IACS UR E26 and E27 are in force: cyber resilience is now built into the newbuild contract
Since 1 July 2024, IACS Unified Requirements E26 and E27 apply to ships contracted for construction on or after that date. Cyber resilience moves from a recommendation to a classification requirement for new vessels of 500 GT and above.
Maritime cyber security has crossed the line from guidance to a hard classification requirement. Since 1 July 2024, the International Association of Classification Societies (IACS) Unified Requirements E26 “Cyber Resilience of Ships” and E27 “Cyber Resilience of On-Board Systems and Equipment” have applied to vessels contracted for construction on or after that date. For new ships, cyber resilience is now something a class society verifies before delivery — not a best-practice suggestion.
The two requirements divide the problem cleanly. E26 treats the ship as a single collective entity, setting a minimum baseline organised around five functions — identify, protect, detect, respond and recover — the same structure that underpins the NIST and IEC 62443 frameworks. The aim is the secure integration of IT and OT (operational technology) systems across the vessel’s whole lifecycle, from the newbuild phase onward. E27 works one level down, targeting the computer-based systems and equipment supplied by third parties, and requiring security to be designed into those products before they are installed aboard.
The scope is deliberately bounded. The requirements apply to commercial and offshore vessels of 500 gross tonnage and above contracted for construction from 1 July 2024, including passenger ships carrying more than 12 people and self-propelled mobile offshore units. Smaller and non-conventional vessels sit largely outside the mandatory core, a concession to the difficulty of retrofitting these controls onto every hull.
The practical shift is one of accountability. Cyber resilience is no longer a single party’s problem: the shipyard must integrate systems securely, the equipment supplier must ship hardened products under E27, and the operator must run and maintain them. Each link now carries a documented, auditable obligation rather than an informal expectation.
For which rule reaches which vessel — and how the IMO safety-management side differs from this — see the full guide: Ship cyber security: which rules actually apply to your vessel?
Apeks view — The quiet significance of E26 and E27 is not the technical controls; it is that cyber resilience is now written into the newbuild contract as a verifiable condition. Regulation is repeating a pattern the industry knows well: a good practice becomes an expectation, then an audit item. The operators who fare best will be those who already treat their systems as something that must be explained and evidenced — because a control you cannot document is, to an auditor, a control that does not exist.
Spot an error? Request a correction
Apeks Tech
Editorial team
The Apeks Tech editorial desk — sourced briefs and engineering-led analysis. See the About page for our publishing principles. About →