With Unified Requirements E26 and E27, IACS has established the first binding minimum standards for the cyber resilience of newbuildings. UR E26 is directed at shipowners and yards, defining requirements at vessel level: the ship as a complete system must be designed, built and operated in a cyber-resilient manner. This encompasses a documented risk assessment, identification of all Computer-Based Systems (CBS), a traceable network architecture and defined protection, detection and recovery capabilities.
UR E27 complements this by addressing the suppliers of onboard systems. Every OEM delivering a CBS must demonstrate that their product can be securely maintained, updated and configured throughout its entire service life. This covers hardening measures, access control, logging capability and documentation of known vulnerabilities.
Both URs have been mandatory since 1 July 2024 for newbuildings whose contracts were signed after that date. Implementation is carried out through the classification societies, which have incorporated UR E26 and E27 into their respective rule sets. Cyber resilience is therefore no longer an optional recommendation but a classification-relevant obligation.
The critical point: IACS does not prescribe a specific product or a particular security level in technological terms. It requires a systematic approach — identify risks, derive measures, document effectiveness. Those who treat this as a pure compliance exercise will meet requirements on paper but gain little operationally.
All networked systems falling under the definition of Computer-Based Systems are affected. In practice this means: navigation (ECDIS, radar, AIS, GPS receivers), machinery automation (alarm and monitoring systems, remote controls, power management), communication (GMDSS, VSAT, internal networks) and increasingly also systems for cargo management, ballast water treatment and emissions monitoring.
The challenge lies in drawing boundaries. Many systems traditionally considered standalone are now connected via Ethernet, serial interfaces or proprietary buses. An alarm monitoring system running on the same network as the crew internet access is a CBS under the URs — even if the manufacturer never labelled it an IT system.
Systems with remote access capabilities are particularly critical. OEM remote maintenance via TeamViewer, VPN tunnels or proprietary platforms creates attack surfaces that in many existing fleets are neither documented nor controlled. UR E26 requires newbuildings to capture every remote access point in the network architecture and subject it to risk assessment.
Another area frequently underestimated in practice involves safety systems — systems whose failure has immediate safety implications. These include fire detection systems with network connectivity, automatic extinguishing systems with digital controls and emergency shutdown systems. Here, the cyber dimension intensifies the existing requirements for redundancy and availability.
UR E27 shifts a substantial part of the responsibility into the supply chain. This is a paradigm shift. Until now, cyber security onboard — if addressed at all — was the operator's concern or at best the yard's task during final integration. Now every system supplier must demonstrate that their CBS meets the requirements.
Specifically, UR E27 requires OEMs to provide: a description of their product's security architecture, a list of known vulnerabilities and their mitigation measures, hardening guidelines for installation, access control concepts and a statement on patching capability over the expected operational lifetime. This sounds like standard IT, but for many maritime OEMs it is uncharted territory. Particularly for automation and navigation suppliers who have been building proprietary systems with long life cycles for decades, this demands a fundamental shift in product documentation.
For yards this means: they must not only integrate CBS deliveries mechanically and electrically but also ensure the network integration is cyber-secure. Overall responsibility for the vessel's network topology lies with the yard. When three different OEMs want to integrate their systems into the same network segment, the yard must resolve this architecturally — not retrospectively, but during design.
In practice, it is already apparent that communication between yards and suppliers is often not yet well established in this area. Many OEMs deliver technical documentation written for their own service department but lacking the information an integrator needs for the network topology. This leads to time losses and the need for rework shortly before delivery.
For newbuildings, an early cyber matrix is advisable — ideally already at the specification stage, not only during detailed planning. Operators should include cyber requirements in tender documents and agree UR E27 conformity as a contractual component with every CBS supplier.
The process begins with identifying all CBS onboard and their network connections. This produces a risk assessment that serves as the basis for network zoning. Which systems may communicate with each other? Which transitions between zones are permitted? Where are firewalls, diodes or air gaps required?
In parallel, operators should review their internal structures. Who is responsible for cyber topics — the superintendent, the IT department, the DPA? In many shipping companies this question remains unanswered. UR E26 forces clarification, because the classification society will verify at delivery whether a functioning cyber risk management system exists.
Network segmentation is the technical backbone of UR E26 compliance. The concept has been established in industrial IT for years (IEC 62443 comes to mind), but the maritime context presents specific challenges. Onboard, there are typically several network domains: the OT network for automation and machinery control, the navigation network, the administrative IT network and the crew welfare network. In theory these are separate. In practice they often share physical infrastructure, and the boundaries are more permeable than documented.
A robust zone concept defines a protection level for each zone and governs communication between zones through so-called conduits — controlled transition points. This may be a firewall, a data diode for unidirectional data flow or an application gateway. What matters is not the technology but the consistency: every data flow between zones must be consciously decided, documented and monitorable.
In practice, many concepts fail at the integration of third-party systems. A ballast water treatment system from one manufacturer, connected to the vessel network via its own switch, can undermine the entire zoning if the connection was not anticipated in the topology. The same applies to retrofitted VSAT installations that suddenly connect OT networks to the internet.
For classification societies, the network topology is a central survey document. They expect a current, complete network plan showing all CBS, their connections and zone boundaries. Discrepancies between documentation and actual installation lead to findings — and in the worst case to delays at delivery.
The implications of UR E26/E27 do not end at delivery. Operators must maintain a cyber risk management system covering the entire operational phase. This includes regular reviews of network topology, monitoring of software versions and patch levels, management of user accounts and access rights, and documentation of every change to CBS.
For superintendents, this means an expansion of their remit. Previously the focus was on mechanical and electrical integrity. Now digital integrity is added. A superintendent need not become an IT specialist, but must understand which systems are networked, where risks lie and which measures are in place.
The management of software updates is particularly relevant. Many OEMs deliver updates via USB sticks or remote sessions. Both are potential entry points. UR E26 requires documented procedures for such operations — who authorises access, how is the installation verified, and how is the change logged.
The ISM Code has required the consideration of cyber risks within the Safety Management System since 2021 via MSC.428(98). UR E26/E27 now give this technical substance. Operators who previously had only a generic cyber risk assessment in their SMS will find that class now expects considerably more depth for newbuildings.
A typical scenario: an operator orders a series of multipurpose cargo vessels. The contract was signed after July 2024, so UR E26/E27 apply in full. The yard mentioned cyber requirements in the specification but did not include them as a dedicated section with concrete delivery requirements for OEMs.
During detailed planning it emerges that the automation supplier cannot deliver UR E27-compliant documentation because their product line has not systematically addressed the topic. The navigation supplier has a hardening document but no statement on patching capability over 15 years. The yard has no dedicated network plan because the individual system islands were previously treated separately.
The result: six months before planned delivery, a hectic remediation phase begins. Network plans are created, OEMs deliver documentation retrospectively, class keeps findings open. The time loss could have been avoided if cyber requirements had been treated as an integral part of the specification from the outset.
The central strategic question for operators is: do we meet UR E26/E27 minimally — or do we use the requirements as leverage for genuine operational resilience? The difference shows in how the risk assessment is handled. A minimal approach identifies CBS, creates a matrix and documents measures. An operational approach goes further: it tests recovery procedures, simulates failure scenarios and embeds cyber routines in daily onboard operations.
The additional effort for the operational approach is manageable when integrated early in the project. The benefit shows not only during audits but also during real incidents. A vessel whose crew knows how to switch navigation to backup systems during a ransomware event has a concrete operational advantage over one whose cyber plan exists only in a folder.
Free initial consultation – we analyze your situation and find the best path forward.
Request Consulting