IACS E27 Procurement Checklist: 15 Cybersecurity Questions to Ask Before Installing Any Connected Marine Equipment

Connected marine equipment now needs a cyber file before it reaches the ship

I would treat IACS E27 as a procurement filter, not a paperwork exercise. The practical shift is that cyber resilience is no longer only a ship-level network discussion. It now reaches the equipment quote itself: propulsion controls, power-management systems, battery systems, steering controls, fire systems, navigation equipment, communications gear, cargo controls, DP systems, sensors, gateways, and any connected device that can affect safety, operation, or environmental protection.

Old habit Buy the connected equipment first, then ask IT or the yard to “secure the network.”
E27 buying shift Ask the supplier for cyber evidence, security capabilities, hardening instructions, lifecycle support, and approval-ready documents before purchase.
Owner risk A cheap connected system can become expensive if class comments, network redesign, patch gaps, remote-access issues, or missing test records appear during installation.
Owner readout

E27 changes the buyer’s job before installation

The most important procurement change is simple: a connected marine system is no longer just judged by function, price, lead time, and brand support. It is also judged by whether the supplier can prove cyber resilience at the equipment level. That proof may include an asset inventory, topology diagrams, security capability descriptions, test procedures, secure configuration guidance, secure development lifecycle records, maintenance and verification plans, incident-response support information, and change-management procedures.

For owners, this makes procurement more technical but also more useful. The checklist below is designed to stop weak systems before they are installed, not after the shipyard, class surveyor, integrator, and crew are already trying to make them fit.

Best first move

Add an E27 evidence schedule to every RFQ for connected marine equipment. Make suppliers state whether the system is type approved, approval-ready, outside scope, or dependent on a ship-specific approval path.

Most common budget miss

Owners budget hardware and installation, then underbudget topology documents, cyber testing, hardening, patch support, remote-access controls, class comments, security-zone changes, and onboard commissioning evidence.

Procurement signal

A supplier that cannot explain asset inventory, network interfaces, hardening, audit logs, updates, recovery, and change management may not be ready for connected equipment procurement under E27 expectations.

Commercial takeaway

The best E27 conversation happens before the purchase order. After installation, missing cyber evidence becomes a schedule problem.

Scope filter

Equipment categories that deserve E27 screening

Owners should screen more than obvious “IT” systems. Many safety and control systems are now computer-based, networked, remotely supported, software-maintained, or connected to shipboard data platforms.

Equipment area Typical connected systems E27 procurement risk Buyer should request Late-stage pain point Priority
Propulsion and machinery Engine control, remote control, CPP, electric propulsion, machinery alarm and monitoring Unsafe configuration, weak remote support, poor recovery path Security capability file and recovery support package Class comments during commissioning Very high
Steering and maneuvering Steering controls, azimuth thrusters, waterjets, heading control Control-system disruption affects vessel safety Access control, alarm handling, network boundary evidence Integration conflicts with bridge systems Very high
Power and batteries PMS, generator controls, converters, battery management, switchboard communications Cyber fault can affect blackout prevention or hybrid operation Topology, interface list, hardening and update policy Unexpected network-zone redesign Very high
Fire and safety systems Fire detection, fixed suppression, gas detection, emergency shutdown, alarm systems Safety function can be impaired or incorrectly operated Test procedures and incident-response support information Survey delay due to missing test evidence Very high
Navigation and bridge Radar, AIS, VDR, ECDIS, GNSS, BNWAS, speed log, heading devices Bridge data integrity and interface trust become unclear Interface protocols, security boundary and hardening instructions Vendor blame between bridge devices High
Cargo and ballast Loading computer, ballast valve control, cargo monitoring, inert gas, reliquefaction, tank monitoring Cargo safety, stability or environmental protection can be affected Asset inventory, topology, access policy and change-control plan Operational limits until evidence is complete Very high
Communications and data GMDSS interfaces, satellite routers, data gateways, remote support systems Untrusted networks touch safety-adjacent systems Zone boundary, firewall, protocol and remote-access documentation Cyber review expands beyond original scope High
DP and offshore systems Dynamic positioning, motion reference, sensor networks, vessel management systems Availability and integrity failures can create immediate operational risk Secure configuration, test evidence and recovery plan Client vetting or class objections Very high
15 procurement questions

Ask these before installing any connected marine equipment

These questions are written for owners, technical superintendents, yards, system integrators and procurement teams that need practical buying language.

Scope

Does this system fall within the E27 equipment scope or a protected security zone?

Do not let the supplier answer only with “it is not IT.” Many covered systems are OT, safety, navigation, communications, electrical, cargo or machinery systems. The buyer needs a scope determination tied to the vessel, network zone and operational consequence.

Demand this Supplier scope statement, system description, safety consequence, security-zone relationship and class confirmation route.
Approval

Is the product type approved, approval-ready or ship-specific only?

Type approval can reduce project friction, but it does not remove every integration question. Ship-specific approval may still require more documentation, testing and survey time. Buyers should know which path they are paying for before award.

Demand this Type approval certificate, approval scope, excluded components, revision level, test reports and ship-specific documentation gap list.
Inventory

Can the supplier provide a complete computer-based system asset inventory?

Owners cannot protect, patch or recover equipment they cannot identify. The asset inventory should include hardware, software, firmware, network devices, virtual components, communication paths and dependent components where relevant.

Demand this Asset inventory with model numbers, firmware, software, operating systems, network devices, interfaces and supported lifecycle status.
Topology

Will the quote include topology diagrams and data-flow maps?

A connected device is part of a shipboard system. The buyer needs to see which devices connect to which networks, which protocols are used, which systems exchange data and which boundaries separate trusted and untrusted networks.

Demand this Network topology, data-flow diagram, protocol list, IP plan, physical interfaces, wireless interfaces and external connection points.
Security

Which security capabilities are built into the system?

Cyber resilience should not depend only on the ship network protecting a weak product. The equipment should have defined security features such as access control, authentication, logging, session control, secure configuration, boundary protection or secure update capability, depending on system role.

Demand this Description of security capabilities, system limits, default settings, required external protections and test procedure for each capability.
Accounts

Are user accounts, roles and service access controlled?

Shared passwords, unmanaged service accounts and permanent vendor access are still common weak points. A connected marine system should support clear roles, least-privilege access, account removal, password policy and controlled maintenance access.

Demand this User-role matrix, default account list, service account policy, password requirements, account lockout behavior and credential handover procedure.
Logs

Does the equipment generate and preserve useful audit records?

Logs matter during troubleshooting, class review, incident response and insurance review. The issue is not only whether logs exist. Buyers need to know which events are recorded, how long records are stored, who can read them and whether they can be exported without vendor intervention.

Demand this Audit record list, storage capacity, export method, time-source behavior, access rights, log protection and sample event report.
Hardening

Is there a secure configuration and hardening guide for the ship?

A system can be compliant in the lab and weak onboard if defaults remain unchanged. The owner needs a hardening guide that the shipyard, integrator, commissioning engineer and crew can follow.

Demand this Secure configuration guide, disabled services list, port and protocol policy, firewall needs, backup settings, account settings and commissioning checklist.
Updates

Who owns security updates, dependent software updates and patch timing?

Connected equipment often depends on operating systems, libraries, controllers, databases, vendor tools or third-party software. The buyer needs a patch policy that fits ship operation, class expectations and safe maintenance windows.

Demand this Security update policy, dependent component update policy, update delivery method, test process, rollback plan and maximum support interval.
Vulnerabilities

Does the supplier have a vulnerability disclosure and correction process?

The system’s cyber condition will change after delivery. Owners need to know how the supplier receives vulnerability reports, evaluates severity, alerts customers, issues fixes and handles products approaching end of support.

Demand this Vulnerability handling policy, security bulletin process, severity scale, customer notification route, patch SLA and end-of-life policy.
Remote

Is remote support controlled, logged and removable?

Remote support is useful, but unmanaged remote access can create serious risk. The owner should avoid permanent vendor tunnels, unknown cloud relays, shared credentials or remote tools that bypass the vessel’s access-control process.

Demand this Remote-access architecture, approval workflow, MFA capability, session logging, emergency access rule, disable method and vendor responsibility matrix.
Recovery

Can the system be restored safely after cyber failure or configuration damage?

Recovery is often missing from procurement. The buyer needs a defined method for restoring configuration, software, firmware, user settings and safe operating status after a failed update, malware event, accidental change or hardware replacement.

Demand this Backup and restore procedure, golden configuration, recovery time estimate, spare media policy, offline recovery option and post-restore test procedure.
Change

Is there a management-of-change plan for software, hardware and configuration drift?

Marine equipment changes during commissioning, warranty service, software updates, vessel handover and crew turnover. Without change control, an approved cyber state can drift quietly.

Demand this Management-of-change plan, configuration baseline, approval workflow, version control, test requirement and class notification trigger.
Testing

Will the supplier demonstrate security functions during commissioning or survey?

Paper claims are not enough. Security capabilities need test procedures and evidence. The owner should know which tests are completed at factory acceptance, harbor acceptance, sea trial, class survey and final handover.

Demand this Security capability test procedure, factory test report, onboard test checklist, signed results, failed-test handling and retest rule.
Handover

Will the owner receive an operation-ready cyber evidence pack?

The end of installation should not leave the owner chasing documents. The handover package should help the owner maintain the system, respond to incidents, satisfy audits and support future upgrades.

Demand this Approved documents, certificates, topology, inventory, hardening guide, update policy, recovery plan, access list, test results and crew instructions.
Approval pathway

A cleaner procurement sequence before the equipment arrives onboard

The strongest owners make the cyber approval path visible before the yard begins installation.

Gate 1

Scope the system

Confirm whether the equipment is safety-relevant, connected to an applicable security zone, or dependent on other onboard computer-based systems.

Gate 2

Check approval status

Separate type approved, approval-ready, previously approved on a sister vessel, and full ship-specific documentation cases.

Gate 3

Collect the evidence pack

Request inventory, topology, security capabilities, testing, hardening, secure development, maintenance, incident support and change-control documents.

Gate 4

Test before handover

Verify security functions, correct configuration, remote access, logging, update behavior, backup, restore and incident-response support.

Gate 5

Keep the cyber state alive

Add patching, vulnerability notices, configuration drift, spares, remote support, supplier lifecycle status and audit exports to the vessel’s maintenance routine.

Buyer matrix

E27 procurement separates good vendors from document-light vendors

The best supplier does not only deliver a working system. It delivers a system that can be approved, maintained, recovered and defended.

Buyer demand Weak supplier answer Strong supplier answer Owner risk if ignored Evidence to request Priority
Approval status Compliant with cyber rules Type approved or clear approval path with scope and exclusions listed Late approval delay and extra class comments Certificate, scope, revision and gap list Very high
Asset visibility Standard bill of materials Computer-based system asset inventory with software, firmware and dependencies Patch and recovery blind spots Asset inventory and lifecycle statement Very high
Network evidence Connects via Ethernet Topology, data flows, protocols, trusted and untrusted interfaces documented Security-zone redesign after installation Topology and protocol map Very high
Secure configuration Factory default setup works Hardening guide, disabled services, account policy and commissioning checklist Approved system installed in a weak configuration Security configuration guide High
Update support Updates available when needed Patch policy, dependency policy, delivery route, rollback and support interval Unpatched systems or unsafe updates at sea Security update documentation High
Remote access Vendor can support remotely Approved, logged, time-limited access with disable method and MFA where appropriate Persistent backdoor into vessel systems Remote-access procedure Very high
Security testing Tested by supplier Security capability test procedure and signed test evidence supplied Security features fail when needed Test plan and signed report Very high
Recovery support Vendor can restore if required Documented backup, restore, rebuild, clean media and post-recovery test process Long downtime after cyber or configuration event Recovery procedure and spare-media policy High
Change control Changes handled case by case Management-of-change plan with configuration baseline and approval triggers Cyber state drifts after commissioning MoC plan and baseline file High

IACS E27 Procurement Readiness Scorecard

Use this planning tool to screen whether a connected marine equipment quote is approval-ready or still missing critical cyber procurement evidence.

E27 procurement gap score
0%
Assessment pending Suggested procurement risk tier
Request the cyber evidence pack before award Recommended owner focus

This scorecard is a planning aid. Final E27 decisions should be aligned with the vessel’s class society, shipyard, system integrator, flag expectations, owner cyber-management program, and supplier approval status.

Commercial playbook

E27 turns connected equipment into a lifecycle obligation

Owners should not think of E27 as a one-time certificate request. The procurement decision should cover the whole equipment lifecycle: factory configuration, onboard integration, security testing, handover, maintenance, patching, vulnerability notices, remote support, change control and recovery.

Best first pilot

Apply the checklist to one high-risk equipment purchase such as PMS, BMS, engine control, ECDIS, cargo monitoring, DP or gas detection, then use the evidence schedule as a template across the fleet.

Best buying rule

Do not buy connected marine equipment until the supplier proves both function and cyber supportability: inventory, topology, security capabilities, hardening, updates, remote access, recovery and test evidence.

Best board metric

Track connected systems by approval status, missing documents, open class comments, unsupported software, unmanaged remote access, patch exposure, recovery readiness and change-control maturity.

Bottom line for owners

IACS E27 makes supplier evidence part of the connected equipment purchase. The stronger the evidence before installation, the fewer surprises during class review, commissioning, cyber audit and vessel operation.

Feedback Welcome

We welcome your feedback, suggestions, corrections, and ideas for enhancements.

Please click here to get in touch
By the ShipUniverse Editorial Team — About Us | Contact