IACS UR E26 and E27, explained for fleet operators
Two unified requirements that changed what a newbuild has to demonstrate. What they cover, who they bind, and what they mean for existing tonnage.
Where they come from
The International Association of Classification Societies publishes unified requirements that its member societies apply. E26 and E27 are the two that address cyber resilience, and they arrived because the existing regime asked owners to manage cyber risk without specifying what a compliant vessel looked like.
They sit alongside, rather than replace, the IMO expectation that cyber risk is addressed within the safety management system.
What E26 covers
E26 treats the vessel as a system. It addresses the design and construction of the ship such that it is resilient to cyber incidents: identification of systems, network architecture and segregation, access control, and the ability to detect, respond to and recover from an incident without losing essential functions.
The orientation is toward the integrator and the yard as much as the owner, because most of what it asks for is decided during design.
What E27 covers
E27 addresses the individual systems and equipment that go aboard: what a supplier must build in, how it is hardened, how it is documented, and what evidence accompanies it.
For owners the practical effect is that equipment arriving on a newbuild should come with security documentation as a matter of course, rather than as a special request.
Who is bound, and when
Both apply to vessels contracted for construction on or after 1 July 2024. That makes them a newbuild and major conversion concern first, and a fleet-wide one gradually, as tonnage turns over.
Existing vessels are not directly bound. That is not the same as being unaffected: charter parties, P&I questionnaires and insurer due diligence increasingly ask questions that are easiest to answer if you can produce the same evidence.
What this means practically
The recurring obstacle is the asset picture. E26 asks about network architecture, segregation and the ability to detect. All three assume you know what is on the vessel network, and on most existing tonnage nobody does, because it was integrated by different yards and vendors across two decades of refits.
Nothing may be actively scanned while the vessel is under way, so that inventory has to be built by observing traffic rather than probing equipment. That constraint shapes every technical decision that follows.
Which requirements apply to your flag, class and trade is confirmed during onboarding rather than assumed here.
Questions, answered
Do E26 and E27 apply to our existing fleet?
How do we evidence compliance?
Can we build the asset inventory without scanning?
Where this goes next
Want this applied to your estate?
Tell us what you are protecting and where you feel exposed. We will map it to the right capabilities and set up a walkthrough.