6 May 2026

Cybersecurity becomes a class matter
The International Association of Classification Societies has made cyber resilience part of a ship's classification: UR E26 addresses the cyber resilience of the vessel as a whole, and UR E27 the systems and equipment aboard it, applying to new vessels contracted from 2024. Cybersecurity has moved from an owner's discretionary policy to a survivable, surveyable condition of class, the same category as watertight integrity.
What the requirements actually ask
The requirements follow the recognisable security lifecycle (identify, protect, detect, respond, recover) applied to a ship: an inventory of onboard OT and IT systems, segmentation between critical control networks and everything else, controlled remote access for vendors ashore, means of detecting incidents at sea, and documented plans for responding and restoring safe operation with the crew on hand.
Why ships are hard cases
A vessel is a floating industrial plant that leaves its security team ashore: navigation, propulsion, power management and cargo systems from many vendors, integrated by yards under commercial pressure, connected via satellite links, crewed by rotating seafarers with limited cyber training. The E26/E27 discipline of design-time architecture and documented responsibilities exists precisely because bolting security on afterwards fails at sea.
The owner's practical agenda
For newbuilds, owners should put cyber requirements into yard and vendor contracts early, because retrofitting compliance is costly. For existing fleets, the same logic applies without the class deadline: inventory, segmentation, remote-access control and crew procedures raise resilience regardless of build date. Insurers, charterers and flag states are all moving the same direction; early movers face fewer surprises.
The practical conclusion for shipowners
For owners and the naval and coastguard programmes that share these waters, the advantage lies in treating cyber resilience as design-time architecture rather than a document produced late to satisfy a surveyor. Write the requirements into yard and vendor contracts at the outset, because retrofitting compliance onto an integrated vessel is slow and costly, and a ship carries its security regime to sea with the security team left ashore. Existing fleets gain from the same logic even without a class deadline: inventory onboard systems, segment critical control networks, broker remote access for vendors, and train rotating crews to respond when help is over the horizon. Owners who move early protect continuity of the mission, satisfy the direction insurers and flag states are already taking, and avoid the surprises that catch those who wait.

