IACS E26/E27 Guide
Plain-English breakdown of IACS UR E26 and E27 maritime cyber resilience requirements
UR E26
Cyber Resilience of Ships
Defines 17 requirements across 5 functional areas (Identify, Protect, Detect, Respond, Recover) based on the NIST Cybersecurity Framework. Shipyards must demonstrate compliance through the Cyber Security Design Description (CSDD).
UR E27
Cyber Resilience of On-Board Systems
Defines requirements for equipment suppliers to provide secure systems, including 41 security capabilities (30 core + 11 for untrusted networks), design documentation, and test procedures.
UR E26Ship Cyber Requirements
Maintain complete inventory of all CBS including hardware, software, network interfaces, and data flows.
UR E27Equipment Supplier Requirements
- 1 Human user identification and authentication (SR 1.1)
- 2 Account management (SR 1.3)
- 3 Identifier management (SR 1.4)
- 4 Authenticator management (SR 1.5)
- 5 Wireless access management (SR 1.6)
- 6 Strength of password-based authentication (SR 1.7)
- 7 Authenticator feedback (SR 1.10)
- 8 Authorization enforcement (SR 2.1)
- 9 Wireless use control (SR 2.2)
- 10 Use control for portable and mobile devices (SR 2.3)
- 11 Mobile code (SR 2.4)
- 12 Session lock (SR 2.5)
- 13 Auditable events (SR 2.8)
- 14 Audit storage capacity (SR 2.9)
- 15 Response to audit processing failures (SR 2.10)
- 16 Timestamps (SR 2.11)
- 17 Communication integrity (SR 3.1)
- 18 Malicious code protection (SR 3.2)
- 19 Security functionality verification (SR 3.3)
- 20 Deterministic output (SR 3.6)
- 21 Information confidentiality (SR 4.1)
- 22 Use of cryptography (SR 4.3)
- 23 Audit log accessibility (SR 6.1)
- 24 Denial of service protection (SR 7.1)
- 25 Resource management (SR 7.2)
- 26 System backup (SR 7.3)
- 27 System recovery and reconstitution (SR 7.4)
- 28 Alternative power source (SR 7.5)
- 29 Network and security configuration settings (SR 7.6)
- 30 Least Functionality (SR 7.7)
How CyberAnchor Orchestrates All 41 E27 Capabilities
CyberAnchor orchestrates the evidence chain for all 41 E27 capabilities and closes 21 of 41 on documentary evidence alone; the rest it drives through test-procedure generation, witnessed-evidence capture, and Society omission decisions.
Ready to Assess Your Compliance?
Use our free Compliance Grader to determine which requirements apply to your vessel and get a personalized compliance roadmap.
Start Free Assessment