IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems
International Association of Classification Societies (IACS) Unified Requirements E26 (Cyber Resilience of Ships) and E27 (Cyber Resilience of On-Board Systems and Equipment), mandatory from 1 July 2024 for new ship construction contracts. E26 addresses ship-level cyber resilience requirements across the vessel lifecycle. E27 addresses equipment-level cyber security requirements for system integrators and equipment suppliers. Together they establish the first mandatory classification society cyber requirements for new builds. All 12 IACS member classification societies must implement these requirements (covering 90%+ of global tonnage). Aligned with IEC 62443 for industrial automation security.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (19)
IACS UR E26 Detect
| Code | Title |
|---|---|
| IACS-UR-E26-Detect-Logging-Monitoring-Audit-Alerting | IACS UR E26 Detect Goal - Logging + Network Monitoring + Audit Trail + Alerting + SIEM |
IACS UR E26 Identify - Asset Inventory + Network Architecture
| Code | Title |
|---|---|
| IACS-UR-E26-Identify-AssetInventory-CBS-NetworkArchitecture-Risk | IACS UR E26 Identify Goal - Asset Inventory of Computer Based Systems + Network Architecture Documentation + Risk-Assessable Scope |
IACS UR E26 Identify - Risk + Plan
| Code | Title |
|---|---|
| IACS-UR-E26-Identify-Plan-Risk-Survey-Documentation | IACS UR E26 Identify Goal - Ship Cyber Resilience Plan + CBS Risk Assessment + Survey + Documentation |
IACS UR E26 Implementation - Training + Supplier
| Code | Title |
|---|---|
| IACS-UR-E26-Implementation-Training-Supplier-OEM-OnboardTraining | IACS UR E26 Implementation - Training + Awareness + Supplier + OEM Management + Cyber Hygiene |
IACS UR E26 Protect - Access + IAM
| Code | Title |
|---|---|
| IACS-UR-E26-Protect-AccessControl-Authentication-IAM-Roles | IACS UR E26 Protect Goal - Access Control + Identity + Authentication + Authorization + User Management |
IACS UR E26 Protect - Malware + Patch
| Code | Title |
|---|---|
| IACS-UR-E26-Protect-Malware-Patch-VulnMgmt-Hardening | IACS UR E26 Protect Goal - Malware Defence + Patch + Vulnerability Management + Hardening + Whitelisting |
IACS UR E26 Protect - Network Segmentation
| Code | Title |
|---|---|
| IACS-UR-E26-Protect-NetworkSegmentation-Zones-Conduits-Boundary | IACS UR E26 Protect Goal - Network Segmentation + Zones + Conduits + Boundary Defence + Data Diodes |
IACS UR E26 Protect - Remote + Wireless + Physical
| Code | Title |
|---|---|
| IACS-UR-E26-Protect-RemoteAccess-Wireless-Physical-Boundary | IACS UR E26 Protect Goal - Remote Access + Wireless + Physical Security + Boundary Protection |
IACS UR E26 Respond + Recover
| Code | Title |
|---|---|
| IACS-UR-E26-Respond-Recover-IncidentResponse-Recovery-Backup-Lessons | IACS UR E26 Respond + Recover Goals - Incident Response + Communication + Recovery + Backup + Lessons Learned |
IACS UR E26 Scope + Applicability
| Code | Title |
|---|---|
| IACS-UR-E26-Scope-Applicability-2024-IMO-MSC-428 | IACS UR E26 - Scope + Applicability + Effective 1 July 2024 + Coordination IMO MSC.428(98) + Member Societies |
IACS UR E26 Survey + Approval
| Code | Title |
|---|---|
| IACS-UR-E26-Survey-Approval-Documentation-OwnerPackage | IACS UR E26 - Class Society Survey + Approval + Owner Documentation + Periodic Review |
IACS UR E27 Documentation + Coordination
| Code | Title |
|---|---|
| IACS-UR-E27-Documentation-Owner-Package-Coordination-IMO-IEC-NIST | IACS UR E27 - Documentation Package for Owner + Coordination IMO + IEC 62443 + NIST CSF + 2024-2025 Pipeline |
IACS UR E27 Hardening + Communications
| Code | Title |
|---|---|
| IACS-UR-E27-Equipment-Hardening-SecureConfig-Communications | IACS UR E27 - Equipment Hardening + Secure Configuration + Secure Communications + Cryptography |
IACS UR E27 Logging + Forensics
| Code | Title |
|---|---|
| IACS-UR-E27-Logging-Forensics-EventCapture | IACS UR E27 - Equipment Logging + Forensic Readiness + Event Capture + Tamper Detection |
IACS UR E27 SBOM + Secure Dev
| Code | Title |
|---|---|
| IACS-UR-E27-SBOM-SecureDev-TypeApproval-SoftwareIntegrity | IACS UR E27 - Software Bill of Materials + Secure Development Lifecycle + Type Approval + Software Integrity |
IACS UR E27 Scope + System Categorization
| Code | Title |
|---|---|
| IACS-UR-E27-Scope-System-Categorization-CategoryI-II-III | IACS UR E27 - Scope + System-Level Applicability + Category I/II/III Classification + IEC 62443 Security Levels |
IACS UR E27 Security Capabilities
| Code | Title |
|---|---|
| IACS-UR-E27-SecurityCapabilities-IEC62443-CategoryProfile | IACS UR E27 - Security Capabilities by Category + IEC 62443-4-2 Foundational Requirements + Component Requirements |
IACS UR E27 Updates + Patch
| Code | Title |
|---|---|
| IACS-UR-E27-Updates-Patch-Mechanisms-Maintenance | IACS UR E27 - Equipment Update + Patch Mechanisms + Maintenance + Lifecycle Support |
IACS UR E27 User Auth
| Code | Title |
|---|---|
| IACS-UR-E27-Equipment-UserAuth-Authentication-Authorization | IACS UR E27 - Equipment User Authentication + Authorization + Session Management + Privileged Access |
Your Compliance Coverage
If you comply with IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems, you already cover:
OWASP ASVS
42%
8 controls mapped
Compare →MITRE D3FEND
42%
8 controls mapped
Compare →AWS Well-Architected Security Pillar
42%
8 controls mapped
Compare →+ 96 more: Azure Security Benchmark (42%), BSI IT-Grundschutz (42%)
See all 99 mapped frameworks ↓Maps to 99 other frameworks
Frequently Asked Questions
What is IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems?
IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems is a compliance framework from International (IACS — 12 classification societies) with 19 domains and 19 controls. International Association of Classification Societies (IACS) Unified Requirements E26 (Cyber Resilience of Ships) and E27 (Cyber Resilience of On-Board Systems and Equipment), mandatory from 1 July 2024 for new ship construction contracts. E26 addresses ship-level cyber resilience requirements across the vessel lifecycle. E27 addresses equipment-level cyber security requirements for system integrators and equipment suppliers. Together they establish the first mandatory classification society cyber requirements for new builds. All 12 IACS member classification societies must implement these requirements (covering 90%+ of global tonnage). Aligned with IEC 62443 for industrial automation security. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems have?
IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems has 19 controls organised across 19 domains. The largest domains are IACS UR E26 Detect (1 controls), IACS UR E26 Identify - Asset Inventory + Network Architecture (1 controls), IACS UR E26 Identify - Risk + Plan (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems map to?
IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems maps to 99 other compliance frameworks. The top mapping partners are OWASP ASVS (42% coverage), MITRE D3FEND (42% coverage), AWS Well-Architected Security Pillar (42% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems compliance?
Start your IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 19 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 723 frameworks.
Get Started Free →Free forever — no credit card required