IACS UR E26 and E27 · Maritime Cyber Resilience · Evidence & Implementation Kit
Meet the IACS cyber-resilience requirements for new ships, without decoding E26 and E27 into a control set yourself.
Every E26 ship-level and E27 equipment-level requirement handed to you as an adopt-ready control, from the asset inventory and network protection through incident recovery and equipment security capabilities, with the evidence a class survey examines.
Class-ready in a weekend, not a build program.
Here is the honest situation. Ships contracted for construction on or after 1 July 2024 must meet the IACS cyber-resilience requirements, E26 at the ship level and E27 at the equipment level, and classification societies survey for them. E26 spans the Cybersecurity Framework functions, identify, protect, detect, respond, recover, and splits responsibility across the shipowner, integrator and suppliers. E27 sets IEC 62443-style security capabilities on the equipment itself. Building all of that into controls, documentation and survey evidence is a real program, and a missing asset inventory or incident recovery plan is exactly what holds up class approval.
This Kit removes that decode. It is every E26 and E27 requirement written as an adopt-ready control you personalize in a weekend, with the evidence a class survey examines.
What you get, the moment you buy
33
Requirements as adopt-ready controls. Every E26 ship-level and E27 equipment-level requirement, from the asset inventory and network protection through detection, recovery and equipment security capabilities, written so you personalize and apply it.
33
Evidence-they-examine checklists. For each requirement, exactly what a class survey examines, plus where new-build cyber requirements are missed, so you close it before commissioning.
1
Maritime Cyber Control Matrix, pre-built. Every requirement in a working spreadsheet, ready to record status and evidence location, split by shipowner and supplier responsibility.
1
Gap & Readiness Assessment. Score each requirement and the workbook returns your readiness as a single percentage, and exactly what to fix next.
Grounded in IACS UR E26 (ship cyber resilience) and E27 (on-board systems and equipment), aligned to the Cybersecurity Framework and IEC 62443, in force for ships contracted for construction on or after 1 July 2024. Editable Word and Excel files.
Two levels, one program: the ship and the equipment
E26 governs the ship as a whole; E27 governs the security capabilities of each on-board system. They interlock, and a supplier that meets E27 still needs the ship-level E26 controls around it. This Kit builds both, split by responsibility, so nothing falls between the shipowner and the suppliers.
What one control looks like
This is the asset inventory of computer-based systems, where E26 compliance begins. All 33 are built to this depth.
E26-1 Asset inventory of computer based systems IDENTIFY
Meet this requirement
[Shipowner] shall compile and maintain a vessel asset inventory that records every in-scope computer based system covering operational technology and information technology, capturing for each system its function, manufacturer, category, software and firmware versions, network interfaces, and whether it connects to untrusted networks, and shall keep the inventory current across the design, construction, commissioning, and operational phases of the ship.
Class note.
The asset inventory is the foundational E26 document and the reference point for zone definition, testing scope, and survey verification.
Evidence class survey examines
- Vessel asset inventory register listing every CBS with OT/IT classification and version data
- System topology or network architecture diagram cross-referenced to inventory entries
- Change record showing inventory updates following equipment replacement or software update
- Classification of each system by exposure to untrusted networks
Common finding they raise: OT and safety systems are often omitted from IT-oriented asset registers, and firmware versions on embedded controllers are rarely tracked.
Why this is not another template pack
- The evidence is the point. A cyber requirement you cannot evidence holds up class. This tells you exactly what a class survey examines and where new-build requirements are missed, for every control.
- Ship and equipment, split by role. E26 ship-level and E27 equipment-level controls are separated and tagged by shipowner or supplier responsibility, so the split that causes gaps is made explicit.
- Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
- It compounds. E26 aligns with the Cybersecurity Framework and E27 with IEC 62443, so this work feeds a broader OT and maritime security program.
Who buys this
Shipyards, shipowners, integrators and equipment suppliers building ships subject to the IACS cyber requirements, plus the class, cyber and OT leads who own compliance. Whether it is a first new-build or a fleet program, you save a build cycle and walk in with the controls and survey evidence structured.
By the end of the weekend you will have
✓ An adopt-ready control for all 33 requirements
✓ A completed maritime cyber control matrix
✓ The evidence a class survey examines
✓ Your shipowner and supplier responsibilities split
✓ A readiness percentage and a fix list
✓ The common new-build gaps designed out
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
Who must comply? Ships contracted for construction on or after 1 July 2024 must meet E26 and E27. This Kit covers both the ship level and the equipment level.
What is the difference between E26 and E27? E26 governs the cyber resilience of the ship as a whole; E27 sets security capabilities on individual on-board systems and their suppliers. Both are covered.
Does it align with IEC 62443? Yes. E27 equipment security capabilities follow the IEC 62443 foundational requirements, and the Kit reflects that.
What if it is not for me? A 30-day money-back guarantee.
Do not decode two maritime cyber URs by hand.
Every E26 and E27 requirement is fast to adopt with the Kit. It is instant, and it is guaranteed.
Add it to your cart and be class-ready this weekend.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com