IACS E27 Procurement Checklist: 15 Cybersecurity Questions to Ask Before Installing Any Connected Marine Equipment

Connected marine equipment now needs a cyber file before it reaches the ship
I would treat IACS E27 as a procurement filter, not a paperwork exercise. The practical shift is that cyber resilience is no longer only a ship-level network discussion. It now reaches the equipment quote itself: propulsion controls, power-management systems, battery systems, steering controls, fire systems, navigation equipment, communications gear, cargo controls, DP systems, sensors, gateways, and any connected device that can affect safety, operation, or environmental protection.
E27 changes the buyer’s job before installation
The most important procurement change is simple: a connected marine system is no longer just judged by function, price, lead time, and brand support. It is also judged by whether the supplier can prove cyber resilience at the equipment level. That proof may include an asset inventory, topology diagrams, security capability descriptions, test procedures, secure configuration guidance, secure development lifecycle records, maintenance and verification plans, incident-response support information, and change-management procedures.
For owners, this makes procurement more technical but also more useful. The checklist below is designed to stop weak systems before they are installed, not after the shipyard, class surveyor, integrator, and crew are already trying to make them fit.
Add an E27 evidence schedule to every RFQ for connected marine equipment. Make suppliers state whether the system is type approved, approval-ready, outside scope, or dependent on a ship-specific approval path.
Owners budget hardware and installation, then underbudget topology documents, cyber testing, hardening, patch support, remote-access controls, class comments, security-zone changes, and onboard commissioning evidence.
A supplier that cannot explain asset inventory, network interfaces, hardening, audit logs, updates, recovery, and change management may not be ready for connected equipment procurement under E27 expectations.
The best E27 conversation happens before the purchase order. After installation, missing cyber evidence becomes a schedule problem.
Equipment categories that deserve E27 screening
Owners should screen more than obvious “IT” systems. Many safety and control systems are now computer-based, networked, remotely supported, software-maintained, or connected to shipboard data platforms.
| Equipment area | Typical connected systems | E27 procurement risk | Buyer should request | Late-stage pain point | Priority |
|---|---|---|---|---|---|
| Propulsion and machinery | Engine control, remote control, CPP, electric propulsion, machinery alarm and monitoring | Unsafe configuration, weak remote support, poor recovery path | Security capability file and recovery support package | Class comments during commissioning | Very high |
| Steering and maneuvering | Steering controls, azimuth thrusters, waterjets, heading control | Control-system disruption affects vessel safety | Access control, alarm handling, network boundary evidence | Integration conflicts with bridge systems | Very high |
| Power and batteries | PMS, generator controls, converters, battery management, switchboard communications | Cyber fault can affect blackout prevention or hybrid operation | Topology, interface list, hardening and update policy | Unexpected network-zone redesign | Very high |
| Fire and safety systems | Fire detection, fixed suppression, gas detection, emergency shutdown, alarm systems | Safety function can be impaired or incorrectly operated | Test procedures and incident-response support information | Survey delay due to missing test evidence | Very high |
| Navigation and bridge | Radar, AIS, VDR, ECDIS, GNSS, BNWAS, speed log, heading devices | Bridge data integrity and interface trust become unclear | Interface protocols, security boundary and hardening instructions | Vendor blame between bridge devices | High |
| Cargo and ballast | Loading computer, ballast valve control, cargo monitoring, inert gas, reliquefaction, tank monitoring | Cargo safety, stability or environmental protection can be affected | Asset inventory, topology, access policy and change-control plan | Operational limits until evidence is complete | Very high |
| Communications and data | GMDSS interfaces, satellite routers, data gateways, remote support systems | Untrusted networks touch safety-adjacent systems | Zone boundary, firewall, protocol and remote-access documentation | Cyber review expands beyond original scope | High |
| DP and offshore systems | Dynamic positioning, motion reference, sensor networks, vessel management systems | Availability and integrity failures can create immediate operational risk | Secure configuration, test evidence and recovery plan | Client vetting or class objections | Very high |
Ask these before installing any connected marine equipment
These questions are written for owners, technical superintendents, yards, system integrators and procurement teams that need practical buying language.
Does this system fall within the E27 equipment scope or a protected security zone?
Do not let the supplier answer only with “it is not IT.” Many covered systems are OT, safety, navigation, communications, electrical, cargo or machinery systems. The buyer needs a scope determination tied to the vessel, network zone and operational consequence.
Is the product type approved, approval-ready or ship-specific only?
Type approval can reduce project friction, but it does not remove every integration question. Ship-specific approval may still require more documentation, testing and survey time. Buyers should know which path they are paying for before award.
Can the supplier provide a complete computer-based system asset inventory?
Owners cannot protect, patch or recover equipment they cannot identify. The asset inventory should include hardware, software, firmware, network devices, virtual components, communication paths and dependent components where relevant.
Will the quote include topology diagrams and data-flow maps?
A connected device is part of a shipboard system. The buyer needs to see which devices connect to which networks, which protocols are used, which systems exchange data and which boundaries separate trusted and untrusted networks.
Which security capabilities are built into the system?
Cyber resilience should not depend only on the ship network protecting a weak product. The equipment should have defined security features such as access control, authentication, logging, session control, secure configuration, boundary protection or secure update capability, depending on system role.
Are user accounts, roles and service access controlled?
Shared passwords, unmanaged service accounts and permanent vendor access are still common weak points. A connected marine system should support clear roles, least-privilege access, account removal, password policy and controlled maintenance access.
Does the equipment generate and preserve useful audit records?
Logs matter during troubleshooting, class review, incident response and insurance review. The issue is not only whether logs exist. Buyers need to know which events are recorded, how long records are stored, who can read them and whether they can be exported without vendor intervention.
Is there a secure configuration and hardening guide for the ship?
A system can be compliant in the lab and weak onboard if defaults remain unchanged. The owner needs a hardening guide that the shipyard, integrator, commissioning engineer and crew can follow.
Who owns security updates, dependent software updates and patch timing?
Connected equipment often depends on operating systems, libraries, controllers, databases, vendor tools or third-party software. The buyer needs a patch policy that fits ship operation, class expectations and safe maintenance windows.
Does the supplier have a vulnerability disclosure and correction process?
The system’s cyber condition will change after delivery. Owners need to know how the supplier receives vulnerability reports, evaluates severity, alerts customers, issues fixes and handles products approaching end of support.
Is remote support controlled, logged and removable?
Remote support is useful, but unmanaged remote access can create serious risk. The owner should avoid permanent vendor tunnels, unknown cloud relays, shared credentials or remote tools that bypass the vessel’s access-control process.
Can the system be restored safely after cyber failure or configuration damage?
Recovery is often missing from procurement. The buyer needs a defined method for restoring configuration, software, firmware, user settings and safe operating status after a failed update, malware event, accidental change or hardware replacement.
Is there a management-of-change plan for software, hardware and configuration drift?
Marine equipment changes during commissioning, warranty service, software updates, vessel handover and crew turnover. Without change control, an approved cyber state can drift quietly.
Will the supplier demonstrate security functions during commissioning or survey?
Paper claims are not enough. Security capabilities need test procedures and evidence. The owner should know which tests are completed at factory acceptance, harbor acceptance, sea trial, class survey and final handover.
Will the owner receive an operation-ready cyber evidence pack?
The end of installation should not leave the owner chasing documents. The handover package should help the owner maintain the system, respond to incidents, satisfy audits and support future upgrades.
A cleaner procurement sequence before the equipment arrives onboard
The strongest owners make the cyber approval path visible before the yard begins installation.
Scope the system
Confirm whether the equipment is safety-relevant, connected to an applicable security zone, or dependent on other onboard computer-based systems.
Check approval status
Separate type approved, approval-ready, previously approved on a sister vessel, and full ship-specific documentation cases.
Collect the evidence pack
Request inventory, topology, security capabilities, testing, hardening, secure development, maintenance, incident support and change-control documents.
Test before handover
Verify security functions, correct configuration, remote access, logging, update behavior, backup, restore and incident-response support.
Keep the cyber state alive
Add patching, vulnerability notices, configuration drift, spares, remote support, supplier lifecycle status and audit exports to the vessel’s maintenance routine.
E27 procurement separates good vendors from document-light vendors
The best supplier does not only deliver a working system. It delivers a system that can be approved, maintained, recovered and defended.
| Buyer demand | Weak supplier answer | Strong supplier answer | Owner risk if ignored | Evidence to request | Priority |
|---|---|---|---|---|---|
| Approval status | Compliant with cyber rules | Type approved or clear approval path with scope and exclusions listed | Late approval delay and extra class comments | Certificate, scope, revision and gap list | Very high |
| Asset visibility | Standard bill of materials | Computer-based system asset inventory with software, firmware and dependencies | Patch and recovery blind spots | Asset inventory and lifecycle statement | Very high |
| Network evidence | Connects via Ethernet | Topology, data flows, protocols, trusted and untrusted interfaces documented | Security-zone redesign after installation | Topology and protocol map | Very high |
| Secure configuration | Factory default setup works | Hardening guide, disabled services, account policy and commissioning checklist | Approved system installed in a weak configuration | Security configuration guide | High |
| Update support | Updates available when needed | Patch policy, dependency policy, delivery route, rollback and support interval | Unpatched systems or unsafe updates at sea | Security update documentation | High |
| Remote access | Vendor can support remotely | Approved, logged, time-limited access with disable method and MFA where appropriate | Persistent backdoor into vessel systems | Remote-access procedure | Very high |
| Security testing | Tested by supplier | Security capability test procedure and signed test evidence supplied | Security features fail when needed | Test plan and signed report | Very high |
| Recovery support | Vendor can restore if required | Documented backup, restore, rebuild, clean media and post-recovery test process | Long downtime after cyber or configuration event | Recovery procedure and spare-media policy | High |
| Change control | Changes handled case by case | Management-of-change plan with configuration baseline and approval triggers | Cyber state drifts after commissioning | MoC plan and baseline file | High |
IACS E27 Procurement Readiness Scorecard
Use this planning tool to screen whether a connected marine equipment quote is approval-ready or still missing critical cyber procurement evidence.
This scorecard is a planning aid. Final E27 decisions should be aligned with the vessel’s class society, shipyard, system integrator, flag expectations, owner cyber-management program, and supplier approval status.
E27 turns connected equipment into a lifecycle obligation
Owners should not think of E27 as a one-time certificate request. The procurement decision should cover the whole equipment lifecycle: factory configuration, onboard integration, security testing, handover, maintenance, patching, vulnerability notices, remote support, change control and recovery.
Apply the checklist to one high-risk equipment purchase such as PMS, BMS, engine control, ECDIS, cargo monitoring, DP or gas detection, then use the evidence schedule as a template across the fleet.
Do not buy connected marine equipment until the supplier proves both function and cyber supportability: inventory, topology, security capabilities, hardening, updates, remote access, recovery and test evidence.
Track connected systems by approval status, missing documents, open class comments, unsupported software, unmanaged remote access, patch exposure, recovery readiness and change-control maturity.
IACS E27 makes supplier evidence part of the connected equipment purchase. The stronger the evidence before installation, the fewer surprises during class review, commissioning, cyber audit and vessel operation.
We welcome your feedback, suggestions, corrections, and ideas for enhancements.
Please click here to get in touch