You are currently viewing Maritime Cyber Compliance Is Not a Vessel-Type Exercise

Maritime Cyber Compliance Is Not a Vessel-Type Exercise

A recurring question surfaces in fleet reviews and board-level risk discussions: Which cyber requirements apply to my ships?

It is almost always asked in terms of vessel type. As though a tanker, a bulk carrier and a passenger ferry each carry a distinct cyber rulebook. They do not. The instinct is understandable, because so much of maritime regulation is stratified by ship type, but for cyber risk it produces a misread of where the obligations actually sit. Owners who scope their exposure by hull category tend to over-engineer for some vessels and leave material gaps on others.

The reality is that maritime cyber obligations attach to a different set of variables:

  • the flag a ship flies
  • its gross tonnage and voyage type
  • its build date
  • the jurisdictional footprint of the operating company
  • [for a growing share of the commercial fleet] the vetting regimes a vessel must satisfy to earn employment.

Vessel type modifies this picture at the edges, sometimes sharply. But it is not the organising principle. Understanding that distinction is the difference between a defensible compliance posture and a matrix full of false confidence.

This article maps the obligations that reach the whole commercial fleet, then isolates the points where vessel type genuinely changes what an owner must do.

The horizontal layer

The following instruments land on essentially every commercial vessel a shipowner operates, keyed not to type but to flag, tonnage and trade.

Article content
Maritime cyber compliance is built across the fleet, not around vessel type.
  1. IMO Resolution MSC.428(98) and the ISM Code. This is the anchor. Adopted in June 2017, the resolution directs administrations to ensure that cyber risks are addressed within the Safety Management System, as defined by the ISM Code, no later than the first annual Document of Compliance verification after 1 January 2021. The resolution is not, in itself, a mandatory instrument. Its force comes from the linkage to the ISM Code under SOLAS Chapter IX: cyber risk management becomes an effective condition of the company’s Document of Compliance and each ship’s Safety Management Certificate. This is the obligation that reaches every ISM-regulated vessel in a fleet, and it is verified, not merely encouraged.
  2. IMO Guidelines MSC-FAL.1/Circ.3/Rev.3. The current high-level guidance. Revision 3 was approved by the Maritime Safety Committee at its 108th session in May 2024 and issued in April 2025. It is materially more current than its predecessor: it now references IACS Unified Requirements E26 and E27 as recommended standards and aligns with version 2.0 of the National Institute of Standards and Technology (NIST) Cybersecurity Framework. The guidance remains non-mandatory, but it defines what “adequate” cyber risk management looks like when a flag or port State assesses SMS compliance. Treating it as optional is a misjudgement of how it is used in practice.
  3. IACS Unified Requirements E26 and E27. These apply to ships contracted for construction on or after 1 July 2024. UR E26, “Cyber Resilience of Ships,” addresses the vessel as an integrated system; UR E27, “Cyber Resilience of On-Board Systems and Equipment,” addresses individual computer-based systems and pushes obligations onto equipment suppliers. The original versions, carrying a 1 January 2024 application date, were withdrawn and superseded. One feature of the revised requirements matters directly to any type-based analysis: applicability is categorised as mandatory or non-mandatory depending on vessel type and size, a deliberate accommodation for smaller and non-conventional vessels. This is the one place in the horizontal layer where type is written into the instrument itself.
  4. EU Cyber Resilience Act. A further supplier-side development to watch is the EU Cyber Resilience Act. It does not regulate a ship as such, but it will increasingly affect the manufacturers and suppliers of connected software, hardware and digital products placed on the EU market. For maritime owners, its practical importance will sit in procurement, lifecycle support, vulnerability handling and supplier assurance.
  5. Classification society cyber rules. Each IACS member operationalizes E26 and E27 through its own class notations: DNV’s Cyber Secure, ABS’s CyberSafety, and the equivalent frameworks from Bureau Veritas, Lloyd’s Register and ClassNK. For an owner, these function as class conditions attached to newbuildings and, increasingly, to retrofits and voluntary notations on existing tonnage.
  6. Flag State requirements. Every flag transposes the International Maritime Organization framework into national law, and some legislate beyond it. The obligation an owner actually carries therefore varies by flag, and a mixed-flag fleet carries a correspondingly mixed obligation set. This is best treated as a per-flag variable rather than a constant.
  7. The NIS2 Directive (EU 2022/2555). This attaches to the relevant organisation and service, not to the individual hull. In maritime, NIS2 sits within the transport sector and covers inland, sea and coastal passenger and freight water transport companies, port managing bodies including port facilities and entities operating works and equipment within ports, and operators of Vessel Traffic Services. Crucially, the Directive expressly excludes the individual vessels operated by those water transport companies. This is a key distinction for shipping groups: NIS2 captures the relevant legal entity and service, not the ship itself. The directive applies broadly to medium-sized and larger entities under the EU SME Recommendation, subject to national implementation and specific NIS2 exceptions; smaller operators may still be captured where, for example, they are the sole provider in a Member State of a service essential to critical societal or economic activity, or where disruption could create significant public-safety, public-security, public-health, systemic or cross-border impact. Obligations include structured cyber-risk management, supply-chain security, incident handling, business continuity, backup and disaster recovery, vulnerability handling, access control, asset management, cyber hygiene, management-body oversight and training, and a staged incident-reporting regime: an early warning within 24 hours, an incident notification within 72 hours, and a final report generally within one month. Transposition was due on 17 October 2024. As of July 2026, the European Commission has referred Ireland, Spain, France and the Netherlands to the Court of Justice of the European Union for failing to notify full transposition, so the practical obligation must be checked against the national implementing law in each Member State where the relevant maritime entity is established or provides in-scope services.
  8. The USCG rule on Cybersecurity in the Marine Transportation System. Codified at 33 CFR 101.600 et seq. and effective 16 July 2025, this applies to U.S. flagged vessels, Outer Continental Shelf facilities, and facilities regulated under the Maritime Transportation Security Act. Implementation is phased: reportable cyber incidents must go to the National Response Center immediately from the effective date; personnel training under 33 CFR 101.650 is required by 12 January 2026 and annually thereafter; and Cybersecurity Officer designation, a Cybersecurity Assessment, and submission of a Cybersecurity Plan are required by 16 July 2027. Foreign-flag owners should not read this as direct application of the USCG cyber rule. Subpart F expressly excludes foreign-flagged vessels subject to 33 CFR Part 104. The practical exposure is different: foreign-flagged vessels calling at U.S. ports may still face Port State Control scrutiny where weak cyber-risk management indicates poor implementation of the ISM Code or a deficient Safety Management System. In other words, the rule does not directly regulate every foreign-flagged vessel trading to the United States, but it raises the inspection and deficiency risk for owners whose cyber controls cannot withstand ISM-based scrutiny.
  9. Industry guidance and commercial obligations. Not regulation, but enforced through the market with comparable effect. The BIMCO and International Chamber of Shipping Guidelines on Cyber Security Onboard Ships [version 5, published at the end of 2024] is the “de facto” SMS reference. On the commercial side, charterer and vetting regimes now embed cyber requirements that are, for many owners, more operationally binding than the statutory floor: OCIMF’s SIRE 2.0 for tankers and RightShip for dry bulk both make cyber posture a condition of employment.

Where vessel type genuinely changes the picture

Against that horizontal baseline, type-specific factors alter the obligation set in identifiable ways. The following matrix isolates them.

Article content
Vessel type modifies cyber obligations. It does not define them.

The pattern is consistent. Passenger ships attract heightened obligation through life-safety exposure and universal ISM applicability. Tankers and bulk carriers pick up their most binding cyber requirements not from statute but from vetting. Offshore units are named directly in U.S. regulation. And the smallest vessels [the segment most likely to be assumed out of scope entirely] are handled explicitly by the E26 and E27 scoping and may still be reached through the operating company under NIS2. Type matters. It simply does not organise the framework.

Scoping a fleet correctly

Article content
Correct scoping turns maritime cyber compliance from assumption into evidence.

In complex shipping structures, the first scoping exercise should identify the relevant legal entity: registered owner, Document of Compliance holder, technical manager, operator, bareboat charterer, port operator, Vessel Traffic Services operator or group parent. Cyber obligations often attach to the entity performing the regulated service, not simply to the asset-owning company.

For any individual hull, the applicable obligation set is a product of five variables. The flag determines which IMO transposition and any national additions apply. Gross tonnage and voyage type determine whether the ISM and ISPS regimes engage at all. The shipbuilding contract date determines whether IACS UR E26 and E27 apply, since the revised requirements apply to ships contracted for construction on or after 1 July 2024. The company’s EU establishment, size, role and criticality determine whether NIS2 applies and whether the entity is treated as essential or important under national implementing law. And the U.S. nexus [whether by U.S. flag, OCS operation, MTSA-regulated facility, or foreign-flag calls at U.S. ports exposed to Port State Control scrutiny] determines the direct or practical reach of the Coast Guard framework.

A defensible maritime cyber compliance file should not only list applicable regulations. It should contain evidence: the SMS cyber-risk procedure, vessel IT/OT asset inventory, remote-access register, backup and restore records, crew familiarisation records, incident escalation matrix, supplier access controls, class/newbuilding cyber documentation, and vetting responses for SIRE 2.0 or RightShip where applicable. In practice, this is what turns cyber compliance from a policy statement into something that can survive audit, inspection or charterer review.

Run those five variables across a fleet and the picture collapses into something far more precise than a hull-by-hull rulebook. Two sister ships under different flags can carry different obligations; a newbuilding and an existing vessel of identical type will diverge on E26 and E27; and a modest coastal operator with a critical port role can fall within NIS2 while a larger deep-sea owner structured differently may face a different classification or obligation set. This is why type-based scoping fails: it holds the wrong variable constant.

The trajectory

The direction of travel is toward convergence. MSC-FAL.1/Circ.3/Rev.3 now points explicitly at the IACS Unified Requirements and at NIST CSF 2.0, drawing the IMO guidance, class rules and a recognised control framework into closer alignment. NIS2 and the USCG rule both introduce something the IMO framework has historically lacked: enforceable incident reporting on defined timelines, and [in the case of NIS2] personal accountability at senior-management level. The regulatory floor is rising, and it is rising fastest where operational technology, supply-chain dependency and shore integration are densest. Those are themes that recur across the threat landscape rather than attaching to any single class of vessel, which is precisely why the obligation framework is moving away from type-based logic and toward a posture assessed at the level of systems, company and trade.

For owners, the practical implication is straightforward. Scope by the variables that actually govern [flag, tonnage, trade, build date and jurisdictional nexus] and treat vessel type as a modifier rather than the map. A compliance matrix built the other way round will look complete and still leave the fleet exposed.


Maritime Cyber Insights is an independent series of articles and posts examining the regulatory, operational, and strategic dimensions of cyber risk across the global maritime industry. It is published by Alexandros Engelen , a Cybersecurity Strategist specializing in maritime cyber risk, with a focus on helping shipping companies, maritime stakeholders, and decision-makers understand how cyber obligations translate into practical risk management.


Sourcing: This analysis draws on primary and authoritative sources including IMO Resolution MSC.428(98) and Guidelines MSC-FAL.1/Circ.3/Rev.3; IACS Unified Requirements E26 and E27 and associated IACS press material; Directive (EU) 2022/2555 (NIS2) and European Commission and ENISA guidance; the U.S. Coast Guard final rule on Cybersecurity in the Marine Transportation System (33 CFR 101.600 et seq.; 90 Fed. Reg. 6298); the ISM and ISPS Codes under SOLAS; and the BIMCO/ICS Guidelines on Cyber Security Onboard Ships (v5). Regulatory positions current as of publication; NIS2 national transposition and the USCG U.S.-flag implementation timeline remain in movement and should be verified against the primary texts for any specific jurisdiction.