Back to Frameworks

IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4)

International (IMO)
vRev.4 (28 May 2026), with Resolution MSC.428(98)
7 domains
34 controls

The International Maritime Organization's Guidelines on maritime cyber risk management, in their fourth revision (MSC-FAL.1/Circ.3/Rev.4, 28 May 2026), with Resolution MSC.428(98), which asks that the company's safety management system under the ISM Code address cyber risk from the first Document of Compliance verification after 1 January 2021. Six concurrent functional elements (Govern, Identify, Protect, Detect, Respond, Recover) each with an outcome and a list of minimum controls: an accountable person with authority and competence; an onboard digital system inventory and a risk assessment of critical systems and supply chains; unique credentials, default passwords changed, multi-factor authentication where appropriate, OT segmented from IT, logs kept, removable media controlled, annual training and familiarization, backups, updates and incident response plans; threat monitoring; reporting to the Administration's deadlines; recovery strategies and root cause analysis. Recommendatory; 34 leaves read against the official text.

Verified

IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) is a compliance framework from International (IMO) with 7 domains and 34 controls that map to 111 other frameworks. The largest domains are Protect – IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) (10 controls), Governance, leadership and the safety management system – IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) (6 controls), Identify – IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) (4 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (7)

Detect – IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4)

3 controls
Controls in the Detect – IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) domain of IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) — 3 controls
CodeTitle
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.43.5.4 Detect: timely detection of cyber incidents
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.4.13.5.4.1 Threat list and active monitoring
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.4.23.5.4.2 Training to recognise an ongoing incident

Governance, leadership and the safety management system – IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4)

6 controls
Controls in the Governance, leadership and the safety management system – IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) domain of IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) — 6 controls
CodeTitle
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.33.3 Senior management leadership, training and cyber risk culture
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.43.4 Current and desired posture comparison and risk-based prioritisation
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.13.5.1 Govern: strategy, policies, roles and continuity
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.1.13.5.1.1 Accountable person or entity for cybersecurity
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.1.23.5.1.2 Authority, support and competence of the accountable party
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::MSC.428-1MSC.428(98) paragraphs 1 and 2: cyber risk management within the approved safety management system

Identify – IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4)

4 controls
Controls in the Identify – IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) domain of IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) — 4 controls
CodeTitle
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.23.5.2 Identify: current cyber risk to ships and ship/port interfaces
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.2.13.5.2.1 Critical systems, dependencies and supply chains
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.2.23.5.2.2 Inventory of onboard digital systems and connections
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.2.33.5.2.3 Risk assessment of critical systems

Protect – IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4)

10 controls
Controls in the Protect – IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) domain of IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) — 10 controls
CodeTitle
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.33.5.3 Protect: risk controls and contingency planning
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.3.13.5.3.1 User credentials, privileged accounts and leavers
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.3.23.5.3.2 Passwords, authentication and secured communications
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.3.33.5.3.3 Exposure, approvals, logging, segmentation and secure acquisition
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.3.43.5.3.4 Protection of connected systems and cryptography
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.3.53.5.3.5 Unauthorized removable media
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.3.63.5.3.6 Cybersecurity training, familiarization and testing
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.3.73.5.3.7 Backups, software updates and incident response plans
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.3.83.5.3.8 Supply chain security policy for critical systems
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.3.93.5.3.9 Assessing effectiveness and reviewing measures

Recover – IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4)

4 controls
Controls in the Recover – IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) domain of IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) — 4 controls
CodeTitle
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.63.5.6 Recover: restoring onboard CBS and networks
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.6.13.5.6.1 Recovery and reinstatement strategies
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.6.23.5.6.2 Training on recovery
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.6.33.5.6.3 Root cause analysis of incidents

Respond – IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4)

4 controls
Controls in the Respond – IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) domain of IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) — 4 controls
CodeTitle
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.53.5.5 Respond: plans, resilience and containment
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.5.13.5.5.1 Incident reporting within set time frames
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.5.23.5.5.2 Records of cyber incidents
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.5.33.5.5.3 Training on responding to an incident

Supporting provisions: documents, awareness, resilient equipment – IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4)

3 controls
Controls in the Supporting provisions: documents, awareness, resilient equipment – IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) domain of IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) — 3 controls
CodeTitle
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.63.6 Ongoing process and protection of cyber documents
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.73.7 Awareness proportionate to roles
imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.83.8 Cyber-resilient equipment and systems

Your Compliance Coverage

If you comply with IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4), you already cover:

Maps to 111 other frameworks

42 total controls
Singapore Government Instruction Manual on ICT&SS Management (IM8)
5 source controls mapped|8 target controls covered
12%
IEC 62443
5 source controls mapped|9 target controls covered
12%
API 1164
5 source controls mapped|9 target controls covered
12%
OWASP ASVS
4 source controls mapped|4 target controls covered
10%
MITRE D3FEND
4 source controls mapped|3 target controls covered
10%
ASD Strategies to Mitigate Cyber Security Incidents
4 source controls mapped|7 target controls covered
10%
FFIEC Cybersecurity Assessment Tool (CAT)
4 source controls mapped|7 target controls covered
10%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
4 source controls mapped|5 target controls covered
10%
ISO/IEC 27011:2024
4 source controls mapped|6 target controls covered
10%
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
4 source controls mapped|2 target controls covered
10%
FFIEC IT Examination Handbook
3 source controls mapped|7 target controls covered
7%
Protective Security Policy Framework (PSPF) Release 2026
3 source controls mapped|3 target controls covered
7%
IEC 62351 - Power Systems Communication Security
3 source controls mapped|4 target controls covered
7%
ASIS SPC.1-2009 - Organizational Resilience Standard
3 source controls mapped|5 target controls covered
7%
ISO/IEC 27031:2011
3 source controls mapped|6 target controls covered
7%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
3 source controls mapped|4 target controls covered
7%
OWASP DevSecOps Maturity Model (DSOMM)
3 source controls mapped|4 target controls covered
7%
BSI IT-Grundschutz
3 source controls mapped|6 target controls covered
7%
India CERT-In Cyber Security Directions 2022
2 source controls mapped|2 target controls covered
5%
APRA CPS 234
2 source controls mapped|4 target controls covered
5%
US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements
2 source controls mapped|2 target controls covered
5%
ISO/IEC 27007:2020
2 source controls mapped|2 target controls covered
5%
COBIT 2019
2 source controls mapped|2 target controls covered
5%
BS 65000:2014 - Guidance on Organizational Resilience
2 source controls mapped|3 target controls covered
5%
US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule
2 source controls mapped|2 target controls covered
5%
TEFCA - Trusted Exchange Framework and Common Agreement
2 source controls mapped|1 target controls covered
5%
SWIFT CSCF
2 source controls mapped|2 target controls covered
5%
Privacy Act 1988 (Australia)
2 source controls mapped|2 target controls covered
5%
OWASP Top 10:2025
2 source controls mapped|1 target controls covered
5%
Ecuador Ley Orgánica de Protección de Datos Personales (LOPDP)
2 source controls mapped|2 target controls covered
5%
Law No. 172-13 on the Protection of Personal Data
2 source controls mapped|2 target controls covered
5%
Iowa Consumer Data Protection Act
2 source controls mapped|2 target controls covered
5%
Indonesia PDP Law
2 source controls mapped|2 target controls covered
5%
India DPDP Act
2 source controls mapped|2 target controls covered
5%
ISO/IEC 27400:2022
2 source controls mapped|2 target controls covered
5%
Florida Digital Bill of Rights (FDBR)
2 source controls mapped|3 target controls covered
5%
FedRAMP High
2 source controls mapped|2 target controls covered
5%
FedRAMP Moderate
2 source controls mapped|2 target controls covered
5%
IAIS Insurance Core Principles (ICPs)
2 source controls mapped|4 target controls covered
5%
Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)
2 source controls mapped|4 target controls covered
5%
AS9100D - Aerospace Quality Management System
2 source controls mapped|2 target controls covered
5%
IEC 62304:2015 Medical Device Software Lifecycle Processes
2 source controls mapped|7 target controls covered
5%
Annex 11 to EU GMP - Computerised Systems
2 source controls mapped|5 target controls covered
5%
Aged Care Quality Standards 2019 (repealed edition)
2 source controls mapped|2 target controls covered
5%
ISO/IEC 27014:2020
2 source controls mapped|3 target controls covered
5%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
2 source controls mapped|4 target controls covered
5%
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)
2 source controls mapped|3 target controls covered
5%
FBI CJIS Security Policy
2 source controls mapped|3 target controls covered
5%
UAE Virtual Asset Regulatory Authority (VARA) Regulations
2 source controls mapped|4 target controls covered
5%
FDA Quality Management System Regulation (QMSR)
2 source controls mapped|3 target controls covered
5%
FTC GLBA Safeguards Rule (16 CFR Part 314)
2 source controls mapped|3 target controls covered
5%
IATA Operational Safety Audit (IOSA) Standards Manual
2 source controls mapped|2 target controls covered
5%
ICH Q10 - Pharmaceutical Quality System
2 source controls mapped|3 target controls covered
5%
Bahrain PDPL
2 source controls mapped|2 target controls covered
5%
SQF Code Edition 9 - Safe Quality Food
2 source controls mapped|3 target controls covered
5%
US Consumer Product Safety Act (CPSC) Manufacturer and Importer Duties
2 source controls mapped|2 target controls covered
5%
5%
ICAO Annex 17 - Aviation Security (AVSEC)
2 source controls mapped|2 target controls covered
5%
German Supply Chain Due Diligence Act (LkSG)
2 source controls mapped|3 target controls covered
5%
South Korea Cloud Security Assurance Program (CSAP)
1 source controls mapped|1 target controls covered
2%
W3C Verifiable Credentials (VC) Data Model 2.0
1 source controls mapped|1 target controls covered
2%
Vietnam Law on Cybersecurity (No. 116/2025/QH15)
1 source controls mapped|2 target controls covered
2%
Vermont Artificial Intelligence and Consumer Data Act (AICDA)
1 source controls mapped|1 target controls covered
2%
USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement)
1 source controls mapped|1 target controls covered
2%
Regulation on the European Health Data Space (EHDS)
1 source controls mapped|1 target controls covered
2%
PCAOB AS 2201 - Audit of Internal Control Over Financial Reporting (ICFR)
1 source controls mapped|4 target controls covered
2%
Pakistan Personal Data Protection Bill 2023
1 source controls mapped|2 target controls covered
2%
OCC Heightened Standards (12 CFR Part 30, Appendix D)
1 source controls mapped|3 target controls covered
2%
NIST Privacy Framework
1 source controls mapped|2 target controls covered
2%
NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205)
1 source controls mapped|1 target controls covered
2%
Nevada Gaming Control Board Cybersecurity Requirements
1 source controls mapped|3 target controls covered
2%
South Korea PIPA
1 source controls mapped|1 target controls covered
2%
India Account Aggregator Framework (RBI)
1 source controls mapped|1 target controls covered
2%
Illinois Biometric Information Privacy Act (BIPA)
1 source controls mapped|1 target controls covered
2%
IEC 60601-1 - Medical Electrical Equipment Safety
1 source controls mapped|4 target controls covered
2%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
1 source controls mapped|8 target controls covered
2%
ISO/IEC 23837:2023
1 source controls mapped|1 target controls covered
2%
ISO/IEC 29100:2024
1 source controls mapped|3 target controls covered
2%
ISO/IEC 29147:2018
1 source controls mapped|3 target controls covered
2%
2%
ISO/IEC 30111:2019
1 source controls mapped|2 target controls covered
2%
ISO/IEC 27004:2016
1 source controls mapped|3 target controls covered
2%
Barbados Data Protection Act 2019
1 source controls mapped|2 target controls covered
2%
DFARS 252.204-7012 - Safeguarding Covered Defense Information
1 source controls mapped|1 target controls covered
2%
Science Based Targets Initiative (SBTi) - Net-Zero Standard
1 source controls mapped|2 target controls covered
2%
APRA CPS 230 Operational Risk Management
1 source controls mapped|4 target controls covered
2%
PCI DSS 4.0
1 source controls mapped|1 target controls covered
2%
ISO/IEC 27050-1:2019
1 source controls mapped|1 target controls covered
2%
Azerbaijan Law on Personal Data (2010)
1 source controls mapped|1 target controls covered
2%
ISO/IEC 29115:2013 - Entity Authentication Assurance Framework
1 source controls mapped|1 target controls covered
2%
US Foreign Corrupt Practices Act (FCPA)
1 source controls mapped|1 target controls covered
2%
Connecticut Data Privacy Act (CTDPA)
1 source controls mapped|1 target controls covered
2%
Singapore AI Governance Framework
1 source controls mapped|1 target controls covered
2%
French Sapin II Law (Law No. 2016-1691)
1 source controls mapped|3 target controls covered
2%
AML/CTF Act 2006 (Australia)
1 source controls mapped|2 target controls covered
2%
ISO/IEC 29134:2023
1 source controls mapped|3 target controls covered
2%
GDPR
1 source controls mapped|1 target controls covered
2%
OWASP API Security Top 10 - 2023
1 source controls mapped|1 target controls covered
2%
Space ISAC (Information Sharing and Analysis Center) - Threat Framework
1 source controls mapped|1 target controls covered
2%
ISO/IEC 27010:2015
1 source controls mapped|2 target controls covered
2%
APPI
1 source controls mapped|1 target controls covered
2%
Canada ITSG-33 - IT Security Risk Management
1 source controls mapped|1 target controls covered
2%
ISO/IEC 27006-1:2024
1 source controls mapped|1 target controls covered
2%
Voluntary Principles on Security and Human Rights (VPs)
1 source controls mapped|1 target controls covered
2%

Coverage is not the same as your position

This page shows what IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.

The Compliance Position Diagnostic, $5,000 fixed, ten business days

What is IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) and who does it apply to?

IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) is a compliance framework from International (IMO) with 7 domains and 34 controls. The International Maritime Organization's Guidelines on maritime cyber risk management, in their fourth revision (MSC-FAL.1/Circ.3/Rev.4, 28 May 2026), with Resolution MSC.428(98), which asks that the company's safety management system under the ISM Code address cyber risk from the first Document of Compliance verification after 1 January 2021. Six concurrent functional elements (Govern, Identify, Protect, Detect, Respond, Recover) each with an outcome and a list of minimum controls: an accountable person with authority and competence; an onboard digital system inventory and a risk assessment of critical systems and supply chains; unique credentials, default passwords changed, multi-factor authentication where appropriate, OT segmented from IT, logs kept, removable media controlled, annual training and familiarization, backups, updates and incident response plans; threat monitoring; reporting to the Administration's deadlines; recovery strategies and root cause analysis. Recommendatory; 34 leaves read against the official text. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) actually require?

IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) has 34 controls organised across 7 domains. The largest domains are Protect – IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) (10 controls), Governance, leadership and the safety management system – IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) (6 controls), Identify – IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) do I already cover?

IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) maps to 111 other compliance frameworks. The top mapping partners are Singapore Government Instruction Manual on ICT&SS Management (IM8) (12% coverage), IEC 62443 (12% coverage), API 1164 (12% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4)?

Start your IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 34 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 705 frameworks.

Get Started Free →

Free forever — no credit card required