Executive Briefing — For Shipowners

IACS UR E26 and E27: What Shipowners Need to Know About Contract Risk and Class Compliance

You don’t need to understand network segmentation or security zones. You need to know how these rules affect your shipbuilding contract, your delivery timeline, and who is liable when something is missed. This briefing covers exactly that — and nothing else.

Applies To
Vessels contracted on or after 1 July 2024
Governing Rules
IACS UR E26 & UR E27
Consequence of Non-Compliance
No Class Certificate
Who Carries Commercial Risk
The Shipowner

The One-Paragraph Version

UR E26 (“Cyber Resilience of Ships”) and UR E27 (“Cyber Resilience of On-Board Systems and Equipment”) are IACS Unified Requirements that became mandatory for any vessel contracted for construction on or after 1 July 2024. They are not optional guidance — once in force, they are a condition of class, meaning a vessel that doesn’t demonstrate compliance does not receive its class certificate and cannot be delivered as classed.

Your shipyard builds the vessel to E26’s ship-level requirements. Your equipment suppliers (OEMs) certify individual systems to E27. But contractually and commercially, you — the shipowner — carry the risk if either one falls short, because it’s your vessel that doesn’t get delivered on schedule if compliance gaps surface late in the build.

Where the Risk Actually Sits

Equipment Suppliers (OEMs)

Deliver individual systems with UR E27 Type Approval Certificates.

Risk: uncertified or legacy equipment
Shipyard / Integrator

Integrates certified equipment per the vessel’s E26 architecture and Cyber Security Design Description.

Risk: poor integration, incomplete documentation
Shipowner

Accepts the vessel and assumes ongoing operational compliance responsibility.

Risk: delivery delay, operational gaps

Every gap upstream — an OEM’s missing Type Approval Certificate, a shipyard’s incomplete Cyber Security Design Description — eventually lands on the shipowner as a delivery delay, a cost dispute, or an unclassed vessel. This is why oversight of the first two boxes, not just acceptance of the third, has to be part of your newbuild governance from contract signature onward.

Where Newbuild Programmes Commonly Run Into Trouble

Uncertified or Legacy Equipment

A shipyard installs lower-cost or already-familiar equipment that was never issued a UR E27 Type Approval Certificate. This typically surfaces late — often near delivery, during Class survey — when it’s most expensive and time-critical to fix.

Incomplete Documentation Handover

E26 requires a detailed Cyber Security Design Description and supporting documentation package. If the shipyard hands over an incomplete package, your own technical team cannot manage patching, updates, or future periodic Class surveys once the vessel is in service.

Vague Contract Language

Shipbuilding contracts that reference “Class Rules” generically, without explicitly naming UR E26/E27 compliance as a condition of acceptance, leave room for disputes over what was actually promised — and who pays if something’s missing.

A commonly reported pattern, not a certainty: some shipowners report that shipyards treat E26/E27 compliance work as grounds for change orders when the original contract specification was vague. This isn’t a rule of the regulation itself — it’s a contractual risk that a well-specified Shipbuilding Contract can largely close off in advance.

Your Oversight Responsibilities, by Newbuild Phase

PhaseShipyard / OEM ResponsibilityYour Required Oversight
1. Specification & Contract Shipyard typically references general “Class Rules” compliance. Explicitly name UR E26 and UR E27 compliance in the Shipbuilding Contract specification — don’t rely on generic Class Rules language.
2. Design & Plan Approval Shipyard produces the network architecture and Cyber Security Design Description; OEMs supply Type Approval Certificates. Review the Maker’s List. Confirm every Category II/III OT supplier (propulsion, ECDIS, power management, cargo systems) holds a valid UR E27 Type Approval Certificate before construction proceeds.
3. Construction & Commissioning Shipyard implements network segmentation, security zones, and access controls per the approved design. Audit shipyard testing. Confirm default passwords have been changed and that service laptop access cannot bypass configured security controls.
4. Sea Trials & Delivery Shipyard demonstrates the vessel’s Ship Cyber Resilience Test Procedure (SCRTP) to Class. Require handover of the complete cyber documentation package — asset inventory, network diagrams, and incident recovery plans — as a condition of final vessel acceptance.

The Ship Cyber Resilience Test Procedure isn’t a one-off sea trials event — it’s also re-applied at periodic Class surveys throughout the vessel’s operational life, which is why a complete documentation handover at delivery matters well beyond the acceptance ceremony itself.

Executive Action Checklist

  • Update your Shipbuilding Contract language — insert explicit clauses naming full IACS UR E26/E27 documentation and Type Approval Certificate delivery as a condition of Final Acceptance, not an assumed byproduct of general Class compliance.
  • Scrutinise the Maker’s List early — confirm Category III (highest-criticality) OT suppliers, such as main propulsion, steering, and integrated navigation, hold valid UR E27 Type Approval Certificates before construction is underway, not at delivery.
  • Secure the full operational handover package — asset inventory, network diagrams, and incident recovery plans must reach your technical superintendents before crew boarding, not after.
  • Align your Safety Management System — ensure your SMS (required under IMO Resolution MSC.428(98)) is updated to manage the cyber-resilient systems and documentation your newbuild will actually deliver.
This briefing summarises publicly available IACS, Class society, and IMO information for shipowner decision-making purposes. It is not legal advice, and it does not replace review of the actual UR E26/E27 texts and your specific Shipbuilding Contract by qualified maritime legal counsel. Official IACS Unified Requirement texts are available without charge at iacs.org.uk.
Going Deeper

For Your Technical Team

This briefing covers commercial exposure at executive level. Your DPA, Technical Superintendent, or ETO will need the detailed compliance methodology — CBS categorisation, risk assessment, and the full Cyber Security Design Description build process — covered in tagsia’s practitioner playbooks.

View the Compliance Playbooks →
Scroll to Top