At a Glance
- Standards: IMO Resolution MSC.428(98) (Maritime Cyber Risk Management in SMS), IACS UR E26 (new build), IACS UR E27 (ship systems)
- Who needs it: All vessel owners and operators (SMS); new builds contracted from 1 July 2024 (UR E26); ship systems suppliers (UR E27)
- Typical timeline: 3-6 months from gap analysis to audit-ready operations
- Engagement model: Gap analysis + SMS integration + control implementation + class-society audit support + annual surveillance
- Response time: instant, no delay. Architecture review starts same or next business day after scoping
What is IMO MSC.428(98) and IACS UR E26 / E27?
IMO Resolution MSC.428(98) requires shipowners and operators to address cyber risks in their Safety Management Systems (SMS) under the ISM Code from the first annual verification of the Document of Compliance after 1 January 2021. It is principle-based and references the IMO Guidelines on Maritime Cyber Risk Management (MSC-FAL.1/Circ.3 Rev.2).
IACS Unified Requirements E26 (Cyber resilience of ships) applies to new-build vessels contracted from 1 July 2024, and UR E27 (Cyber resilience of on-board systems and equipment) applies to ship systems and equipment suppliers. Together they make cyber resilience a class-society-enforceable requirement. Codesecure runs the full programme: SMS integration, control implementation, class audit support and ongoing surveillance.
Why It Matters
IMO MSC.428(98) is enforced through the ISM Code. Port State Control increasingly reviews cyber elements in the SMS during inspections, and non-conformance can lead to detentions. IACS UR E26 / E27 is enforced at class-society level: new-build vessels contracted after 1 July 2024 cannot be issued class without E26 compliance, and equipment suppliers must demonstrate UR E27 conformity in their products.
Beyond regulation, charterers, P&I clubs and cyber insurance underwriters now ask for evidence of cyber risk management in vessel SMS, especially for tanker, LNG, container and high-value asset trades. TMSA 3 explicitly references cyber security under Element 13. Demonstrating a structured programme aligned to IMO and IACS unlocks charter opportunities and reduces insurance premiums.
What's Included
Codesecure's IMO & IACS programme covers SMS integration, E26 / E27 readiness and class audit support:
Cyber Risk AssessmentVessel-specific cyber risk assessment per IMO Guidelines (MSC-FAL.1/Circ.3 Rev.2)
SMS IntegrationCyber risk procedures integrated into vessel SMS under ISM Code clauses
Roles & ResponsibilitiesDPA, master, chief engineer, ETO cyber responsibilities documented
Asset Inventory (IT & OT)Full bridge, ECR, cargo, communication asset inventory with criticality
Control ImplementationControls aligned to IMO Guidelines categories: identify, protect, detect, respond, recover
UR E26 New-Build ReadinessCyber-resilient design package for new-build contracts after 1 July 2024
UR E27 System ConformityEvidence of cyber resilience for individual ship systems and equipment
Drills & Tabletop ExercisesCyber incident drills with master, ETO and shore team
Class-Society Audit SupportNamed consultant present during IRS / DNV / BV / LR / ABS cyber audits
Annual SMS SurveillanceYearly SMS cyber refresh, drill cadence, control evidence review
Get a Free IMO / IACS Gap Analysis
45-minute call with our maritime compliance lead. Bring your fleet, current SMS state and class society, leave with a phased remediation roadmap. Instant response, no delay.
Book Free Strategy Call
Methodology
Every IMO & IACS engagement follows a 5-phase methodology aligned with IMO and IACS guidance:
1
Gap Analysis & Scoping
Scoping call, NDA, fleet survey, current SMS review, gap assessment against IMO MSC.428(98), UR E26 and UR E27 as applicable.
2
Risk Assessment & Asset Inventory
Per-vessel cyber risk assessment, IT and OT asset inventory, criticality classification, threat modelling.
3
SMS Integration & Controls
Cyber procedures integrated into SMS, roles and responsibilities defined, controls implemented across vessels.
4
Drills & Validation
Tabletop exercises with master, ETO and DPA. Internal walkthrough of cyber procedures. Evidence consolidation.
5
Class Audit & Surveillance
Class-society cyber audit accompaniment by named consultant. Annual SMS surveillance and DoC verification support.
What You Get
Every IMO & IACS engagement ships with the same operational handoff:
Cyber Risk Assessment ReportPer-vessel cyber risk assessment with risk register
SMS Cyber ProceduresProcedures integrated into vessel Safety Management System
Control MatrixControls mapped to IMO Guidelines and UR E26 / E27 categories
Asset Inventory (IT & OT)Full inventory across bridge, ECR, cargo, communications
Class Audit SupportNamed consultant present during class-society cyber audits
Annual SMS SurveillanceYearly cyber refresh and DoC verification support
Timeline
Most IMO / IACS programmes reach audit-ready status within 3-6 months. Instant response, no delay, kickoff scheduled same or next business day after scoping.
Month 1
Gap & Risk
Scoping, fleet survey, gap analysis, cyber risk assessment, asset inventory.
Month 2-3
SMS & Controls
Cyber procedures integrated into SMS, roles defined, controls implemented across fleet.
Month 4-6
Drill & Audit
Drills, internal walkthrough, class-society audit, SMS surveillance handoff.
// Frameworks & Standards We Cover
IMO MSC.428(98)
MSC-FAL.1/Circ.3 Rev.2
ISM Code
IACS UR E26 (2024+)
IACS UR E27
BIMCO Cyber Guidelines
TMSA 3 Element 13
NIST 800-82 OT
IEC 62443
IRS
DNV
BV
LR
ABS
Talk to a Maritime Compliance Lead
30-minute call with our maritime compliance lead. Discuss your fleet, SMS state and class-society relationship with no sales pressure.
Schedule Free Call
Frequently Asked Questions
Does IMO MSC.428(98) apply to all vessels?
Yes, it applies to all vessels covered by the ISM Code. The cyber risk must be addressed in the Safety Management System from the first annual verification of the Document of Compliance after 1 January 2021. Smaller vessels not under ISM Code are not directly in scope, but charterers and insurers increasingly expect similar controls regardless.
When does IACS UR E26 apply?
IACS UR E26 (cyber resilience of ships) applies to new-build vessels contracted from 1 July 2024 onwards. Existing vessels are not retroactively in scope but typically need IMO MSC.428(98) compliance instead. Some classification societies are encouraging early adoption of E26 elements for existing vessels.
What is the difference between UR E26 and UR E27?
UR E26 governs cyber resilience at the vessel level, mandating overall design, integration and operational requirements. UR E27 governs cyber resilience at the individual ship system and equipment level, mandating that suppliers (ECDIS, RADAR, engine controls, cargo systems) build cyber-resilient products. Together they form a layered cyber-resilience approach for new builds.
How quickly can you start?
Instant response, no delay. We respond within an hour during business hours, send a fixed-fee scoped proposal in 24-48 hours under NDA, and start gap analysis same or next business day after sign-off.
Will Port State Control actually check this?
Yes, increasingly. Paris MoU, Tokyo MoU and US Coast Guard inspection regimes now include cyber elements in their SMS review during PSC inspections. Detentions related to cyber-deficient SMS have already been reported. Failing a PSC inspection has real cost: delay, charterer penalty, reputational damage.
Does this overlap with TMSA 3 for tankers?
Yes. TMSA 3 Element 13 (Maritime Security) explicitly covers cyber security. Tanker operators serving major charterers (Shell, BP, Chevron, ExxonMobil, etc.) are subject to TMSA self-assessment and vetting. A well-structured IMO MSC.428(98) + UR E26 programme largely satisfies TMSA 3 Element 13 cyber expectations.
Can IMO / IACS evidence satisfy other compliance regimes?
Partially. IMO and IACS cyber controls overlap with NIST 800-82 (OT security), IEC 62443 (industrial automation security) and BIMCO Cyber Guidelines. Many of our maritime clients run a combined IMO + IACS + NIST 800-82 programme for the strongest possible posture.
Ready to Get Your Fleet IMO / IACS Compliant?
Codesecure runs your maritime cyber compliance programme: gap analysis, SMS integration, control implementation and class-society audit support. Free 30-minute strategy call, instant response, no obligation.
Get a Free Strategy Call
See All Maritime Services