IACS UR E26 and E27: What Shipowners Need to Know About Contract Risk and Class Compliance
You don’t need to understand network segmentation or security zones. You need to know how these rules affect your shipbuilding contract, your delivery timeline, and who is liable when something is missed. This briefing covers exactly that — and nothing else.
The One-Paragraph Version
UR E26 (“Cyber Resilience of Ships”) and UR E27 (“Cyber Resilience of On-Board Systems and Equipment”) are IACS Unified Requirements that became mandatory for any vessel contracted for construction on or after 1 July 2024. They are not optional guidance — once in force, they are a condition of class, meaning a vessel that doesn’t demonstrate compliance does not receive its class certificate and cannot be delivered as classed.
Your shipyard builds the vessel to E26’s ship-level requirements. Your equipment suppliers (OEMs) certify individual systems to E27. But contractually and commercially, you — the shipowner — carry the risk if either one falls short, because it’s your vessel that doesn’t get delivered on schedule if compliance gaps surface late in the build.
Where the Risk Actually Sits
Equipment Suppliers (OEMs)
Deliver individual systems with UR E27 Type Approval Certificates.
Shipyard / Integrator
Integrates certified equipment per the vessel’s E26 architecture and Cyber Security Design Description.
Shipowner
Accepts the vessel and assumes ongoing operational compliance responsibility.
Every gap upstream — an OEM’s missing Type Approval Certificate, a shipyard’s incomplete Cyber Security Design Description — eventually lands on the shipowner as a delivery delay, a cost dispute, or an unclassed vessel. This is why oversight of the first two boxes, not just acceptance of the third, has to be part of your newbuild governance from contract signature onward.
Where Newbuild Programmes Commonly Run Into Trouble
Uncertified or Legacy Equipment
A shipyard installs lower-cost or already-familiar equipment that was never issued a UR E27 Type Approval Certificate. This typically surfaces late — often near delivery, during Class survey — when it’s most expensive and time-critical to fix.
Incomplete Documentation Handover
E26 requires a detailed Cyber Security Design Description and supporting documentation package. If the shipyard hands over an incomplete package, your own technical team cannot manage patching, updates, or future periodic Class surveys once the vessel is in service.
Vague Contract Language
Shipbuilding contracts that reference “Class Rules” generically, without explicitly naming UR E26/E27 compliance as a condition of acceptance, leave room for disputes over what was actually promised — and who pays if something’s missing.
Your Oversight Responsibilities, by Newbuild Phase
| Phase | Shipyard / OEM Responsibility | Your Required Oversight |
|---|---|---|
| 1. Specification & Contract | Shipyard typically references general “Class Rules” compliance. | Explicitly name UR E26 and UR E27 compliance in the Shipbuilding Contract specification — don’t rely on generic Class Rules language. |
| 2. Design & Plan Approval | Shipyard produces the network architecture and Cyber Security Design Description; OEMs supply Type Approval Certificates. | Review the Maker’s List. Confirm every Category II/III OT supplier (propulsion, ECDIS, power management, cargo systems) holds a valid UR E27 Type Approval Certificate before construction proceeds. |
| 3. Construction & Commissioning | Shipyard implements network segmentation, security zones, and access controls per the approved design. | Audit shipyard testing. Confirm default passwords have been changed and that service laptop access cannot bypass configured security controls. |
| 4. Sea Trials & Delivery | Shipyard demonstrates the vessel’s Ship Cyber Resilience Test Procedure (SCRTP) to Class. | Require handover of the complete cyber documentation package — asset inventory, network diagrams, and incident recovery plans — as a condition of final vessel acceptance. |
The Ship Cyber Resilience Test Procedure isn’t a one-off sea trials event — it’s also re-applied at periodic Class surveys throughout the vessel’s operational life, which is why a complete documentation handover at delivery matters well beyond the acceptance ceremony itself.
Executive Action Checklist
- Update your Shipbuilding Contract language — insert explicit clauses naming full IACS UR E26/E27 documentation and Type Approval Certificate delivery as a condition of Final Acceptance, not an assumed byproduct of general Class compliance.
- Scrutinise the Maker’s List early — confirm Category III (highest-criticality) OT suppliers, such as main propulsion, steering, and integrated navigation, hold valid UR E27 Type Approval Certificates before construction is underway, not at delivery.
- Secure the full operational handover package — asset inventory, network diagrams, and incident recovery plans must reach your technical superintendents before crew boarding, not after.
- Align your Safety Management System — ensure your SMS (required under IMO Resolution MSC.428(98)) is updated to manage the cyber-resilient systems and documentation your newbuild will actually deliver.
For Your Technical Team
This briefing covers commercial exposure at executive level. Your DPA, Technical Superintendent, or ETO will need the detailed compliance methodology — CBS categorisation, risk assessment, and the full Cyber Security Design Description build process — covered in tagsia’s practitioner playbooks.
View the Compliance Playbooks →