A Port State Control officer or ISM auditor who walks onto the bridge in 2026 no longer asks whether you have a cyber security policy. They ask to see the procedure that controls software changes on this specific vessel, the patch log, and the report from the last incident-response drill. That shift — from policy document to objective evidence — is the whole story of maritime cyber compliance today, and it catches out operators who treated the requirement as a binder to be filled once. The reason it has teeth is structural: since 1 January 2021, IMO Resolution MSC.428(98) has required cyber risk management to sit inside the Safety Management System that the ISM Code mandates for every company and vessel. That means cyber is not a separate IT project but a part of the SMS, audited through the same machinery that audits fire drills and lifeboat maintenance — and a non-conformity found there can affect the Document of Compliance and Safety Management Certificate for an entire fleet, not just one ship. Layered on top, the class societies' unified requirements now govern new vessels, and national rules from the US Coast Guard and the EU add further obligations. This guide sets out maritime cyber compliance for the DPAs, technical managers and IT and OT teams who carry it — why it lives in the ISM Code, the regulatory stack, the framework functions, and above all the audit evidence inspectors now demand. To keep cyber procedures, system inventories, drill records and incident logs organised and audit-ready across your fleet, start a free trial or book a demo.
COMPLIANCE GUIDE · MARITIME CYBER SECURITY
Maritime Cyber Security Compliance: MSC.428(98), IACS UR E26 and E27 Explained
Cyber risk management now lives inside the ISM Code, audited through the same machinery as every other safety requirement. Here is the regulatory stack, the framework functions, and the objective audit evidence inspectors demand — so a cyber gap does not become a Document of Compliance non-conformity for your whole fleet.
Cyber lives inside the ISM Code
Safety Management System
contains
Cyber risk management
Audited through the same verification, audit and detention machinery as every other ISM requirement
Why Cyber Is an ISM Matter
The single most important thing to understand about maritime cyber compliance is where it lives. It is not a standalone regime with its own certificate; it is embedded in the Safety Management System, and that placement is deliberate and consequential.
Resolution MSC.428(98) requires that cyber risk be addressed within the SMS in accordance with the objectives and functional requirements of the ISM Code, and it has done so since the first annual Document of Compliance verification after 1 January 2021. Reading this as a light-touch obligation is the mistake that produces a thin compliance file. The ISM Code is not a paperwork regime; it requires that risks be identified and that safeguards be established and maintained. So an officer who finds that the cyber risk assessment is a generic template — with no ship-specific systems named, no risk ranking, and no evidence of crew familiarity — can raise a non-conformity that, if serious enough, holds the ship. The quiet strength of putting cyber inside the ISM Code is that it inherits a verification, audit and detention machinery that already exists and already has teeth: the internal audit, the DOC annual verification and the management review all now reach the cyber procedures, the risk assessment, the training records and the drill logs. Cyber resilience is therefore maintained on the same cycle as fire drills and lifeboat maintenance, rather than as a one-time IT project — and a serious ISM non-conformity can affect the DOC and Safety Management Certificate for the entire fleet under that management, which is what makes the stakes fleet-wide. To keep the cyber elements of your SMS as maintained and evidenced as the rest of it, start a free trial or book a demo.
The Regulatory Stack
Several instruments now apply, and they overlap rather than conflict. Understanding which applies to your vessels avoids both gaps and duplicated effort.
MSC.428(98)
The IMO foundation — cyber in the SMS
The base requirement, effective since 1 January 2021, mandating cyber risk management inside the ISM Code Safety Management System for all vessels. Supported by the guidelines in MSC-FAL.1/Circ.3, revised to its third revision in April 2025. Everything else builds on this.
IACS E26
Cyber resilience of ships
The class requirement covering the vessel as a whole — the owner's documented inventory of computer-based systems, network segmentation and the integration of those systems. Mandatory for ships contracted for construction on or after 1 July 2024, drawing on the IEC 62443 standard.
IACS E27
Cyber resilience of onboard systems and equipment
The companion requirement covering individual onboard systems — protection against unauthorised access, tampering and malware across everything computer-based, from main-engine control and steering to fire detection, communications and navigation. Also mandatory for newbuilds from 1 July 2024.
USCG
US Coast Guard Final Rule
Effective 16 July 2025 for US-flagged vessels and MTSA facilities, adding a twelve-hour cyber-incident reporting obligation, a Cybersecurity Plan and Cyber Incident Response Plan, and a designated shoreside Cybersecurity Officer required by July 2027.
EU NIS2
EU network and information security
The EU directive that entered into force in 2023, with member states required to transpose it into national law by 17 October 2024, extending cyber obligations to maritime operators within its scope as part of the broader European framework.
Local
National and port codes
Local layers such as flag-state requirements and port cyber codes sit underneath the international baseline, generally designed to be coherent with IMO and IACS expectations, with locally specific additions like national incident-reporting timelines.
i
MSC.428(98) applies to every ship; E26 and E27 apply to new ships
The distinction matters for knowing what applies to your fleet. MSC.428(98) is an operational requirement that applies to every vessel through its SMS, regardless of age — it is about how the ship is run. IACS UR E26 and E27, by contrast, are design-and-construction requirements that apply to ships contracted for construction on or after 1 July 2024, closing the gap MSC.428(98) leaves at the newbuilding stage by building resilience in from the yard. So an existing ship must satisfy MSC.428(98) through its safety management system today, while a newbuild must additionally meet E26 and E27 by design. The two are complementary: one governs operation, the other governs construction, and both draw on the same underlying idea of identifying computer-based systems and protecting them.
The Framework Functions
Effective cyber risk management within the SMS is built around a recognised set of functions, mirroring international standards. These are the pillars an assessment and the supporting procedures should cover.
Govern
Assign cyber responsibilities both shipboard and ashore, with clear roles, accountability and senior-management ownership, since effective cyber risk management starts at the top.
Identify
Maintain a complete, current inventory of every IT and OT system on board, and a ship-specific risk assessment that names those systems and ranks their risks rather than relying on a generic template.
Protect
Implement safeguards — network segmentation, access controls, account management, removable-media rules and backup procedures — that reduce the likelihood and impact of a compromise.
Detect
Monitor logs and network activity for abnormal behaviour, so an intrusion or malfunction is noticed rather than discovered only when a critical system fails at sea.
Respond
Maintain a documented incident-response plan with manual override protocols, exercised through drills, so the crew can act decisively and safely when an incident occurs.
Recover
Hold secure, tested backups of critical system configurations so operations and safety-critical functions can be restored after an incident, closing the loop back to safe operation.
The functions are only as good as the evidence behind them
Govern, Identify, Protect, Detect, Respond and Recover each produce records an auditor will ask to see. Marine Inspection keeps the system inventory, risk assessment, drill reports, incident logs and access evidence organised per vessel — so the framework is not just designed but demonstrably maintained.
The Audit Evidence Inspectors Demand
This is where compliance is won or lost. Auditors, PSC inspectors and vetting officers now look for objective evidence, not a policy in a binder, and they ask specific, pointed questions. These are the artifacts to have ready.
Roles and escalation list, ship and shore
A documented list of cyber responsibilities and escalation paths for both shipboard and shoreside personnel, with named deputies, showing governance is assigned rather than assumed.
Critical-systems and remote-access inventory
A current inventory of computer-based systems, including remote-access paths and vendor connections, so the ship-specific attack surface is known and documented, not generic.
Network diagram at an operational level
A practical network diagram showing how systems connect and where they are segmented, detailed enough to be useful but not so technical it is unusable by the crew who rely on it.
Backup and restore proof for a critical system
Evidence that at least one critical system has been backed up and successfully restored — screenshots, timestamps, test records — proving recovery is real rather than theoretical.
Access control and account evidence
Records of unique logins, least-privilege access and prompt offboarding of departed personnel, demonstrating that account management is actively controlled.
Incident playbook and last drill record
A documented incident-response playbook and the report from the most recent cyber drill — the single artifact inspectors most often ask for, and the clearest proof the plan is exercised, not shelved.
Vendor access approval and log review
A vendor-access approval process and evidence of routine log review, showing that third-party connections — a common weak point — are controlled and monitored.
Removable-media rules and crew awareness
Onboard rules for removable media and evidence of crew training and awareness, since social-engineering and infected media remain leading routes in and crew awareness is often the weakest link.
Missing evidence can withdraw the DOC for the whole fleet
The consequence of failing to show objective evidence of cyber risk management during an audit — missing drill records, an untrained crew, a generic risk assessment with no ship-specific systems named — is not confined to one vessel. Because cyber lives in the ISM Code, a serious non-conformity can affect the Document of Compliance and the Safety Management Certificate, and the DOC covers the whole managed fleet. That is the mechanism that turns a thin cyber file on one ship into a fleet-level problem. It is also why the evidence, not the policy, is what matters: a well-written plan with no drill records, no maintained inventory and no crew awareness is exactly the profile that produces a non-conformity, whereas a modest plan that is demonstrably lived — evidenced, drilled and current — is what passes.
Approached correctly, maritime cyber compliance is demanding but entirely achievable, and the path is clear because the requirement is clear: identify the ship's computer-based systems, assess and rank their risks specifically, protect them, monitor them, plan and drill the response, and above all keep the evidence that all of this is genuinely maintained. The operators who struggle are those who wrote a policy once and filed it; the operators who pass are those who treat cyber as a living part of the SMS, maintained on the same cycle as every other safety-critical system, with the drill reports, inventories and logs to prove it. As threats from ransomware, phishing, AIS spoofing and GPS jamming continue to grow and connectivity widens the attack surface, that discipline is not just a compliance requirement but a genuine protection for the vessel, its crew and its cargo. To keep your fleet's cyber inventories, risk assessments, drill records and incident logs organised, current and ready for any audit, start a free trial or book a demo.
Frequently Asked Questions
What is MSC.428(98) and when did it take effect?
IMO Resolution MSC.428(98), Maritime Cyber Risk Management in Safety Management Systems, requires that cyber risk be addressed within the Safety Management System in accordance with the objectives and functional requirements of the ISM Code. It has applied since the first annual Document of Compliance verification after 1 January 2021, meaning every company and vessel operating under the ISM Code must include cyber risk management in its SMS. It does not mandate a separate standalone cyber system — cyber is integrated into the existing SMS. It is supported by the IMO's guidelines in MSC-FAL.1/Circ.3, revised to its third revision in April 2025. The significance is that cyber is enforced through the same ISM audit and verification machinery as every other safety requirement, giving it real teeth.
What is the difference between IACS UR E26 and E27?
Both are class unified requirements mandatory for ships contracted for construction on or after 1 July 2024, and both draw on the IEC 62443 standard, but they operate at different levels. E26, Cyber Resilience of Ships, covers the vessel as a whole — the owner's documented inventory of computer-based systems, network segmentation and the integration of those systems into a resilient whole. E27, Cyber Resilience of On-board Systems and Equipment, covers the individual onboard systems, requiring protection against unauthorised access, tampering and malware across everything computer-based, from main-engine control and steering to fire detection, communications and navigation. In short, E26 is the ship-level resilience requirement and E27 is the equipment-level requirement, and together they build cyber resilience in from the design and construction stage.
Do E26 and E27 apply to my existing ship?
No — IACS UR E26 and E27 are design-and-construction requirements that apply to ships contracted for construction on or after 1 July 2024, so they do not retroactively apply to existing vessels. However, this does not leave older ships exempt from cyber requirements. Every vessel, regardless of age, must satisfy IMO MSC.428(98) by addressing cyber risk management within its Safety Management System. So an existing ship must meet the operational cyber requirement through its SMS today, while a newbuild contracted from July 2024 must additionally meet E26 and E27 by design. The two sets of rules are complementary: MSC.428(98) governs how every ship is operated, and E26 and E27 govern how new ships are built.
What evidence do auditors want for cyber compliance?
Objective evidence, not a policy document. Inspectors and auditors now ask to see specific artifacts: a roles and escalation list for ship and shore with named deputies; a current inventory of critical systems and remote-access paths including vendor connections; a practical network diagram; backup and restore proof for at least one critical system with timestamps; access control evidence such as unique logins, least privilege and offboarding records; an incident-response playbook and the report from the last cyber drill; a vendor-access approval process with log review; and removable-media rules with evidence of crew awareness. The single most commonly requested item is the last drill record. The theme is that the plan must be demonstrably lived and maintained, because a well-written policy with no supporting evidence is exactly what produces a non-conformity.
Can a cyber failure lead to detention or affect my DOC?
Yes. Because cyber risk management lives inside the ISM Code Safety Management System, it is enforced through ordinary ISM machinery, which includes the possibility of non-conformities and detention. An officer who finds a generic cyber risk assessment with no ship-specific systems named, no risk ranking and no evidence of crew familiarity can raise a non-conformity that, if serious enough, holds the ship. More significantly, a serious ISM non-conformity can affect the Document of Compliance and Safety Management Certificate, and the DOC covers the entire managed fleet — so a cyber failing on one vessel can escalate into a fleet-level problem. This fleet-wide exposure is what makes maintaining genuine, evidenced cyber compliance across every vessel essential rather than optional.
Who is responsible for cyber security on board?
Responsibility is shared between the company and the master, and in practice much of the audit accountability falls on the Designated Person Ashore and the technical superintendent, because they operate the SMS in which cyber risk management lives. The company must establish the programme, train the crew and provide the tools; the master is responsible for implementing procedures on board. Under the US Coast Guard rule, a shoreside Cybersecurity Officer must additionally be designated by July 2027 for vessels in its scope, but that does not remove shipboard responsibility. Software vendors carry their slice through type-approval evidence and patch commitments, but they do not own the SMS. When a surveyor comes aboard asking to see the patch log and the last drill report, those questions land on the DPA and technical superintendent, since the management company holds the Document of Compliance.
Evidence Is the Compliance
Cyber lives in the ISM Code, and inspectors now want the drill report and the patch log, not the policy binder. Marine Inspection keeps the system inventory, ship-specific risk assessment, drill records, incident logs and access evidence organised and current per vessel — so cyber compliance is demonstrably maintained, and a gap on one ship never becomes a Document of Compliance problem for your whole fleet.