join the ShipPaulJobs Community
Join →

I see UR E27 less as a class compliance exercise and more as a supply-chain capability test.
ReplyDeleteIf a supplier can only provide a certificate but cannot demonstrate how cybersecurity controls are actually implemented and verified, are we really E27-ready?
For me, supplier readiness starts long before class approval — at design, procurement and system integration.