Compliance Guide

IACS E26/E27 Guide

Plain-English breakdown of IACS UR E26 and E27 maritime cyber resilience requirements

UR E26

Cyber Resilience of Ships

Defines 17 requirements across 5 functional areas (Identify, Protect, Detect, Respond, Recover) based on the NIST Cybersecurity Framework. Shipyards must demonstrate compliance through the Cyber Security Design Description (CSDD).

UR E27

Cyber Resilience of On-Board Systems

Defines requirements for equipment suppliers to provide secure systems, including 41 security capabilities (30 core + 11 for untrusted networks), design documentation, and test procedures.

UR E26Ship Cyber Requirements

4.1.1Vessel Asset Inventory

Maintain complete inventory of all CBS including hardware, software, network interfaces, and data flows.

UR E27Equipment Supplier Requirements

  • 1 Human user identification and authentication (SR 1.1)
  • 2 Account management (SR 1.3)
  • 3 Identifier management (SR 1.4)
  • 4 Authenticator management (SR 1.5)
  • 5 Wireless access management (SR 1.6)
  • 6 Strength of password-based authentication (SR 1.7)
  • 7 Authenticator feedback (SR 1.10)
  • 8 Authorization enforcement (SR 2.1)
  • 9 Wireless use control (SR 2.2)
  • 10 Use control for portable and mobile devices (SR 2.3)
  • 11 Mobile code (SR 2.4)
  • 12 Session lock (SR 2.5)
  • 13 Auditable events (SR 2.8)
  • 14 Audit storage capacity (SR 2.9)
  • 15 Response to audit processing failures (SR 2.10)
  • 16 Timestamps (SR 2.11)
  • 17 Communication integrity (SR 3.1)
  • 18 Malicious code protection (SR 3.2)
  • 19 Security functionality verification (SR 3.3)
  • 20 Deterministic output (SR 3.6)
  • 21 Information confidentiality (SR 4.1)
  • 22 Use of cryptography (SR 4.3)
  • 23 Audit log accessibility (SR 6.1)
  • 24 Denial of service protection (SR 7.1)
  • 25 Resource management (SR 7.2)
  • 26 System backup (SR 7.3)
  • 27 System recovery and reconstitution (SR 7.4)
  • 28 Alternative power source (SR 7.5)
  • 29 Network and security configuration settings (SR 7.6)
  • 30 Least Functionality (SR 7.7)

How CyberAnchor Orchestrates All 41 E27 Capabilities

CyberAnchor orchestrates the evidence chain for all 41 E27 capabilities and closes 21 of 41 on documentary evidence alone; the rest it drives through test-procedure generation, witnessed-evidence capture, and Society omission decisions.

Ready to Assess Your Compliance?

Use our free Compliance Grader to determine which requirements apply to your vessel and get a personalized compliance roadmap.

Start Free Assessment