IACS UR E26/E27 for Newbuilds: What Owners Must Demand From Yards in 2026
IACS UR E26 and E27 apply to ships contracted for construction on or after 1 July 2024, and compliance is a condition of class. As the owner, demand the class-required deliverables in writing — a zones and conduit diagram, vessel asset inventory, cyber-security design description, and ship cyber resilience test procedure — plus E27 type approval for essential systems. Put these in the newbuild contract before signing, because a non-compliant ship will not get its class certificate.
On this page
Who this applies to: Owners, managers and newbuild project teams taking delivery of vessels contracted on or after 1 July 2024, plus fleet IT and OT leads across the UAE and wider GCC.
If you are taking delivery of a ship contracted after mid-2024, cyber resilience is no longer a nice-to-have you can negotiate away in the final yard meeting. It is a condition of class, and the paperwork that proves it has to exist before the ship enters service. The gap most owners discover too late is that these requirements sit across three parties — yard, systems integrator, and equipment suppliers — and unless the contract nails down who delivers what, you inherit the shortfall.
What actually changed, and when did it take effect?#
IACS published two Unified Requirements — UR E26 "Cyber Resilience of Ships" and UR E27 "Cyber Resilience of On-Board Systems and Equipment." Both originally applied to new ships from 1 January 2024. After industry feedback, IACS revised them. Given that the original requirements had not yet entered into force, IACS decided to apply only the revised requirements from 1 July 2024. To avoid confusion, the original versions, along with their previous application date of 1 January 2024, were withdrawn.
The scope split matters. UR E26 applies to ships as a whole, while UR E27 applies to on-board systems and equipment. Crucially, when a UR comes into force it becomes a condition of class, and a vessel that doesn't comply won't get its class certificate. That is the lever. A yard cannot deliver, and you should not accept, a ship that fails class on cyber grounds.
E26/E27 are not guidance. They are surveyable class rules tied to the contract-for-construction date. If your newbuild was contracted on or after 1 July 2024, the deliverables below are mandatory — not optional extras.
These URs translate a general IMO obligation into engineering terms. IMO Resolution MSC.428(98) requires cyber risks to be addressed in company safety management systems no later than the first annual verification of the company's Document of Compliance after 1 January 2021. E26 and E27 give class societies something concrete to survey against.
IACS UR E26
In forceShip-level cyber resilience
Applies to the whole OT network and owner management processes for ships contracted on or after 1 July 2024.
IACS UR E27
In forceOnboard systems & equipment
Type-approval pathway for suppliers of essential systems; based on IEC 62443 security capabilities.
IMO MSC.428(98)
In forceAll ships via ISM Code
Requires cyber risk in the SMS from the first DoC verification after 1 January 2021. The baseline E26/E27 build on.
View as table
| Regime | Who it binds | Status |
|---|---|---|
| IACS UR E26 | Ship-level cyber resilience | In force — Applies to the whole OT network and owner management processes for ships contracted on or after 1 July 2024. |
| IACS UR E27 | Onboard systems & equipment | In force — Type-approval pathway for suppliers of essential systems; based on IEC 62443 security capabilities. |
| IMO MSC.428(98) | All ships via ISM Code | In force — Requires cyber risk in the SMS from the first DoC verification after 1 January 2021. The baseline E26/E27 build on. |
Which deliverables must the yard and integrator produce?#
E26 organises around five functions — Identify, Protect, Detect, Respond and Recover, with activities and deliverables defined for each, factoring in the vessel lifecycle and the stakeholders involved. The UR recognises the different roles of the suppliers, integrators, owners and class society.
Demonstrating compliance is document-driven across the vessel lifecycle. Demonstrating compliance with E26 requires submission of documents relating to three stages: in design and construction the systems integrator submits a zones and conduit diagram, a vessel asset inventory, and a cyber-security design description; at commissioning the systems integrator submits a ship cyber-resilience test procedure; and in operation the ship owner submits a ship cyber-security and resilience programme.
Put plainly, under UR E26 the shipbuilder is responsible for creating the Zones and Conduit Diagram, Vessel Asset Inventory, Ship Cyber Resilience Test Procedure and Cyber Security Design Description, and during operation the shipowner is responsible for maintaining the Ship Cyber Security and Resilience Programme. The asset inventory is not a token spreadsheet. It must be a documented list of all computer-based systems and networks essential to safe and secure operation — PMS, ECDIS, propulsion controls, fire detection, cargo management — including manufacturer, model, firmware version and network connectivity.
| Your situation | Yard / Integrator | Owner |
|---|---|---|
| Zones & conduit diagram | Applies | Not applicablereview |
| Vessel asset inventory | Applies | Conditionalmaintain |
| Cyber-security design description | Applies | Not applicablereview |
| Ship cyber resilience test procedure | Applies | Conditionalwitness |
| Ship cyber security & resilience programme | Not applicable | Applies |
| E27 type approval for essential systems | Conditionalvia suppliers | Conditionalverify |
What must you demand from equipment suppliers under E27?#
E27 is where owners get burned, because the type-approval certificate is narrower than people assume. Type-approval under UR E27 covers the equipment as supplied — firmware version, network interface, security baseline at month zero. After that, the system is integrated, patched and changed, and those changes fall under E26 and your SMS.
Technically, E27 is based on and incorporates elements of IEC 62443, covering 30 security capabilities required by all computer-based systems and 11 additional capabilities for systems that share an interface with untrusted networks. For procurement, the practical test is documentation. Compliant equipment comes with documented update processes, vulnerability disclosure channels, and end-of-life timelines — and for a post-July 2024 newbuild you should be asking vendors for their E27 compliance documentation. Suppliers who cannot demonstrate this are already being screened out. E27 compliance is increasingly written into procurement contracts, and a supplier who can't show a vulnerability disclosure policy and update mechanism risks being excluded from bids.
When do surveys start biting, and what gets checked?#
This is now live, not theoretical. The first cohort of E26/E27 newbuilds entered service through 2024 and 2025, and by mid-2026 their first cyber-relevant surveys are starting. If you manage any newbuild contracted from mid-2024 onwards, your first cyber-relevant in-service survey is imminent.
Compliance is ongoing, not a delivery-day box tick. Compliance with UR E26 and E27 is audited annually, and at the first annual survey the shipowner presents records or documented evidence demonstrating implementation of the Ship Cyber Security and Resilience Programme. That evidence covers practical operational hygiene — anti-malware maintained and updated, procedures for portable and removable devices followed, access control policies followed, and physical safeguards maintained. The ship cyber resilience test procedure is required again at the vessel's special survey.
1 Jan 2021
MSC.428(98) — cyber risk in SMS from first DoC verification
passed1 Jul 2024
Revised UR E26/E27 in force for ships contracted on/after this date
passed1 Jan 2024
First E26/E27 newbuilds enter service
passed1 Jul 2026
First cyber-relevant annual surveys begin
passed
What should Gulf owners put in the newbuild contract now?#
For owners ordering from yards in Korea, China, Japan or building at Gulf facilities, the leverage is the contract. Once the ship is on the water, closing gaps is a retrofit at your cost.
Before contract signature
- Name E26 and E27 as class conditions and require the class notation as a delivery milestone.
- Make the four E26 build deliverables (zones & conduit diagram, asset inventory, cyber-security design description, test procedure) contractual deliverables, not annexes.
- Require E27 type-approval evidence for every essential system on the vendor list.
During construction
- Have your team or a class-independent advisor review the zones and conduit diagram against the as-built network.
- Verify the asset inventory captures manufacturer, model, firmware version and connectivity for each essential system.
- Confirm OT/IT segregation is designed in, not bolted on at commissioning.
At commissioning & handover
- Witness the ship cyber resilience test procedure and retain the results.
- Take handover of all E27 supplier documentation, including update and vulnerability-disclosure processes.
- Ensure your SMS and Ship Cyber Security and Resilience Programme reflect what the ship actually does before the first annual survey.
One caution on sourcing: IACS categorised applicability into mandatory and non-mandatory depending on vessel type and size, so confirm exactly how the requirements bite for your specific hull. The scope of applicability was categorised as mandatory and non-mandatory compliance depending on vessel types and sizes. Verify the precise scope and any notation options with your chosen class society and flag state before you finalise the specification.
The E27 type-approval certificate is a snapshot at month zero. It does not cover integration, patching or configuration drift across the ship's life — that is E26 and SMS territory, and it is your responsibility as owner.
The pattern to avoid is treating cyber as a class formality the yard handles quietly. The deliverables are specific, the survey regime is annual, and the owner carries the operational programme for the life of the ship. Get the split of responsibility written down before signature, verify the documents against the as-built ship, and walk into the first annual survey with evidence rather than assurances.
If you are scoping a newbuild specification or reviewing what a yard has actually delivered against E26/E27, book a consultation with Solas Security to pressure-test your deliverables and survey readiness.
Frequently asked
When did IACS UR E26 and E27 come into force?
IACS confirmed the revised requirements apply only from 1 July 2024, to ships contracted for construction on or after that date. The earlier 1 January 2024 versions were withdrawn to avoid confusion.
Do E26 and E27 apply to my existing ships?
No. They apply to newbuilds contracted on or after 1 July 2024 and do not retroactively apply to existing vessels. Existing ships remain governed by IMO MSC.428(98) through the ISM Code, and class societies increasingly recommend E26-aligned practice.
What is the difference between E26 and E27?
E26 covers cyber resilience of the ship as a whole — the integrated OT network and owner management processes. E27 covers individual onboard systems and equipment through a type-approval pathway for suppliers.
Who produces the E26 deliverables — the yard or the owner?
The shipbuilder and systems integrator produce the design and commissioning documents. The owner is responsible for the ship cyber security and resilience programme during operation, which is checked at annual surveys.
Is E27 type approval a one-time thing?
Type approval reflects the equipment's security baseline as supplied. After delivery the system is integrated, patched and changed, so ongoing management under E26 and your SMS still applies.

Bring the control-by-control questions
Your environment, your regulators, and your hardest question. We answer control by control, and we publish where the overlay stops before you ask.
