IACS Recommendation No. 194 - Cybersecurity Controls for Existing Ships
IACS Recommendation No. 194 (December 2025) sets a minimum baseline of fourteen cybersecurity controls for existing ships (contracted before 1 July 2024, over 100 GT), which the class rules of UR E26 and E27 do not cover: an OT asset inventory; network segmentation into OT, IT and crew zones; malware protection, access control, wireless limits, controlled remote access, USB and portable device protection, crew training and managed updates; network monitoring; shore contacts, incident reporting and response with network isolation; and backup and restore. Each control points to the UR E26 requirement it scales down for the existing fleet.
IACS Recommendation No. 194 - Cybersecurity Controls for Existing Ships is a compliance framework from International (maritime classification) with 1 domains and 14 controls that map to 2 other frameworks. The largest domains are Cybersecurity controls (section 4.2 table) – IACS Recommendation No. 194 - Cybersecurity Controls for Existing Ships (14 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (1)
Cybersecurity controls (section 4.2 table) – IACS Recommendation No. 194 - Cybersecurity Controls for Existing Ships
Maps to 2 other frameworks
Coverage is not the same as your position
This page shows what IACS Recommendation No. 194 - Cybersecurity Controls for Existing Ships overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is IACS Recommendation No. 194 - Cybersecurity Controls for Existing Ships and who does it apply to?
IACS Recommendation No. 194 - Cybersecurity Controls for Existing Ships is a compliance framework from International (maritime classification) with 1 domains and 14 controls. IACS Recommendation No. 194 (December 2025) sets a minimum baseline of fourteen cybersecurity controls for existing ships (contracted before 1 July 2024, over 100 GT), which the class rules of UR E26 and E27 do not cover: an OT asset inventory; network segmentation into OT, IT and crew zones; malware protection, access control, wireless limits, controlled remote access, USB and portable device protection, crew training and managed updates; network monitoring; shore contacts, incident reporting and response with network isolation; and backup and restore. Each control points to the UR E26 requirement it scales down for the existing fleet. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does IACS Recommendation No. 194 - Cybersecurity Controls for Existing Ships actually require?
IACS Recommendation No. 194 - Cybersecurity Controls for Existing Ships has 14 controls organised across 1 domains. The largest domains are Cybersecurity controls (section 4.2 table) – IACS Recommendation No. 194 - Cybersecurity Controls for Existing Ships (14 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of IACS Recommendation No. 194 - Cybersecurity Controls for Existing Ships do I already cover?
IACS Recommendation No. 194 - Cybersecurity Controls for Existing Ships maps to 2 other compliance frameworks. The top mapping partners are IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems (100% coverage), BIMCO Cyber Security (100% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement IACS Recommendation No. 194 - Cybersecurity Controls for Existing Ships?
Start your IACS Recommendation No. 194 - Cybersecurity Controls for Existing Ships compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about IACS Recommendation No. 194 - Cybersecurity Controls for Existing Ships requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 14 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 723 frameworks.
Get Started Free →Free forever — no credit card required