The Next Decade of Maritime Cyber Regulation, Read Through Five Stages of Environmental Rules
Ballast water, EEDI, CII and the EU ETS took thirty years to move from guidelines to money. If cyber regulation follows the same five stages, the direction is readable. The timing is not — and this is a forecast, not a fact.
- LinkedIn : https://www.linkedin.com/in/abysstoinfinity
In shipping, the longest record of regulation creating a market belongs to environmental rules. Cyber regulation has just entered the second of the five stages that record describes. This article extracts the pattern, places cyber on it, and sets out fast, base and slow scenarios for what may follow. Parts 1 and 2 are verified record. Everything from Part 3 onward is forecast and assumption built on that record.
The longest record of regulation creating a market in shipping
In the thirty-odd years since the IMO Assembly adopted ballast water guidelines in 1993 (resolution A.774(18)), environmental regulation has shifted its centre of gravity from recommendation to convention, from newbuildings to existing ships, from equipment to data, and from data to money. Along the way it produced, in turn, a ballast water treatment system (BWMS) retrofit market, a scrubber market, an emissions data verification market and an emissions allowance market.
Cyber regulation has just entered its second stage. IACS Unified Requirements UR E26/E27 became mandatory for newbuildings contracted on or after 1 July 2024, and in 2026 the IMO began work on a non-mandatory Maritime Cyber Code. There is no guarantee that regulatory patterns repeat. But if they do, the past thirty years of environmental regulation are a useful map for reading the next ten years of cyber.
Part 1 — The five-stage pattern of environmental regulation
Divide the progress of environmental regulation into stages and five appear. Each has real cases and dates.
| Stage | What it is | Cases and dates |
|---|---|---|
| 1. Guidelines | Recommendation, voluntary | Ballast water guidelines 1993 (A.774(18)) and 1997 (A.868(20)); GHG policy resolution 2003 (A.963(23)); voluntary EEOI 2009 |
| 2. Mandatory for newbuildings | New ships only, by contract or build date | EEDI in force 1 Jan 2013 (adopted July 2011); BWM Convention in force 8 Sep 2017 — keel laid on or after that date meets D-2 at delivery |
| 3. Retroactive to existing ships | Retrofit obligation timed to surveys | BWMS for existing ships from first IOPP renewal after 8 Sep 2019, completed 8 Sep 2024; EEXI 1 Jan 2023; 0.50% sulphur 1 Jan 2020 (scrubber retrofit wave) |
| 4. Operational reporting and rating | Annual measurement, reporting, verification; ratings with commercial consequences | EU MRV from 1 Jan 2018; IMO DCS 1 Jan 2019; CII rating from 2023 (first ratings 2024) |
| 5. Economic instruments | Allowances, levies, fuel rules; money directly at stake | EU ETS for shipping 1 Jan 2024 (40% → 70% → 100%); FuelEU Maritime 1 Jan 2025; IMO Net-Zero Framework (approved Apr 2025, adoption vote postponed to Oct 2026) |
The time between stages
The higher the stage, the bigger the market, and the less it depends on the cycle
More important than the time is the change in the nature of the money.
Part 2 — Where maritime cyber regulation stands today: UR E26/E27 is stage 2
Apply the same frame to cyber and its current position becomes clear. One difference must be noted first: for cyber, shipboard technical requirements and shore-side management requirements are at different stages.
Stage 1 — IMO guidelines (2017–)
In 2017, resolution MSC.428(98) encouraged administrations to address cyber risks within the safety management system under the ISM Code, no later than the first annual verification of the Document of Compliance after 1 January 2021. The companion guidance MSC-FAL.1/Circ.3 reached Rev.3 in April 2025. It is a management-system requirement with no technical content.
There is a notable new development. In February 2026 the 27 EU member states and the Commission jointly proposed to FAL 50 the development of a non-mandatory, goal-based Maritime Cyber Code, and in May 2026 MSC 111 approved a FAL-led roadmap targeting completion in 2028 (FAL 52). The proposal keeps the code non-mandatory but states that, after an experience-building phase, member states should reconsider whether to make it mandatory. That is the first step on the same path by which the ballast water guidelines (1993, 1997) became a convention (2004).
Stage 2 — IACS UR E26/E27 (July 2024–): here and now
UR E26 (ship level) and E27 (system and equipment level) apply mandatorily to newbuildings contracted on or after 1 July 2024. For existing ships they are recommendatory, per ClassNK and ABS guidance. This corresponds exactly to the EEDI stage of environmental regulation.
Tools for existing ships are already on sale. DNV issued its Cyber Secure (Basic) notation for ships in operation in July 2018; ABS introduced CR-Ex, applying UR E26 elements to existing ships, in June 2025 and awarded the first one in September. IACS Recommendation No. 166 (April 2020) addressed cyber resilience across the ship's life. Products arriving before the rule is the same pattern as the sixty-odd type-approved BWMS systems that were ready before the convention entered into force.
Partly ahead — shore and management systems are entering stages 3–4
Read through this frame: shipboard technical requirements at stage 2, shore and management systems at the threshold of stages 3–4, and the IMO has just drawn the roadmap from stage 1 to stage 2. That is as far as the verifiable present goes. From here on, this is forecast.
Part 3 — Forecast: how the cyber regulation market may progress (base scenario)
The years below are a base scenario produced by applying the stage-to-stage intervals of environmental regulation directly to cyber. Faster and slower cases are treated separately in Part 4.
Stage 2 settles in — bottlenecks and disputes over interpretation
"Passing the compliance gate is itself the product."
Newbuildings contracted after July 2024 begin delivering in earnest from 2026–2027. This period looks likely to accumulate differences in interpretation between class societies, suppliers unprepared for E27, and delayed sea trials. Industry material already notes that most suppliers have yet to obtain type approval and that the burden concentrates on system integrators and shipyards; IACS has acknowledged the need to standardise survey requirements. The picture will probably resemble the first three or four years of EEDI.
In parallel, the draft IMO Maritime Cyber Code is scheduled to take shape (2027 correspondence and working groups → FAL 52 in 2028). How its goals and functional requirements are written will, in our view, strongly shape stages 3 and 4.
Stage 3, retroactivity to existing ships — why we think it is likely
"Newbuildings are led by yards. Retrofits are ordered by owners and managers."
There are three reasons to expect that retroactivity will come at some point. None of them is a document that confirms it.
We assume political resistance would be smaller than for environmental rules, because a BWMS cost USD 0.5–3 million per ship while segmentation, access control and monitoring cost less and carry a security rationale. This is an estimate; how owners' associations respond will only be known when an actual proposal appears. The form seems more likely to be specific ship types, ports of call or flags than blanket retroactivity — a USCG-style port-state requirement first, the EU following. In ballast water, too, the USCG final rule (2012) preceded the IMO convention (2017) by five years.
If that assumption holds, the market becomes a retrofit wave: demand to install segmentation, access control, logging and remote-access controls on tens of thousands of existing ships, arriving on the survey cycle as BWMS retrofits did in 2019–2024. For cyber system integrators this could be the largest market. Whether it reaches BWMS scale depends on the level of the requirement and cannot be known today.
Stage 4, operational monitoring, reporting and rating
"The drivers are more likely to be insurers and charterers than the IMO."
Four forms are expected: incident reporting obligations (already in USCG and NIS2), log retention, vulnerability-management status reporting, and a cyber rating. The first three already partly exist; the rating does not. Just as CII's A–E ratings reached the charter market — BIMCO issued its CII Operations Clause in November 2022 — a cyber maturity score demanded by insurers, class and charterers could emerge. Unlike CII, however, there is no agreed standard of what to measure, and that is a major variable.
If this stage arrives, the market becomes annual recurring services: monitoring, verification and reporting platforms, structurally similar to the DCS/MRV verification market. Post-delivery operating contracts could be formed here.
Stage 5, economic instruments — the most uncertain
"Cyber has no 'cyber emissions.' The market, not the regulator, would have to make the price."
Environmental regulation had a measurable quantity, which made allowances possible. Cyber has none, so we think an allowance-type market is unlikely. Instead, differentiated premiums, financing terms and charter rates could play the role: a poorly rated ship pays more to insure and is harder to charter. Because the market rather than regulation would make this, it may also never form. The only reference is that CII's commercial effect appeared in charter contracts and bank loan conditions before it appeared in IMO rules.
Geopolitics could pull the timing forward. In May 2025 MSC Antonia grounded off Jeddah after GNSS spoofing, and threat-intelligence vendor CYTUR counted a doubling of maritime cyber incidents in 2025 (408 → 828) on its own platform — a single-vendor tally best read as a trend only. If sanctions, blockades, GPS interference and ship hacking increase, states could attach cyber requirements to port entry. Unlike environmental regulation, this is a field where a single incident could pull the schedule forward considerably. Conversely, without incidents this stage may never come.
Part 4 — Widening the timing: fast, base and slow scenarios
The years in Part 3 are the base scenario. Split each stage into fast, base and slow cases and set the accelerators and brakes beside them.
| Stage | Fast | Base | Slow | Accelerators | Brakes |
|---|---|---|---|---|---|
| 3. Existing-ship retroactivity | 2027–2029 | 2029–2032 | 2033–2036 | A major cyber incident involving a ship; tighter PSC amid US–China tension; insurers making cyber a condition of cover | Owner-association pushback; IMO consensus delays; cost-versus-benefit disputes over retrofits |
| 4. Operational monitoring and rating | 2029–2031 | 2032–2035 | 2036–2040 | Technical verification entering vetting (SIRE, RISQ); insurer rating demands; expanded USCG and EU incident reporting | Failure to standardise metrics; fatigue from fragmentation |
| 5. Economic differentiation | 2031–2034 | 2035–2040 | After 2040, or never | Accumulated insured losses; banks reflecting cyber in collateral assessment | If incidents stay rare, the market has no reason to differentiate |
How to read it
The fast scenario is most likely to be made by a single incident. Environmental regulation offers such cases. In these three, incident to regulatory amendment took one to two years. Not every incident changed regulation, of course.
Events that might play that role in cyber include a large container ship or LNG carrier taken out of service, a port paralysed, or a ship hacked with a military background. The MSC Antonia grounding in May 2025 did not change regulation. The same type of incident combined with loss of life or environmental damage could change the situation, but when such an incident might happen, and whether it would lead to regulation even then, cannot be known.
The slow scenario is when incidents keep not happening. Unlike the environment, ships keep sailing perfectly well without cyber regulation, so "why must we do this?" will keep being asked. The IMO code stays non-mandatory for a long time and the market may find no reason to build a rating. The probability of this scenario is by no means low. It is the same picture as the ballast water convention waiting thirteen years between adoption (2004) and entry into force (2017).
The base scenario assumes the United States and the EU push first through port state control and the IMO follows. It borrows the 2010s pattern in which the USCG ballast water rule (2012) preceded the IMO convention (2017) by five years and EU MRV (2018) preceded IMO DCS (2019) by a year. In cyber, the USCG rule (2025) and the EU's IMO code proposal (2026) have so far moved in that order, but whether they continue to do so remains to be seen.
Part 5 — Where cyber differs from environmental regulation (the uncertainty of the forecast)
There are at least three points where copying the frame directly is likely to be wrong. If the forecast misses, it will probably miss here.
Part 6 — What it means for business: do not try to time it
If the forecast is this uncertain, how should it be used? Reading the timing broadly does not mean giving up on forecasting; it means preferring choices that do not lose badly in any scenario. Sorted into three groups:
Design a retrofit product; pilot with one or two owners
Pilot a post-delivery monitoring service
Build insurer and charterer networks
Recoverable in the newbuilding market even in the slow case
Large-scale monitoring platform investment
Defer until signals confirm; prepare partners and the blueprint only, so scaling can be quick
Carbon regulation is already at stage 5; its demand is comparatively certain
ETS, FuelEU and CII data capability would overlap with cyber stage 4 if it arrives
If stage 4 comes, the money is more likely in monitoring, verification and reporting services than in equipment.
Ratings are more likely to be made by insurers, charterers and cargo owners than by regulators.
Part 7 — A cyber regulation clock: five leading signals to check each quarter
Timing cannot be known in advance, but signals that suggest it is approaching can be chosen. We chose five and record each one's current reading. These are indicators of the author's choosing; others may serve better.
| # | Signal | Reading, Sep 2026 | What counts as "moved" |
|---|---|---|---|
| 1 | USCG enforcement and EU follow-on legislation | USCG rule in force (Jul 2025), plans due Jul 2027. IMO Maritime Cyber Code at draft stage, target 2028 | PSC detentions of foreign-flagged ships cite cyber deficiencies; debate on amending NIS2's vessel exclusion; technical requirements enter the draft code |
| 2 | Cyber items in charterer and vessel vetting | Already present — TMSA3 Element 13 (Apr 2017), SIRE 2.0 ch. 7.5 (Jan 2022), RightShip RISQ 3.2 Q12.7 (Nov 2025) — all at procedure and management-system level | Questions deepen into technical verification or class certification, and carry weight in scoring |
| 3 | P&I club and H&M insurer cyber cover conditions | P&I: International Group pooling does not exclude cyber (war and terrorism excepted). H&M: CL380/LMA5402 exclusion or LMA5403 cover. Sompo Japan's GNSS product carries a training condition (Aug 2026) | Multiple cases in P&I and H&M of cyber posture reflected in cover conditions or premium rating |
| 4 | Existing ships holding class cyber notations | No published fleet statistics. Individual cases only: DNV Cyber Secure (2018–), first ABS CR-Ex (Sep 2025), TEN shuttle tanker series (2025–2026) | Class publishes counts, or voluntary owner take-up for charter or insurance purposes becomes a recurring news item — readable as the pre-retroactivity stage |
| 5 | Publicly disclosed ship and port cyber incidents | NHL Stenden MCAD: more than 295 cumulative incidents. CYTUR: 828 in 2025 (single vendor) | Official statistics from reporting obligations (USCG, NIS2); ships taken out of service or casualties disclosed |
☑ One moving may be noise; two moving may be coincidence
☑ Update the readings every quarter, and revise the threshold itself as it goes
Direction and sequence have relative support: the same five steps repeated across ballast water, EEDI, CII and the EU ETS, and cyber has so far moved in the same order. Timing is close to guesswork: one incident could pull the schedule forward sharply, and without incidents some stages might never arrive. One industry's past does not guarantee another subject's future.
The years and scenarios here are not there to be right. They are there to organise what to watch — and if the signals move differently, this forecast should be rewritten.
Principal sources
This article is analysis and forecast based on public sources as of September 2026. Dates and figures for future stages are the author's assumptions, not regulatory facts. It does not constitute legal, compliance or investment advice.
Owner-side maritime cybersecurity advisor covering IACS UR E26/E27 compliance, zone and conduit design, and OT/IT security architecture for commercial vessels — working across LR, ClassNK, DNV, ABS, and BV newbuilding projects.
🌐 More Articles ↗⚓ Join the ShipPaulJobs Community
Join →
Excellent analysis of the next phase of maritime cyber regulation.
ReplyDeleteOne particularly important direction is the shift from newbuilding compliance toward lifecycle cyber resilience for existing vessels.
This connects directly with the practical implementation of IACS UR E26/E27 and the emerging interaction between class requirements and national cyber regulations.
Related practical insights:
🔹 IACS E26/E27 Compliance Guide
🔹 USCG Cybersecurity Rule & E26/E27
The next decade may be less about individual compliance requirements and more about continuous cyber resilience across the vessel lifecycle.