When IMO Resolution MSC.428(98) took effect on January 1, 2021, many in the maritime industry treated it as a box-ticking exercise. Four years later, that complacency has become a liability. The regulatory tsunami that followed has transformed maritime cybersecurity from a best practice into a survival requirement.

This article is part of the Maritime Cyber Playbook series, developed in collaboration with Margetis Maritime.

The IMO Foundation: What MSC.428(98) Actually Required

IMO Resolution MSC.428(98), adopted in 2017, mandated that cyber risk management be incorporated into Safety Management Systems (SMS) under the ISM Code. The deadline was the first Document of Compliance verification after January 1, 2021.

The resolution was deliberately non-prescriptive. It required ship operators to:

  • Identify cyber risks in their operations
  • Implement safeguards appropriate to those risks
  • Document cyber risk management in their SMS
  • Ensure crews could respond to cyber incidents

What it did not specify: technical standards, specific controls, or audit criteria. This flexibility was intentional—the IMO recognised that a 300,000 DWT tanker has different cyber risks than a 1,500 TEU feeder vessel.

But flexibility became ambiguity. Without clear standards, many operators developed paper-thin cyber policies that satisfied auditors but offered minimal protection.

IACS UR E26 and E27: The Technical Teeth

The International Association of Classification Societies (IACS) filled the standards gap with two Unified Requirements that took effect on July 1, 2024:

UR E26: Cyber Resilience of Ships

E26 applies to ships of 500 GT and above on international voyages. It requires:

  • Asset inventory: Documented list of all computer-based systems aboard, including operational technology (OT) like navigation, propulsion controls, and cargo handling systems
  • Risk assessment: Systematic evaluation of cyber threats to each system
  • Security zones: Network segmentation separating critical OT from less-critical IT systems
  • Access control: Documented procedures for user management across all systems
  • Incident response: Defined procedures for detecting, responding to, and recovering from cyber incidents

UR E27: Cyber Resilience of Onboard Systems and Equipment

E27 targets equipment manufacturers and system integrators. It establishes baseline security requirements for:

  • Network-connected onboard equipment
  • Integration of systems from multiple vendors
  • Software update and patch management procedures
  • Secure communication protocols

Together, E26 and E27 create a chain of accountability from equipment manufacturers through system integrators to ship operators.

NIS2: The European Enforcement Layer

The EU's Network and Information Security Directive 2 (NIS2), with a transposition deadline of October 17, 2024, designated maritime transport as an "essential" sector. This classification carries significant implications:

  • Mandatory security measures: Risk analysis, incident handling, business continuity, supply chain security
  • Reporting obligations: Significant incidents must be reported within 24 hours, with full reports within 72 hours
  • Management accountability: Senior management can be held personally liable for compliance failures
  • Penalties: Fines up to €10 million or 2% of global annual turnover, whichever is higher

NIS2 applies to shipping companies operating in EU waters, regardless of where they are headquartered. A Singapore-flagged vessel calling at Rotterdam is subject to NIS2 requirements for that operation.

The Convergence Problem

These three regulatory frameworks—IMO, IACS, and NIS2—address the same underlying risks but from different angles and with different enforcement mechanisms:

FrameworkFocusEnforcementPenalty
IMO MSC.428(98)Safety ManagementFlag State / Port StateDetention, loss of DOC
IACS UR E26/E27Technical StandardsClassification SocietiesLoss of class
NIS2Organisational SecurityNational Authorities€10M / 2% turnover

A shipping company must satisfy all three simultaneously. The policies developed for IMO compliance may not meet IACS technical requirements. The technical measures for IACS may not include the incident reporting demanded by NIS2.

What This Means for Ship Operators

The regulatory landscape has fundamentally shifted. Compliance is no longer about having a cyber policy in your SMS binder. It requires:

  1. Technical competence: Understanding the IT/OT systems aboard your vessels and their vulnerabilities
  2. Integrated management: Cyber risk management woven into operational procedures, not bolted on
  3. Continuous monitoring: Cyber threats evolve; your defences must evolve with them
  4. Documented evidence: Auditors, inspectors, and regulators all want proof of compliance

The Path Forward

The Maritime Cyber Playbook series will address each of these requirements in depth. Upcoming articles will cover:

  • IT/OT Convergence: Why your navigation systems talk to your email server, and what to do about it
  • IACS Compliance: Practical steps to meet UR E26 and E27 requirements
  • Incident Response at Sea: When you are 500 miles from the nearest shore-based SOC
  • Flag State Inspections: What PSC officers actually look for during cyber inspections
  • Crew Training: Building human firewalls on vessels where crew turnover is constant

IMO 2021 was the opening move. IACS 2024 raised the stakes. NIS2 added enforcement teeth. The regulatory trajectory is clear: maritime cyber compliance will only become more demanding.

The question is not whether to comply. It is whether you will lead, follow, or be dragged.


This article is the first in the Maritime Cyber Playbook series, a collaboration between IWH and Margetis Maritime. For maritime cybersecurity advisory services, contact us.