海仕德数据服务
SolutionsCompliance

E26 / E27 cyber-resilience compliance

Which E27 clauses you fall short on, how long to close them, how to assemble the evidence — minimizing the trial-and-error cost of a first Type Approval.

2024.7.1Rev.1 mandatory
Mandatory for new builds contracted on or after this date; the original edition does not apply — only Rev.1 is in force.
30+11Security capabilities
E27 specifies 30 baseline capabilities (required of every CBS) plus 11 additional capabilities (triggered when an interface connects to an untrusted network).
SP1Minimum to comply
Security Profile level; SP1 is the minimum requirement for E26/E27 compliance, with technical requirements drawn from IEC 62443-3-3.
Why now · who's responsible

E26 covers the ship, E27 the device — the two interlock into one compliance chain

First get the responsibility boundary clear: E26 addresses the whole ship (shared by integrator/yard, owner and class society), E27 the maker of a single CBS. Once your device is on board, E26 integrates, networks, segregates and verifies it at the ship level.

Five functions: compliance is not a document, it's five capabilities

E26/E27 share the lineage of IMO and NIST, organized by five functions — and our remediation lands item by item against them.

Spelling out the rules

What E27 actually requires: a security level + 30 baseline + 11 additional

Two diagrams make E27's core requirements clear — the starting point for aligning scope and pricing the work with you.

Security Profile level

Set the target SP first, then work back to the capabilities to close.

Number of capabilities

Whether you connect an 'untrusted network' decides if you need the extra 11.

How we walk it with you

Compliance lifecycle · 6 stages

Each stage has clear actions and deliverable evidence — the heart of the E26/E27 flagship page.

  1. Gap assessmentGap Assessment

    Check the current state clause by clause against E27's 30+11 security capabilities (or E26's 17 requirements), set the target Security Profile level, and identify interfaces to 'untrusted networks'.

    Deliver: Gap-assessment report · clause-level compliance matrix · SP rating recommendation

  2. Remediation plan & implementationRemediation

    Close the gaps: access control, zones & conduits segmentation, system hardening, logging and event recording, backup and recovery, and where necessary the design of compensating measures.

    Deliver: Remediation roadmap · secure-configuration guide · compensating-measure justification

  3. Pre-submission / pre-type-test checkPre-submission Check

    An internal rehearsal before submission and type test: verifying the document set is complete and self-testing against the 'security-capability test procedure' to reduce rework from failing on the first attempt. Note: the real verification of cyber resilience is the type test; FAT itself proceeds as a routine acceptance and usually does not add a separate security test.

    Deliver: Submission completeness checklist · security-capability self-test record · draft test procedure

  4. Type Approval submission & type testType Approval & Type Test

    Prepare the E27 statutory document set (asset inventory, physical/logical topology, security-capability description, test procedures, secure-configuration guide, SDLC documents, maintenance and verification plan, change-management plan, etc.) and undergo the classification society's type test; once passed, do a streamlined plan approval for the specific ship.

    Deliver: Complete submission document pack · type-test attendance support · goal = cyber-resilience Type Approval certificate

  5. Remote access & maintenance complianceRemote Access & Maintenance

    Any interface to an 'untrusted network' (remote maintenance, data collection for the owner, wireless access) triggers E27's 11 additional capabilities, which must be disclosed and justified in the risk assessment and plan approval.

    Deliver: Remote/wireless interface disclosure · risk assessment · additional-capability compliance evidence

  6. Annual survey & maintaining complianceAnnual Survey

    During operation the classification society verifies continued conformance at the annual survey using the 'cyber-resilience test procedure'; we provide review preparation and change- and maintenance-verification support.

    Deliver: Annual-survey preparation pack · change/maintenance records · test-procedure execution records

Method · visible rigor

Clause-level compliance matrix: traceable, auditable

We don't say 'we'll do security for you'; we map each E27 capability to a specific IEC 62443-3-3 clause and mark the status and gap. Below is the matrix's structural illustration.

※ Structural illustration only, not any client's real data. The actual matrix is filled in clause by clause for your device model.

What it is

IACS UR E26 (cyber resilience of ships) and E27 (cyber resilience of on-board systems and equipment) Rev.1 are mandatory from 1 July 2024 for new builds contracted on or after that date. E26 addresses the whole ship, organizing 17 requirements under Identify / Protect / Detect / Respond / Recover; E27 addresses the maker of a single CBS (computer-based system), specifying 30 baseline plus 11 additional security capabilities (technical requirements drawn from IEC 62443-3-3), verified through Type Approval. We work alongside on-board equipment makers and yards to walk the compliance backbone from gap assessment to annual survey.

Who it's for

Equipment makers and yard technical leads who were just asked for E27 documentation and don't yet know how far short they are or where to start.

What we do / deliverables

  • Gap-assessment report and clause-level compliance matrix (against E27 30+11 / E26's 17 / IEC 62443-3-3)
  • Security Profile rating recommendation and untrusted-network interface identification
  • Remediation roadmap, secure-configuration guide and compensating-measure justification
  • Submission-ready E27 statutory document set (asset inventory, physical/logical topology, security-capability description, test procedures, SDLC documents, etc.)
  • Type-test attendance support and annual-survey preparation pack

Why choose us

  1. Process clarity — turning the real backbone (Type Approval → per-ship plan approval → type test/commissioning → annual survey) into an executable, staged roadmap that lowers trial-and-error for a first certification (as of end-2024 most mainstream suppliers were not yet approved — a genuine pain point).

  2. Mapping rigor — a clause-level compliance matrix (against E27 30+11 / E26's 17 / IEC 62443-3-3) that keeps everything traceable and auditable, rather than vaguely 'doing security'.

  3. Standards bridging — familiarity with how IEC 62443-3-3/4-1 and IEC 61162-460 relate to E27, helping products that already hold related compliance assets transition at low cost.

Standards & basis

IACS UR E26IACS UR E27 Rev.1IEC 62443-3-3IEC 62443-4-1IEC 61162-460Type Approval

FAQ

How does E27 relate to IEC 62443? If we've already done 62443, do we start over?
E27's security capabilities are drawn directly from IEC 62443-3-3 and reference 62443-4-1 (secure development lifecycle). Products that already hold related compliance assets can usually transition to E27 at lower cost — we first do an equivalence mapping and reuse your existing evidence rather than reinventing the wheel.
My device isn't networked — do I still need all 11 additional capabilities?
Not necessarily. The 11 additional capabilities are only triggered when the CBS has an interface to an 'untrusted network' (e.g. remote maintenance, data collection for the owner, wireless access). The first step of the gap assessment is to clarify your interfaces, so you avoid over-compliance and wasted spend.
Will FAT (factory acceptance) suddenly require cybersecurity testing?
The real verification of cyber resilience is the 'type test', carried out with a classification-society surveyor present; FAT itself proceeds as a routine acceptance and usually does not add a separate security test (unless the society requires otherwise). We run a pre-check before submission/type test precisely to reduce rework from failing on the first attempt.
Can you issue the certificate directly?
No — and we shouldn't. Statutory actions such as type tests and annual surveys are carried out by the classification society; what we provide is preparation, clause mapping, remediation and review support, helping you clear the society's gate efficiently and traceably.
Start an inquiry

Tell us what you need

The message below is pre-filled with the solution you're viewing (you can still edit it). Haishide's compliance engineering team will get back to you within 1–2 business days.

E26 / E27 cyber-resilience compliance

Provide at least a phone or an email so we can reach you.