You are currently viewing What are IMO Resolution MSC.428(98) and the IMO Guidelines on Maritime Cyber Risk Management?

What are IMO Resolution MSC.428(98) and the IMO Guidelines on Maritime Cyber Risk Management?

Maritime Cyber Insights #4

Article content
Cyber resilience begins beyond compliance.

Many shipping companies state that they “comply with MSC.428(98).” That shorthand is understandable, but technically incomplete.

International Maritime Organization Resolution MSC.428(98) is not a standalone company certification standard, nor did it establish a separate maritime cyber certificate. The mandatory framework is found in SOLAS chapter IX and the International Safety Management Code, as implemented by the relevant flag Administration. MSC.428(98) confirms that cyber risk management must be addressed within an approved Safety Management System in accordance with the objectives and functional requirements of the ISM Code.

This distinction is more than semantic.

It determines how the obligation is implemented, where cyber risk should appear within the Safety Management System, what evidence auditors and inspectors may expect, how deficiencies may be recorded and how failure to implement the company’s own procedures can escalate into an ISM finding.

It also explains why a company can hold a valid Document of Compliance while still remaining materially exposed to cyber risk. Certification confirms that a management system has been established and verified at particular points in time. It does not guarantee that every procedure is consistently followed across every vessel, department, supplier and operational environment.

This article explains what MSC.428(98) actually says, what the current IMO Guidelines require following their substantial 2025 revision and subsequent 2026 update, and how the framework relates to the ISM Code, IACS Unified Requirements E26 and E27, national or regional legislation and industry guidance.

It is written for the people who must operationalize these requirements, not merely describe them in a compliance statement.

What MSC.428(98) actually says

Resolution MSC.428(98), Maritime Cyber Risk Management in Safety Management Systems, was adopted by the IMO Maritime Safety Committee on 16 June 2017.

  • Its operative content is brief.
  • It affirms that an approved Safety Management System should take cyber risk management into account in accordance with the objectives and functional requirements of the ISM Code.
  • It encourages Administrations to ensure that cyber risks are appropriately addressed within Safety Management Systems no later than the first annual verification of the company’s Document of Compliance after “1 January 2021”.
  • It acknowledges that precautions may be necessary to preserve the confidentiality of certain aspects of cyber risk management.
  • It requests Member States to bring the resolution to the attention of relevant maritime stakeholders.

It did not establish a separate certification regime

MSC.428(98) did not amend the ISM Code or create a separate cybersecurity certification process. Instead, it removed any remaining ambiguity about whether the ISM Code’s existing risk-management obligations extend to cyber risk.

The ISM Code requires companies to assess all identified risks to their ships, personnel and the environment and to establish appropriate safeguards. MSC.428(98) confirms that cyber threats, vulnerabilities and technology-related operational failures fall within that risk-management framework.

The practical obligation therefore rests within the approved SMS. Not in a separate declaration of “MSC.428 compliance.”

Its implementation call is primarily directed at Administrations

The resolution’s direct implementation language primarily addresses flag Administrations.

Its effect reaches shipping companies and vessels through flag-State implementation, company DOC verification, shipboard SMC verification, recognized-organization audits and, where applicable, Port State Control.

This is why deficiencies normally arise under the ISM Code, the company’s approved SMS or another applicable legal requirement. They are not usually treated as findings against a standalone “MSC.428 standard.”

The implementation deadline has passed

The first annual DOC verification after 1 January 2021 has long since taken place for affected companies, and several annual verification cycles have now followed.

The relevant question in 2026 is therefore no longer whether the company has inserted a cybersecurity section into its SMS.

The real question is whether cyber risk management has been effectively integrated into normal company and vessel operations—and whether the company can demonstrate that integration through objective evidence.

That is a materially higher standard than possessing a policy document.

The Guidelines: the 2025 overhaul and the 2026 update

Article content
Rev.4 is the current benchmark; Rev.3 delivered the transformation.

MSC.428(98) establishes the regulatory direction. The operational detail is contained in the jointly approved IMO Guidelines on Maritime Cyber Risk Management.

The current instrument is MSC-FAL.1/Circ.3/Rev.4, issued on 28 May 2026 following approval by the Facilitation Committee at FAL 50 in March 2026 and the Maritime Safety Committee at MSC 111 in May 2026.

Rev.4 carries forward the substantial changes introduced through Rev.3 in April 2025 and adds the IAPH Cyber Resilience Guidelines for Emerging Technologies in the Maritime Supply Chain to the non-exhaustive list of supporting industry guidance in section 4.3.

The principal substantive transformation therefore occurred in Rev.3 and remains fully reflected in Rev.4.

A new terminology baseline

The current Guidelines are built around the concept of the Computer Based System (CBS).

A CBS is defined as a programmable electronic device [or an interoperable set of such device] organized to collect, process, maintain, use, share, disseminate or dispose of information.

Onboard CBSs include both information technology and operational technology systems. They may consist of connected subsystems and may communicate with shore-based systems, other ships or external facilities through private or public communications infrastructure.

This terminology is important because it creates closer alignment between the IMO Guidelines and the language used in IACS UR E26, UR E27 and UR E22.

It also discourages the artificial separation of “IT cybersecurity” from the operational systems on which navigation, propulsion, power generation, cargo operations, communications and vessel safety increasingly depend.

A sixth functional element: Govern

Earlier versions of the Guidelines followed five familiar functional elements:

  1. Identify
  2. Protect
  3. Detect
  4. Respond
  5. Recover.

The revised framework adds Govern at the beginning, reflecting the governance function introduced through the NIST Cybersecurity Framework 2.0.

Under Govern, companies should establish and monitor cyber risk-management strategies, expectations and policies, define roles and responsibilities. And ensure business continuity, backup management, disaster recovery and crisis management.

The Guidelines also state that a person or entity should be designated as accountable for the planning, resourcing and execution of cybersecurity activities. That person or entity should be given the authority, support, knowledge and expertise required to perform the role.

This establishes a clear IMO governance expectation.

Cyber risk should not be nominally assigned to an IT department that has no authority over vessel operations, procurement, crewing, third-party access or operational technology. Nor should it be assigned to the Designated Person Ashore purely because the DPA already occupies a recognized position within the ISM structure, unless the DPA is given the necessary cybersecurity competence, authority, support and resources.

Accountability without authority is not governance.

Controls described as minimums

The current Guidelines continue to describe themselves as providing high-level recommendations. They remain a non-mandatory IMO circular and predominantly use the term “should.”

However, paragraph 3.5 states that the functional and technical cybersecurity controls listed under each functional element represent the minimum controls that should be implemented, with additional controls considered according to the identified cyber risks.

This wording does not convert the circular into a directly mandatory instrument.

An auditor or inspector should still ground a formal finding in an applicable ISM requirement, flag-State requirement, class rule, national regulation or provision of the company’s approved SMS. Not simply in the failure to follow a non-mandatory circular.

Nevertheless, the language materially strengthens the Guidelines’ practical value.

They now provide an IMO-issued benchmark against which the adequacy of a company’s cyber risk-management arrangements may be evaluated. The scope for claiming that almost any minimal arrangement is sufficient has narrowed considerably.

Named functional and technical controls

The Guidelines now expressly address measures including:

  • Unique user credentials and the separation of standard and privileged accounts.
  • Deactivation of accounts belonging to departing personnel.
  • Removal of default passwords and implementation of strong password policies.
  • Multi-factor or continuous authentication where appropriate.
  • Limitation of exploitable internet-facing services.
  • Hardware and software approval processes.
  • Secure collection and retention of logs for intrusion detection and incident response.
  • Segmentation of OT device networks from IT networks.
  • Security controls for systems connected to the internet, corporate intranets, third parties and ship-to-port interfaces.
  • Policies governing the use of cryptography.
  • Controls against unauthorized removable media.
  • Regular system backups and software updates.
  • Maintained incident-response plans.
  • Software and hardware supply-chain policies for systems identified as critical.
  • Periodic assessment, auditing, review and updating of cyber risk-management measures.

The Guidelines also make clear that effective risk assessment should extend beyond systems physically installed onboard..

Cyber risk assessment should consider third-party vendors, embedded systems, hardware and software supply chains, maintenance devices, remote access arrangements and the interdependencies between safety-critical systems. That is essential because a vessel’s cyber exposure does not end at the ship’s physical boundary.

The human element

The Guidelines call for annual basic cybersecurity training for all employees, OT-specific cybersecurity training for OT users and cybersecurity familiarization for crew members when they join the vessel.

  • Training should address cyber hygiene, recognition and detection of an ongoing cyber incident, response and recovery.
  • Cybersecurity knowledge should also be tested periodically. For example, through drills and exercises. The document does not state that cyber drills themselves must be conducted annually, and that distinction should be preserved.
  • The “Respond and Recover” elements also expect cyber incidents to be recorded, reported to the necessary parties within timeframes defined by the relevant Administration and subjected to root-cause analysis to resolve underlying issues and reduce the likelihood of recurrence.
  • Documents created to satisfy the functional elements should themselves be protected against unauthorized access, deletion, destruction or amendment.

The training, drill, reporting, record-keeping, corrective-action and root-cause language is not incidental. It reflects the vocabulary and management logic of the ISM Code.

Integration into the Safety Management System

Article content
Cyber risk must be embedded across the entire ISM framework.

The IMO position is that cyber risk management should be incorporated into existing risk-management and safety-management processes. It should not operate as a disconnected parallel management system.

A standalone cybersecurity manual may still be useful as a controlled supporting document, but only where its requirements are linked to the relevant SMS procedures, responsibilities, records, audit processes and operational controls.

Otherwise, it becomes a compliance attachment rather than part of the way the company manages safety.

Proper integration should be visible across the ISM architecture.

ISM 1.2.2.2: Risk assessment and safeguards

Cyber threats and vulnerabilities should enter the same structured risk-assessment process used for other safety and operational hazards.

The assessment should consider the vessel’s type, operating profile, trading pattern, onboard-system complexity, external connectivity, data dependencies, remote support arrangements and potential consequences of compromised availability, integrity or confidentiality.

It should be reviewed after significant system modifications, network changes, new vendor connections, cyber incidents, changes in operational profile or the identification of material new vulnerabilities.

ISM 3: Company responsibilities and authority

The company should define who is accountable for cyber risk management and how authority is distributed between management, IT, OT specialists, marine operations, technical departments, procurement, crewing, safety functions and vessels.

Responsibility should be documented, but it must also be operationally credible. The person held accountable must be capable of obtaining information, directing action, escalating unresolved risks and securing the necessary resources.

ISM 5: Master’s responsibility and authority

The Master should understand the vessel’s cyber-related operational risks and the procedures that apply when system integrity, availability or trustworthiness is in doubt.

The SMS should preserve the Master’s overriding authority to take decisions necessary for safety, including suspending unsafe digital processes, limiting external connectivity or reverting to manual or degraded operating modes where appropriate.

ISM 6: Resources and personnel

Competence requirements, familiarization, shore-based support and recurrent training should include an explicit cyber dimension.

General cybersecurity awareness alone is insufficient for personnel who operate, maintain or administer safety-critical OT systems. Training should reflect actual responsibilities.

Bridge personnel, engineers, electro-technical officers, IT support teams, procurement staff, superintendents and senior management do not all require the same level or type of cyber competence.

ISM 7: Shipboard operations

Procedures for key shipboard operations should consider the CBSs on which those operations depend.

This includes navigation, propulsion, steering, power generation, cargo management, ballast operations, communications, safety systems and other functions whose disruption or manipulation could create a hazardous situation.

Procedures should address what happens when a system becomes unavailable, produces unreliable data or may have been compromised.

ISM 8: Emergency preparedness

Cyber incidents should be incorporated into emergency planning and exercises.

Scenarios may include loss of navigation data, ransomware affecting shore or vessel systems, compromised remote access, loss of communications, failure of cargo-management systems, malicious alteration of operational data or simultaneous loss of multiple interconnected systems.

The company should define technical and operational decision-making responsibilities, communication arrangements, escalation paths and procedures for safe degraded operation.

ISM 9: Reporting and analysis

Cyber incidents and relevant near-misses should enter the established reporting, investigation and corrective-action process. The objective should not be limited to restoring a system.

The company should determine why the incident occurred, which procedural or technical controls failed, whether similar exposure exists elsewhere in the fleet and what corrective or preventive measures are required.

ISM 10: Maintenance of the ship and equipment

Software updates, security patches, configuration management, backup verification, account administration, malware protection, network-device maintenance and vendor-access controls should be treated as managed maintenance activities.

Where patching is delayed because of operational or vendor constraints, the resulting risk and any compensating controls should be documented.

ISM 11: Documentation

Cybersecurity policies, risk assessments, inventories, diagrams, incident-response plans and related records should be controlled as SMS documentation where applicable.

Access should be restricted according to need, changes should be authorized, obsolete documents should be removed and sensitive technical information should be protected.

ISM 12: Company verification, review and evaluation

Internal audits should examine cyber risk management, and management reviews should consider its effectiveness.

The audit should not be reduced to confirming that a cybersecurity policy exists. It should test whether procedures are being followed, records are reliable, responsibilities are understood and controls remain appropriate for the actual vessel and shore environment.

If cyber risk appears in the SMS but touches none of these areas, it has not been meaningfully integrated. It has been appended.

Shipowner and operator responsibilities

The current Guidelines state that effective cyber risk management should begin at senior-management level and be embedded across the organisation.

For ISM purposes, formal responsibility rests with the Company. Meaning the owner or another organisation, such as a ship manager, that has assumed responsibility for operating the ship and agreed to discharge the duties imposed by the ISM Code.

In practical terms, the Company should:

  1. Establish accountability. A person or entity should be designated to oversee the planning, resourcing and execution of cybersecurity activities, with sufficient authority, support and competence.
  2. Maintain an accurate asset inventory. The company should identify onboard digital systems, software, hardware, network connections, critical data, internal and external dependencies and connections to shore or third-party infrastructure. An incomplete inventory undermines every subsequent control because a company cannot reliably protect, monitor, maintain or recover systems it has not identified. In my professional observation, asset visibility remains one of the most significant implementation weaknesses across maritime environments.
  3. Conduct and maintain risk assessments. Risk assessment should cover systems, services, assets, data and capabilities whose sudden failure or compromise could affect safe operations, human safety, the vessel or the environment. It should also cover software and hardware supply-chain exposure.
  4. Implement proportionate controls. The controls described in the IMO Guidelines should be considered a baseline, supplemented where the assessed risk justifies stronger measures.
  5. Train shore and vessel personnel. Training should be appropriate to role and should be supported by familiarisation, exercises and periodic testing of knowledge.
  6. Prepare for incidents. The company should be able to detect, respond to, record, report and recover from cyber incidents while maintaining or restoring safe operations.
  7. Analyze and improve. Incidents, near-misses, audit findings and identified weaknesses should lead to root-cause analysis, corrective action and fleet-wide learning where relevant.
  8. Protect cyber documentation. Risk assessments, network diagrams, asset inventories, credentials, incident records and response plans may themselves be sensitive. They should be protected against unauthorised disclosure, modification or destruction.

Where an owner transfers ISM responsibility to a third-party ship manager, the manager may become the formal ISM Company. That does not mean the owner has no remaining exposure.

The owner continues to face asset, commercial, contractual, financing, insurance and reputational consequences if the manager’s cyber risk-management arrangements are ineffective. Owners should therefore exercise appropriate due diligence rather than assume that the existence of a manager’s DOC automatically proves effective cyber implementation across the managed fleet.

Evidence of effective implementation

Article content
A policy shows intent; evidence proves implementation.

This is where the framework becomes operational. The ISM framework distinguishes between observations, non-conformities and major non-conformities.

A major non-conformity includes an identifiable deviation posing a serious threat to personnel, ship safety or the environment and requiring immediate corrective action. The definition also covers a lack of effective and systematic implementation of an ISM Code requirement.

This does not mean that every cyber weakness automatically constitutes a major non-conformity.

The classification of a finding depends on objective evidence, the applicable requirement, the seriousness of the condition, the consequences, the extent of the failure and the Administration’s or recognized organization’s audit procedures.

However, where cyber risk management has been included within the approved SMS but is not being effectively or systematically implemented, the issue is capable of supporting an ISM finding. In serious cases, and depending on the circumstances, escalation to a major non-conformity is possible.

The Port State Control perspective

Article content
Port State Control tests implementation—not policy wording.

The US Coast Guard’s published work instruction for Marine Inspectors and Port State Control Officers, CVC-WI-027 (document), provides a useful example of how this logic may be applied. The current revision, CVC-WI-027(3), dates from October 2023.

The guidance directs inspectors to consider cyber hygiene and, where clear grounds exist, conduct a more detailed examination.

It also makes two important points.

  1. Poor cyber hygiene or a more detailed inspection does not automatically mean that an ISM deficiency exists.
  2. Where objective evidence demonstrates that the vessel has failed to implement the cyber risk-management provisions of its own SMS, a deficiency may be issued against the relevant SMS requirement. Inspectors are not instructed to impose their preferred cybersecurity checklist on the vessel; the test is whether the company’s approved management system is being effectively implemented.

For foreign vessels, the work instruction distinguishes between several possible situations. Where an expanded examination reveals that cyber risk management was not incorporated into the vessel’s SMS by the required DOC verification, the PSCO may issue an action code 17 deficiency requiring rectification and an external audit before departure. Where cyber risk management has been incorporated but the vessel has failed to implement it, the PSCO may issue the related operational deficiency together with an ISM deficiency carrying action code 40 [rectification before the vessel’s next U.S. port after sailing foreign] or action code 50, requiring rectification within 30 days and an internal audit focused on the vessel’s cyber risk management. Deficiency Codes List.

Where a serious failure to implement cyber risk management directly resulted in a cybersecurity incident affecting ship operations, diminished safety or security, or increased environmental risk, the work instruction contemplates action code 30 [ship detained] following concurrence from the Officer in Charge, Marine Inspection, together with an external audit before release from detention.

Publicly verifiable cases of Port State Control detention arising specifically and exclusively from cyber-related ISM findings remain difficult to identify in the open record.

-= No such claim is made here =-.

The available enforcement and audit consequences are nevertheless documented and real. Depending on the circumstances, they may include an operational deficiency, an ISM deficiency, a non-conformity or major non-conformity, additional internal or external audit requirements, certificate-related action or detention.

What objective evidence looks like

Auditors and inspectors do not verify intent. They verify implementation through evidence.

Relevant evidence may include:

  • An accurate onboard asset inventory reconciled against what is actually installed.
  • Current network diagrams and records of external connections.
  • Cyber risk assessments that are dated, approved, reviewed and updated following material changes.
  • Records demonstrating control of privileged and inactive accounts.
  • Training and familiarization records, including OT-specific training where applicable.
  • Exercise and drill records showing that lessons were identified and addressed.
  • Cyber incident and near-miss records.
  • Root-cause analyses and corrective-action close-outs.
  • Internal audit reports that meaningfully assess cyber risk.
  • Management-review records demonstrating senior-level oversight.
  • Vendor remote-access approvals, access logs and termination records.
  • Software, configuration, patching and backup records.
  • Evidence that restoration procedures and backups have been tested.
  • Records demonstrating that removable media and portable devices are controlled.
  • Evidence of hardware, software and supplier approval processes.

A policy document with no supporting records is not evidence of implementation. It is evidence of intent.

How the IMO framework fits with the ISM Code, IACS E26/E27 and industry guidance

Article content
One framework, multiple layers.

The maritime cyber framework is best understood as several interacting layers, each performing a different function.

Confusing those layers is the source of many compliance errors.

1. The ISM Code: the mandatory management framework

The ISM Code is mandatory for applicable companies and ships through SOLAS chapter IX.

It requires a structured Safety Management System, assessment of identified risks, appropriate safeguards, defined responsibilities, emergency preparedness, maintenance, reporting, documentation, internal verification and management review.

MSC.428(98) confirms that cyber risk management belongs within that framework. The ISM obligation applies according to the scope of SOLAS chapter IX and the relevant flag-State implementation. It is not limited to vessels constructed after a particular cyber-regulation date.

2. MSC-FAL.1/Circ.3/Rev.4: the current IMO benchmark

The current Guidelines are formally non-mandatory and provide high-level recommendations.

They nevertheless offer the most current IMO benchmark for understanding how maritime cyber risks should be governed, identified, protected against, detected, responded to and recovered from.

Their use is not a substitute for considering flag-State requirements, national law, class rules or the company’s own risk profile.

The Guidelines themselves direct users toward relevant Administration requirements, international standards and industry best practices for more detailed implementation.

3. IACS UR E26 and E27: class requirements for covered new construction

IACS UR E26 addresses the cyber resilience of the ship as a collective and integrated entity.

IACS UR E27 addresses the cyber resilience of onboard systems and equipment, including requirements intended to ensure that security capabilities are incorporated at the design and manufacturing stages.

The Rev.1 versions are to be uniformly implemented by IACS member societies for covered ships contracted for construction on or after1 July 2024″. They may be used for other ships as non-mandatory guidance.

Their mandatory vessel scope includes:

  • Passenger ships, including passenger high-speed craft, engaged in international voyages.
  • Cargo ships of 500 GT and above engaged in international voyages.
  • High-speed craft of 500 GT and above engaged in international voyages.
  • Mobile offshore drilling units of 500 GT and above.
  • Specified self-propelled mobile offshore units engaged in construction activities, such as wind-turbine installation, maintenance and repair units, crane units, drilling tenders and accommodation units.

The boundary between the IMO and IACS regimes is important.

  • E26 and E27 do not retrospectively impose their mandatory new-construction requirements across the existing fleet.
  • A vessel built in 2015 will ordinarily fall outside their mandatory application. However, the requirements or equivalent controls may still be used voluntarily, through class notations, retrofits, owner specifications, charterer requirements, contractual arrangements or company standards.
  • That vessel may also remain subject to cyber risk-management requirements through the ISM Code, flag-State rules, port-State requirements and other applicable legislation.
  • Equally, a newbuilding constructed to meet E26 and E27 is not automatically compliant with every cyber-related ISM obligation.
  • Class verification of design, integration, onboard systems and technical resilience is distinct from the company’s responsibility to integrate cyber risk into its SMS and demonstrate effective implementation during operations.

At the same time, it would be inaccurate to describe E26 as relevant only at delivery.

E26 contains operational-life requirements for shipowners, including management of technical and organizational security measures, maintenance of documentation, operational procedures, periodic training and drills, updating of cyber-resilience test procedures and verification through annual and other class surveys.

The two regimes therefore overlap operationally, but they remain different in legal basis, scope, verification mechanism and purpose.

4. Industry guidance: where much of the practical detail lives

The Guidelines on Cyber Security Onboard Ships, Version 5, published on “14 November 2024” and supported by major shipping organizations, remains an important industry implementation reference.

The current IMO Guidelines also refer users to:

  • ISO/IEC 27001.
  • IACS UR E26 and UR E27.
  • Consolidated IACS Recommendation No. 166 on Cyber Resilience.
  • The NIST Cybersecurity Framework 2.0.
  • The IAPH Cybersecurity Guidelines for Ports and Port Facilities.
  • The IAPH Cyber Resilience Guidelines for Emerging Technologies in the Maritime Supply Chain.

These materials are not all IMO instruments, and they do not all carry the same legal status.

Their value is that they provide technical, organizational and procedural detail that a short, high-level IMO circular cannot reasonably contain.

Additional national and regional requirements

Other legal regimes may apply alongside the IMO framework.

The US Coast Guard’s final rule on cybersecurity in the Marine Transportation System was published on “17 January 2025” and became effective on “16 July 2025”. It establishes specific requirements for covered U.S.-flagged vessels, regulated facilities and Outer Continental Shelf facilities.

It is separate from the USCG Port State Control work instruction used to assess foreign vessels under the ISM framework.

Within the European Union, NIS2 may apply to qualifying entities in the water-transport sector, depending on their size, activities, jurisdiction and national transposition.

NIS2 obligations do not replace the ISM Code. They address the cybersecurity risk-management and reporting responsibilities of in-scope entities under a separate legal framework.

The applicable maritime cyber obligations therefore depend on a combination of factors, including vessel type, tonnage, voyage profile, contract or construction date, flag, class, operating jurisdiction, company status and connections to regulated infrastructure.

They do not depend on vessel type alone, and they cannot be demonstrated through a single certificate.

Where this is heading

Article content
The next milestone is the Maritime Cyber Code.

The current IMO architecture consists of a mandatory management Code, an interpretive resolution and non-mandatory supporting Guidelines. That framework has raised maritime cyber risk to the level of formal safety management, but it remains structurally fragmented.

The IMO has now begun developing a dedicated, goal-based and non-mandatory Maritime Cyber Code.

At MSC 110 in June 2025, the Maritime Safety Committee agreed that a non-mandatory cybersecurity code should be developed using a risk-management-oriented approach. FAL 50 subsequently recorded that the Working Group established during MSC 110 had agreed that the ISPS Code was not an appropriate approach for developing comprehensive cybersecurity arrangements within IMO, and that a goal-based, non-mandatory Maritime Cyber Code offered a more comprehensive pathway.

At FAL 50 in March 2026, the Facilitation Committee approved a new output for the development of a non-mandatory Maritime Cyber Code, with a target completion year of 2028. It invited the Maritime Safety Committee to participate as an associated organ, approved the road map for the approval of the Code, approved the formation of an Intersessional Correspondence Group to develop it, and approved an intersessional joint FAL-MSC expert group on the Code, to meet in 2027.

MSC 111, in May 2026, agreed to participate as an associated organ and concurrently approved the road map.

Both the Correspondence Group and the joint FAL-MSC expert group remain subject to consideration and endorsement by the IMO Council at its 137th session. The Correspondence Group is to report to FAL 51, provisionally scheduled for February 2027, where a dedicated working group on the Code is anticipated.

The Code is intended to be goal-based and to address the wider maritime digital ecosystem, including computer-based systems supporting the safe operation of port facilities, shipping and the ship-to-shore interface.

During FAL 50, one of the views recorded in support of the proposal was that the Code’s initially non-binding nature, potentially coupled with an experience-building phase, would allow States and industry to build capability, test solutions and identify gaps without immediately creating a fully prescriptive global regime.

Whether the Maritime Cyber Code will eventually form the basis of a mandatory IMO instrument has not been decided.

The development of the Maritime Autonomous Surface Ships Code demonstrates one possible pathway. Beginning with a non-mandatory instrument, followed by experience building and later consideration of mandatory status.

Applying the same trajectory to the Maritime Cyber Code, however, would currently be an inference rather than an agreed IMO position. The only firm conclusion is that the regulatory direction is toward greater structure, clearer governance and broader harmonization.

The intervening period should not be treated as a grace period.


Article content
Cyber resilience is demonstrated through implementation—not documentation.

MSC.428(98) is a short resolution with a precise purpose.

It confirms that maritime cyber risk belongs within the ISM risk-management framework and should be addressed through the approved Safety Management System.

It did not establish a separate cyber certificate, and the obligation cannot be satisfied merely by stating that the company “complies with MSC.428.”

The operational instrument to read today is MSC-FAL.1/Circ.3/Rev.4.

It carries forward a significantly stronger framework than the one against which many early maritime cybersecurity policies were developed:

  • A formal governance function.
  • A designated accountable person or entity.
  • Controls described as minimums.
  • Identification of onboard systems and dependencies.
  • IT and OT network segmentation.
  • Supply-chain risk management.
  • Annual basic cybersecurity training.
  • OT-specific competence.
  • Periodic testing through drills and exercises.
  • Incident recording and reporting.
  • Root-cause analysis.
  • Periodic assessment of effectiveness.
  • Protection of cyber risk-management documentation.

The bar in 2026 is not the existence of documentation. It is demonstrable implementation.

The ISM framework places particular weight on objective evidence and on the effective and systematic operation of the company’s management system. Companies most exposed are therefore not necessarily those without a cybersecurity policy.

They are the companies with a detailed policy, a valid DOC and insufficient evidence that the policy is understood, resourced, followed, tested and improved across their shore organisation and fleet.

The IMO’s development of a non-mandatory Maritime Cyber Code will bring another stage of maturity to this framework.

Companies that have genuinely integrated cyber risk into their Safety Management Systems will be able to absorb that development as an evolution. Companies that have built only a compliance artefact may eventually find themselves rebuilding their arrangements under audit, regulatory, contractual or incident-driven pressure. On someone else’s timeline.


Sources

This article draws primarily on the following official instruments, regulatory documents and recognized industry publications:

  • IMO Resolution MSC.428(98), Maritime Cyber Risk Management in Safety Management Systems, adopted 16 June 2017.
  • MSC-FAL.1/Circ.3/Rev.4, Guidelines on Maritime Cyber Risk Management, issued 28 May 2026.
  • MSC-FAL.1/Circ.3/Rev.3, Guidelines on Maritime Cyber Risk Management, issued 4 April 2025.
  • The International Safety Management Code and SOLAS chapter IX.
  • IMO Resolution A.1188(33), 2023 Guidelines on Implementation of the International Safety Management (ISM) Code by Administrations, adopted 6 December 2023.
  • IACS Unified Requirement E26 Rev.1, Cyber Resilience of Ships.
  • IACS Unified Requirement E27 Rev.1, Cyber Resilience of On-Board Systems and Equipment.
  • Consolidated IACS Recommendation No. 166 on Cyber Resilience.
  • IACS Recommendation No. 41 Rev.5, Guidance for Auditors to the ISM Code, October 2019.
  • Report of the Facilitation Committee on its fiftieth session (FAL 50/20), including the road map for the approval of the Maritime Cyber Code.
  • IMO meeting outcomes for MSC 108, MSC 110, FAL 49 and MSC 111.
  • US Coast Guard Work Instruction CVC-WI-027(3), Vessel Cyber Risk Management Work Instruction, 11 October 2023.
  • The US Coast Guard final rule, Cybersecurity in the Marine Transportation System, published 17 January 2025 and effective 16 July 2025.
  • The Guidelines on Cyber Security Onboard Ships, Version 5, published 14 November 2024.
  • Directive (EU) 2022/2555 (NIS2).
  • IAPH cybersecurity and cyber-resilience guidance.
  • IMO Resolution A.1188(33), 2023 Guidelines on Implementation of the International Safety Management (ISM) Code by Administrations, adopted 6 December 2023.
  • IACS Recommendation No. 41 Rev.5, Guidance for Auditors to the ISM Code, October 2019.
  • US Coast Guard Work Instruction CVC-WI-027(3), Vessel Cyber Risk Management Work Instruction, 11 October 2023.

No commercial relationship exists with any vendor, classification society or organisation referenced in this article.

Publicly documented Port State Control detentions arising specifically and exclusively from cyber-related ISM findings could not be reliably verified in the open record at the time of writing, and no such claim is made.


Maritime Cyber Insights is an independent series of articles and posts examining the regulatory, operational, and strategic dimensions of cyber risk across the global maritime industry. It is published by Alexandros Engelen, a Cybersecurity Strategist specializing in maritime cyber risk, with a focus on helping shipping companies, maritime stakeholders, and decision-makers understand how cyber obligations translate into practical risk management.