海仕德数据服务
BriefingEquipment vendorYard / ownerDesign house

IMO 2021: How Maritime Cyber Risk Management Began

In one lineBefore E26/E27, the IMO folded cyber risk into the safety management system. Understand the watershed between the “in-service” and “new-build” logics.

Key takeaways

  • IMO Resolution MSC.428(98) (2017) requires cyber risk to be addressed in the safety management system (SMS).
  • Deadline: the company's Document of Compliance must cover it from the first annual verification after 1 January 2021.
  • Companion guidance MSC-FAL.1/Circ.3 gives five functions: Identify, Protect, Detect, Respond, Recover (NIST-aligned).
  • The IMO regime targets in-service ships (process / owner responsibility); E26/E27 targets new-builds (design / build).

Many assume maritime cybersecurity began with E26/E27. It started earlier — in 2017 the IMO wrote cyber risk management into the mandatory safety management system, with a 2021 deadline the industry calls "IMO 2021." This article traces the regulatory origin, the enforcement chain, the five functions and their operational meaning, the complementary logic of in-service versus new-build regimes, and the changes brought by Rev.3 in 2025 — for yards, shipowners, and equipment suppliers.

Why 2017: the regulatory origin and catalytic events

The passage of MSC.428(98) was not an unprompted policy move — it was a delayed response to a string of real events. As early as 2011, researchers at Erasmus University Rotterdam publicly demonstrated cyberattacks against a vessel's antifouling system. From 2011 to 2013, the port of Antwerp became the scene of a drug-trafficking operation in which criminals infiltrated the port's container logistics and release systems to time pickups of concealed narcotics — an operation that ran for roughly two years before arrests in 2013. Proof-of-concept reports on ECDIS spoofing, GPS jamming, and remote steering-system takeovers were appearing regularly in specialist media. By 2016–2017, a consensus had formed among flag states and classification societies: conventional safety management systems were essentially silent on cyber threats — no asset inventories, no intrusion detection, no incident response plans.

The IMO's Maritime Safety Committee reviewed this threat landscape at its 98th session (MSC 98, 7–16 June 2017) and adopted Resolution MSC.428(98) on 16 June 2017. Within weeks of the session's close, the NotPetya ransomware swept the globe — Maersk Group bore the full brunt, reportedly suffering losses of around USD 250–300 million, with roughly 45,000 computers and 4,000 servers requiring full reinstallation. That event demonstrated to the global shipping industry that cyber risk was not a future threat but an immediate operational reality. The legislative timing of IMO 2021 thus carries genuine historical significance.

One resolution: the normative content of MSC.428(98)

On 16 June 2017, the IMO's Maritime Safety Committee adopted Resolution MSC.428(98), affirming that "an approved safety management system should take into account cyber risk management in accordance with the objectives and functional requirements of the ISM Code," and encouraging administrations to ensure cyber risk is addressed by "the first annual verification of the company's Document of Compliance after 1 January 2021." This sentence is the legal anchor of the entire IMO 2021 framework and deserves careful reading word by word.

"Encourages" is not an exemption — parsing the resolution's language

The resolution uses "encourages" rather than "requires," leading some to treat it as soft law. The mandatory effect, however, derives from the ISM Code itself: SOLAS Chapter IX (in force from 1 July 1998) requires that every applicable ship's SMS address "all identified hazards." Once cyber threats are recognized as hazards, failure to address them in the SMS constitutes a non-conformity under the ISM Code — one that will be cited during annual DoC verifications or port state control inspections. Major flag states (Panama, Bahamas, Marshall Islands, and others) have issued their own circulars converting the "encourages" into a flag-state-level requirement. The practical enforcement effect is nearly identical to a hard mandate — defer to the specific rules of the applicable flag state / administration.

The enforcement chain: SMS → DoC → SMC → Port State Control

The key to understanding IMO 2021 is the three-tier certification structure established by the ISM Code (Resolution A.741(18), adopted 4 November 1993) and how MSC.428(98) slots into it.

First tier: the Safety Management System (SMS). The ISM Code requires every shipping company to establish and operate a documented SMS covering everything from company policy to shipboard operating procedures. MSC.428(98)'s core requirement is to write cyber risk management into that system — including asset registers, risk assessments, operating procedures, incident response plans, and periodic drills. The SMS is the foundation; without substantive integration at this tier, no downstream certification can hold.

Second tier: the Document of Compliance (DoC). The DoC is a company-level (not ship-level) certificate, valid for up to five years and subject to annual verification within three months before or after its anniversary date. This annual verification is MSC.428(98)'s enforcement trigger: "the first annual DoC verification after 1 January 2021" means that a company whose DoC anniversary falls in March faces a March 2021 deadline; one with an October anniversary faces October 2021. Fleet-wide compliance was therefore phased across the full calendar year 2021, not a single uniform cutoff date. Verification is conducted by the administration or its delegated Recognized Organization (RO / classification society). If an auditor finds the SMS lacking cyber risk management content, a Non-Conformity (NC) is raised; the company must close it within a specified period or face DoC suspension or withdrawal.

Third tier: the Safety Management Certificate (SMC) and Port State Control. The SMC is the ship-level certificate — also a five-year cycle with at least one intermediate verification — confirming that the vessel operates in accordance with the company's approved SMS. Port State Control (PSC) then provides a "last line of defense" via random inspections at ports worldwide: the Paris MOU, Tokyo MOU, and US Coast Guard all conduct ISM Code compliance checks on calling vessels. This means that even if a flag state's annual verification process has gaps, a ship calling at European or Asia-Pacific ports can still be detained for lacking cyber risk content in its SMS. This gives IMO 2021 genuine global enforcement teeth.

The mechanism: it rides on the ISM Code

Cyber risk isn't separately certified; it folds into the existing safety management system (SMS) — evidenced through the company's DoC and the ship's SMC. So it naturally applies to the existing, in-service fleet, owned by the operator (DPA). The ISM Code covers: passenger ships (including high-speed craft) on international voyages; cargo ships (including high-speed craft) of 500 GT or more; and MODUs on international voyages. Even a single-ship company must hold a DoC.

Companion guidance: four versions of MSC-FAL.1/Circ.3

Resolution MSC.428(98) sets the direction; the operational technical framework is carried by joint circular MSC-FAL.1/Circ.3. The "MSC-FAL" designation reflects joint approval by both the Maritime Safety Committee (MSC) and the Facilitation Committee (FAL) — cyber risk spans both safety and port facilitation, and the joint issuance reflects that cross-domain nature. Four versions have been issued to date:

Original (5 July 2017): jointly approved by FAL 41 (4–7 April 2017) and MSC 98 (7–16 June 2017), issued on 5 July 2017. The original established a functional-element risk management framework covering identification, analysis, communication, mitigation, and monitoring — but did not yet use the explicit NIST CSF labels (Identify / Protect / Detect / Respond / Recover) as direct terminology; that mapping was made progressively more explicit in later revisions. Rev.1 (14 July 2021): retained the five-function structure with content updates, issued in tandem with the 2021 implementation deadline. Rev.2 (7 June 2022): further refined content, still aligned to NIST CSF 1.x five functions; NIST CSF 2.0 had not yet been published at that date. Rev.3 (4 April 2025): approved by MSC 108 (15–24 May 2024) and jointly approved by FAL 49 (10–14 March 2025), issued on 4 April 2025. Rev.3 aligns the guidelines with NIST CSF 2.0, adds a sixth function "Govern," and explicitly cross-references IACS UR E26/E27 as applicable implementation standards for new-builds — completing the reference integration between the strategic layer (IMO guidelines) and the technical layer (IACS rules).

Five functions (six from 2025)

The companion guidance MSC-FAL.1/Circ.3 gives five NIST-aligned functional elements: Identify, Protect, Detect, Respond, Recover. One easy mistake to avoid: Rev.3 (April 2025) added a sixth, "Govern," aligning with NIST CSF 2.0 — so "five functions" describes the 2017–2022 model. The Rev.3 six-function structure is covered in the "Rev.3 addition: the Govern layer" section below.

  1. Identify
  2. Protect
  3. Detect
  4. Respond
  5. Recover
The five functions of cyber risk management (a sixth, "Govern," added from 2025). · SourceIMO MSC-FAL.1/Circ.3 Rev.2 / Rev.3

Operational meaning of the five functions — implications for yards, owners, and suppliers

Function 1: Identify. The Identify function requires the shipping company to systematically inventory all IT and OT assets, understand cyber dependencies between systems, and assess vulnerabilities and threat paths that could be exploited. For a ten-year-old bulk carrier, this means at minimum mapping: ECDIS terminals and their chart update media (USB/network), AIS transceivers, engine room automation systems (PMS/PLC), ballast water management systems, ship-shore communication links (VSAT/Iridium), and remote-access entry points for engine room maintenance software. The asset register need not be exhaustive in granularity, but must be sufficient to support the subsequent risk assessment — "I don't know what I have" is the most common initial Non-Conformity cited in ISM audits. For yards, the Identify deliverable maps directly to the asset inventory component of the Cyber Security Management System (CSMS) required under E26.

Function 2: Protect. The Protect function requires implementing access controls, personnel training programs, data security measures, maintenance procedures, and contingency plans to reduce the attack surface. For the in-service fleet, the practical focus typically falls on: enforcing multi-factor authentication for all ship-shore remote access, scanning USB media before use, physically or logically segregating engine room OT networks from crew Wi-Fi segments, maintaining a patch management plan for critical systems (even via offline updates), and incorporating cybersecurity into annual safety drill curricula. Critically, protective measures should be proportionate to the risk assessment findings — an operator need not impose LNG-carrier-grade controls on a simple bulk carrier, but must be able to document in writing why current controls are commensurate with identified risks. This risk-proportionate principle is central to the ISM framework's logic, and represents the sharpest contrast with the prescriptive requirements of E26/E27.

Function 3: Detect. The Detect function requires processes that enable timely identification of cybersecurity events. For most in-service vessels, this is the hardest of the five functions to implement practically — many legacy OT systems have no logging capability, and engine room networks lack established traffic baselines. In practice, SMS-level detection more often manifests as: establishing anomaly-reporting procedures (what a crew member does when ECDIS behaves unexpectedly), deploying endpoint protection on both ship and shore communication nodes, and monitoring VSAT traffic through a shore-based Security Operations Center (SOC). For equipment suppliers, Rev.3's cross-reference to E26 means that procurement teams will increasingly list "auditable log output" as a technical requirement when evaluating equipment.

Function 4: Respond. The Respond function requires activating plans, managing communications, and containing and mitigating the impact of detected cybersecurity incidents. At the SMS level, response procedures should at minimum define: incident classification criteria (what conditions trigger emergency response), the division of responsibility between the shore-based DPA and the master, degraded operating procedures for maintaining navigational safety when a single system fails, and reporting obligations to the flag state and relevant authorities. During NotPetya, Maersk's inability to process bookings, customs declarations, and container tracking for days was partly attributable to the absence of effective incident response plans — a lesson that has since been incorporated into ISM training materials by multiple classification societies. For equipment suppliers, response plans should also cover emergency shutdown procedures for third-party remote maintenance windows.

Function 5: Recover. The Recover function requires restoring affected systems and capabilities after an incident, capturing lessons learned, and updating plans accordingly. At the SMS level, recovery plans should include: offline backup strategies for critical navigation and engine room systems along with tested recovery cycles, off-vessel storage arrangements for critical configuration parameters (e.g., ECDIS chart license keys, PMS parameter sets), and a documented post-incident review mechanism. Note that "recovery" encompasses not just technical system restoration but also operational process rebuilding and communications management with affected parties. ISM auditors are increasingly examining whether there is evidence that a company actually updated its SMS following past incidents — "drills conducted but procedures never updated" has become a common NC category in recent audit cycles.

The watershed: in-service vs new-build

IMO 2021 (in-service)

  • Scope: existing fleet / operations
  • Nature: process & management (SMS)
  • Owner: shipowner / operator (DPA)
  • Trigger: first DoC verification after 2021-01
  • Enforced via: ISM Code / flag State

E26 & E27 (new-build)

  • Scope: new-builds
  • Nature: prescriptive technical requirements
  • Owner: yards / integrators / suppliers
  • Trigger: contracted on/after 2024-07-01
  • Enforced via: class society rules
Two complementary logics — neither replaces the other.

There is a notable regulatory gap between the two frameworks: ships contracted before 1 July 2024 must satisfy IMO 2021's management-based requirements, but IACS UR E26/E27's prescriptive engineering standards do not apply to them. Such vessels need only demonstrate in their SMS that cyber risk has been identified and managed — they face no requirement to meet E26's 30 security capabilities or E27's equipment type-approval requirements. Two ships flying the same flag on the same trade route may thus face radically different cyber compliance burdens based solely on contract date. This disparity will narrow gradually as fleets renew, but will persist through the coming decade.

They stack, they don't replace

A ship contracted after 2024-07-01 must both meet E26/E27 during construction and keep cyber risk inside its safety management system in operation. E26/E27 does not exempt IMO 2021. From Rev.3 (April 2025), the IMO guidelines explicitly cross-reference E26/E27 as implementation standards for new-builds — the two frameworks are now formally linked at the regulatory-document level.

Rev.3 addition: what the Govern function means

NIST released CSF 2.0 in February 2024 (a public draft had circulated in August 2023), adding "Govern" to the original five functions — elevating cyber risk from the IT department to the boardroom and senior management. IMO followed with Rev.3 (issued 4 April 2025), making it one of the first IMO maritime safety guidance documents to explicitly incorporate all six NIST CSF 2.0 functions (per ABS regulatory summary of MSC-FAL.1/Circ.3/Rev.3).

The Govern function is defined as: establishing and monitoring risk management strategy, expectations, and policy; and defining personnel roles and responsibilities for cyber risk management. For shipping companies, this means in practice that cyber risk must enter the agenda of the company's highest management tier — not just the IT manager or Ship Security Officer (SSO), but DPA and company executives who must be able to explain to an auditor how the company makes strategic decisions about acceptable cyber risk levels, how related budgets are allocated, and how accountability is assigned. Classification societies (ABS, DNV, Lloyd's Register, and others) have already incorporated such governance questions into ISM audit checklists. An SMS cyber chapter that contains only operating procedures — but lacks a governance policy and a management-signed statement — will increasingly be flagged as a gap item against the spirit of Rev.3. For equipment suppliers, the Govern function's impact manifests in procurement: buyers evaluating cybersecurity-related equipment or services will increasingly require suppliers to produce written policies on cybersecurity supply-chain management, not just product specification sheets. This is Rev.3's new pressure point for the supply chain.

Companion industry guidance

A set of companion industry documents is often cited alongside: the Guidelines on Cyber Security Onboard Ships (5th edition, 14 November 2024, jointly published by BIMCO and 18 other organizations), the tanker industry's TMSA3, and the US Coast Guard's NVIC 01-20 — not IMO-mandatory, but widely adopted by owners and charterers. The v5 guidelines added in-depth analysis of cyber threat actors and their tactics, and placed particular emphasis on dynamically updating the cyber security risk assessment whenever networks, systems, connections, or hardware change — closely aligned with the ISM framework's core continuous-improvement philosophy. For yards, assisting owners in completing the initial cyber security risk assessment during the newbuild phase helps satisfy the documentation requirements of both the ISM framework and E26 at delivery.

Share this asset

Share this asset

https://www.haishide.com/en/resources/imo-2021-cyber-risk-management

This asset's reading of IACS UR E26/E27 is for reference only; formal compliance requirements and classification are decided by the class society.