E26 / E27 cyber-resilience compliance
Which E27 clauses you fall short on, how long to close them, how to assemble the evidence — minimizing the trial-and-error cost of a first Type Approval.
- 2024.7.1Rev.1 mandatory
- Mandatory for new builds contracted on or after this date; the original edition does not apply — only Rev.1 is in force.
- 30+11Security capabilities
- E27 specifies 30 baseline capabilities (required of every CBS) plus 11 additional capabilities (triggered when an interface connects to an untrusted network).
- SP1Minimum to comply
- Security Profile level; SP1 is the minimum requirement for E26/E27 compliance, with technical requirements drawn from IEC 62443-3-3.
E26 covers the ship, E27 the device — the two interlock into one compliance chain
First get the responsibility boundary clear: E26 addresses the whole ship (shared by integrator/yard, owner and class society), E27 the maker of a single CBS. Once your device is on board, E26 integrates, networks, segregates and verifies it at the ship level.
Cyber Resilience of Ships · integration / networking / segregation / verification
Five functions: compliance is not a document, it's five capabilities
E26/E27 share the lineage of IMO and NIST, organized by five functions — and our remediation lands item by item against them.
What E27 actually requires: a security level + 30 baseline + 11 additional
Two diagrams make E27's core requirements clear — the starting point for aligning scope and pricing the work with you.
Security Profile level
Set the target SP first, then work back to the capabilities to close.
Number of capabilities
Whether you connect an 'untrusted network' decides if you need the extra 11.
Compliance lifecycle · 6 stages
Each stage has clear actions and deliverable evidence — the heart of the E26/E27 flagship page.
Gap assessmentGap Assessment
Check the current state clause by clause against E27's 30+11 security capabilities (or E26's 17 requirements), set the target Security Profile level, and identify interfaces to 'untrusted networks'.
Deliver: Gap-assessment report · clause-level compliance matrix · SP rating recommendation
Remediation plan & implementationRemediation
Close the gaps: access control, zones & conduits segmentation, system hardening, logging and event recording, backup and recovery, and where necessary the design of compensating measures.
Deliver: Remediation roadmap · secure-configuration guide · compensating-measure justification
Pre-submission / pre-type-test checkPre-submission Check
An internal rehearsal before submission and type test: verifying the document set is complete and self-testing against the 'security-capability test procedure' to reduce rework from failing on the first attempt. Note: the real verification of cyber resilience is the type test; FAT itself proceeds as a routine acceptance and usually does not add a separate security test.
Deliver: Submission completeness checklist · security-capability self-test record · draft test procedure
Type Approval submission & type testType Approval & Type Test
Prepare the E27 statutory document set (asset inventory, physical/logical topology, security-capability description, test procedures, secure-configuration guide, SDLC documents, maintenance and verification plan, change-management plan, etc.) and undergo the classification society's type test; once passed, do a streamlined plan approval for the specific ship.
Deliver: Complete submission document pack · type-test attendance support · goal = cyber-resilience Type Approval certificate
Remote access & maintenance complianceRemote Access & Maintenance
Any interface to an 'untrusted network' (remote maintenance, data collection for the owner, wireless access) triggers E27's 11 additional capabilities, which must be disclosed and justified in the risk assessment and plan approval.
Deliver: Remote/wireless interface disclosure · risk assessment · additional-capability compliance evidence
Annual survey & maintaining complianceAnnual Survey
During operation the classification society verifies continued conformance at the annual survey using the 'cyber-resilience test procedure'; we provide review preparation and change- and maintenance-verification support.
Deliver: Annual-survey preparation pack · change/maintenance records · test-procedure execution records
Clause-level compliance matrix: traceable, auditable
We don't say 'we'll do security for you'; we map each E27 capability to a specific IEC 62443-3-3 clause and mark the status and gap. Below is the matrix's structural illustration.
| E27 capability (illustrative) | IEC 62443-3-3 clause | Status | Gap & remediation |
|---|---|---|---|
| Identification & authentication control | SR 1.1 / 1.2 | Met | Accounts and password policy in place; add audit trail |
| Remote-access management | SR 1.6 / 2.6 | Partial | Triggers the 11 additional capabilities; add MFA & session management |
| Network segmentation (zones & conduits) | SR 5.1 | Gap | IT/OT not segregated; design zone & conduit boundaries |
| Event logging & time sync | SR 2.8 / 2.11 | Partial | Local logs exist; missing central retention & unified clock |
| Backup & recoverability | SR 7.3 / 7.4 | Gap | Establish a verifiable backup & recovery procedure |
※ Structural illustration only, not any client's real data. The actual matrix is filled in clause by clause for your device model.
Find the E27 breakdown for your equipment
Pick your shipboard system to jump straight to its E27 page — its category, applicable clauses, common fail points and submission evidence at a glance.
- Navigation & CommsIACS UR E27 Category II · E27View E27 landing page
- Automation (IAS)IACS UR E27 Category III · E27View E27 landing page
- Engine Room MonitoringIACS UR E27 Category II · E27View E27 landing page
- Electric PropulsionIACS UR E27 Category III · E27View E27 landing page
- Marine Network EquipmentIACS UR E27 Category II · E27View E27 landing page
- Fire & AlarmIACS UR E27 Category II · E27View E27 landing page
- Cargo ControlIACS UR E27 Category II · E27View E27 landing page
- Ballast SystemIACS UR E27 Category I · E27View E27 landing page
What it is
IACS UR E26 (cyber resilience of ships) and E27 (cyber resilience of on-board systems and equipment) Rev.1 are mandatory from 1 July 2024 for new builds contracted on or after that date. E26 addresses the whole ship, organizing 17 requirements under Identify / Protect / Detect / Respond / Recover; E27 addresses the maker of a single CBS (computer-based system), specifying 30 baseline plus 11 additional security capabilities (technical requirements drawn from IEC 62443-3-3), verified through Type Approval. We work alongside on-board equipment makers and yards to walk the compliance backbone from gap assessment to annual survey.
Who it's for
Equipment makers and yard technical leads who were just asked for E27 documentation and don't yet know how far short they are or where to start.
What we do / deliverables
- Gap-assessment report and clause-level compliance matrix (against E27 30+11 / E26's 17 / IEC 62443-3-3)
- Security Profile rating recommendation and untrusted-network interface identification
- Remediation roadmap, secure-configuration guide and compensating-measure justification
- Submission-ready E27 statutory document set (asset inventory, physical/logical topology, security-capability description, test procedures, SDLC documents, etc.)
- Type-test attendance support and annual-survey preparation pack
Why choose us
Process clarity — turning the real backbone (Type Approval → per-ship plan approval → type test/commissioning → annual survey) into an executable, staged roadmap that lowers trial-and-error for a first certification (as of end-2024 most mainstream suppliers were not yet approved — a genuine pain point).
Mapping rigor — a clause-level compliance matrix (against E27 30+11 / E26's 17 / IEC 62443-3-3) that keeps everything traceable and auditable, rather than vaguely 'doing security'.
Standards bridging — familiarity with how IEC 62443-3-3/4-1 and IEC 61162-460 relate to E27, helping products that already hold related compliance assets transition at low cost.
Standards & basis
FAQ
How does E27 relate to IEC 62443? If we've already done 62443, do we start over?
My device isn't networked — do I still need all 11 additional capabilities?
Will FAT (factory acceptance) suddenly require cybersecurity testing?
Can you issue the certificate directly?
Tell us what you need
The message below is pre-filled with the solution you're viewing (you can still edit it). Haishide's compliance engineering team will get back to you within 1–2 business days.
E26 / E27 cyber-resilience compliance

