IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4)
The International Maritime Organization's Guidelines on maritime cyber risk management, in their fourth revision (MSC-FAL.1/Circ.3/Rev.4, 28 May 2026), with Resolution MSC.428(98), which asks that the company's safety management system under the ISM Code address cyber risk from the first Document of Compliance verification after 1 January 2021. Six concurrent functional elements (Govern, Identify, Protect, Detect, Respond, Recover) each with an outcome and a list of minimum controls: an accountable person with authority and competence; an onboard digital system inventory and a risk assessment of critical systems and supply chains; unique credentials, default passwords changed, multi-factor authentication where appropriate, OT segmented from IT, logs kept, removable media controlled, annual training and familiarization, backups, updates and incident response plans; threat monitoring; reporting to the Administration's deadlines; recovery strategies and root cause analysis. Recommendatory; 34 leaves read against the official text.
IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) is a compliance framework from International (IMO) with 7 domains and 34 controls that map to 111 other frameworks. The largest domains are Protect – IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) (10 controls), Governance, leadership and the safety management system – IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) (6 controls), Identify – IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) (4 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (7)
Detect – IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4)
| Code | Title |
|---|---|
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.4 | 3.5.4 Detect: timely detection of cyber incidents |
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.4.1 | 3.5.4.1 Threat list and active monitoring |
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.4.2 | 3.5.4.2 Training to recognise an ongoing incident |
Governance, leadership and the safety management system – IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4)
| Code | Title |
|---|---|
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.3 | 3.3 Senior management leadership, training and cyber risk culture |
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.4 | 3.4 Current and desired posture comparison and risk-based prioritisation |
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.1 | 3.5.1 Govern: strategy, policies, roles and continuity |
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.1.1 | 3.5.1.1 Accountable person or entity for cybersecurity |
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.1.2 | 3.5.1.2 Authority, support and competence of the accountable party |
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::MSC.428-1 | MSC.428(98) paragraphs 1 and 2: cyber risk management within the approved safety management system |
Identify – IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4)
| Code | Title |
|---|---|
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.2 | 3.5.2 Identify: current cyber risk to ships and ship/port interfaces |
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.2.1 | 3.5.2.1 Critical systems, dependencies and supply chains |
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.2.2 | 3.5.2.2 Inventory of onboard digital systems and connections |
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.2.3 | 3.5.2.3 Risk assessment of critical systems |
Protect – IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4)
| Code | Title |
|---|---|
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.3 | 3.5.3 Protect: risk controls and contingency planning |
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.3.1 | 3.5.3.1 User credentials, privileged accounts and leavers |
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.3.2 | 3.5.3.2 Passwords, authentication and secured communications |
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.3.3 | 3.5.3.3 Exposure, approvals, logging, segmentation and secure acquisition |
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.3.4 | 3.5.3.4 Protection of connected systems and cryptography |
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.3.5 | 3.5.3.5 Unauthorized removable media |
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.3.6 | 3.5.3.6 Cybersecurity training, familiarization and testing |
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.3.7 | 3.5.3.7 Backups, software updates and incident response plans |
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.3.8 | 3.5.3.8 Supply chain security policy for critical systems |
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.3.9 | 3.5.3.9 Assessing effectiveness and reviewing measures |
Recover – IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4)
| Code | Title |
|---|---|
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.6 | 3.5.6 Recover: restoring onboard CBS and networks |
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.6.1 | 3.5.6.1 Recovery and reinstatement strategies |
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.6.2 | 3.5.6.2 Training on recovery |
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.6.3 | 3.5.6.3 Root cause analysis of incidents |
Respond – IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4)
| Code | Title |
|---|---|
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.5 | 3.5.5 Respond: plans, resilience and containment |
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.5.1 | 3.5.5.1 Incident reporting within set time frames |
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.5.2 | 3.5.5.2 Records of cyber incidents |
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.5.5.3 | 3.5.5.3 Training on responding to an incident |
Supporting provisions: documents, awareness, resilient equipment – IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4)
| Code | Title |
|---|---|
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.6 | 3.6 Ongoing process and protection of cyber documents |
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.7 | 3.7 Awareness proportionate to roles |
| imo-maritime-cybersecurity-guidelines-msc-fal-1-circ-3-rev-4::3.8 | 3.8 Cyber-resilient equipment and systems |
Your Compliance Coverage
If you comply with IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4), you already cover:
Singapore Government Instruction Manual on ICT&SS Management (IM8)
12%
5 controls mapped
Compare →IEC 62443
12%
5 controls mapped
Compare →API 1164
12%
5 controls mapped
Compare →+ 108 more: IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1) (12%), OWASP ASVS (10%)
See all 111 mapped frameworks ↓Maps to 111 other frameworks
Coverage is not the same as your position
This page shows what IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) and who does it apply to?
IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) is a compliance framework from International (IMO) with 7 domains and 34 controls. The International Maritime Organization's Guidelines on maritime cyber risk management, in their fourth revision (MSC-FAL.1/Circ.3/Rev.4, 28 May 2026), with Resolution MSC.428(98), which asks that the company's safety management system under the ISM Code address cyber risk from the first Document of Compliance verification after 1 January 2021. Six concurrent functional elements (Govern, Identify, Protect, Detect, Respond, Recover) each with an outcome and a list of minimum controls: an accountable person with authority and competence; an onboard digital system inventory and a risk assessment of critical systems and supply chains; unique credentials, default passwords changed, multi-factor authentication where appropriate, OT segmented from IT, logs kept, removable media controlled, annual training and familiarization, backups, updates and incident response plans; threat monitoring; reporting to the Administration's deadlines; recovery strategies and root cause analysis. Recommendatory; 34 leaves read against the official text. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) actually require?
IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) has 34 controls organised across 7 domains. The largest domains are Protect – IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) (10 controls), Governance, leadership and the safety management system – IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) (6 controls), Identify – IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) do I already cover?
IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) maps to 111 other compliance frameworks. The top mapping partners are Singapore Government Instruction Manual on ICT&SS Management (IM8) (12% coverage), IEC 62443 (12% coverage), API 1164 (12% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4)?
Start your IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 34 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 705 frameworks.
Get Started Free →Free forever — no credit card required