💡 Regulatory Outlook IACS UR E26/E27 Scenarios 2026–2040 Owners · Yards · Insurers

The Next Decade of Maritime Cyber Regulation, Read Through Five Stages of Environmental Rules

Ballast water, EEDI, CII and the EU ETS took thirty years to move from guidelines to money. If cyber regulation follows the same five stages, the direction is readable. The timing is not — and this is a forecast, not a fact.

Julius
Julius
Maritime Technical Consultant · Shipboard Cybersecurity & Compliance
- LinkedIn : https://www.linkedin.com/in/abysstoinfinity

In shipping, the longest record of regulation creating a market belongs to environmental rules. Cyber regulation has just entered the second of the five stages that record describes. This article extracts the pattern, places cyber on it, and sets out fast, base and slow scenarios for what may follow. Parts 1 and 2 are verified record. Everything from Part 3 onward is forecast and assumption built on that record.

5-stage pattern from 30 years of environmental rules UR E26/E27 = the EEDI moment Retrofit wave: base case 2029–2032 3 scenarios: fast · base · slow 5 leading signals, checked quarterly Forecast, not fact

The longest record of regulation creating a market in shipping

In the thirty-odd years since the IMO Assembly adopted ballast water guidelines in 1993 (resolution A.774(18)), environmental regulation has shifted its centre of gravity from recommendation to convention, from newbuildings to existing ships, from equipment to data, and from data to money. Along the way it produced, in turn, a ballast water treatment system (BWMS) retrofit market, a scrubber market, an emissions data verification market and an emissions allowance market.

Cyber regulation has just entered its second stage. IACS Unified Requirements UR E26/E27 became mandatory for newbuildings contracted on or after 1 July 2024, and in 2026 the IMO began work on a non-mandatory Maritime Cyber Code. There is no guarantee that regulatory patterns repeat. But if they do, the past thirty years of environmental regulation are a useful map for reading the next ten years of cyber.

Within the forecast, the direction and sequence have reasonable support; the timing must be read broadly and may well be wrong. Environmental regulation itself mixed steps that took more than twenty years with steps that arrived in two.

Part 1 — The five-stage pattern of environmental regulation

Divide the progress of environmental regulation into stages and five appear. Each has real cases and dates.

Stage What it is Cases and dates
1. Guidelines Recommendation, voluntary Ballast water guidelines 1993 (A.774(18)) and 1997 (A.868(20)); GHG policy resolution 2003 (A.963(23)); voluntary EEOI 2009
2. Mandatory for newbuildings New ships only, by contract or build date EEDI in force 1 Jan 2013 (adopted July 2011); BWM Convention in force 8 Sep 2017 — keel laid on or after that date meets D-2 at delivery
3. Retroactive to existing ships Retrofit obligation timed to surveys BWMS for existing ships from first IOPP renewal after 8 Sep 2019, completed 8 Sep 2024; EEXI 1 Jan 2023; 0.50% sulphur 1 Jan 2020 (scrubber retrofit wave)
4. Operational reporting and rating Annual measurement, reporting, verification; ratings with commercial consequences EU MRV from 1 Jan 2018; IMO DCS 1 Jan 2019; CII rating from 2023 (first ratings 2024)
5. Economic instruments Allowances, levies, fuel rules; money directly at stake EU ETS for shipping 1 Jan 2024 (40% → 70% → 100%); FuelEU Maritime 1 Jan 2025; IMO Net-Zero Framework (approved Apr 2025, adoption vote postponed to Oct 2026)

The time between stages

1 → 2 (guidelines to newbuilding mandate): 10–24 years. GHG took ten years from the 2003 resolution to EEDI in 2013. Ballast water took eleven years to convention adoption and twenty-four to entry into force. New convention versus annex amendment made the difference.
2 → 3 (newbuilding mandate to existing ships): 2–10 years. Ballast water, two years (2017 to 2019). EEDI to EEXI, ten (2013 to 2023). Sulphur 2020 skipped the newbuilding stage and hit the whole fleet at once.
3 → 4 (existing ships to reporting and rating): almost simultaneous. EEXI and CII came in the same resolution (MEPC.328(76)). Data reporting (DCS 2019, MRV 2018) actually arrived before the technical rules for existing ships.
4 → 5 (reporting to economic instruments): 5–6 years. MRV 2018 to EU ETS for shipping 2024. From IMO DCS in 2019, the IMO carbon price is still not adopted.

The higher the stage, the bigger the market, and the less it depends on the cycle

More important than the time is the change in the nature of the money.

Stages 2–3: equipment sales
At newbuilding the yard orders and the market rides the newbuilding cycle. Retroactivity brings an owner-ordered retrofit wave. DNV GL estimated in 2019 that roughly 30,000 ships needed a BWMS at USD 0.5–3 million each; by March 2020, 4,014 ships had scrubbers installed or on order, 2,960 of them retrofits.
Stage 4: data and services
Annual, repeating measurement, reporting and verification. EU MRV and IMO DCS make owners pay verifiers and reporting platforms every year, regardless of the newbuilding cycle.
Stage 5: finance and trading
EU ETS requires allowances for 40% of 2024 emissions, 70% of 2025 and 100% of 2026. FuelEU Maritime penalises non-compliance at EUR 2,400 per tonne of VLSFO-equivalent energy. Regulation becomes cost.
These three shifts in the nature of the money are the assumptions on which the rest of this forecast rests. Whether cyber regulation will take the same road, nobody yet knows.

Part 2 — Where maritime cyber regulation stands today: UR E26/E27 is stage 2

Apply the same frame to cyber and its current position becomes clear. One difference must be noted first: for cyber, shipboard technical requirements and shore-side management requirements are at different stages.

Stage 1 — IMO guidelines (2017–)

In 2017, resolution MSC.428(98) encouraged administrations to address cyber risks within the safety management system under the ISM Code, no later than the first annual verification of the Document of Compliance after 1 January 2021. The companion guidance MSC-FAL.1/Circ.3 reached Rev.3 in April 2025. It is a management-system requirement with no technical content.

There is a notable new development. In February 2026 the 27 EU member states and the Commission jointly proposed to FAL 50 the development of a non-mandatory, goal-based Maritime Cyber Code, and in May 2026 MSC 111 approved a FAL-led roadmap targeting completion in 2028 (FAL 52). The proposal keeps the code non-mandatory but states that, after an experience-building phase, member states should reconsider whether to make it mandatory. That is the first step on the same path by which the ballast water guidelines (1993, 1997) became a convention (2004).

Stage 2 — IACS UR E26/E27 (July 2024–): here and now

UR E26 (ship level) and E27 (system and equipment level) apply mandatorily to newbuildings contracted on or after 1 July 2024. For existing ships they are recommendatory, per ClassNK and ABS guidance. This corresponds exactly to the EEDI stage of environmental regulation.

Tools for existing ships are already on sale. DNV issued its Cyber Secure (Basic) notation for ships in operation in July 2018; ABS introduced CR-Ex, applying UR E26 elements to existing ships, in June 2025 and awarded the first one in September. IACS Recommendation No. 166 (April 2020) addressed cyber resilience across the ship's life. Products arriving before the rule is the same pattern as the sixty-odd type-approved BWMS systems that were ready before the convention entered into force.

Partly ahead — shore and management systems are entering stages 3–4

USCG cybersecurity rule (33 CFR Part 101 Subpart F, published 17 Jan 2025, effective 16 Jul 2025) requires US-flagged vessels, MTSA-regulated facilities and OCS facilities to designate a Cybersecurity Officer, assess and plan, train, and report incidents. Plans are due by 16 July 2027. Foreign-flagged vessels are excluded; the USCG has checked ISM cyber implementation through port state control since January 2021. As of September 2026 no publication confirming the discussed 2–5 year delay for US-flagged ships could be found.
EU NIS2 treats shipping companies as essential entities but explicitly excludes the individual vessels they operate. It brings shore-side risk management, 24-hour / 72-hour / one-month incident reporting and management accountability, but no shipboard technical requirement.
Insurer and charterer vetting: the OCIMF SIRE 2.0 question library (v1.0, January 2022) already has a chapter 7.5 Cyber Security, and question 7.5.1 asks whether the master and officers know and apply the company's cyber risk procedures. It checks procedure, not technology, but cyber being in charterer vetting at all is the seed of stage 4.

Read through this frame: shipboard technical requirements at stage 2, shore and management systems at the threshold of stages 3–4, and the IMO has just drawn the roadmap from stage 1 to stage 2. That is as far as the verifiable present goes. From here on, this is forecast.


Part 3 — Forecast: how the cyber regulation market may progress (base scenario)

The years below are a base scenario produced by applying the stage-to-stage intervals of environmental regulation directly to cyber. Faster and slower cases are treated separately in Part 4.

2026–2028

Stage 2 settles in — bottlenecks and disputes over interpretation

"Passing the compliance gate is itself the product."

Newbuildings contracted after July 2024 begin delivering in earnest from 2026–2027. This period looks likely to accumulate differences in interpretation between class societies, suppliers unprepared for E27, and delayed sea trials. Industry material already notes that most suppliers have yet to obtain type approval and that the burden concentrates on system integrators and shipyards; IACS has acknowledged the need to standardise survey requirements. The picture will probably resemble the first three or four years of EEDI.

In parallel, the draft IMO Maritime Cyber Code is scheduled to take shape (2027 correspondence and working groups → FAL 52 in 2028). How its goals and functional requirements are written will, in our view, strongly shape stages 3 and 4.

2028–2032

Stage 3, retroactivity to existing ships — why we think it is likely

"Newbuildings are led by yards. Retrofits are ordered by owners and managers."

There are three reasons to expect that retroactivity will come at some point. None of them is a document that confirms it.

· The ISM Code already places a management requirement on existing ships (MSC.428(98)). Adding a technical requirement where a management requirement exists should be easier than creating a new regulation.
· The USCG rule covers existing US-flagged ships and checks foreign-flagged ships through PSC. The port-state route has generally been faster than an IMO convention.
· Class societies already sell existing-ship notations (DNV Cyber Secure Basic, ABS CR-Ex), and the IMO code proposal itself writes in a "reconsider mandatory status after experience-building" step.

We assume political resistance would be smaller than for environmental rules, because a BWMS cost USD 0.5–3 million per ship while segmentation, access control and monitoring cost less and carry a security rationale. This is an estimate; how owners' associations respond will only be known when an actual proposal appears. The form seems more likely to be specific ship types, ports of call or flags than blanket retroactivity — a USCG-style port-state requirement first, the EU following. In ballast water, too, the USCG final rule (2012) preceded the IMO convention (2017) by five years.

If that assumption holds, the market becomes a retrofit wave: demand to install segmentation, access control, logging and remote-access controls on tens of thousands of existing ships, arriving on the survey cycle as BWMS retrofits did in 2019–2024. For cyber system integrators this could be the largest market. Whether it reaches BWMS scale depends on the level of the requirement and cannot be known today.

2030–2035

Stage 4, operational monitoring, reporting and rating

"The drivers are more likely to be insurers and charterers than the IMO."

Four forms are expected: incident reporting obligations (already in USCG and NIS2), log retention, vulnerability-management status reporting, and a cyber rating. The first three already partly exist; the rating does not. Just as CII's A–E ratings reached the charter market — BIMCO issued its CII Operations Clause in November 2022 — a cyber maturity score demanded by insurers, class and charterers could emerge. Unlike CII, however, there is no agreed standard of what to measure, and that is a major variable.

· The cyber exclusion CL380 (2003) is standard in hull insurance, and in November 2019 the LMA separated exclusion (LMA5402) from non-malicious cover (LMA5403). The structure that would let insurers demand a ship's cyber posture as a condition of cover is in place. Whether they use it depends on loss experience.
· According to press reports, in August 2026 Sompo Japan launched a GNSS-interference product with completion of ClassNK Academy cyber training by crew as a condition of cover. An early case of insurance commercially requiring a cyber measure — still a single product, too early to call a trend.
· SIRE 2.0 already contains question 7.5.1. If it deepens from procedure check to technical verification and is converted into a rating, it could become a de facto cyber CII. Whether it does depends on the charterers.

If this stage arrives, the market becomes annual recurring services: monitoring, verification and reporting platforms, structurally similar to the DCS/MRV verification market. Post-delivery operating contracts could be formed here.

2035 and beyond

Stage 5, economic instruments — the most uncertain

"Cyber has no 'cyber emissions.' The market, not the regulator, would have to make the price."

Environmental regulation had a measurable quantity, which made allowances possible. Cyber has none, so we think an allowance-type market is unlikely. Instead, differentiated premiums, financing terms and charter rates could play the role: a poorly rated ship pays more to insure and is harder to charter. Because the market rather than regulation would make this, it may also never form. The only reference is that CII's commercial effect appeared in charter contracts and bank loan conditions before it appeared in IMO rules.

Geopolitics could pull the timing forward. In May 2025 MSC Antonia grounded off Jeddah after GNSS spoofing, and threat-intelligence vendor CYTUR counted a doubling of maritime cyber incidents in 2025 (408 → 828) on its own platform — a single-vendor tally best read as a trend only. If sanctions, blockades, GPS interference and ship hacking increase, states could attach cyber requirements to port entry. Unlike environmental regulation, this is a field where a single incident could pull the schedule forward considerably. Conversely, without incidents this stage may never come.


Part 4 — Widening the timing: fast, base and slow scenarios

The years in Part 3 are the base scenario. Split each stage into fast, base and slow cases and set the accelerators and brakes beside them.

Stage Fast Base Slow Accelerators Brakes
3. Existing-ship retroactivity 2027–2029 2029–2032 2033–2036 A major cyber incident involving a ship; tighter PSC amid US–China tension; insurers making cyber a condition of cover Owner-association pushback; IMO consensus delays; cost-versus-benefit disputes over retrofits
4. Operational monitoring and rating 2029–2031 2032–2035 2036–2040 Technical verification entering vetting (SIRE, RISQ); insurer rating demands; expanded USCG and EU incident reporting Failure to standardise metrics; fatigue from fragmentation
5. Economic differentiation 2031–2034 2035–2040 After 2040, or never Accumulated insured losses; banks reflecting cyber in collateral assessment If incidents stay rare, the market has no reason to differentiate

How to read it

The fast scenario is most likely to be made by a single incident. Environmental regulation offers such cases. In these three, incident to regulatory amendment took one to two years. Not every incident changed regulation, of course.

Exxon Valdez · Mar 1989 OPA 90 · double hulls, phase-out from 1995 MARPOL 13F · 1992
Erika · Dec 1999 MARPOL 13G amended · Apr 2001, accelerated single-hull phase-out
Prestige · Nov 2002 EU-15 proposal · Apr 2003 13G amended · Dec 2003, HGO ban 2005, phase-out 2010

Events that might play that role in cyber include a large container ship or LNG carrier taken out of service, a port paralysed, or a ship hacked with a military background. The MSC Antonia grounding in May 2025 did not change regulation. The same type of incident combined with loss of life or environmental damage could change the situation, but when such an incident might happen, and whether it would lead to regulation even then, cannot be known.

The slow scenario is when incidents keep not happening. Unlike the environment, ships keep sailing perfectly well without cyber regulation, so "why must we do this?" will keep being asked. The IMO code stays non-mandatory for a long time and the market may find no reason to build a rating. The probability of this scenario is by no means low. It is the same picture as the ballast water convention waiting thirteen years between adoption (2004) and entry into force (2017).

The base scenario assumes the United States and the EU push first through port state control and the IMO follows. It borrows the 2010s pattern in which the USCG ballast water rule (2012) preceded the IMO convention (2017) by five years and EU MRV (2018) preceded IMO DCS (2019) by a year. In cyber, the USCG rule (2025) and the EU's IMO code proposal (2026) have so far moved in that order, but whether they continue to do so remains to be seen.


Part 5 — Where cyber differs from environmental regulation (the uncertainty of the forecast)

There are at least three points where copying the frame directly is likely to be wrong. If the forecast misses, it will probably miss here.

? The nature of the political driver. Environmental regulation had a sustained, predictable driver: climate. Cyber has a security driver instead, which reacts to events irregularly. Political drivers can retreat, as the IMO carbon price did when its October 2025 vote was postponed; a security driver may accelerate sharply after one incident, or stay quiet for a long time. This is the biggest reason timing is hard to forecast.
? The difficulty of inspection. A scrubber is either there or it is not. Cyber is hard for a surveyor to confirm, so we think a third-party verification and certification market could grow larger than for the environment. The IMO code proposal's own admission that there is no structured framework for the human element points to the same problem.
? Fragmentation. Environmental regulation was a single IMO-centred system with MARPOL as the backbone. Cyber has the USCG, the EU (NIS2, CRA), flag states, IACS, the LMA and OCIMF each moving on their own. Fragmentation raises compliance cost and may create demand for advisory and integration work. Because the IMO code will be non-mandatory even in 2028, we expect fragmentation to persist for some time.

Part 6 — What it means for business: do not try to time it

If the forecast is this uncertain, how should it be used? Reading the timing broadly does not mean giving up on forecasting; it means preferring choices that do not lose badly in any scenario. Sorted into three groups:

Valid in every scenario
Deepen newbuilding SI capability
Design a retrofit product; pilot with one or two owners
Pilot a post-delivery monitoring service
Build insurer and charterer networks
Recoverable in the newbuilding market even in the slow case
Only in the fast scenario
Mass hiring of retrofit staff
Large-scale monitoring platform investment
Defer until signals confirm; prepare partners and the blueprint only, so scaling can be quick
Hedging the slow scenario
Broaden into OT integration and regulatory data
Carbon regulation is already at stage 5; its demand is comparatively certain
ETS, FuelEU and CII data capability would overlap with cyber stage 4 if it arrives

If stage 4 comes, the money is more likely in monitoring, verification and reporting services than in equipment.

Ratings are more likely to be made by insurers, charterers and cargo owners than by regulators.


Part 7 — A cyber regulation clock: five leading signals to check each quarter

Timing cannot be known in advance, but signals that suggest it is approaching can be chosen. We chose five and record each one's current reading. These are indicators of the author's choosing; others may serve better.

# Signal Reading, Sep 2026 What counts as "moved"
1 USCG enforcement and EU follow-on legislation USCG rule in force (Jul 2025), plans due Jul 2027. IMO Maritime Cyber Code at draft stage, target 2028 PSC detentions of foreign-flagged ships cite cyber deficiencies; debate on amending NIS2's vessel exclusion; technical requirements enter the draft code
2 Cyber items in charterer and vessel vetting Already present — TMSA3 Element 13 (Apr 2017), SIRE 2.0 ch. 7.5 (Jan 2022), RightShip RISQ 3.2 Q12.7 (Nov 2025) — all at procedure and management-system level Questions deepen into technical verification or class certification, and carry weight in scoring
3 P&I club and H&M insurer cyber cover conditions P&I: International Group pooling does not exclude cyber (war and terrorism excepted). H&M: CL380/LMA5402 exclusion or LMA5403 cover. Sompo Japan's GNSS product carries a training condition (Aug 2026) Multiple cases in P&I and H&M of cyber posture reflected in cover conditions or premium rating
4 Existing ships holding class cyber notations No published fleet statistics. Individual cases only: DNV Cyber Secure (2018–), first ABS CR-Ex (Sep 2025), TEN shuttle tanker series (2025–2026) Class publishes counts, or voluntary owner take-up for charter or insurance purposes becomes a recurring news item — readable as the pre-retroactivity stage
5 Publicly disclosed ship and port cyber incidents NHL Stenden MCAD: more than 295 cumulative incidents. CYTUR: 828 in 2025 (single vendor) Official statistics from reporting obligations (USCG, NIS2); ships taken out of service or casualties disclosed
☑ Two or more of the five move in the same direction within one quarter → suspect a tilt toward the fast scenario
☑ One moving may be noise; two moving may be coincidence
☑ Update the readings every quarter, and revise the threshold itself as it goes
Setting a threshold in advance reduces the temptation to fit the story after the fact.

Direction and sequence have relative support: the same five steps repeated across ballast water, EEDI, CII and the EU ETS, and cyber has so far moved in the same order. Timing is close to guesswork: one incident could pull the schedule forward sharply, and without incidents some stages might never arrive. One industry's past does not guarantee another subject's future.

The years and scenarios here are not there to be right. They are there to organise what to watch — and if the signals move differently, this forecast should be rewritten.

Principal sources

·IMO — BWM Convention and guidelines (A.774(18), A.868(20)); Implementing the BWM Convention; Historic Background GHG; A.963(23); MEPC.1/Circ.684; MEPC.203(62); MEPC.328(76) and EEXI/CII FAQ; MEPC 70 sulphur 2020; MEPC.278(70) DCS; Net-Zero Framework and MEPC/ES.2 (Oct 2025); Maritime cyber risk (MSC.428(98), MSC-FAL.1/Circ.3 Rev.3); Tanker safety (MARPOL 13F/13G)
·EUR-Lex — Regulation (EU) 2015/757 (MRV); Directive 2023/959 (ETS); Regulation (EU) 2023/1805 (FuelEU Maritime); Directive (EU) 2022/2555 (NIS2) Annex I; Council doc. 6080/26 / SWD(2026) 31 (Maritime Cyber Code proposal)
·Federal Register — 90 FR 6298 (USCG Cybersecurity in the MTS, 17 Jan 2025); 77 FR 17254 (USCG Ballast Water Discharge Standard, 23 Mar 2012)
·IACS — UR E26/E27 press release; Rec. No. 166 (Apr 2020). ABS Regulatory News; ABS/Offshore Magazine (CR-Ex, Sep 2025). ClassNK UR E26/27 guidance. DNV GL — Cyber Secure notation (Jul 2018); ballast water expert story (Sep 2019); FAL 50 and MSC 111 summaries. LR — FAL 50 Summary Report. Riviera Maritime Media — TEN shuttle tankers (2025)
·OCIMF — SIRE 2.0 Question Library Part 1 (Jan 2022); TMSA3 Fast Facts (Apr 2017). Safety4Sea / MaritimeCyprus — RightShip RISQ 3.2 (Nov 2025). IBA — BIMCO CII Clause (Nov 2022)
·Insurance — LMA Property and Marine Cyber Clauses LMA5402/5403 (Nov 2019); Lexology/IUA on CL380; UK P&I Club, West P&I and IG P&I on cyber cover and 2026/27 pooling; Britannia P&I on PSC cyber checks; Splash247 / (Re)in Asia / IndexBox on Sompo Japan (Aug 2026)
·Incidents and history — gCaptain / Inside GNSS (MSC Antonia, May 2025); Maritime Executive / Cyprus Mail (CYTUR 2026 white paper); NHL Stenden Maritime Cyber Attack Database; NOAA Office of Response and Restoration (single-hull phase-out); US House hearing record on OPA 90 double hulls; Steamship Mutual (post-Erika and post-Prestige phase-out); Offshore Energy citing DNV GL AFI (scrubbers, Mar 2020)

This article is analysis and forecast based on public sources as of September 2026. Dates and figures for future stages are the author's assumptions, not regulatory facts. It does not constitute legal, compliance or investment advice.

#MaritimeCybersecurity #IACSURE26 #URE27 #MaritimeRegulation #ShipRetrofit #CyberRating #IMOCyberCode
Julius
Julius
Maritime Technical Consultant · Shipboard Cybersecurity & Compliance

Owner-side maritime cybersecurity advisor covering IACS UR E26/E27 compliance, zone and conduit design, and OT/IT security architecture for commercial vessels — working across LR, ClassNK, DNV, ABS, and BV newbuilding projects.

🌐 More Articles ↗

⚓ Join the ShipPaulJobs Community

Join →
Share

Comments

  1. Excellent analysis of the next phase of maritime cyber regulation.

    One particularly important direction is the shift from newbuilding compliance toward lifecycle cyber resilience for existing vessels.

    This connects directly with the practical implementation of IACS UR E26/E27 and the emerging interaction between class requirements and national cyber regulations.

    Related practical insights:

    🔹 IACS E26/E27 Compliance Guide⁠
    🔹 USCG Cybersecurity Rule & E26/E27⁠

    The next decade may be less about individual compliance requirements and more about continuous cyber resilience across the vessel lifecycle.

    ReplyDelete

Post a Comment

Top Ranked · All Posts

Popular Posts