Who Enforces: Port State Control, Class Societies & the USCG
In one line:Cyber compliance isn't just on paper: PSC checks it through the ISM Code, class societies review and certify, and the USCG's 2025 rule puts real money behind it — three enforcement tracks in one view.
Key takeaways
- PSC has no standalone “cyber” item, but a cyber gap can count as a serious SMS (ISM) failure → detention.
- Class societies are the reviewer, witness and certifier for new-build E26/E27 — “class society decides.”
- The US Coast Guard's 2025 rule requires a Cybersecurity Officer, a Cybersecurity Plan, and reporting to the NRC.
- Each class society also offers voluntary cyber notations stacked above the baseline.
"Compliance" ultimately means someone checks, certifies, and penalizes. Maritime cyber compliance has three complementary enforcement tracks: Port State Control (the operations side), class societies (the new-build side), and national mandatory regulation (such as the US Coast Guard). The three operate independently yet interlock — class societies build cyber resilience into a ship during construction; flag state administrations issue ISM certificates and verify that the SMS functions; Port State Control provides the backstop, inspecting any vessel of any flag at any port call. No layer has full visibility into the others. For vendors, yards, and designers, the real question is: under what circumstances does each enforcement track come knocking, what are the consequences, and how far must preparation go?
Layer 1: Port State Control — enforcing cyber through the ISM Code
Port State Control currently has no standalone "cybersecurity" checklist item. You will not find a line on the inspection sheet reading "please produce your cybersecurity policy." But this does not mean cyber risk is invisible during a PSC inspection. On the contrary, since IMO MSC-FAL.1/Circ.3 incorporated cyber risk management into the ISM Safety Management System, the absence of cyber controls can be recorded and acted upon as an ISM deficiency. The mechanism works as follows: the ISM Code requires shipping companies to identify every risk that affects safe operations — including OT control systems, IT ship-shore communications, and the boundary between them. If an inspector finds no cyber risk procedures in the SMS, no evidence of crew training, or a cyber incident to which the company had no response — that constitutes a "serious failure to implement the SMS," triggering an ISM deficiency entry.
The USCG's internal work instruction CVC-WI-027 (Vessel Cyber Risk Management) is one of the most explicit public documents mapping this logic. It states: when objective evidence shows a serious failure to implement the SMS with respect to cyber risk management, and that failure directly resulted in a cybersecurity incident affecting vessel operations, the Port State Control Officer (PSCO) shall issue both an operational deficiency and an ISM deficiency with action code 30 — Ship Detained — with the additional requirement of an external ISM audit within three months (or before the vessel returns to a US port after sailing foreign). Less serious cyber deficiencies trigger pre-departure correction plus an internal audit within 90 days. CVC-WI-027 has been updated continuously (first issued October 2020, revised several times since); the action-code mechanism has been consistent across versions.
Zooming out: the Paris MoU and Tokyo MoU all-causes detention rates for 2023 were 3.81% and 4.32% respectively, from their annual reports. Both figures cover detentions arising from all causes — fire safety, life-saving appliances, navigational safety, and others — and neither report breaks out a cyber-specific detention figure. The Paris MoU 2023 Annual Report also shows that the ISM Code had the highest deficiency non-compliance rate (4.8%) among the categories the report highlights — and cyber risk deficiencies are captured through that ISM channel. The Tokyo MoU completed 30,887 inspections in 2023, finding 75,867 deficiencies aboard 18,806 ships; the top three categories (fire safety, life-saving appliances, safety of navigation) accounted for 46% of all deficiencies, with cybersecurity not appearing as a standalone line.
No dedicated cyber item does not mean zero risk
The 2025 joint Paris/Tokyo MoU Concentrated Inspection Campaign (CIC) targets Ballast Water Management Convention compliance, not cybersecurity — neither MoU has announced a cyber-specific CIC. But this is not good news: once cyber gaps are captured as SMS deficiencies, the same action codes apply, with consequences identical to any other serious ISM deficiency.
For vendors and yards, this enforcement logic has a concrete implication: if equipment or systems you deliver directly cause a cyber control gap in the SMS, your equipment will appear on PSC deficiency records. Even without a dedicated cyber checklist, the ISM umbrella is wide enough. Yards must ensure, at the design stage, that all control systems, auxiliary systems, and ship-shore communication interfaces fall within the SMS cyber risk management scope — otherwise the shipowner may face trouble at the first post-delivery PSC inspection, and liability may trace back up the contract chain.
Layer 2: Class societies — the reviewer and certifier for new-builds
For new-builds contracted on or after 1 July 2024, the International Association of Classification Societies (IACS) mandates UR E26 and UR E27 as the baseline. E26 addresses ship-level cyber resilience, setting requirements for owners and operators at the fleet-system level; E27 addresses individual on-board Computer Based Systems (CBS), covering each piece of equipment from design and construction through system integration, on-board installation, and delivery. Together the two URs form a dual-axis mandatory framework — ship-level and equipment-level — enforced by all IACS member societies through their own class rules within the scope of contracted vessels.
The enforcement process for new-builds works as follows: the yard submits cyber security design documents to the class society at the design stage; the society reviews and approves (or requires revision); during construction and factory acceptance testing (FAT), class society surveyors witness cyber security tests of critical systems on site; at delivery, the class society issues the System Certificate — a document that forms part of the vessel's official record and is one of the preconditions for the flag state to issue the ISM compliance certificate. "Class society decides" means precisely this: without the class society's design approval and System Certificate, the ship cannot sail. Above the baseline, each society offers voluntary cyber notations for projects that need higher security levels — LNG carriers, unmanned vessels, and offshore wind service operation vessels, for example.
| Society | Cyber notation (voluntary, above baseline) |
|---|---|
| DNV | Cyber Secure (entry / Essential / Advanced) |
| ABS | CR (Cyber Resilience, mandatory for contracts on/after Jul 2024) / CyberSafety CS-1·CS-2 (legacy voluntary) |
| Lloyd's Register | Cyber Resilience |
| Bureau Veritas | NR659 (Cyber Managed / Secure / Resilient) |
| ClassNK | CybR-G (G = Guideline-based) |
Looking at each society's practice: DNV's Cyber Secure (Essential) aligns with IEC 62443 security profile 1, the UR E26 baseline; Cyber Secure (Advanced) covers security profile 3 for higher-risk or more complex new-builds. ABS distinguishes two programmes: the legacy CyberSafety (CS-1, CS-2, voluntary, introduced around 2016) and the new CR notation (Cyber Resilience, mandatory for contracts on/after July 2024 under ABS MVR Section 4-9-13); an optional CR-Ex notation for existing vessels became available from 1 June 2025. Lloyd's Register's Cyber Resilience classification saw its first in-service awards in 2025, granted to North Star's offshore wind service operation vessels Grampian Kestrel and Grampian Eagle — marking the transition from rule-on-paper to operational certification. BV added the CYBER RESILIENT level to NR659 in the 2023 update, specifically to align with IACS UR E26; the current version is the July 2024 edition (659-NR_2024-07). ClassNK's CybR-G notation (G = Guideline-based) applies to pre-July 2024 contracted projects following ClassNK's proprietary guidelines; post-July 2024 contracts follow the mandatory UR E26/E27 track, a separate pathway from CybR-G.
The critical bottleneck for equipment vendors: E27 type approval
E27 requires each CBS (Computer Based System) aboard to hold a cyber resilience type approval from an IACS member society. As of late 2024, the number of approved systems remains extremely limited. Without type approval, a system cannot be specified for new-build designs contracted on/after 1 July 2024. For vendors, this is the single most urgent bottleneck right now: type approval timelines can run months, processes differ across societies, and engagement must begin early.
Layer 3: USCG 2025 — the first hard national cyber mandate
On 17 January 2025, the US Coast Guard published the final rule "Cybersecurity in the Marine Transportation System" in the Federal Register (90 FR 6298), effective 16 July 2025, codified at 33 CFR Part 101 Subpart F. This is the first rule in the world to establish mandatory national maritime cybersecurity requirements at the federal regulatory level — not a guideline, not an IMO resolution, not a recommendation, but a binding CFR rule. The previous USCG NVIC 01-20 (2020, Facility Cyber Risk Management) was voluntary; this time the standard is "must comply or face legal consequences."
The rule's scope is defined through the existing MTSA (Maritime Transportation Security Act) coverage — it does not expand the regulated population, but layers cybersecurity obligations on top of existing maritime security requirements. Covered entities include: US-flagged vessels required to hold a Vessel Security Plan under 33 CFR Part 104; MTSA facilities (ports, terminals, chemical and petroleum storage terminals) required to hold a Facility Security Plan under 33 CFR Part 105; and offshore facilities on the outer continental shelf required to hold a security plan under 33 CFR Part 106. Inland towing vessels and barges were explicitly retained in scope despite industry requests for exclusion. According to the rule's Regulatory Impact Analysis preamble, approximately 11,222 US-flagged vessels and approximately 3,718 facilities are covered.
- US-flagged vessels covered (per rule RIA)
- ~11,222US-flagged vessels covered (per rule RIA)
- facilities covered (per rule RIA)
- ~3,718facilities covered (per rule RIA)
- est. 10-yr cost (exact: $1,245,594,930)
- ~$1.2Best. 10-yr cost (exact: $1,245,594,930)
- effective
- 2025-07-16effective
The rule's core obligations fall into three tiers. First, structural: each covered entity must designate a Cybersecurity Officer (CySO) responsible for developing, implementing, and maintaining a Cybersecurity Plan; the plan must be approved by the relevant authority and updated after material changes. Second, assessment: a cybersecurity risk assessment must be conducted covering all IT and OT systems, identifying critical assets, vulnerabilities, and countermeasures; the assessment findings are incorporated into the plan and reviewed periodically. Third, reporting: upon the occurrence of a "Reportable Cyber Incident," immediate notification to the National Response Center (NRC) is required — "without delay." The NRC is the same federal hotline used for marine pollution and hazardous material incidents; it now also receives maritime cyber incident reports. Following the final rule, USCG released NVIC 02-24 Change 1 and Policy Letter 01-25, providing operational interpretation of training requirements and incident reporting procedures.
- 2020-02USCG NVIC 01-20Facility cyber-risk guidance (voluntary)
- 2024-07E26/E27 mandatoryNew-build cyber-resilience baseline
- 2025-07USCG rule effective90 FR 6298 (33 CFR 101 Subpart F)
- 2027-07Plan / assessment dueCySO + Cybersecurity Plan
The phased compliance roadmap is as follows: 16 July 2025, the rule takes effect and NRC reporting obligations apply immediately; 12 January 2026, all relevant personnel must complete cybersecurity training specified under 33 CFR 101.650, with annual recurrence thereafter; 16 July 2027, the CySO must be in place, the Cybersecurity Assessment must be completed, and the Cybersecurity Plan must be submitted and approved. The estimated ten-year total cost is approximately $1.245 billion (exact: $1,245,594,930), annualized at approximately $138.7 million (2022 dollars), with peak annual private-sector expenditure of approximately $178.7 million, concentrated in the initial deployment and system hardening phase.
A fact that may move: US-flagged vessel deadline possibly deferred
The rule simultaneously sought public comment on delaying vessel compliance by 2-5 years for US-flagged ships; the comment period closed 18 March 2025. As of this article's research date (2026-06-28), no published Federal Register amendment or USCG notice has confirmed that the delay was granted. The current compliance deadline (2027-07-16) remains in effect for both facilities and vessels. If you operate covered US-flagged vessels, defer to the latest Federal Register and USCG official notices — do not assume the delay was approved.
EU NIS2 and ports: a parallel mandatory enforcement track
Reporting obligations are tightening on both sides of the Atlantic, but via different channels. In the EU, the NIS2 Directive (Directive (EU) 2022/2555, adopted by the European Parliament on 14 December 2022) classifies maritime transport as a "highly critical sector" (Annex I), bringing port operators that meet size thresholds into scope as "essential entities" subject to mandatory regulation. EU Member States were required to transpose NIS2 into national law by 17 October 2024, with NIS1 repealed from 18 October 2024. As of this article's research date, Member States are at varying stages of transposition, producing uneven enforcement intensity across EU ports.
NIS2 Article 23 establishes a strict multi-stage incident reporting obligation: within 24 hours of becoming aware of a significant incident, an "early warning" must be submitted to the competent authority or CSIRT; within 72 hours, an "incident notification" including a preliminary impact assessment and measures taken; within one month, a "final report" including root-cause analysis, detailed impact assessment, and improvement measures. Penalties for non-compliance reach up to €10 million or 2% of global annual turnover for essential entities, whichever is higher. NIS2 Article 21 also requires risk management measures across 21 security domains, including supply-chain security — meaning port customers will increasingly pass NIS2 compliance requirements downstream to the vendors and integrators who supply port systems.
Where the three tracks converge: a practical checklist for vendors, yards, and designers
Viewing the three enforcement tracks together: the audiences differ and the specific obligations differ, but for vendors, yards, and designers sitting upstream in the maritime supply chain, the impacts are cumulative, not optional. Here are the critical action points that require attention now:
First, yards accepting new-build contracts dated on/after 1 July 2024 must use IACS UR E26 and E27 as the design baseline, engaging the class society no later than the concept design stage to confirm the scope of required cybersecurity documentation; FAT-stage cyber security witnessing is a mandatory process step, which must be allocated time in the project schedule. Second, equipment vendors wishing to be specified for vessels contracted on/after 1 July 2024 must obtain E27 type approval from an IACS member society for each relevant CBS; approval cycles can run months, processes differ by society, and vendors must proactively assess their target markets and select an approval path. Third, operators of US-flagged vessels or MTSA facilities must establish NRC reporting capability (process, contact, drill) by 16 July 2025; complete personnel training by 12 January 2026; and complete CySO designation, risk assessment, and plan submission by 16 July 2027 — the 2027 deadline for facilities remains firm; the vessel-delay question is pending. Fourth, vendors supplying EU ports or European shipping companies should anticipate downstream NIS2 supply-chain security pressure: port operators may demand evidence of Article 21 compliance from equipment suppliers, or embed cybersecurity requirements in procurement contracts.
Across every enforcement track, maritime cyber compliance has moved from "advisory guidance" to "checked, certified, and penalized." The ISM umbrella captures PSC's indirect enforcement; E26/E27 locks the design gate for new-builds; the USCG rule and NIS2 each establish traceable, penalizable hard obligations at the national and regional level. For every link in the maritime supply chain, the question is no longer "whether to take cybersecurity seriously" — it is "on which track will scrutiny arrive first, and how deep must preparation go."
Sources
- Paris MoU Annual Report 2023 (detention rate 3.81%; 639 detentions, annual report basis) — Paris MoU on Port State Control · 2024-07-01
- Tokyo MoU Annual Report 2023 (1,334 detentions / 4.32%; 30,887 inspections) — Tokyo MoU on Port State Control in the Asia-Pacific Region · 2024
- Final rule — Cybersecurity in the Marine Transportation System, 90 FR 6298 (33 CFR 101 Subpart F) — US Coast Guard / Federal Register · 2025-01-17
- NIS2 Directive (EU) 2022/2555 Article 23 (multi-stage incident reporting) — European Parliament and of the Council of the EU · 2022-12-14
- USCG CVC-WI-027 Vessel Cyber Risk Management Work Instruction (action code 30 = detention + external ISM audit within 3 months) — US Coast Guard, Office of Commercial Vessel Compliance (DCO) · 2020-10
- DNV Cyber Secure Class Notation (entry / Essential / Advanced; Essential maps to IEC 62443 security profile 1) — DNV · 2024
- ABS Maritime Cybersecurity Regulatory Updates (CR mandatory notation for post-Jul 2024 contracts; CyberSafety CS-1/CS-2 legacy voluntary) — American Bureau of Shipping · 2025
- LR Cyber Resilience Classification: North Star Grampian Kestrel / Grampian Eagle world's first certified vessels — Lloyd's Register · 2025
- Bureau Veritas NR659 Rules on Cyber Security (Jul 2024 ed.; CYBER RESILIENT level added 2023 to align with UR E26) — Bureau Veritas Marine & Offshore · 2024-07
- ClassNK IACS UR E26/E27 Implementation (CybR-G notation; G = Guideline-based) — ClassNK (Nippon Kaiji Kyokai) · 2024
- eCFR 33 CFR Part 101 Subpart F — Cybersecurity (current text) — eCFR / GPO · 2025
- USCG Final Rule Implementation Timeline (training 2026-01-12; CySO + plan 2027-07-16) — US Coast Guard Maritime Commons · 2025
- 2025 Joint Paris/Tokyo MoU CIC: Ballast Water Management (not cybersecurity) — Paris MoU / Tokyo MoU · 2025
Share this asset
Share this asset
https://www.haishide.com/en/resources/enforcement-psc-class-and-uscg
This asset's reading of IACS UR E26/E27 is for reference only; formal compliance requirements and classification are decided by the class society.

