IACS UR E26 Ship-Level Cyber Resilience + UR E27 On-Board Systems & Equipment

IACS E26 / E27 Cyber Readiness Assessment Tool

Screen project readiness for IACS UR E26 Rev.1 and UR E27 Rev.1 without treating a self-assessment score as class approval. Simple mode scores ten high-level readiness domains. Advanced mode separates ship-level E26 control families from E27 supplier/equipment evidence, applicability and survey-readiness artifacts.

Data type
↑
Need E26 ship-integration controls and E27 supplier evidence separated? Click Advanced above.Advanced also screens Rev.1 applicability from the contract date and vessel category. Warships/troopships are treated as non-mandatory guidance under the IACS UR scope, not as mandatory E26/E27 applicability.

10-Domain Cyber Readiness Screen

Select the current maturity state for each domain. These are Ship Universe screening categories mapped to the intent of E26/E27, not official IACS paragraph scores.

Scope & CBS / OT inventory
Network architecture, zones & interfaces
Access control & authentication
Remote access & external connectivity
System hardening, malware & removable media
Software updates / patch governance
Monitoring, logging & attack detection
Incident response & isolation
Backup, recovery & restoration
E27 supplier / equipment cyber evidence

Applicability & Project Basis

Rev.1 is uniformly implemented for covered ships contracted on or after 1 July 2024.
Proprietary project target, not an IACS pass mark.
Planning count only.

E26 Ship-Level Control Families

Fixed screening families cover identification, protection, detection, response and recovery across the integrated ship. Each maturity dropdown is a Ship Universe planning score.

System scope, asset identification & ownership Identify
Network architecture, zones, conduits & external interfaces Identify
Identity, authentication, authorization & least privilege Protect
Remote access, shore/vendor connectivity & session control Protect
Hardening, malware protection & removable-media controls Protect
Secure configuration, change control & software updates Protect
Security logging, monitoring & anomaly/event detection Detect
Alarm handling, event escalation & cyber incident detection Detect
Incident response, isolation & degraded-mode procedures Respond
Backup, restore, recovery images & configuration recovery Recover
Cyber resilience verification / test evidence Recover
As-built documentation, handover & lifecycle maintenance basis Recover

E27 On-Board System / Equipment Register

Use one row per supplier/system family. System names are excluded from Tool Data and results. Criticality weighting is proprietary and does not represent IACS risk classification.

System / equipmentQtyCriticality weightSupplier cyber evidence %Secure development / hardening %Auth / access control %Logging / monitoring %Update / recovery %Network / interface protection %

Survey / Verification Readiness

Readiness screen only: this tool does not determine class compliance, issue an IACS/recognised-organisation finding, replace the applicable class rules, or prove that a computer-based system is cyber resilient. Final applicability, evidence, testing, acceptance and survey requirements are determined by the selected IACS member society and the project-specific rule set.
By the ShipUniverse Editorial Team — About Us | Contact