IACS Unified Requirements E26/E27 — Cyber Resilience of Ships and On-Board Systems
International Association of Classification Societies (IACS) Unified Requirements E26 (Cyber Resilience of Ships) and E27 (Cyber Resilience of On-Board Systems and Equipment), mandatory from 1 July 2024 for new ship construction contracts. E26 addresses ship-level cyber resilience requirements across the vessel lifecycle. E27 addresses equipment-level cyber security requirements for system integrators and equipment suppliers. Together they establish the first mandatory classification society cyber requirements for new builds. All 12 IACS member classification societies must implement these requirements (covering 90%+ of global tonnage). Aligned with IEC 62443 for industrial automation security.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (5)
UR E26 — Detect
| Code | Title |
|---|---|
| E26-R10 | Network monitoring |
| E26-R11 | Logging and audit trail |
| E26-R12 | Alerting mechanisms |
UR E26 — Identify
| Code | Title |
|---|---|
| E26-R1 | Asset inventory |
| E26-R2 | Network architecture documentation |
| E26-R3 | Risk assessment |
UR E26 — Protect
| Code | Title |
|---|---|
| E26-R4 | Network segmentation |
| E26-R5 | Access control |
| E26-R6 | Secure remote access |
| E26-R7 | Physical security of systems |
| E26-R8 | Protection of wireless communications |
| E26-R9 | Software maintenance and update management |
UR E26 — Respond and Recover
| Code | Title |
|---|---|
| E26-R13 | Incident response plan |
| E26-R14 | Incident communication |
| E26-R15 | Recovery planning |
| E26-R16 | Backup and restoration |
| E26-R17 | Lessons learned |
UR E27 — On-Board Systems and Equipment
| Code | Title |
|---|---|
| E27-R1 | System hardening |
| E27-R2 | Secure communications |
| E27-R3 | User authentication |
| E27-R4 | Software integrity |
| E27-R5 | Security event logging |
Maps to 490 other frameworks
Frequently Asked Questions
What is IACS Unified Requirements E26/E27 — Cyber Resilience of Ships and On-Board Systems?
IACS Unified Requirements E26/E27 — Cyber Resilience of Ships and On-Board Systems is a compliance framework from International (IACS — 12 classification societies) with 5 domains and 22 controls. International Association of Classification Societies (IACS) Unified Requirements E26 (Cyber Resilience of Ships) and E27 (Cyber Resilience of On-Board Systems and Equipment), mandatory from 1 July 2024 for new ship construction contracts. E26 addresses ship-level cyber resilience requirements across the vessel lifecycle. E27 addresses equipment-level cyber security requirements for system integrators and equipment suppliers. Together they establish the first mandatory classification society cyber requirements for new builds. All 12 IACS member classification societies must implement these requirements (covering 90%+ of global tonnage). Aligned with IEC 62443 for industrial automation security. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does IACS Unified Requirements E26/E27 — Cyber Resilience of Ships and On-Board Systems have?
IACS Unified Requirements E26/E27 — Cyber Resilience of Ships and On-Board Systems has 22 controls organised across 5 domains. The largest domains are UR E26 — Protect (6 controls), UR E26 — Respond and Recover (5 controls), UR E27 — On-Board Systems and Equipment (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does IACS Unified Requirements E26/E27 — Cyber Resilience of Ships and On-Board Systems map to?
IACS Unified Requirements E26/E27 — Cyber Resilience of Ships and On-Board Systems maps to 490 other compliance frameworks. The top mapping partners are CSA CCM v4 (55% coverage), AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) (55% coverage), CISA ICS-CERT Advisories and Industrial Control Systems Security Guidelines (55% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with IACS Unified Requirements E26/E27 — Cyber Resilience of Ships and On-Board Systems compliance?
Start your IACS Unified Requirements E26/E27 — Cyber Resilience of Ships and On-Board Systems compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about IACS Unified Requirements E26/E27 — Cyber Resilience of Ships and On-Board Systems requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 22 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required