IACS UR E26 and E27 are in force: cyber resilience is now built into the newbuild contract
Since July 1, 2024, IACS UR E26 and E27 require cyber resilience for newbuild vessels of 500 GT and above.
IMPACT SNAPSHOT
- Who is affected
- Worldwide
Maritime cyber security has crossed the line from guidance to a hard classification requirement. Since 1 July 2024, the International Association of Classification Societies (IACS) Unified Requirements E26 “Cyber Resilience of Ships” and E27 “Cyber Resilience of On-Board Systems and Equipment” have applied to vessels contracted for construction on or after that date. For new ships, cyber resilience is now something a class society verifies before delivery — not a best-practice suggestion.
The two requirements divide the problem cleanly. E26 treats the ship as a single collective entity, setting a minimum baseline organised around five functions — identify, protect, detect, respond and recover — the same structure that underpins the NIST and IEC 62443 frameworks. The aim is the secure integration of IT and OT (operational technology) systems across the vessel’s whole lifecycle, from the newbuild phase onward. E27 works one level down, targeting the computer-based systems and equipment supplied by third parties, and requiring security to be designed into those products before they are installed aboard.
The scope is deliberately bounded. The requirements apply to commercial and offshore vessels of 500 gross tonnage and above contracted for construction from 1 July 2024, including passenger ships carrying more than 12 people and self-propelled mobile offshore units. Smaller and non-conventional vessels sit largely outside the mandatory core, a concession to the difficulty of retrofitting these controls onto every hull.
The practical shift is one of accountability. Cyber resilience is no longer a single party’s problem: the shipyard must integrate systems securely, the equipment supplier must ship hardened products under E27, and the operator must run and maintain them. Each link now carries a documented, auditable obligation rather than an informal expectation.
For which rule reaches which vessel — and how the IMO safety-management side differs from this — see the full guide: Ship cyber security: which rules actually apply to your vessel?
Apeks view — The quiet significance of E26 and E27 is not the technical controls; it is that cyber resilience is now written into the newbuild contract as a verifiable condition. Regulation is repeating a pattern the industry knows well: a good practice becomes an expectation, then an audit item. The operators who fare best will be those who already treat their systems as something that must be explained and evidenced — because a control you cannot document is, to an auditor, a control that does not exist.
Spot an error? Request a correction
Apeks Tech Editorial Team
Sourced curation
The Apeks Tech editorial team — sourced briefs and engineering-led curation; sources are listed on every brief. Editorial policy →
Forward this to a colleague
Should your DPA, technical superintendent or a fellow owner see this? Forwarding costs nothing.
Was this forwarded to you? Take your own copy → subscribe here.