🔒 Safety & Security

Maritime Cybersecurity in 2026:
What Every Ship Manager Needs to Know

📅 July 2026 ⏱ 7 min read ✍️ IAMP Editorial Team
Ship bridge navigation systems representing maritime cybersecurity

Modern ships run on connected systems — navigation, engine control, cargo management, and crew communications all depend on digital infrastructure that was rarely designed with cybersecurity in mind. In 2026, three regulatory frameworks now overlap to govern maritime cyber risk, and shipping companies that satisfy only one of them may still fail the others.

1. The Foundation: IMO Resolution MSC.428(98)

Everything in maritime cybersecurity regulation traces back to IMO Resolution MSC.428(98), adopted in 2017 and effective from 1 January 2021. It made cyber risk management a mandatory component of the International Safety Management (ISM) Code — meaning every shipping company's Safety Management System must explicitly address cyber risk. If your SMS doesn't cover it, your company is already non-compliant with the ISM Code.

The resolution is supported by MSC-FAL.1/Circ.3, the IMO's detailed Guidelines on Maritime Cyber Risk Management, most recently revised to Rev.3 in April 2025.

📊 Key Fact

Non-conformities found during ISM audits — including cyber-related ones — can affect a company's Document of Compliance (DOC) and a vessel's Safety Management Certificate (SMC), putting an entire fleet's certification at risk.

2. IACS Unified Requirements E26 and E27

The International Association of Classification Societies (IACS) has gone further with Unified Requirements E26 and E27, based on the IEC 62443 industrial cybersecurity standard. These requirements are mandatory for classed ships contracted for construction on or after 1 July 2024, and voluntary for existing fleets. They cover both IT and operational technology (OT) — everything from main-engine controls and steering to fire detection and public address systems — throughout a ship's design, construction, and operational life.

3. National and Regional Rules

4. Practical Compliance: What Auditors and PSC Inspectors Look For

Port State Control officers and ISM auditors are increasingly looking for objective evidence, not just a policy document sitting in a binder:

5. Frequently Asked Questions

Is maritime cybersecurity legally mandatory?

Yes. Since 1 January 2021, cyber risk management has been a mandatory part of the ISM Code under IMO Resolution MSC.428(98), applying to every shipping company's Safety Management System.

What are IACS UR E26 and E27?

Classification society requirements for cyber resilience of newbuild ships, mandatory for vessels contracted on or after 1 July 2024, covering both IT and operational technology systems on board.

What happens if a ship fails a cybersecurity audit?

Cyber-related non-conformities under the ISM Code can affect a company's Document of Compliance and a vessel's Safety Management Certificate, with consequences that can extend across an entire fleet.

Build Cyber-Ready Maritime Skills with IAMP

Join IAMP for access to training resources and updates on the evolving cybersecurity, safety, and technical standards shaping modern ship operations.

Join IAMP Today →
Maritime Cybersecurity ISM Code IACS UR E26 E27 MSC.428(98) Ship Safety

Sources: International Maritime Organization (imo.org), DNV, IACS. This article is for general information and does not constitute regulatory, legal, or cybersecurity advice.