IACS Unified Requirements E26 and E27 came into force on July 1, 2024. Unlike the principle-based IMO guidelines, these requirements have teeth: specific technical criteria that classification surveyors will verify. This article provides practical guidance for achieving compliance.

This article is part of the Maritime Cyber Playbook series, developed in collaboration with Margetis Maritime.

Understanding the Scope

IACS UR E26 and E27 apply to:

  • Ships of 500 gross tonnage and above
  • On international voyages
  • Contracted for construction on or after July 1, 2024

Existing vessels are not immediately subject to these requirements. However, significant modifications to onboard computer-based systems may trigger compliance obligations. More importantly, the requirements establish the baseline that all maritime cyber assessments will eventually reference.

UR E26: Cyber Resilience of Ships — The Five Pillars

E26 establishes five functional requirements that ship operators must address. Each has specific documentation and evidence requirements.

1. Asset Inventory

Requirement: Maintain a documented inventory of all computer-based systems (CBS) aboard the vessel.

What surveyors look for:

  • Complete list of networked systems including navigation, propulsion, cargo, and administrative systems
  • Hardware details: manufacturer, model, firmware version
  • Software details: operating system, application versions
  • Network connectivity: IP addresses, ports, protocols
  • System criticality classification

Common gaps:

  • Undocumented systems added during repairs or retrofits
  • Embedded systems in OT equipment not identified as CBS
  • Crew personal devices that connect to ship networks
  • VSAT and communication system components

Practical approach: Conduct a physical survey of all compartments. Interview the Master, Chief Engineer, and ETO. Cross-reference with vendor documentation and network diagrams.

2. Risk Assessment

Requirement: Conduct cyber risk assessment for identified CBS, considering threats, vulnerabilities, and consequences.

What surveyors look for:

  • Documented methodology (ISO 27005, NIST CSF, or equivalent)
  • Threat identification relevant to maritime operations
  • Vulnerability assessment for each system category
  • Impact analysis considering safety, environmental, and commercial consequences
  • Risk treatment decisions (accept, mitigate, transfer, avoid)

Common gaps:

  • Generic risk assessments not tailored to the specific vessel
  • Failure to consider OT-specific threats
  • Missing supply chain risks (vendor access, updates)
  • Outdated assessments not reflecting system changes

Practical approach: Use a scenario-based methodology. For each critical system, ask: "What could go wrong? How would an attacker reach this system? What would be the consequences?"

3. Security Zones and Network Segmentation

Requirement: Implement network architecture with defined security zones and controlled interfaces between zones.

What surveyors look for:

  • Network topology diagrams showing zone boundaries
  • Documented zone definitions with assigned systems
  • Firewall rules controlling inter-zone traffic
  • Evidence of zone enforcement (firewall logs, configuration exports)
  • Physical separation where appropriate

Minimum zone structure:

ZoneSystemsExternal Connectivity
SafetyNavigation, GMDSS, fire detectionNone (or one-way out)
ControlPropulsion, cargo, ballastRestricted, monitored
OperationalMaintenance, administrationControlled
UntrustedCrew internet, guest accessIsolated

Common gaps:

  • Flat networks with no segmentation
  • Segmentation on paper but not enforced in practice
  • Undocumented connections bypassing firewalls
  • VSAT management interfaces accessible from crew networks

4. Access Control

Requirement: Implement measures to control physical and logical access to CBS.

What surveyors look for:

  • User account management procedures
  • Password policies (complexity, rotation, no shared accounts)
  • Privileged access management for administrative functions
  • Physical access controls to server rooms and network equipment
  • Procedures for granting and revoking access

Common gaps:

  • Shared accounts (e.g., single "admin" account used by all officers)
  • Default passwords unchanged from installation
  • No procedures for crew handover access management
  • USB ports unrestricted on critical systems

Practical approach: Implement individual accounts for all regular users. Maintain a privileged account register with documented access approvals. Establish procedures for disembarking crew account deactivation.

5. Incident Response

Requirement: Establish procedures for detecting, responding to, and recovering from cyber incidents.

What surveyors look for:

  • Documented incident response procedures in the SMS
  • Defined roles and responsibilities
  • Communication procedures (internal and external)
  • Evidence preservation guidance
  • Recovery procedures for critical systems
  • Training and drill records

Common gaps:

  • Generic procedures not adapted to vessel operations
  • No consideration of operations at sea vs. in port
  • Missing procedures for operating in degraded mode
  • No drills conducted or documented

UR E27: Equipment and System Requirements

E27 applies to equipment manufacturers and system integrators rather than ship operators. However, operators must verify that installed equipment meets E27 requirements:

  • Secure development: Equipment developed following secure development practices
  • Hardening guidelines: Manufacturer-provided hardening guidance followed
  • Update mechanisms: Secure methods for software updates
  • Authentication: Strong authentication for administrative access
  • Communication security: Encryption for sensitive data in transit

When procuring new equipment, require E27 compliance certificates or equivalent documentation from vendors.

Preparing for Classification Survey

Documentation Package

Prepare the following before survey:

  1. CBS Inventory: Complete, current, version-controlled
  2. Network Diagrams: Topology showing all connections and zone boundaries
  3. Risk Assessment Report: Dated, with revision history
  4. Security Policies: Access control, password, USB, incident response
  5. Zone Documentation: Zone definitions, assigned systems, interface controls
  6. Firewall Rules: Documented and justified rules for inter-zone traffic
  7. Training Records: Cyber awareness training completion
  8. Drill Records: Cyber incident drills conducted and lessons learned

Technical Evidence

Surveyors may request evidence of implementation:

  • Firewall configuration exports
  • User account listings (anonymised if needed)
  • Network traffic logs demonstrating zone enforcement
  • Patch status reports for critical systems
  • Backup verification records

Survey Timeline

Plan cyber resilience survey activities alongside regular classification surveys. Allow time for:

  • Pre-survey documentation review (2-4 weeks before)
  • On-board verification (typically 0.5-1 day additional)
  • Findings rectification if required

Common Findings and How to Avoid Them

FindingPrevention
Incomplete asset inventoryPhysical survey + network scanning
Generic risk assessmentVessel-specific scenarios, not templates
Undocumented network connectionsRegular network audits, change management
Shared user accountsIndividual accounts, audit trail requirement
No cyber drill recordsQuarterly drills, documented and reviewed
Outdated documentationAnnual review cycle, change triggers

The Compliance Journey

IACS compliance is not a one-time exercise. Establish processes for:

  1. Continuous inventory management: Update CBS inventory when systems change
  2. Regular risk review: Annual assessment, plus triggered reviews for significant changes
  3. Ongoing monitoring: Review logs, detect anomalies, investigate alerts
  4. Training refresh: Regular cyber awareness training for all crew
  5. Drill programme: Scheduled drills with varying scenarios

Next in the Series

What happens when a cyber incident occurs 500 miles from shore? The next article addresses incident response at sea—where help is far away and degraded operations may be the only option.


This is the third article in the Maritime Cyber Playbook series, a collaboration between IWH and Margetis Maritime. For maritime cybersecurity advisory services, contact us.