IACS Unified Requirement E27 Cyber Resilience of On-Board Systems and Equipment adopted April 2022 by IACS. Complements UR E26 (ship-level) by addressing equipment / system level. Applies to: third-party equipment + OEM systems installed on ships subject to UR E26. Effective: new ships contracted from 1 July 2024. System categorization by impact on ship safety + operation: Category I (essential for ship safety + propulsion + steering + DP + navigation + alarm + safety systems); Category II (essential to ship operation + cargo + ballast + bilge + emission); Category III (administrative / convenience / crew). Higher category = stricter security capability requirements. Security capability profiles map to IEC 62443-3-3 Security Levels (SL 1 / SL 2 / SL 3 / SL 4): Category I typically SL 2-3; Category II typically SL 1-2; Category III typically SL 1. UR E27 requires equipment manufacturers / suppliers / vendors to: demonstrate security capabilities by category profile; complete type approval / class society approval per Member Society + UR E27; provide documentation package for ship owner; support vulnerability disclosure + patching + lifecycle. UR E27 capability requirements aligned with IEC 62443-4-2 Component Requirements (CR) covering authentication + use control + system integrity + data confidentiality + restricted data flow + timely response to events + resource availability. IACS UR E27 + system categorization + I/II/III + IEC 62443 SL + type approval applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.