Platform

HexaCore, The unified resilience core HexaSOC, AI agentic SOC & MDR HexaInt, Cyber & dark-web intelligence HexaOT, OT & ICS security HexaComply, Compliance & TPRM HexaAI, AI security & governance HexaCustody, Digital content custody HexaStrike, Agentic offensive security HexaMatrix, ATT&CK coverage & mapping HexaView, Multi-tenant customer portal

Solutions

Managed Detection & Response, 24/7 AI-agentic detection & response Co-Managed SOC, Your team and ours, one operation Detection Engineering, Coverage you can measure Incident Response Retainer, A hand on the wheel before you need it Penetration Testing, See your estate the way attackers do Red & Purple Teaming, Offence that hardens your defence Continuous Security Validation, Validate continuously, not annually Cyber Crisis Tabletop & War-Gaming, Rehearse the bad day Continuous Threat Exposure Management, From a list of vulns to a plan Cyber Risk Quantification, Risk as a number the board can use Managed Threat Intelligence, Signal, not noise Digital Risk & Brand Protection, Protect your name where you cannot see Managed OT & IoT Monitoring, Security for systems that cannot go down OT/ICS Assessment, Know your OT before an attacker does Compliance as a Service, Gap assessment to certification Third-Party & Supply-Chain Risk Management, Risk does not stop at your perimeter Virtual CISO & Governance Advisory, Executive security leadership, on tap AI Security & Governance, Govern the AI you are adopting Managed Content Custody, Custody for your crown jewels

Industries

Maritime, Fleets, ports and shore-side IT Media & Entertainment, Pre-release content and production Casino & Gaming, Platform integrity and player trust Financial Services, DORA, resilience and fraud Critical National Infrastructure, Converged IT and OT estates Manufacturing, Plants, PLCs and supply chain Healthcare, Clinical systems and patient data Pharmaceutical & Life Sciences, Research IP, GxP and data integrity Energy & Utilities, Generation, grid and SCADA Government, Sovereign data and assurance

Partners

Partner programme, Refer, resell or white-label Cyber Dockside AI, Maritime, exclusive partner TeamLogic IT, US channel partner Walking Comet, Australia, casino & gaming Copla, GRC technology partner Nexovern, Runtime AI sensor partner

Learning

Learning Hub: explainers, guides and briefings

Company

About HexaShield Contact Book a meeting Client Login Book a demo
Explainer

IACS UR E26 and E27, explained for fleet operators

Two unified requirements that changed what a newbuild has to demonstrate. What they cover, who they bind, and what they mean for existing tonnage.

Updated August 2026 · 6 minute read

Where they come from

The International Association of Classification Societies publishes unified requirements that its member societies apply. E26 and E27 are the two that address cyber resilience, and they arrived because the existing regime asked owners to manage cyber risk without specifying what a compliant vessel looked like.

They sit alongside, rather than replace, the IMO expectation that cyber risk is addressed within the safety management system.

What E26 covers

E26 treats the vessel as a system. It addresses the design and construction of the ship such that it is resilient to cyber incidents: identification of systems, network architecture and segregation, access control, and the ability to detect, respond to and recover from an incident without losing essential functions.

The orientation is toward the integrator and the yard as much as the owner, because most of what it asks for is decided during design.

What E27 covers

E27 addresses the individual systems and equipment that go aboard: what a supplier must build in, how it is hardened, how it is documented, and what evidence accompanies it.

For owners the practical effect is that equipment arriving on a newbuild should come with security documentation as a matter of course, rather than as a special request.

Who is bound, and when

Both apply to vessels contracted for construction on or after 1 July 2024. That makes them a newbuild and major conversion concern first, and a fleet-wide one gradually, as tonnage turns over.

Existing vessels are not directly bound. That is not the same as being unaffected: charter parties, P&I questionnaires and insurer due diligence increasingly ask questions that are easiest to answer if you can produce the same evidence.

What this means practically

The recurring obstacle is the asset picture. E26 asks about network architecture, segregation and the ability to detect. All three assume you know what is on the vessel network, and on most existing tonnage nobody does, because it was integrated by different yards and vendors across two decades of refits.

Nothing may be actively scanned while the vessel is under way, so that inventory has to be built by observing traffic rather than probing equipment. That constraint shapes every technical decision that follows.

Which requirements apply to your flag, class and trade is confirmed during onboarding rather than assumed here.

FAQ

Questions, answered

Do E26 and E27 apply to our existing fleet?
Not directly. They apply to vessels contracted for construction on or after 1 July 2024. Existing tonnage is governed by the IMO expectation that cyber risk is managed within the safety management system, and increasingly by commercial pressure from charterers and insurers asking similar questions.
How do we evidence compliance?
Through class. These are unified requirements applied by IACS member societies, so demonstration happens at survey rather than by self-declaration. That makes the quality of your evidence, and how current it is, the thing that determines how the survey goes.
Can we build the asset inventory without scanning?
Yes, and on a live vessel it is the only responsible way. Passive discovery observes network traffic and identifies assets, firmware and protocols without introducing traffic that bridge and engine-room equipment was never designed to receive.

Want this applied to your estate?

Tell us what you are protecting and where you feel exposed. We will map it to the right capabilities and set up a walkthrough.