Maritime Compliance
Guidance on IACS UR E26/E27, IMO regulations, classification society requirements, and cybersecurity standards shaping global shipbuilding and vessel operations — organized by topic.
This hub tracks the key international and regional frameworks governing maritime cybersecurity and vessel compliance. Content is reviewed by credentialed maritime cyber professionals and aligned with primary regulatory sources.
Last reviewed: September 2026 | Editorial & Verification Policy
Regulatory Framework at a Glance
Mandatory for newbuildings contracted on or after 1 July 2024. Covers shipboard OT/IT system requirements, network segmentation, and supplier cyber obligations.
→ Official IACS UR E26 ↗Companion to E26. Sets security requirements for software, hardware, and system integrators supplying equipment to class-surveyed vessels.
→ Official IACS UR E27 ↗IMO guidelines requiring cyber risk to be addressed in Safety Management Systems (SMS) under the ISM Code. The official IMO source currently identifies Rev.3 as the Guidelines on Maritime Cyber Risk Management. Rev.2 (2021) established the foundational ISM Code integration deadline.
→ IMO Cybersecurity ↗U.S. Coast Guard navigation circular establishing cyber risk assessment and response expectations for vessels operating in U.S. waters and ports.
→ USCG NVIC ↗EU-wide cybersecurity regulation effective October 2024. Applies to maritime transport operators in EU member states as a critical infrastructure sector.
→ NIS2 Official Text ↗Mandatory since 2004 under SOLAS Chapter XI-2. Requires Ship Security Plans (SSP), Ship Security Officers (SSO), and port facility assessments.
→ IMO ISPS ↗IACS UR E26 vs UR E27 — Key Differences
| Aspect | UR E26 (Ships) | UR E27 (Systems & Equipment) |
|---|---|---|
| Who it targets | Shipowners, shipyards, class societies | Equipment manufacturers, system integrators |
| Scope | Vessel-level cyber resilience requirements | Component/system-level security requirements |
| Effective date | Newbuilds contracted ≥ 1 Jul 2024 | Same — aligned with E26 |
| Key obligation | Cyber Risk Assessment, network segmentation, access control | Secure software development, vulnerability disclosure, patch management |
| Linked standard | IEC 62443-2-1, ISM Code | IEC 62443-4-1, IEC 62443-4-2 |
| Class survey impact | Required for plan approval & survey | Type approval of equipment |
Frequently Asked Questions — Maritime Compliance & Cybersecurity Regulations
What is IACS UR E26 and why does it matter for shipbuilding?
IACS Unified Requirement E26 establishes mandatory cyber resilience standards for ships contracted on or after 1 July 2024. It requires shipowners and yards to implement risk assessments, network segmentation, access controls, and incident response plans as a condition of class. Non-compliance means a vessel cannot receive class approval from any of the 12 IACS member societies — effectively blocking market entry. See the official IACS UR E26 text ↗.
How does IACS UR E27 differ from UR E26?
While UR E26 addresses vessel-level cyber resilience (the shipowner/shipyard perspective), UR E27 targets equipment manufacturers and system integrators. UR E27 requires suppliers to follow a secure-by-design approach aligned with IEC 62443-4-1/4-2, provide vulnerability disclosure processes, and support patch management throughout the product lifecycle. A vessel's UR E26 compliance depends directly on its suppliers meeting UR E27 — the two requirements are architecturally linked.
Is IMO MSC-FAL.1/Circ.3 still in force, or has it been superseded?
The official IMO source currently identifies MSC-FAL.1/Circ.3/Rev.3 as its Guidelines on Maritime Cyber Risk Management. It specifies that cyber risks must be addressed within a ship's Safety Management System (SMS) under the ISM Code. Flag states and port state control (PSC) officers reference it during inspections. Rev.2 (2021) established the original ISM Code integration requirement and remains a key historical reference. A Rev.4 document (dated 28 May 2026) is analysed in a dedicated article on this site — see MSC-FAL.1/Circ.3/Rev.4: What Has Changed? ↗ — however, current document status and applicability should be verified against the official IMO source ↗.
Does the EU NIS2 Directive apply to ships and shipping companies?
Yes — NIS2 (Directive 2022/2555, effective October 2024) classifies maritime transport as a critical infrastructure sector. EU-based shipping companies operating ferry services, cargo routes, or port facilities meeting the size thresholds (≥50 employees or €10M annual turnover) are "essential entities" subject to mandatory incident reporting, risk management obligations, and executive liability. Companies operating outside the EU but serving EU ports may be indirectly affected through their EU-based subsidiaries or contractual partners.
What does the USCG NVIC 01-20 require for vessels in U.S. waters?
USCG Navigation and Vessel Inspection Circular 01-20 provides a voluntary but expected framework for cyber risk management for vessels and facilities regulated under 33 CFR Parts 104–106. It aligns with the NIST Cybersecurity Framework and requires operators to identify OT/IT assets, assess cyber risks, develop and test cyber incident response plans, and report significant cyber incidents to the National Response Center. USCG marine inspectors use it as a benchmark during facility safety audits.
How do IACS, IMO, and flag state requirements interact?
IACS URs apply through classification — they are private-sector technical standards that all 12 major class societies have agreed to enforce uniformly. IMO instruments (including SOLAS and the ISM Code) are international law ratified by flag states. Flag states translate IMO obligations into domestic law and enforce them during surveys; class societies often act as Recognized Organizations (ROs) on behalf of flag states. In practice, a modern vessel must satisfy all three layers: class requirements (IACS), flag state law (IMO-derived), and — for vessels calling specific ports — coastal state regulations (USCG, NIS2, etc.).