海仕德数据服务
Standards Explained · Pillar

What is IACS UR E26 / E27

E26 covers the whole ship, E27 covers shipboard systems; together they require new-build ships to prove cyber resilience before delivery. This page explains what it is, how it relates to you and what to do — and lists every document to submit plus the two submission paths.

Interpretations of IACS UR E26/E27 on this page are for reference only; formal requirements and classification are determined by the class society review.

What is E26 / E27

IACS UR E26 (Cyber Resilience of Ships) targets the whole ship: cybersecurity must be engineered into ship design and construction — covering network segregation, access control, malware protection, backup and recovery.

IACS UR E27 (Cyber Resilience of On-board Systems and Equipment) targets individual systems and equipment: shipboard Computer Based Systems (CBS) must meet a set of verifiable cyber-resilience requirements in hardware, software, network interfaces and security functions.

In short: E26 says 'the whole ship must be secure', E27 says 'each critical system must prove it is secure'. A ship's E26 compliance is built on each system meeting E27.

Keywords: IACS UR E26 · IACS UR E27 · ship cyber resilience · shipboard system cybersecurity · CBS · mandatory from 01 Jul 2024

How it relates to you

E26/E27 is mandatory for new-build ships contracted on or after 01 Jul 2024. Different roles will be asked for E27 evidence along the delivery chain:

  • Equipment makers / OEMs

    Yards require E27 conformity material before you can join a project; without it you are blocked at supplier qualification.

  • Shipyards / Owners

    Whole-ship E26 compliance depends on each system's E27 status; evidence must be collected and tracked per system.

  • Design institutes / Integrators

    Network segregation and equipment selection must embed E26/E27 at the design stage, or rework later is costly.

What to do

Whatever your role, getting E27 done follows roughly the same path:

  1. Confirm scope

    Determine whether your system is a CBS in E27 scope and which clauses and security functions apply.

  2. Run a gap assessment

    Self-assess against each clause and produce a gap list between your product and the requirements.

  3. Remediate and gather evidence

    Close the gaps and prepare submission-ready evidence (test reports, design docs, configuration notes, etc.).

  4. Go through submission

    Follow one of the two submission paths below to complete plan approval, witnessing and certificate issuance.

The 8 documents to submit

Below is the document list (evidence package) typically involved in E27 submission. Exact names, counts and acceptable formats follow the latest class society guidance and review for your project.

  • 1. System description and boundary

    Defines the CBS scope, composition, network topology and trust boundary.

  • 2. Cyber-resilience design statement

    Design rationale for meeting each E27 security function requirement.

  • 3. Asset and interface inventory

    Complete list of hardware, software, communication interfaces and external connections.

  • 4. Risk assessment report

    Cybersecurity risk identification and mitigation for the system.

  • 5. Security function test report

    Test evidence for access control, logging, malware protection and other functions.

  • 6. Configuration and hardening note

    Secure-by-default configuration, port/service minimization and a hardening baseline.

  • 7. Backup and recovery plan

    Data backup, recovery procedures and availability assurance with verification.

  • 8. Operations and incident response procedure

    Procedures for patch management, monitoring and cybersecurity incident response.

Two submission paths

Depending on whether the system/equipment already holds Type Approval, the submission path splits in two. Both end with a System Certificate.

Path 1: With type approval

The equipment already passed E27 type approval; the project phase mainly references the type approval plus installation verification, and is relatively fast.

  1. Plan Approval

    Submit the system description and type approval certificate; class reviews the plan documents.

  2. Survey / FAT

    On-site witnessing of installation and factory acceptance test, verifying the type approval scope matches the actual installation.

  3. System Certificate

    On passing, a system-level cyber-resilience conformity certificate is issued.

Path 2: Without type approval

The equipment holds no type approval; the project must complete a full design review and testing for evidence, with a larger document set.

  1. Plan Approval

    Submit the full design documents and evidence package; class reviews item by item against E27.

  2. Survey / FAT

    On-site witnessing of full functional and security testing (factory acceptance test), verifying each security function.

  3. System Certificate

    Once all clauses are verified, a system-level cyber-resilience conformity certificate is issued.

Frequently asked questions

What is the difference between E26 and E27?
E26 targets whole-ship cyber resilience (system-level integration, network segregation, etc.); E27 targets the cyber-resilience requirements of individual shipboard systems and equipment. Whole-ship E26 compliance is built on each system meeting E27.
When does E27 become mandatory?
It is mandatory for new-build ships whose construction contract is signed on or after 01 Jul 2024. The exact scope and transitional arrangements follow the latest class circulars.
Does my equipment have to be type approved?
Not necessarily. With type approval you can take the faster reference + installation verification path; without it you complete a full design review and testing in the project. Both paths lead to a system certificate.
What material should I roughly prepare to submit?
Typically a system description, design statement, asset inventory, risk assessment, test reports, configuration hardening, backup/recovery and operations procedures (see 'The 8 documents to submit' on this page). The final list follows the class society requirements.
What if the first submission fails?
Very common — legacy shipboard equipment was never designed for cybersecurity. Running a gap assessment and remediating with evidence in advance significantly reduces the risk of failing the formal witnessing test.