apeks.tech
News · Cybersecurity 10 July 2026 · 2 min read

IACS UR E26 and E27 are in force: cyber resilience is now built into the newbuild contract

Since July 1, 2024, IACS UR E26 and E27 require cyber resilience for newbuild vessels of 500 GT and above.

Editorial Team

Bu haberin Türkçesi →

IMPACT SNAPSHOT

Who is affected
Worldwide

Maritime cyber security has crossed the line from guidance to a hard classification requirement. Since 1 July 2024, the International Association of Classification Societies (IACS) Unified Requirements E26 “Cyber Resilience of Ships” and E27 “Cyber Resilience of On-Board Systems and Equipment” have applied to vessels contracted for construction on or after that date. For new ships, cyber resilience is now something a class society verifies before delivery — not a best-practice suggestion.

The two requirements divide the problem cleanly. E26 treats the ship as a single collective entity, setting a minimum baseline organised around five functions — identify, protect, detect, respond and recover — the same structure that underpins the NIST and IEC 62443 frameworks. The aim is the secure integration of IT and OT (operational technology) systems across the vessel’s whole lifecycle, from the newbuild phase onward. E27 works one level down, targeting the computer-based systems and equipment supplied by third parties, and requiring security to be designed into those products before they are installed aboard.

The scope is deliberately bounded. The requirements apply to commercial and offshore vessels of 500 gross tonnage and above contracted for construction from 1 July 2024, including passenger ships carrying more than 12 people and self-propelled mobile offshore units. Smaller and non-conventional vessels sit largely outside the mandatory core, a concession to the difficulty of retrofitting these controls onto every hull.

The practical shift is one of accountability. Cyber resilience is no longer a single party’s problem: the shipyard must integrate systems securely, the equipment supplier must ship hardened products under E27, and the operator must run and maintain them. Each link now carries a documented, auditable obligation rather than an informal expectation.

For which rule reaches which vessel — and how the IMO safety-management side differs from this — see the full guide: Ship cyber security: which rules actually apply to your vessel?

Apeks view — The quiet significance of E26 and E27 is not the technical controls; it is that cyber resilience is now written into the newbuild contract as a verifiable condition. Regulation is repeating a pattern the industry knows well: a good practice becomes an expectation, then an audit item. The operators who fare best will be those who already treat their systems as something that must be explained and evidenced — because a control you cannot document is, to an auditor, a control that does not exist.

Spot an error? Request a correction

Apeks Tech Editorial Team

Sourced curation

The Apeks Tech editorial team — sourced briefs and engineering-led curation; sources are listed on every brief. Editorial policy →

Was this useful?

Forward this to a colleague

Should your DPA, technical superintendent or a fellow owner see this? Forwarding costs nothing.

Was this forwarded to you? Take your own copy → subscribe here.

Share LinkedIn X

Related reading

Apeks Brief

Free

Decision intelligence for the people who run ships: what changed, who is affected, what to do.

  • One email a week — the default; you can change it anytime.
  • The week's notable developments: a headline and one line on what changed.
  • Turkish or English. Unsubscribe in one click; your address is never shared.
From the latest issue 12 September 2026
  • RINA Reviews Silverstream's Energy Savings Methodology
  • IMO MSC 111: MASS Code, LRIT Access, Piracy Data Update
  • IMO Net-Zero Talks End With Key Issues Still Unresolved
Read the full issue →

Free, with no paid tier. We send a confirmation link first — nothing arrives until you confirm.