Maritime Compliance · Global Shipbuilding & Maritime Regulation

Maritime Compliance

Guidance on IACS UR E26/E27, IMO regulations, classification society requirements, and cybersecurity standards shaping global shipbuilding and vessel operations — organized by topic.

This hub tracks the key international and regional frameworks governing maritime cybersecurity and vessel compliance. Content is reviewed by credentialed maritime cyber professionals and aligned with primary regulatory sources.

Last reviewed: September 2026  |  Editorial & Verification Policy

Regulatory Framework at a Glance

IACS
UR E26 — Cyber Resilience of Ships

Mandatory for newbuildings contracted on or after 1 July 2024. Covers shipboard OT/IT system requirements, network segmentation, and supplier cyber obligations.

→ Official IACS UR E26 ↗
IACS
UR E27 — Cyber Resilience of On-board Systems

Companion to E26. Sets security requirements for software, hardware, and system integrators supplying equipment to class-surveyed vessels.

→ Official IACS UR E27 ↗
IMO
MSC-FAL.1/Circ.3 — Maritime Cyber Risk Management Guidelines

IMO guidelines requiring cyber risk to be addressed in Safety Management Systems (SMS) under the ISM Code. The official IMO source currently identifies Rev.3 as the Guidelines on Maritime Cyber Risk Management. Rev.2 (2021) established the foundational ISM Code integration deadline.

→ IMO Cybersecurity ↗
USCG
NVIC 01-20 — Cyber Strategies for Marine Transportation

U.S. Coast Guard navigation circular establishing cyber risk assessment and response expectations for vessels operating in U.S. waters and ports.

→ USCG NVIC ↗
EU
NIS2 Directive (2022/2555) — Network & Information Security

EU-wide cybersecurity regulation effective October 2024. Applies to maritime transport operators in EU member states as a critical infrastructure sector.

→ NIS2 Official Text ↗
IMO / SOLAS
ISPS Code — International Ship & Port Facility Security

Mandatory since 2004 under SOLAS Chapter XI-2. Requires Ship Security Plans (SSP), Ship Security Officers (SSO), and port facility assessments.

→ IMO ISPS ↗

IACS UR E26 vs UR E27 — Key Differences

AspectUR E26 (Ships)UR E27 (Systems & Equipment)
Who it targetsShipowners, shipyards, class societiesEquipment manufacturers, system integrators
ScopeVessel-level cyber resilience requirementsComponent/system-level security requirements
Effective dateNewbuilds contracted ≥ 1 Jul 2024Same — aligned with E26
Key obligationCyber Risk Assessment, network segmentation, access controlSecure software development, vulnerability disclosure, patch management
Linked standardIEC 62443-2-1, ISM CodeIEC 62443-4-1, IEC 62443-4-2
Class survey impactRequired for plan approval & surveyType approval of equipment
📡 Loading Maritime Compliance…
No posts tagged "Compliances" yet.
Most-viewed Maritime Compliance posts, ranked among recent articles
Counting views…

Frequently Asked Questions — Maritime Compliance & Cybersecurity Regulations

What is IACS UR E26 and why does it matter for shipbuilding?

IACS Unified Requirement E26 establishes mandatory cyber resilience standards for ships contracted on or after 1 July 2024. It requires shipowners and yards to implement risk assessments, network segmentation, access controls, and incident response plans as a condition of class. Non-compliance means a vessel cannot receive class approval from any of the 12 IACS member societies — effectively blocking market entry. See the official IACS UR E26 text ↗.

How does IACS UR E27 differ from UR E26?

While UR E26 addresses vessel-level cyber resilience (the shipowner/shipyard perspective), UR E27 targets equipment manufacturers and system integrators. UR E27 requires suppliers to follow a secure-by-design approach aligned with IEC 62443-4-1/4-2, provide vulnerability disclosure processes, and support patch management throughout the product lifecycle. A vessel's UR E26 compliance depends directly on its suppliers meeting UR E27 — the two requirements are architecturally linked.

Is IMO MSC-FAL.1/Circ.3 still in force, or has it been superseded?

The official IMO source currently identifies MSC-FAL.1/Circ.3/Rev.3 as its Guidelines on Maritime Cyber Risk Management. It specifies that cyber risks must be addressed within a ship's Safety Management System (SMS) under the ISM Code. Flag states and port state control (PSC) officers reference it during inspections. Rev.2 (2021) established the original ISM Code integration requirement and remains a key historical reference. A Rev.4 document (dated 28 May 2026) is analysed in a dedicated article on this site — see MSC-FAL.1/Circ.3/Rev.4: What Has Changed? ↗ — however, current document status and applicability should be verified against the official IMO source ↗.

Does the EU NIS2 Directive apply to ships and shipping companies?

Yes — NIS2 (Directive 2022/2555, effective October 2024) classifies maritime transport as a critical infrastructure sector. EU-based shipping companies operating ferry services, cargo routes, or port facilities meeting the size thresholds (≥50 employees or €10M annual turnover) are "essential entities" subject to mandatory incident reporting, risk management obligations, and executive liability. Companies operating outside the EU but serving EU ports may be indirectly affected through their EU-based subsidiaries or contractual partners.

What does the USCG NVIC 01-20 require for vessels in U.S. waters?

USCG Navigation and Vessel Inspection Circular 01-20 provides a voluntary but expected framework for cyber risk management for vessels and facilities regulated under 33 CFR Parts 104–106. It aligns with the NIST Cybersecurity Framework and requires operators to identify OT/IT assets, assess cyber risks, develop and test cyber incident response plans, and report significant cyber incidents to the National Response Center. USCG marine inspectors use it as a benchmark during facility safety audits.

How do IACS, IMO, and flag state requirements interact?

IACS URs apply through classification — they are private-sector technical standards that all 12 major class societies have agreed to enforce uniformly. IMO instruments (including SOLAS and the ISM Code) are international law ratified by flag states. Flag states translate IMO obligations into domestic law and enforce them during surveys; class societies often act as Recognized Organizations (ROs) on behalf of flag states. In practice, a modern vessel must satisfy all three layers: class requirements (IACS), flag state law (IMO-derived), and — for vessels calling specific ports — coastal state regulations (USCG, NIS2, etc.).

Share