IACS UR E26/E27IndustrialGlobalMaritime Industrial / Mining

IACS Unified Requirements for Cyber Resilience

International Association of Classification Societies requirements for cyber security of ships and offshore units. Applies to computer-based systems in heavy equipment and maritime operations.

Get a Gap Assessment
The Mapping

What your auditor cites,
and what produces the evidence

The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.

IACS UR E26/E27E26 §5.1A record of access

Security Event Logging

Computer-based systems MUST log security-relevant events for forensic investigation.

A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.

IACS UR E26/E27E27 §4.3Least privilege and privileged useA record of access

Access Control

REQUIRES implementation of access controls with audit logging for OT systems.

Authorisation is configured in the database; proving it holds is what this requirement actually needs. Vulnerability scanning surfaces excessive privilege and role sprawl, default and weak credentials, and stale or orphaned accounts — including privilege inherited through nested roles, which is where least-privilege reviews usually go wrong. Real-time SQL auditing then shows which of those grants were exercised, so an access review reflects observed use rather than intent.

IACS UR E26/E27E26 §5.3Integrity of the record

Log Integrity

Log integrity MUST be verified by classification society surveyor during inspections.

A requirement like this is about the record surviving the person who would rather it did not, which means the audit trail has to be protected as carefully as the data. File activity monitoring hashes the datafiles, the transaction logs, the backups, and the audit trail itself with XXH3, then baselines them — so an alteration or a deletion is evident rather than inferred, and it is attributed to the session and OS user behind it. Because the same platform holds the query trail, a destructive statement and the file-level change it produced are two views of one event rather than two investigations.

IACS UR E26/E27E27 §5.1Routing and evidencing the response

Incident Response

Organizations MUST have incident response procedures with forensic evidence preservation.

Findings route by severity to Slack, Teams, email, PagerDuty, or your SIEM, and escalate automatically when nobody acknowledges them and again when nobody resolves them. Every alert arrives with the query, the identity, and the data classification already attached, so the response starts with context rather than with an investigation. The acknowledge-to-resolve history is retained, which is what evidences that the procedure was followed. Your ticketing system stays where it is — what this produces is a finding worth opening a ticket for.

What IACS UR E26/E27 covers

This instrument defines no data category of its own. Governs onboard computer-based SYSTEMS on new-build vessels, through classification. The unit is the system and its criticality.

How IACS UR E26/E27 is enforced

Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The classification society, at plan approval and survey.

A scheme rule or contract, not law. Enforced by the counterparty.

UR E26 and E27 are unified requirements applied by IACS member societies to new-build vessels and their onboard systems. They are enforced through classification: a design that does not meet them does not get approval, and a vessel without class cannot be insured or, in practice, chartered.

These apply on a contractual date basis to new construction, so whether they bind depends on the contract date of the vessel.

Uncapped exposure that sits outside this instrument

These come from company law rather than from IACS UR E26/E27, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.

Duty of oversight

Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.

Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.

Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.

This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.

In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).

Enforcement data reviewed August 2026. Several figures are indexed annually and move.

Ships With It

Built for IACS UR E26/E27,
not configured for it afterwards

Policy Template

Maritime Industrial Monitoring

Log access to vessel and offshore unit control systems

Report

IACS Survey Evidence

Log integrity documentation for class surveyor verification

Classification

Maritime OT Data

Identify DP systems, cargo handling, and industrial control data

Alert

OT System Access Alert

Alert on unauthorized access to maritime industrial systems

Walk into the IACS UR E26/E27 audit knowing the answer

228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.

Get a Gap Assessment