Publications
Curated research papers, industry studies, and knowledge resources on maritime technology, cybersecurity, and shipping regulation — organized by topic.
This library curates research papers, industry studies, and official knowledge resources on maritime cybersecurity, shipbuilding regulations, and shipping technology. Each publication is sourced from authoritative institutions and linked to its primary source where available. Content is reviewed by credentialed maritime professionals.
Last reviewed: September 2026 | Editorial & Verification Policy
Key Publishing Institutions in Maritime Cybersecurity
Publishes Unified Requirements (UR), Recommendations, and Procedural Requirements. UR E26 and E27 are the primary cyber resilience standards for newbuildings.
→ IACS Publications ↗Issues MSC and MEPC circulars, resolutions, and the core SOLAS, MARPOL, and STCW conventions. The official IMO source currently identifies MSC-FAL.1/Circ.3/Rev.3 as its Guidelines on Maritime Cyber Risk Management. Earlier revisions, including Rev.2 (2021), are retained as historical references.
→ IMO Knowledge Centre ↗Ship owner and operator associations publish practical guidance, incident data, and best-practice documents including the widely-cited Guidelines on Cyber Security Onboard Ships.
→ BIMCO Publications ↗IEC 62443 (Industrial Automation and Control Systems security) is the primary technical standard referenced by IACS UR E26/E27. ISO 23806 covers maritime OT cybersecurity. NIST CSF underpins USCG guidance.
→ IEC Standards ↗📋 How to Cite a Maritime Regulation in Academic or Professional Work
IACS UR E26 (2022): Cyber Resilience of Ships. International Association of Classification Societies. [Effective 1 July 2024]. Available at: https://www.iacs.org.uk/publications/unified-requirements/e/ IMO (2021): MSC-FAL.1/Circ.3/Rev.2 — Guidelines on Maritime Cyber Risk Management. International Maritime Organization. [Issued 5 August 2021]. Available at: https://www.imo.org
Frequently Asked Questions — Maritime Research & Publications
What are the most authoritative publications on maritime cybersecurity?
The most authoritative primary sources are: (1) IACS UR E26 and E27 — the mandatory class requirements for new vessels; (2) IMO MSC-FAL.1/Circ.3/Rev.3 (per the official IMO source) — the ISM Code cyber risk guidance; (3) Guidelines on Cyber Security Onboard Ships (BIMCO/ICS, v5) — the industry-consensus implementation guide; and (4) ENISA's annual Maritime Cybersecurity Report, which tracks threats and incidents across the EU. For OT security standards, IEC 62443 and ISO/IEC 27001 are the key technical references.
Are IACS publications freely available online?
Some IACS publications are freely available on the IACS website ↗, including selected Unified Requirements and Recommendations in summary or full text. UR E26 and E27 are available in full. However, some procedural requirements and technical details require purchase or access through a class society membership portal. Individual class societies (Lloyd's Register, Bureau Veritas, DNV, etc.) also publish guidance documents that interpret and supplement the URs.
What is the difference between an IMO Resolution and an IMO Circular?
An IMO Resolution is a formal decision adopted by an IMO Assembly or committee meeting — it can be mandatory (if incorporated into a convention like SOLAS) or non-mandatory (as a recommendation). An IMO Circular (e.g., MSC-FAL.1/Circ.3) is an administrative document issued between sessions to convey guidance, unified interpretations, or operational information. Circulars are generally non-mandatory but carry significant weight in flag-state implementation and PSC inspections, especially when they clarify obligations under mandatory conventions.
How does IEC 62443 relate to IACS UR E26/E27?
IEC 62443 is the international standard series for Industrial Automation and Control Systems (IACS) cybersecurity. IACS UR E26 references IEC 62443-2-1 (for security management systems) and IEC 62443-3-3 (for system security requirements). UR E27 references IEC 62443-4-1 (secure development lifecycle) and IEC 62443-4-2 (component security requirements). Compliance with UR E26/E27 therefore requires demonstrable alignment with IEC 62443 at both the vessel system level and the component/supplier level — making IEC 62443 a de facto requirement for maritime OT in newbuildings.
Where can I find official research on the impact of CII regulations on the fleet?
Key CII research sources include: UNCTAD's annual Review of Maritime Transport, which tracks fleet efficiency and trade volumes; Clarksons Research for fleet-level CII rating distributions; the IMO Fourth IMO GHG Study for baseline emissions data; and BIMCO/ICS for practical operator impact assessments. The EU's EUR-Lex ↗ portal is the primary source for EU ETS maritime provisions (EU 2023/959).