UR E26/27 Q&A

FAQ / Related Files

UR E26/27 Q&A and Related Files

This page provides Q&A information regarding compliance with UR E26/27 in HTML format. By publishing the questions and answers directly on this page, it improves readability and searchability while also providing quick access to the official Q&A list on Box.

* The HTML version of this FAQ reflects the content as of the update date shown above. For the latest and official version, please refer to the Excel file on Box.

Open the official Q&A list on Box

HTML FAQ
Updated
2026/07/08
Coverage All Q&As
Number of Q&As 136
Categories 6
Official version Excel file on Box

How to Use This FAQ

  • Use “Search and Filter FAQs” to find the relevant topic, then open the corresponding category heading.
  • Stakeholder labels indicate whether each Q&A is mainly relevant to shipowners, integrators, or suppliers.
  • For the latest information, please refer to the official Excel file on Box.

Search and Filter FAQs

You can filter FAQs by keyword, category, and stakeholder. You can also expand or collapse all accordion items as needed.

General 3 items
Q4 4.2.1(15) & 5.2.1(10)., Part X of the Rules

Is the term "integrated system" used in Part X, Chapters 4 and 5, the same as "system of systems" used in Chapter 3?
ShipownerIntegratorSupplier

These are different terms defined as follows: An "integrated system" is limited to those that "interact" with each other.

"Integrated system" means a system combining a number of interacting sub-systems and/or equipment organized to achieve one or more specified purposes.
“System of systems” means a system which is made up of several systems. In the context of this Chapter, a system of systems encompasses all monitoring, control and safety systems delivered from the shipyard as a part of a vessel.

Category
General
Tag
Term
Update date
2024/06/26
Q11 1.1.1, Part X of the Rules

Is it necessary to obtain approval under Chapter 4 of Part X of the Rules for systems and equipment that do not use computer-based systems?
IntegratorSupplier

The requirements of Part X of the Rules apply to computer-based systems. Therefore, systems and equipment that do not use computers are not subject to the requirements of Chapters 4 and 5 of Part X, and approval is not required.

Category
General
Tag
Applicable system
Update date
2024/08/28
Q12 Does a system that uses a microcomputer fall under the category of a computer system?
IntegratorSupplier

In Chapters 4 and 5, Part X of the Rules, a "computer-based system" is defined as "a programmable electronic device, or an interoperable set of programmable electronic devices, organized to achieve one or more specified purposes such as collection, processing, maintenance, use, sharing, dissemination, or disposition of information."

The systems that utilize the following are also considered to fall under the definition of a computer-based system as defined in Chapters 4 and 5 of Part X:
-Microcomputer
-PLC
-Embedded PC
-etc.

Category
General
Tag
Applicable system
Update date
2024/08/28
Ch4 Part X(E27) 40 items
Q5 4.4.1(4)(b), Part X of the Rules

Description of security Capabilities states that " means to update test results and record findings during the testing" should be included. Does this mean that updates and records should be made electronically?
Supplier

The means for updating and recording observations are not specifically prescribed; therefore, electronic updates or handwritten records on paper are acceptable as long as the method is specified.

Category
Ch4 Part X(E27)
Tag
Document
Update date
2024/06/26
Q6 4.1.2-1.(2), Part X of the Rules

For ships listed in this section, it is stated that the guidelines can be used as "non-mandatory guidelines." If this chapter is not applied, is it correct to assume that on-board computer-based systems do not need to be approved in accordance with Chapter 4?
IntegratorSupplier

That is correct. However, if the ship applies this chapter, the on-board computer-based systems must comply with Chapter 4.

Category
Ch4 Part X(E27)
Tag
Applicable system
Update date
2024/06/26
Q7 Item 2 of Table4.1 in Part X

There is no definition of a human users, but is it correct to understand that it includes not only crew members but also supplier engineers?
Supplier

That is correct.

Category
Ch4 Part X(E27)
Tag
Term
Update date
2024/06/26
Q16 Chapter 4,Part X of the Rules

Who determines whether Chapter 4 of Part X / IACS UR E27 is applicable to a certain system (supplier or system integrator)?
IntegratorSupplier

The supplier is to in cooperation with the system integrator determine if this Chapter 4 of Part X / IACS UR E27 is mandatory for the system.
(4.6.1-1, Part X of the Rules)

Category
Ch4 Part X(E27)
Tag
Applicable system
Update date
2024/08/28
Q18 Chapter 4,Part X of the Rules

How to find products that have obtained ClassNK's UR E27 (Part X Chapter 4) approval?
ShipownerIntegrator

Products approved by ClassNK are published on the following website:
https://www.classnk.or.jp/appr_list/material_search.aspx?lang=en
Please turn on the advanced search option, then enter "CY" in the "Approval No.
/Appraisal No." field of the advance search section on the above URL.

Category
Ch4 Part X(E27)
Tag
Type approval
Update date
2024/9/26
2026/3/19
Q20 Item 14 of Table4.1 in Part X

Regarding audit storage capacity, are there any specific requirements on the required capacity?
Supplier

Supplier needs to consider and determine the necessary capacity for incident analysis, taking into account factors such as:
-Logging frequency during normal operation
-Logging frequency during cyberattacks
-Log review intervals

Category
Ch4 Part X(E27)
Tag
Security capability
Update date
2024/09/27
Q21 Table4.1 in Part X

Is it permissible to create a hidden account that is recognized only by the supplier?
Supplier

Details such as passwords do not need to be included in the documents, but the documents must include a statement that there is a supplier-only account.

Category
Ch4 Part X(E27)
Tag
Security capability
Update date
2024/10/02
Q23 Chapter 4,Part X of the Rules

How the supplier should submit the relevant documents for obtainment of type approval certificate related to UR E27 (Chapter 4, Part X)?
Supplier

The relevant documents should be submitted to us via NK-PASS. Advanced registration is mandatory for usage of NK-PASS. As for how to register/use of NK-PASS is referred to the following link of our web site.
https://www.classnk.or.jp/hp/zh/activities/portal/nk-pass.html

If it is difficult to submit documents via NK-PASS, email submissions are also acceptable. In this case, please send the documents to the Machinery Department (mcd@classnk.or.jp).

Category
Ch4 Part X(E27)
Tag
Type approval
Update date
2024/10/02
Q32 I think each supplier (manufacturer) will get E27 (Chapter 4, Part X) type approval, but I am concerned about the progress.
ShipownerIntegratorSupplier

You can check the type approved products on the NK website.
(Enter "CY" in the approval number/appraisal number and search)
https://www.classnk.or.jp/appr_list/material_search.aspx?lang=ja

Category
Ch4 Part X(E27)
Tag
Type approval Test
Update date
2024/10/02
Q33 Are the controllers of thrusters in scope of the rules?
IntegratorSupplier

We consider that they are in scope in case they are used as propulsion equipment, or Class 2 or 3 DPS (Dynamic positioning system)component.

In other words, if they are not used for propulsion or DPS, they are not applicable.
However, even in this case, they may still be subject to the requirements depending on the system and/or network configuration of the system and/or the ship. For the details, please refer to the attached file.
(Q10_reference.pdf)

Category
Ch4 Part X(E27)
Tag
Applicable system, DPS
Update date
2024/10/11
2025/10/27
Q36 Is it a prerequisite to obtain UR E10 or E22 approval to obtain UR E27 approval?
Supplier

Obtaining UR E10 or E22 approval is not a prerequisite for obtaining E27 approval.

Regarding E10 or E22 approval, please consider obtaining approval based on the requirements that require each approval.

Category
Ch4 Part X(E27)
Tag
Compliance process
Update date
2024/10/29
Q38 -Does an L3 switch require UR E27 (Chapter 4, Part X) approval?
-Does an L2 switch require UR E27 (Chapter 4, Part X) approval?
-Does a firewall require UR E27 (Chapter 4, Part X)approval?
ShipownerIntegratorSupplier

-If an L3 switch controls communication within the applicable system, or with external systems, E27 approval is required.

-If an L2 switch controls communication within the applicable system, or with external systems, E27 approval is required. However, approval is not required if it is an unmanaged switch.*
(*According to the rules, we consider that the locations where it can actually be used are limited.)

-If a firewall controls communication within the applicable system, or with external systems, E27 approval is required.

Category
Ch4 Part X(E27)
Tag
Applicable system
Update date
2024/10/29
2024/11/13
Q45 Chpater 4, Part X / Part 7 Chapter 10, Guidance for the Approval of Materials and Equipment for Marine Use

What documents should the Supplier prepare and submit to NK when obtaining E27 approval?
Supplier

The documents to be prepared and submitted by the supplier are the following 9 types of documents.
1.Computer-based system asset inventory: A list of hardware and software components constituting the system.
2.Topology diagrams: Diagrams showing the physical and logical network configuration of the system.
3.Description of security capabilities: A document explaining how the system meets the required security capabilities.
4.Test procedure of security capabilities: A document describing how compliance with the required security capabilities is demonstrated by testing.
5.Security configuration guidelines: A document describing the default settings and other information necessary for the system integrator and shipowner to properly install, configure, and operate the system.
6.Secure development lifecycle documents: Documents describing that the supplier has established internal processes and controls to consider security and incorporate appropriate security measures at each stage of the product lifecycle, including planning and requirements analysis, design, implementation, verification, release, maintenance, and end of life.
7.Plans for maintenance and verification of the computer-based system: Documents describing procedures for maintaining, checking, and verifying the security functions of the system.
8.Information supporting the owner's incident response and recovery plan: Information or instructions necessary for the shipowner to prepare and implement incident response and recovery plans.
9.Management of change plan: A document describing the management of change process.

In addition, test reports are to be submitted after type approval has been granted, when the product is assigned to an individual ship. These reports provide evidence, based on the supplier’s internal tests, that design, construction, testing, configuration, and hardening have been completed.

Category
Ch4 Part X(E27)
Tag
Document
Update date
2024/11/18
2026/4/17
2026/5/22
Q46 Chpater 4, Part X / Part 7 Chapter 10, Guidance for the Approval of Materials and Equipment for Marine Use

If a product obtains the approval of use of systems and equipment with improved cyber resilience (E27 type approval), will the supplier no longer need to submit drawings and conduct shop test in the presence of NK Surveyor?
Supplier

For products that have been granted E27 type approval, the supplier will need to submit the following 3+2 documents for each vessel to Machinery Department:
-Computer-based system asset inventory (Specific to the individual ship*1)
-Topology diagrams (Specific to the individual ship*1)
-Test reports
-In addition, you must submit the above documents along with an application for omission (*2) that includes which product is assigned to which vessel, and a soft copy of the type approval certificate.
On the other hand, shop tests in the presence of NK Surveyor are not required.

*1. This means, for example, specifying the version information described as a range at the time of type approval (e.g., 1.x→1.1), or identifying the specifications and configurations within the approved scope that are applicable to the individual ship.
*2. For the format of the application for omission, please refer to FAQ Q97.

Category
Ch4 Part X(E27)
Tag
Document, Type approval
Update date
2024/11/18
2025/02/14
2025/03/03
2025/04/30
2025/05/17
2025/08/01
2025/12/16
2026/5/18
Q49 Chpater 4, Part X / Part 7 Chapter 10, Guidance for the Approval of Materials and Equipment for Marine Use

What is the estimated time required to obtain Type approval?
Supplier

While the timeframe may vary depending on the degree of completion of the submitted documents at the time of submission, etc., it generally takes at least 4 months from the document review to the test witnessing, and at least another 2 months from the test witnessing to the issuance of the certificate.

Category
Ch4 Part X(E27)
Tag
Type approval
Update date
2024/11/25
2025/03/14
Q50 Chpater 4, Part X

Is there a provision for omitting document submission and/or attendance at surveys for E27 individual approval in cases where a system lacks Type approval but shares specifications with a previously approved system on a sister vessel?
Supplier

Regarding the possibility of omitting without a Type approval, the details are as follows:
-Submission of drawings: "Reuse" of drawings using our drawing submission system "NK-PASS" is possible.
-Attendance survey:It cannot be omitted.
(Q50_reference.pdf)

※We initially explained that when installing the same system on sister vessels, the document submission and the attendance at surveys could be omitted. This was also explained in the "Guidelines on Cyber Resilience of on-board systems and equipment(Edition 1.0)".

Category
Ch4 Part X(E27)
Tag
Type approval, Omission
Update date
2024/11/26
Q56 Chpater 4, Part X

Is there a way to find out about products that are currently under application (under review) for UR E27 (Chapter 4 of Part X) Type approval?
ShipownerIntegrator

NK does not disclose information about products that are currently under review.

Category
Ch4 Part X(E27)
Tag
Type approval
Update date
2024/12/13
Q59 Regarding the following four documents required by E27(Chapter 4, Part X), E27 Section 3.1 (4.4.1, Part X) states that "This documents/documentation is to be submitted to the Society "upon request". Could you please clarify in which cases submission to NK is required?
-Secure development lifecycle documents
-Plans for maintenance and verification of the computer-based system
-Information supporting the owner’s incident response and recovery plan
-Management of change plan
Supplier

In principle, submission is required.
(By the way, if you are reusing documents previously submitted to ClassNK for approval under Part X, Chapter 3 / E22, you may omit submission by specifying this in the application form 7-10.)

Category
Ch4 Part X(E27)
Tag
Type approval, Document
Update date
2025/01/17
Q62 Regarding systems or equipment installed on E26 applicable ships, could you please tell me in what cases E27 approval is not required?
IntegratorSupplier

We believe that the cases where chapter 4 of Part X (E27) approval is not required (outside the scope of application) can be organized into the following three cases. ※1
-Case 1: Not a computer-based system
-Case 2: It is a computer-based system, but it is not an applicable OT system ※2
-Case 3: It is a computer-based system and an applicable OT system, but it can be excluded from the application by the exclusion provision of X5.5 (Chapter 6 of E26).

※1: Computer-based systems include network devices.
※2: Except for cases where the applicable computer-based system has functions for IP communication with other systems.

Category
Ch4 Part X(E27)
Tag
Applicable system, Risk assessment
Update date
2025/01/24
Q63 Is it possible to obtain E27 approval for individual components (e.g., a general-purpose PLC alone) that make up computer-based system?
Supplier

Even if an individual component obtains E27 approval, it is necessary to obtain E27 approval again for the entire computer-based system in a configured state.

Category
Ch4 Part X(E27)
Tag
Type approval
Update date
2025/01/24
Q66 I would like to know about the process of assigning E27 type approved products to individual vessels.
1. Is a witness test required?
2. Is it necessary to submit any documents?
3. Will a certificate be issued?
4. Is there a specific format for the application for omission?
Supplier

1. A witness test is not required.
2. For each vessel, you will need to submit the following 3+2 documents to the ClassNK Machinery Department:
-Computer-based system asset inventory (Specific to the individual ship)
-Topology diagram (Specific to the individual ship)
-Test Report signed by the supplier
-An application for exemption stating which products will be assigned to which vessels, and a soft copy of the type approval certificate.
3.No certificate will be issued. (However, if a witness test is conducted due to requirements other than E27, a certificate may be issued based on those requirements and test result.)
4. A specific format is not required. For the format of the application for omission, please refer to FAQ Q97.

Category
Ch4 Part X(E27)
Tag
Type approval
Update date
2025/02/17
2025/04/30
2025/05/17
2025/08/01
2025/12/16
Q72 Regarding UR E27 type approval:
-How can I obtain type approval?
-Where can I find detailed information about type approval?
-Which application form should I use for the type approval application?
-What documents are required when applying for type approval?
-What methods are available for submitting the documents for type approval?
-Who should I contact regarding the fees for type approval?
-What is the validity period of type approval?
Supplier

At first, please refer to the dedicated portal including guidelines ClassNK has created, FAQ, etc.
https://www.classnk.or.jp/hp/zh/activities/cybersecurity/ur-e26e27.html

■Application Form
Applicants for type approval should submit application form “Form 7-10(E)” to Machinery Department.

■Document Submission
At the time of application, the application form and following documents are to be submitted.
1. CBS asset inventory
2. Topology diagrams
3. Description of Security capabilities
4. Test procedure of security capabilities
5. Security configuration guidelines
6. Secure development lifecycle documents
7. Plans for maintenance and verification of the CBS
8. Information supporting the owner’s incident response and recovery plan
9. Management of change plan

The application form and following documents are to be submitted in one of the following ways.
a)NK-PASS
b)Email (mcd@classnk.or.jp)
c)Regular mail (three copies of each document are to be submitted.)

■Estimated time
The estimated time required to obtain type approval is a total of 6 months, with 4 months for drawing review and 2 months from testing to certificate issuance.

■Approval fee
For inquiries regarding fees, please contact the Machinery Department (mcd@classnk.or.jp) and include an overview of your product as well as details of its network configuration by your e-mail.

■Validity Period
Valid for 5 years.

Category
Ch4 Part X(E27)
Tag
Type approval
Update date
2025/03/31
2025/04/07
Q73 Table X2.3, Part X / E27 Appendix II
4.4.1(10), Part X / E27 3.1.10

Even after obtaining E27 Type Approval, the submission of a "Test Report" is required for each product/ship. Does this refer to the report of Test of security capabilities (2.2.2.3, Part X) conducted at the time of obtaining the E27 Type Approval?
Supplier

No, this does not refer to the test report of Test of security capabilities generated when obtaining Type Approval.
It is documentation serving as evidence that security function configuration and hardening have been implemented for each product/ship. This refers to the results of the supplier's internal tests concerning these specific implementations.

Please note that although the wording in UR E27 is somewhat unclear on this point, we consider that this does not require conducting Test of security capabilities via internal testing for every individual ship.

Category
Ch4 Part X(E27)
Tag
Document, Type approval
Update date
2025/03/31
Q76 Is it possible to issue a single type approval certificate that integrates the existing E10 and E22 certificates with the E27 certificate?

・E10(Environmental performance)
・E22(Manufacturing quality of computer systems)
・E27(Cyber resilience of computer systems)
Supplier

It is possible to combine the type approvals for the E10, E22, and E27 requirements into one certificate. Please notify us of your intention when applying for type approval. (Select yes or no in the checkbox on application Form 7-10.)
・E10: Guidance for the Approval of Materials and Equipment for Marine Use, 7-1, Automatic Devices and Equipment
・E22: Guidance for the Approval of Materials and Equipment for Marine Use, 7-8, Computer Based Systems
・E27: Guidance for the Approval of Materials and Equipment for Marine Use, 7-10, Equipment with Improved Cyber Resilience
(Form 7-10 Example: Q76_reference.pdf)

However, the following points should be considered:
・If integrating with an existing certificate, the shortest expiration date will apply. (Or you can apply for renewal at the same time)
Differences in the components included in the approval scope.
Differences in the intended purpose of the system.

Category
Ch4 Part X(E27)
Tag
Type approval
Update date
2025/4/7
2026/2/26
Q82 Is there a template or sample format for the E27(Chapter 4, Part X) documents to be submitted by a supplier?
Supplier

To help you understand the expected content for the documents listed below, we have prepared examples detailing some security capabilities. Please use these for reference:
-Description of security capabilities (Example Description_Description of security capabilities.pdf)
-Test procedure of security capabilities (Example Description_Test procedure of security capabilities.pdf)

Category
Ch4 Part X(E27)
Tag
Document, Type approval
Update date
2025/05/02
Q87 Is it mandatory to prepare an English version of the documents for E27 Type Approval?
Supplier

According to the Rules, the preparation of an English version of the documents for E27 Type Approval is not a mandatory requirement.
However, please note that the type approval documents you submit will be handed over from the Supplier to the Shipyard, and then from the Shipyard to the Shipowner, in accordance with the provisions of the Rules. Therefore, if it is anticipated that your product will be used by overseas Shipowners or crew, it is strongly recommended that you prepare an English version of these documents.

Part X, 4.6.2-3 / E27, 6.2, Part X, 2.2.3-2.(5) / E26, Ch.5

Category
Ch4 Part X(E27)
Tag
Document, Type approval
Update date
2025/06/02
Q88 Can a VPN connection itself be counted as one of the "factors" for multi-factor authentication?

Part X 4.4.3, Table X4.2 / UR E27 4.2, Table 2, No. 31
Supplier

To be precise, the VPN connection, which is a communication channel, is not an authentication factor in itself. However, it is considered possible to achieve multi-factor authentication by incorporating a "device certificate" into the VPN's authentication process.

In this case, the combination of:
・The first factor (something you have): A "device certificate" installed only on an authorized PC.
・The second factor (something you know): A "password" entered by the user.
This combination can confirm that access is from the "correct PC with the certificate" by the "correct person who knows the password." Therefore, this approach is considered to satisfy the requirements for multi-factor authentication.

Category
Ch4 Part X(E27)
Tag
Security capability, Untrusted network
Update date
2025/06/10
Q92 Part X, 4.4.1(3)(e)iii) / E27, 3.1.3

The rules state that a compensating countermeasure should not be a security control required by other requirements. However, is it possible for a single measure, such as a port blocker, to satisfy multiple requirements?
Supplier

Yes, that is correct. The key is to distinguish between "substituting a requirement" and "using a single measure for multiple purposes."

Prohibited: Substituting a Requirement
You cannot use the fulfillment of one requirement (e.g., audit log generation) to justify not meeting another (e.g., user authentication). Each requirement must be independently satisfied.
Permitted: Using a Single Measure for Multiple Requirements
It is acceptable for a single "measure," like a port blocker, to satisfy multiple requirements simultaneously.

In conclusion, substituting one requirement for another is prohibited, but satisfying multiple requirements with a single countermeasure is permissible.

Category
Ch4 Part X(E27)
Tag
Security capability
Update date
2025/06/30
Q95 Part X 4.4.3, Table X4.2, No. 31
Can a firewall's IP address whitelist (a setting that permits communication only from specific IP addresses) be considered one of the "factors" for multi-factor authentication (MFA)?
Supplier

No, an IP address whitelist itself is not considered a factor for multi-factor authentication.

Multi-factor authentication typically verifies a user's identity by combining two or more of the three common authentication factors:
-Something you know (knowledge)
-Something you have (possession)
-Something you are (biometrics)
An IP address whitelist permits access from a specific "location" and does not directly fall under any of these authentication factors.

Category
Ch4 Part X(E27)
Tag
Security capability, Untrusted network
Update date
2025/07/14
Q96 For a product with E27 (Part X, Chapter 4) Type Approval, is Approval of Manufacturers also required to omit the attendance of the Society's surveyor at the shop tests regarding E27 for each individual ship, which are conducted at the supplier's factory?
Supplier

No, Approval of Manufacturers is not required.
If a product has a valid Type Approval for E27 (Part X, Chapter 4), the attendance of the Society's surveyor for shop tests regarding E27 conducted at the supplier's factory for each individual ship is not required, even without Works Approval. However, please note that the submission of some documents, such as the "Test reports signed by the supplier," is still necessary for each ship.

(Please note that the handling of test omissions related to E22 (Part X, Chapter 3) is out of the scope of this FAQ. For details, please refer to NK Technical Information TEC-1348.)

Category
Ch4 Part X(E27)
Tag
Type approval, Omission
Update date
2025/07/29
2025/07/30
Q97 Is there a specific format for the "application for omission" when assigning an E27 type-approved product to an individual ship?
Supplier

ClassNK has prepared an application form template.
-Form_Application for Omission for Type Approved Products.docx

This form can be used when applying to assign a product with Type Approval to an individual ship.

Please note that the use of this form is optional. You may continue to submit your application in any format.

Category
Ch4 Part X(E27)
Tag
Document, Type approval
Update date
2025/08/01
Q100 I'm not sure how to fill out the following sections on the Type approval application Form 7-10:
-Apply to additional security capabilities
-Apply to “Automatic Devices and Equipment (Environmental Test)”
-Apply to “Approval of Use of Computer Based System”
Supplier

Please determine how to fill in each item as follows:
Apply to additional security capabilities
"Yes": Select this if your product has the capability to communicate with "untrusted networks" (as specified in the additional security capabilities required by Part X, 4.4.3 / UR E27 4.2).
"No": Select this if your product does not have this capability.

Apply to “Automatic Devices and Equipment (Environmental Test)”
"Yes": Select this if you are simultaneously applying for approval of environmental testing (equivalent to UR E10)*¹, or if you wish to integrate it with an existing certificate*².

Apply to “Approval of Use of Computer Based System”
"Yes": Select this if you are simultaneously applying for approval of the manufacturing quality of computer-based systems (equivalent to UR E22)*¹, or if you wish to integrate it with an existing certificate*².

*¹: If you wish to receive separate certificates, please select "No", and please submit Form 7-1 or Form 7-8 separately.
*²: If you wish to integrate with an existing certificate, please enter the existing certificate number (e.g., xxAxxx, xxCPxxx, TAxxxxxM) in the "Remarks" section.

Category
Ch4 Part X(E27)
Tag
Type approval
Update date
2025/08/26
Q104 Part X 4.5.8(1) / E27 5.7a)

What is "security context"?
Supplier

It refers to the overall security situation and configuration of the environment where a product actually operates. It encompasses not only the functions of the product itself but also the surrounding environment, including:
-Technical environment: such as other connected systems, network configurations, and firewalls.
-Organizational environment: such as operational policies defined by the shipowner, including password policies and access control rules.
-Physical environment: such as the lock management of the room where the equipment is installed.

Category
Ch4 Part X(E27)
Tag
SDLC
Update date
2025/09/24
Q105 Part X 4.5.8(1) / E27 5.7a)

What does "Integration of the product, including third-party components, with its product security
context" require?
Supplier

This requires the product supplier (manufacturer) to provide "security hardening guidelines" that describe specific procedures for securely integrating their product into the customer's operational environment (the security context).

In other words, it's not enough to simply supply a product and state that it's secure. The supplier is required to provide documented, concrete instructions to adapt the product to its operational environment, such as:
-"When connecting to this system, please use these specific port settings."
-"Please change the minimum password length to align with the shipowner's policy."
-"If this function is not needed, please disable it to reduce the potential attack surface."

Category
Ch4 Part X(E27)
Tag
SDLC
Update date
2025/09/24
Q109 Are Class 1 Dynamic Positioning Systems (DPS) or DPS installed voluntarily (not subject to class approval) considered applicable OT systems under UR E26/E27?
IntegratorSupplier

These DPS are not considered applicable OT systems.
However, E27 (Part X, Chapter 4) approval is required if installed in the same security zone as an applicable computer-based system (applicable OT system). (E26 4.2.1.3 / Part X, 5.4.3(1)(c)i))

Category
Ch4 Part X(E27)
Tag
Applicable system, DPS
Update date
2025/10/27
Q112 4.1.2-2.(1)(k), Part X of the Rules

For navigation and radio communication equipment that has obtained IEC 61162-460 certification, is it necessary to obtain approval under Chapter 4 of Part X (UR E27), and are document submission and testing required?
Supplier

Even if the equipment has obtained IEC 61162-460 certification, approval under Chapter 4 of Part X (UR E27) is required, and submission of documents and review by the Society are necessary.
In the submitted documents (such as the Description of security capabilities), compliance must be organized and described for each requirement of Chapter 4 of Part X (UR E27).

However, if test results conducted during the IEC 61162-460 certification process are submitted, the Society will review the contents. For items judged to be equivalent to the tests required by Chapter 4 of Part X (UR E27), the execution of those tests may be omitted.

Category
Ch4 Part X(E27)
Tag
Compliance process
Update date
2025/12/04
Q127 4.4.1(10), Part X / E27 3.1.10
When assigning an E27 type-approved product to an individual ship, the submission of "Test reports" is required. However, if no ship-specific security configuration or hardening work is generated due to the product's specifications (e.g., security settings are hardcoded), what should be stated in the test report?
Supplier

Please state in the test reports that there are no applicable items for ship-specific security configuration or hardening due to the product's specifications (e.g., settings are fixed by design).
Please note that even if no individual configuration work is required, the test report must still include the confirmation results showing that the product is built to the approved specifications, the results of operational checks, and the installed software versions.

Category
Ch4 Part X(E27)
Tag
Document, Type approval
Update date
2026/04/17
Q129 Is access to the management interface of a firewall or similar device installed at a zone boundary with an untrusted network subject to the additional security capabilities specified in Part X 4.4.3 / UR E27 4.2?
Supplier

Yes. If the management function of a firewall, router, or other zone boundary device can be accessed from the untrusted network side, such access is also subject to the additional security capabilities specified in Part X 4.4.3 / UR E27 4.2.

If the management function of a zone boundary device is compromised, security functions such as traffic control and access control may be modified or disabled.
Therefore, management access from the untrusted network side should be disabled, and this should be clearly stated in the Description of security capabilities or other relevant documents. Where such access is necessary, appropriate protective measures, such as MFA, encrypted communication, source restriction, explicit onboard approval, and logging, are to be applied and described in the Description of security capabilities.

Category
Ch4 Part X(E27)
Tag
Security capability, Untrusted network
Update date
2026/05/07
Q130 Can existing alarm history logging functions or similar functions of OT systems, such as an AMS data logger, be used as a means of storing or reviewing audit records required by Items No.13, No.14 and No.23 of Table X4.1, Part X of the Rules (E27 4.1 Table 1)?
Supplier

Yes. Items No.13, No.14 and No.23 of Table X4.1, Part X of the Rules (E27 4.1 Table 1) require functions related to generation of audit records, audit storage capacity and audit log accessibility, but they do not uniformly require a dedicated device or system to be newly provided for audit records. Therefore, existing alarm history logging functions or similar functions of OT systems, such as an AMS data logger, may be used as a means of storing or reviewing audit records, provided that the required auditable events can be recorded and reviewed as necessary. However, the auditable events to be recorded, recorded information, retention period or storage capacity, and review method are to be clearly described in the submitted documents, such as the Description of security capabilities.

Category
Ch4 Part X(E27)
Tag
Security capability
Update date
2026/05/28
Q135 What is the difference between "approval of use" and "type approval" relating to UR E27 (Part X, Chapter 4)? Has the terminology been changed?
IntegratorSupplier

For applications submitted on or after 1 July 2026, the approval previously referred to as "Approval of Use" has been renamed"Type Approval." Accordingly, the title of the relevant Guidance has also been changed from "Guidance for the Approval and Type Approval of Materials and Equipment for Marine Use" to "Guidance for the Approval of Materials and Equipment for Marine Use." This amendment is intended solely to consolidate and clarify the nomenclature; no substantive change has been made to the technical requirements. The old and new terms are therefore to be understood as referring to the same approval scheme.

Category
Ch4 Part X(E27)
Tag
Type approval
Update date
2026/07/01
Ch5 Part X(E26) 62 items
Q1 1.2.4-35., Part A of the Rules

For ships contracted for construction on or after July 1, 2024, is there a difference between the drawings/documents that should be submitted and those required for the class notation "CybR"?
ShipownerIntegratorSupplier

Among ships contracted for construction on or after 1 July 2024, there are ships for which the application of Chapters 4 and 5 of Part X (UR E27 and E26) is mandatory, and those for which it is not. The class notation "CybR" will be affixed to all ships subject to the application of these requirements.

For all ships to which the "CybR" notation is affixed, all drawings and documents listed in Part X 2.1.1(1)(b) and (c) as well as (2)(b) must be submitted.
On the other hand, for ships to which the "CybR" notation is not affixed, the submission of such documents is not required.

Category
Ch5 Part X(E26)
Tag
Document
Update date
2024/6/26
2026/3/4
Q2 2.2.3-5.(5)., Part X of the Rules

If the supplier of an onboard computer-based system goes bankrupt or withdraws, does the system need to be immediately replaced?
ShipownerSupplier

If the supplier goes bankrupt or withdraws, it is not necessary to replace the system immediately, but it is necessary to replace it as soon as possible to keep each computer-based system up to date. It is generally expected that documents and support are handed over to another supplier, and it is rare for support to end immediately.

Category
Ch5 Part X(E26)
Tag
MoC
Update date
2024/06/26
Q3 2.2.3-5.(5)., Part X of the Rules

For on-board computer-based systems, how can we demonstrate that they are maintained up to date, and how does the classification society verify this?
Shipowner

In accordance with 5.4.2(1)(d)iii)3) of Part X, the rules provide two examples of how to verify that software is kept up to date:

- Vulnerability scanning (services that identify exploitable weaknesses, including software that needs updating on the system)
- Checking the software versions of computer-based systems while switched on (manually or using tools to confirm that the software version is up to date).

As indicated in Item 1 of Table B5.32 in Part B, the Society will verify these during special surveys.

Category
Ch5 Part X(E26)
Tag
Test
Update date
2024/06/26
Q8 5.4.3(4)(c)i), Part X of the Rules

As a requirement for physical access control, it is stated that "Computer-based systems of Category II and Category III are to generally be located in rooms that can normally be locked or in controlled space to prevent unauthorized access, or are to be installed in lockable cabinets or consoles." Do the following spaces qualify as "controlled spaces"?
- Engine control room where the engine room alarm monitoring systems is installed
- Engine room where the main engine local control systems is installed
- Cargo control room where monitoring systems for cargo control is installed
Integrator

That is correct. "Controlled spaces" refer to rooms where visual monitoring by the crew is carried out (e.g., rooms where crew are constantly present) or rooms where access control is implemented by sealing doors with tamper-evident seals.

Category
Ch5 Part X(E26)
Tag
Term
Update date
2024/06/26
Q9 5.4.5(4), Part X of the Rules

What does "fallback to minimal risk condition" specifically refer to?
ShipownerIntegrator

Fallback to minimal risk condition meansbring itself in a stable, stopped condition to reduce the risk of possible safety issues, as stated in 5.4.5(4)(a), Part X of the Rules.

Category
Ch5 Part X(E26)
Tag
Term
Update date
2024/06/26
Q17 What is the existing class notation "CybR-G"?
ShipownerIntegrator

The notation "CybR" (abbreviated of Cyber Resilience) is affixed to the ships that are subject to the application of Chapter 4 and Chapter 5 of Part X which incorporate IACS UR E26 Rev.1 and E27 Rev.1.

On the other hand, the notation "CybR-G" (abbreviated of Cyber Resilience-Guideline) is affixed to ships that conform to our non-mandatory guideline "Cybersecurity Design Guidelines for Ships".

Category
Ch5 Part X(E26)
Tag
Applicable ship, Notation
Update date
2024/08/28
Q19 5.5, Part X of the Rules

Is a risk assessment necessary even for computer based systems that do not seek exemption?
IntegratorSupplier

It is not necessary.

Category
Ch5 Part X(E26)
Tag
Risk assessment
Update date
2024/09/27
Q22 5.4.2(1), Part X of the Rules

Is it necessary to include computer based systems that are out of scope or have been excluded in the risk assessment in the vessel asset inventory?
ShipownerIntegrator

It is not mandatory.

Category
Ch5 Part X(E26)
Tag
Document
Update date
2024/10/02
Q24 4-7, Guidelines for Cyber Resilience of Ships
5.4.3(1)(d)iv)1), Part X of the Rules

Regarding section "5.4.3(1), Part X of the Rules / Security zones and network segmentation" in "4-7 Ship cyber security and resilience program", chapter 4 of the guidelines, the description of the guidelines list "4) Protection against connection of unauthorized devices" in the security audit records of firewalls.
Does this mean to require NAC/Network Access Control ?
ShipownerIntegrator

The explanation in this guideline does not require the implementation of NAC. This explanation assumes network-related events as audit targets, and basic auditing is possible through methods such as IP address monitoring or log analysis. Therefore, we believe that configuration can be performed on zone boundary devices such as firewalls.

(Reference)
While NAC solutions manage devices based on multiple factors such as:
- Device IDs such as MAC addresses
- Policies such as OS versions, antivirus software versions, etc.
- Behavior in the application layer

Category
Ch5 Part X(E26)
Tag
Network configuration, Protect, Segmentation
Update date
2024/10/02
Q26 In "Zone and conduit diagram", to what extent should zones outside the scope of E26 be indicated?
Integrator

Please refer to the attached file for a flowchart summarizing "Necessity of inclusion in Vessel asset inventory" and "Whether to include in Zone and conduit diagram"
(Q26_reference.pdf)

In the Zone and Conduit Diagram, it is necessary to clearly indicate the communication between devices within the E26 range and non-applicable devices. (5.4.3(d)i)2), Part X)
Therefore, it is requested that non-applicable devices that communicate with applicable devices and the zones or segments that include them be clearly indicated.

Category
Ch5 Part X(E26)
Tag
Document
Update date
2024/10/02
Q27 Guidelines for Cyber Resilience of Ships Fig. 2.5 and Fig. 4.2

In Fig. 2.5, the Radar downstream of the VDR is indicated as being within the E26 range. However, in the sample diagram of the zone and conduit diagram in Fig. 4.2, the equipment in the OT zone downstream of the VDR is outside the E26 range. Please let us know whether the equipment downstream of the VDR that makes IP connection to the VDR is applicable to the E26.
IntegratorSupplier

A radar is an applicable system of E26(E27) as indicated in 2-2.1 of the Guidelines.
Also, a system connected to VDR (an applicable system of E26(E27)) via IP without going through a zone boundary device are covered by E26.

On the other hand, if a system is not an applicable system of E26(E27) and is not connected via IP, it is not covered by E26.

Category
Ch5 Part X(E26)
Tag
Applicable system
Update date
2024/10/02
Q28 In the "Guidelines for Cyber Resilience of Ships" issued by NK Fig. 4.2

In the sample of the zone and conduit diagram, there are 2 firewalls (both within the E26 scope). Is a network configuration acceptable where only the upper firewall is installed, and it connects to each zone?
Integrator

There are no specific regulations regarding the number of Firewalls (or other zone boundary devices) to be installed. Therefore, according to the rules, it is possible to achieve the segmentation of each zone with a single Firewall. However, please be aware that there may be potential drawbacks, such as the Firewall rule settings becoming complex, and possible security vulnerabilities when compared to a setup with separate Firewalls for each zone.

Category
Ch5 Part X(E26)
Tag
Network configuration
Update date
2024/10/02
Q29 5.4.4(1)(d)iii)1), Part X

Regarding the requirement in Part X, 5.4.4(1)(d)iii)1) of the Rules for the Survey and Construction of Steel Ships:
"Test that abnormally high network traffic is detected, and that alarm and audit record is generated."

Depending on the design, network traffic may not reach the alarm threshold. In such cases, is it still possible to pass the test?
Integrator

Countermeasures such as bandwidth limiting are implemented, and if the alarm threshold is not reached, it is acceptable to clearly state that such countermeasures are in place in the "Security Function Specification," "Security Function Test Procedure," and "Ship Cyber Resilience Test Procedure." During testing, it is confirmed that the countermeasures function correctly and the alarm threshold is not reached.

In addition, if the test has been conducted in the test for obtaining approval for each computer system regarding Part X, Chapter 4 (UR E27), the test at the shipyard can be omitted.

Category
Ch5 Part X(E26)
Tag
Test, Detect
Update date
2024/10/02
Q30 Regarding the information to be included in the documents submitted to NK, such as details on owner-supplied items, if the information about owner-supplied items cannot be obtained before an early stage of construction and is mentioned as TBD (To Be Determined), by when should this information be updated?
Integrator

The deadline for updating the "TBD" information and finalizing the documents is the delivery of the ship. However, since attendance surveys will be conducted based on these documents, you need to obtain approval with sufficient time to ensure these surveys can be carried out smoothly.

For this reason, the shipyard needs to closely coordinate with the shipowner.

Category
Ch5 Part X(E26)
Tag
Document, Compliance process
Update date
2024/10/02
Q31 If the information required at the time of drawing design is not shared among items supplied by the shipowner, it is stated that it is OK to display it as "TBD" for the time being, but if the necessary drawings are not collected for items other than those supplied by the shipowner, is it okay to submit it as "TBD" for the time being?
Integrator

That is correct.

Category
Ch5 Part X(E26)
Tag
Document
Update date
2024/10/02
Q34 5.4.3(1)(a)i), Part X

Does "air gapped" mean that there is no connection from other systems? Is it correct to understand that it is not necessary to separate rooms?
Integrator

"air gapped" means that a system is isolated from other networks both physically and logically. It is not something that cannot be achieved without separating rooms.

Category
Ch5 Part X(E26)
Tag
Protect
Update date
2024/10/11
Q39 5.4.4, Part X

Regarding the alarm required for detection, are there any rules regarding the alarm destination (e.g., output to AMS), alarm display method, or presence/absence of an audible alarm?
Integrator

There are no specific provisions regarding the alarm destination, alarm display method, or presence/absence of an audible alarm. Therefore, signal output to an alarm monitoring system (AMS) and the installation of an audible alarm are not mandatory.

However, alarms are essential elements for early detection of cyber incidents and for executing response procedures and recovery plans. The design of the alarm system will influence the content of the Ship Cyber Security Resilience Plan, which is created by the shipowner to plan for these incidents. Therefore, please design your system with this in mind.

Category
Ch5 Part X(E26)
Tag
Detect
Update date
2024/10/29
Q40 In NK's explanation documents, a configuration with two firewalls installed is shown as an example, but is NK requiring the installation of two or more firewalls?
Integrator

There is no specific requirement for the number of firewalls to be installed; it is merely an example. Installing only one firewall is acceptable under the rules.

Please consider factors such as security and maintainability when designing your configuration.

Category
Ch5 Part X(E26)
Tag
Network configuration
Update date
2024/10/29
Q42 5.5.4-2(3), Part X

4-4.2 of the "Guidelines for Cyber Resilience of Ships" cites compartments that are constantly monitored by crew members, such as the bridge and engine control room, as examples of "areas to which physical access is controlled".

However, on M0 ships, the engine control room is periodically unmanned. Also, there are times when the bridge is unmanned, such as during cargo operations. In these cases, can the compartments still be considered "areas where physical access is controlled"?
ShipownerIntegrator

Those compartments can be considered "areas where physical access is controlled" if they are lockable.

The management of locking must be described in the Ship Cyber Security and Resilience Program created by the shipowner and operated accordingly.

Category
Ch5 Part X(E26)
Tag
Risk assessment
Update date
2024/11/01
Q43 5.4.6(1)(c)iii), Part X / E26 4.5.1.3

Are there any specific rules regarding the recovery time objective (RTO) and recovery point objective (RPO)?
Shipowner

RTO/RPO must be specified in the ship owner's recovery plan, but there are no rules regarding specific time periods.

Achievable RTO/RPO depends on the ship and system design, so it is recommended that this be considered by the ship owner, shipyard, and relevant suppliers.
In general, RTO/RPO are decided in consideration of the importance of the system, the impact on the vessel, the time required for recovery, the frequency of data updates, etc.

Category
Ch5 Part X(E26)
Tag
Document, Recover, Recovery plan
Update date
2024/11/08
Q44 5.4.3(2)(d)iii)1), Part X

Regarding the "Test denial of service (DoS) attacks targeting zone boundary protection devices, as applicable." in the commissioning phase, from what position to what position should the load be applied in the assumed data flow?
Shipowner

You will need to apply the load from the IT zone side (outside the scope of UR E26 application). Please refer to the reference document.
By the way, installation/testing of the firewall at the lower side of the attached document is optional. However, if you install it, E27 approval is required for it.
(Q44_reference.pdf)

Category
Ch5 Part X(E26)
Tag
Test, Dos, Protect
Update date
2024/11/12
Q47 Chapter 5, Part X

What documents should the Systems Integrator (Shipyard) prepare and submit to NK when obtaining E26 approval?
Integrator

Systems Integrator (Shipyard) prepares and submits the following 6 documents.
1.Zone and conduit diagram: A diagram that visually illustrates the configuration of the ship's security zones.
2.Cybersecurity design description: A document that describes the technical measures for the ship's cyber security.
3.Ship asset inventory: A list of hardware and software for computer systems onboard.
4.Risk assessment for the exclusion of computer-based systems: A document for computer systems for which exclusion is requested, which is intended to show that the exclusion is reasonable.
5.Description of compensating countermeasures: Compensating countermeasures to meet the security requirements of computer-based systems.
6.Ship cyber resilience test procedure: A test plan for evaluating the ship's cyber resilience.

Category
Ch5 Part X(E26)
Tag
Document
Update date
2024/11/18
Q48 Chapter 5, Part X

What document should the Shipowner (Management company) prepare and submit to NKl?
Shipowner

Shipowner (Management company) prepares and submits the Ship Cyber Security and Resilience Program.
This is a document that describes the management of computer system cyber security and cyber resilience.

Category
Ch5 Part X(E26)
Tag
Document
Update date
2024/11/18
Q51 The firewall (indicated by the blue frame in the reference material p.1) that separates the IT zone (outside the scope of E26) and the OT zone (within the scope of E26) will be supplied by the shipowner. However, information about the firewall cannot be shared with the shipyard until the ship management company is decided. How should we shipowner proceed? (Q51_reference.pdf-p.1)
ShipownerIntegrator

Please consider the following measures.
Regardless of the ship management company, the shipyard should be informed of the provisional selection of the Firewall (UR E27 approved product), which is expected to be adopted. (Parts that cannot be decided should be marked as TBD (To Be Determined), and the shipyard should be informed sequentially as each part is decided.)

When contracting with the ship management company, it should be discussed that the Firewall should be an E27 approved product.

If an E27 approved product cannot be selected for the firewall, the ship management company should be informed that the equipment in the IT zone cannot be connected to the equipment within the scope of E26 (ship OT system). (Q51_reference.pdf-p.2)

Category
Ch5 Part X(E26)
Tag
Owner supply, Network configuration
Update date
2024/12/06
Q52 5.4, Part X

The Rules require a demonstration during the commissioning phase. Does this indicate that the demonstration must be done during the sea trial? Must this be completed during the sea trial?
Integrator

The rules do not require the demonstration to be performed during sea trials. If there is enough time in the schedule after the sea trial and before the vessel's delivery, it is acceptable to conduct the demonstration after the sea trials.

Category
Ch5 Part X(E26)
Tag
Test
Update date
2024/12/06
Q53 Is it necessary to link the Ship Cyber Security and Resilience Program to the SMS Manual?
Shipowner

It is not mandatory to link the Ship Cyber Security and Resilience Program to the SMS Manual.

If you wish to link them, the relevant part of the SMS Manual needs to be reviewed in accordance with the ISM Code. Therefore, you will need to submit the relevant part also to the NK Ship Management System Department (SMD)*.
*In the case of vessels for which NK conducts ISM Code reviews.
(Q53_Reference.pdf)

Category
Ch5 Part X(E26)
Tag
Document, ISM Code, SMS Manual
Update date
2024/12/13
Q54 For E26 applicable vessels, is it necessary to apply to NK when installing a new satellite communication system after commissioning?
Shipowner

Not only when installing a new satellite communication system, but also when there is a change in the drawings required to be submitted at the time of newbuilding (e.g., Ship Asset Inventory, Zones and Conduit Diagram), you must submit the modified drawings to the NK Machinery Department and conduct tests based on the test procedure approved in an occasional survey.※

※ The criteria for requesting submission of modified drawings are: When replacing components (applicable items) in the Ship Asset Inventory, and when the Zones and Conduit Diagram changes due to changes in connections.

Category
Ch5 Part X(E26)
Tag
Existing ships, Modification, Test, Survey
Update date
2024/12/13
Q57 Is there a template or sample format for the E26(Chapter 5, Part X) documents to be submitted?
IntegratorSupplier

We have prepared the following samples. Please make sure to understand the contents of each of the information sheets before using them.
-Vessel asset inventory(sample_Vessel Asset Inventory.xlsx)
-Risk assessment for the exclusion of computer-based systems (sample_Risk Assessment for Exclusion of CBS_English.xlsx)

Category
Ch5 Part X(E26)
Tag
Document, Identify, Risk assessment
Update date
2024/12/24
2025/03/03
2025/05/02
Q58 Can multiple VLANs on a single L2 switch be used for logical segmentation? / Can multiple VLANs on a single L2 switch be used for physical segmentation?
(Is a configuration allowed in which security zones are separated using VLANs and the VLANs are connected via zone boundary devices?)
Integrator

By using VLANs, you can create multiple virtual LANs on a single L2 switch and logically segment the network by separating those VLANs with zone boundary devices.
However, physical segmentation is required in 5.4.3(1)(c), Part X of the Rules for the following two cases, and therefore segmentation by VLANs (logical segmentation) built on a single L2 switch is not permitted.
iii) Separating systems that provide required safety functions.
vi) Separating a network (security zone) containing applicable systems from an untrusted network.
(Q58_reference.pdf)

Category
Ch5 Part X(E26)
Tag
Network configuration, Protect, Segmentation
Update date
2025/01/10
Q65 I would like to know about the work and schedule related to UR E26 for shipyards.
Integrator

Please refer to the attached document, which summarizes the typical work and schedule required for shipyards to comply with E26.
(Q65_reference.pdf)

As described on page 2 of the reference material, in order to smoothly proceed with the shipbuilding project, it is important that by the inquiry stage, each manufacturer (supplier) understands the necessity of obtaining E27 approval, and for products that require approval, it is essential that they have already acquired E27 use approval or have the prospect of acquiring it. We believe that shipyards will proactively request potential manufacturers to take necessary actions for this matter. However, if there is any doubt about the manufacturers’ understanding or concerns about their response, please inform the ClassNK Machinery Department. We will provide support, including direct guidance.

Category
Ch5 Part X(E26)
Tag
Document, Compliance process
Update date
2025/02/10
Q67 The explanatory documents and samples for the vessel asset inventory include IP addresses. If an IP address is changed, is it necessary to update the entry on the vessel asset inventory each time?
ShipownerIntegrator

If you include IP addresses in the vessel asset inventory, you need to update it each time.

However, including IP addresses in the vessel asset inventory is not mandatory, so it is also possible not to include them. It is recommended to discuss this matter with the shipyard and the shipowner beforehand.

Category
Ch5 Part X(E26)
Tag
Document, Identify
Update date
2025/02/17
Q68 Normally, chart updates are performed using the ECDIS server, but if communication becomes impossible due to a failure, etc., updates are performed using a USB memory stick. If a USB memory stick is used, is it necessary to revise the Ship Cyber Security and Resilience Program?
Shipowner

If you include the operation of using a USB memory stick for chart updates in advance, we believe that it will not be necessary to revise the Ship Cyber Security and Resilience Program.

Category
Ch5 Part X(E26)
Tag
Document
Update date
2025/02/21
Q69 5.5.4-2(2), Part X

We are considering installing port blockers on physical interface ports such as USB as a method of physically disabling them. Is it acceptable to use dust caps?
IntegratorSupplier

We considery that dust caps do not meet the intended purpose. It is necessary to select blockers that cannot be removed without a dedicated key or tool.

Category
Ch5 Part X(E26)
Tag
Risk assessment
Update date
2025/03/03
Q71 Is compliance with UR E26 not required for ships that have absolutely no internet connectivity?
ShipownerIntegrator

No, compliance is required.
Even for ships not connected to the internet, cybersecurity threats exist, such as malware infections via USB drives and insider threats. UR E26 establish comprehensive cybersecurity requirements, including measures against these threats, and apply regardless of internet connectivity.

Category
Ch5 Part X(E26)
Tag
Applicable ship
Update date
2025/03/24
Q75 5.4.5(1)(c)ii), Part X / E26 4.4.1.3

E26・In the Incident Response Plan (included in the Ship Cyber Security and Resilience Program), reporting/notifying to the the proper authority is required, but where is the specific reporting/notifying destination?

"The Incident response plan shall provide procedures to respond to detected cyber incidents on networks by notifying the proper authority, reporting needed evidence of the incidents..."
Shipowner

E26 provides a framework for cyber resilience of ships, but does not specify the authority to be reported/notified in the event of a cyber incident. It is assumed that this requirement is intended to incorporate the procedure in cases where reporting obligations are stipulated in requirements other than E26 (requirements of the flag/port authority, etc.).

Category
Ch5 Part X(E26)
Tag
Document, Respond
Update date
2025/04/07
Q80 Is training required in UR E26?
Shipowner

Yes.
-UR E26 requires the shipowner to provide periodic training and carry out drills for onboard personnel and other concerned personnel ashore. This is to ensure they are familiar with the computer systems and networks onboard and can properly manage the measures adopted to meet the requirements (E26 5.3 / 2.2.3-5.(4), Part X).
-Personnel with administrator privileges are required to be appropriately trained (E26 4.2.4.3.5 / 5.4.3(4)(c)v)3), Part X).
-It states that users of Intrusion Detection Systems (IDS) should be trained and qualified personnel (E26 4.3.1.3 / 5.4.4(1)(c), Part X).
-However, there are no specific provisions regarding the detailed content of the training itself.

Category
Ch5 Part X(E26)
Tag
Training
Update date
2025/04/28
Q81 Is it required to include content related to training in the Ship cyber security and resilience program?
Shipowner

The Ship cyber security and resilience program is the document that covers the processes and activities for managing cybersecurity and cyber resilience as required by E26 (E26 5.3.1 / 2.2.3-5., Part X). Additionally, E26 5.3 / 2.2.3-5.(4), Part X requires the shipowner to provide periodic training. For these reasons, the Ship cyber security and resilience program needs to include policies, procedures, plans, or other relevant information concerning the implementation of this required training.

Category
Ch5 Part X(E26)
Tag
Document, Training
Update date
2025/04/28
Q83 How long does it take for the Ship Cyber Security and Resilience Program to be approved and returned after submitting it to ClassNK?
Shipowner

The standard review and return period is approximately one month from the receipt of the documents. However, please be aware that programs submitted for the first time by a shipowner may require more time for detailed review, potential inquiries, and subsequent revisions, as they tend to have more points requiring modification. Therefore, we kindly request that you submit the program with ample time to ensure its approval before the first annual survey.

Category
Ch5 Part X(E26)
Tag
Document
Update date
2025/05/12
Q84 It is understood that the "Ship Cyber Security and Resilience Program" must be approved before the first annual survey. Is there a specific period stipulated for the operational records that need to be presented during this survey?
(Is it necessary to have the program approved before the first annual survey to be able to record these operations?)
Shipowner

UR E26 does not stipulate a specific number of days for the operational record-keeping period. However, at the first annual survey, the shipowner is required to present records demonstrating that operations have been conducted in accordance with the approved "Ship Cyber Security and Resilience Program". So, we kindly request that the shipowner ensure sufficient time for program approval, subsequent operations, and the creation of records ahead of the first annual survey.

Category
Ch5 Part X(E26)
Tag
Document
Update date
2025/05/12
Q91 Is it necessary to keep the Incident Response Plan and the Recovery Plan, which are part of the Ship Cyber Security and Resilience Program, in hard copy?
Shipowner

Yes, it is necessary. The requirements stipulate the following:

Incident Response Plan: The Incident response plan is to
be kept in hard copy in the event of complete loss of electronic devices enabling access to it.
(Part X 5.4.5(1)(c)iii) / E26 4.4.1.3)

Recovery Plan: Recovery plans in hard copy onboard and ashore are to be available to personnel responsible for cyber security and who are tasked with assisting in cyber incidents.
(Part X 5.4.6(1)(c)vi) / E26 4.5.1.3)

These are requirements to ensure that response and recovery actions can be carried out reliably, even during a system outage.

Category
Ch5 Part X(E26)
Tag
Document, Respond, Recover
Update date
2025/06/23
Q94 5.4.6(1)(c)iii), Part X / E26 4.5.1.3

Must the Recovery Time Objective (RTO) and Recovery Point Objective (RPO) be determined individually for every computer-based system?
Shipowner

No, it is not strictly necessary to define them individually for every computer-based system.

The RTO and RPO are to be defined within the recovery plan (Ship Cyber Security and Resilience Program) created by the shipowner. It is required to set rational and achievable objectives, considering factors such as the criticality of the system, the impact on the vessel, the realistic time required for recovery, and the frequency of data updates.

Therefore, while it is desirable to set individual objectives for critical systems, it is also permissible to group multiple systems and establish common objectives based on their functions or other relevant factors.

Category
Ch5 Part X(E26)
Tag
Document, Recover, Recovery plan
Update date
2025/07/08
Q98 Are there any specific testing tools that shipyards must use for onboard testing? Also, do these tools need to be certified in advance?
Integrator

No. There are no specific products or models designated for the testing tools, and prior certification for these tools is not required.

However, it is necessary to specify the testing equipment to be used in the Ship Cyber Resilience Test Procedure. [Part X, 2.2.3-4.(2) / E26 5.2.1]

Category
Ch5 Part X(E26)
Tag
Test
Update date
2025/08/12
Q99 In cases where physical segmentation is required, is it necessary to install a separate firewall for each security zone?
Integrator

It is not strictly necessary to install a separate firewall. The requirements can be met as long as physical separation is ensured through the functions and configuration of a single firewall.

[Explanation]
The Rules requires physical segmentation in the following two cases:
-Separating systems that provide required safety functions. (Part X, 5.4.3(1)(c)iii) / E26 4.2.1.3)
-Separating a network (security zone) containing applicable systems from an untrusted network. (Part X 5.4.3(1)(c)vi) / E26 4.2.1.3)
"Physical segmentation" is defined as a network segment where physical components are not shared by other network segments (Part X, 5.2.1(15) / E26 Section 2).

Many firewalls are equipped with functions that treat each physical port as an independent network segment, where physical components are not considered to be shared between the ports. Therefore, for such firewalls, a configuration that connects a "zone providing safety functions" and "another zone" to different physical ports of a single firewall is acceptable as meeting the requirement for physical segmentation.

However, please note that methods that logically divide a network by sharing a single physical port, such as VLANs, are not considered physical segmentation.

Category
Ch5 Part X(E26)
Tag
Network configuration, Protect, Segmentation
Update date
2025/08/18
2025/08/20
Q101 Are penetration tests required during the ship's commissioning phase?
Integrator

No, penetration testing is not explicitly required by the Rules.

What the rules require during the commissioning phase is primarily security capability verification testing. This testing is to confirm that the designed and implemented security capabilities (e.g., access controls, firewall rules, network monitoring functions) operate correctly as specified in the approved documents.

The objective of this verification testing differs from that of a penetration test, which involves actively attempting to breach the system from an attacker's perspective to discover and exploit unknown vulnerabilities.

Category
Ch5 Part X(E26)
Tag
Test, Dos, Protect
Update date
2025/09/04
Q102 Denial of Service (DoS) attack tests and vulnerability scans are also mentioned. Are they different from penetration tests?
Integrator

Their objectives and scope are different.

DoS Attack Test: In accordance with Part X, 5.4.3(2)(d)iii), a test to demonstrate resilience against Denial of Service (DoS) attacks is required. While this can be considered a component of penetration testing, the rules specifically require testing against this particular attack scenario to verify the system's response.

In contrast, a penetration test is a comprehensive assessment that employs a wide range of attack methodologies, which may include DoS attacks, to actively search for and attempt to exploit unknown vulnerabilities to gain unauthorized access.

Category
Ch5 Part X(E26)
Tag
Test, Dos, Protect
Update date
2025/09/08
Q110 5.5.4-2.(4), Part X of the Rules

Is equipment controlled by contact signals from an IAS (Integrated Automation System) (e.g., an LO pump control system) considered an "integrated control system" due to its connection to the IAS? (Does this mean it cannot meet the exclusion criterion in Part X, 5.5.4-2.(4), which states: "The computer-based system is not to be an integrated control system providing more than one of the ship's functions in the scope of applicability of this Chapter"?)
IntegratorSupplier

No, it is not considered an "integrated control system." If the equipment provides only a single function, it meets this criterion (i.e., it can be excluded).

Part X, 5.5.4-2.(4) stipulates that the computer-based system to be excluded must not itself be an integrated system responsible for multiple functions (e.g., both propulsion and steering). If the equipment in question (e.g., LO pump control system) provides only a single function (e.g., lubrication of the main engine), it does not fall under the definition of an "integrated control system," even if it receives contact signals from the IAS.

Furthermore, connection via contact signals (e.g., hardwired connection) is not considered an IP network connection. Therefore, it does not conflict with the requirement for "isolation (i.e., no IP network connection)" stipulated in 5.5.4-2.(1). Consequently, providing other exclusion criteria are also met, the equipment may be excluded from the scope of applicability.

Category
Ch5 Part X(E26)
Tag
Risk assessment
Update date
2025/11/18
Q111 Does EtherCAT communication constitute an "IP network connection" as defined in 5.5.4-2(1), Part X?
IntegratorSupplier

Whether EtherCAT communication constitutes an "IP network connection" depends on its implementation method.
Standard EtherCAT communication (which operates at Layer 2 of the OSI model and does not use the IP protocol) is not considered an "IP-network connections" under 5.5.4-2(1), Part X.

However, if EtherCAT over Ethernet (EoE) is used, where the EtherCAT protocol is encapsulated within UDP/IP packets for communication, this utilizes the IP network and is considered an "IP network connection."

Category
Ch5 Part X(E26)
Tag
Risk assessment
Update date
2025/11/25
Q113 Part X 5.5 / UR E26 Section 6

If a computer-based system is excluded from the application of Part X Chapter 5 (E26) based on the risk assessment under Part X 5.5 (E26 Section 6), is it also excluded from the application of Part X Chapter 3 (IACS UR E22)?
IntegratorSupplier

No, it is not excluded. The exclusion under Part X 5.5 applies only to the requirements of Part X Chapter 5 (E26). The applicability of Part X Chapter 3 (E22) must be determined separately in accordance with the provisions of Chapter 3 (3.1.1 and 3.3).

Category
Ch5 Part X(E26)
Tag
Risk assessment
Update date
2025/12/11
Q114 Part X 5.5 / UR E26 Section 6

For computer-based systems excluded from the application based on the risk assessment under Part X 5.5 (E26 Section 6), is it correct to assume that UR E27 (Part X Chapter 4) approval is not required?
IntegratorSupplier

Your understanding is correct. For computer-based systems excluded from the scope of Part X Chapter 5 in accordance with Part X 5.5, UR E27 (Part X Chapter 4) approval is not required.

Category
Ch5 Part X(E26)
Tag
Risk assessment
Update date
2025/12/11
Q115 Part X 5.5 / UR E26 Section 6

Who carries out the risk assessment for the exclusion of computer-based systems, and who verifies it?
IntegratorSupplier

The Integrator (typically the Shipyard) is to carry out the risk assessment and submit the results (Risk assessment for the
exclusion of computer-based systems) to the Society. ClassNK will verify and approve the content. (Refer to Part X, 5.5.3-1. and Table X2.4)

Suppliers wishing to have their products excluded are strongly recommended to consult with the Integrator to ensure that their products are included and appropriately evaluated in the said risk assessment.

Category
Ch5 Part X(E26)
Tag
Risk assessment
Update date
2025/12/16
Q116 Part X 5.5 / UR E26 Section 6

Is the Shipowner required to review the "Risk assessment for the exclusion of computer-based systems" during the operational phase?
Shipowner

The Rules require the Shipowner to update the risk assessment during the ship's operational life (refer to Part X, 5.5.3-2).

However, as long as the conditions for exclusion (such as isolation from networks and disabling of physical ports) are maintained, it is considered rare that the risk assessment needs to be revised. Please notify the Society and submit the updated risk assessment only when the risk level may exceed the acceptable threshold due to changes in system configuration, etc.

Category
Ch5 Part X(E26)
Tag
Risk assessment
Update date
2025/12/26
Q117 Part X 5.5 / UR E26 Section 6

In what specific cases is it necessary for the Shipowner to review the "Risk assessment for the exclusion of computer-based systems" during the operational phase?
Shipowner

Basically, a review is required when there are changes to the "isolation status" or "physical management status" of the system. Specifically, the following cases are envisaged:

1. Changes in System Configuration (Changes in Connectivity)
-When a previously standalone system is connected to a network.
-When disabled physical ports are enabled for use.

2. Changes in Operational Environment (Changes in Physical Access)
-When a location that was previously locked becomes constantly open.
-When the system is relocated to an area accessible by unauthorized personnel.

3. Discovery of New Vulnerabilities (Rare Case)
-When a critical vulnerability is discovered in the system, and it is determined that current physical protection measures (such as locking and isolation) alone are insufficient to keep the risk at an acceptable level.

Please note that as long as no such changes are made and the approved status (isolation, locking, etc.) is maintained, it is considered that in most cases, periodic review work will be substantially unnecessary.

Category
Ch5 Part X(E26)
Tag
Risk assessment
Update date
2026/01/05
Q118 Part X 5.4.3(2)(d)iii)1)

Regarding the "Test denial of service (DoS) attacks targeting zone boundary protection devices," what specific scope and intensity of testing is required?
Integrator

The purpose of this test is to verify that zone boundary protection devices (e.g., firewalls) "respond" as designed in the approved documents when subjected to a DoS attack (e.g., traffic load).
Specifically, the test should be conducted at a level sufficient to confirm the following:
-Operation of Defense Mechanisms: Verify that defense functions, such as blocking traffic or limiting bandwidth, operate correctly when subjected to intentional communication loads (e.g., SYN flood attacks).
-Detection and Recording: Verify that alarms are triggered and logs (audit records) are generated appropriately when an attack occurs. (Refer to Part X, 5.4.4)
-Maintenance of Security State: Verify that security capabilities are maintained even under traffic load. (Ensure that the device does not enter an insecure state, such as "failing open" and allowing blocked traffic to pass due to overload.)

Category
Ch5 Part X(E26)
Tag
Test, Dos, Protect
Update date
2026/01/15
Q119 Part X 5.4.3(2)(d)iii)2)

Regarding the DoS attack test (network flooding and application layer attacks) required in the Ship Cyber Resilience Test Procedure during the commissioning phase, what specific content and load levels should be applied?
Integrator

The Society recommends reproducing a "reasonably high load condition in actual operation" of the target system and verifying its behavior. Specifically, based on the definitions in the Rules, the test content should include the following perspectives:

1. Network Flooding (Consuming available capacity)
-Method: Generate traffic at a level that pressures the actual communication bandwidth (e.g., loads exceeding set bandwidth limits or alarm thresholds).
-Verification: Confirm that network alarms (Part X, 5.4.4(1)(c)i)5)) are correctly triggered and that critical control communication is maintained even under high load (effectiveness of QoS, etc.).

2. Application Layer Attacks (Consuming processing capacity)
-Method: Use valid protocols utilized by the target equipment (Modbus/TCP, HTTP, etc.) and apply a load by sending a large volume of requests in a short time to consume the endpoint's CPU or memory resources.
-Verification: Confirm that the equipment does not freeze or run out of control and that it processes (or limits) requests appropriately. If the equipment malfunctions, it is acceptable if it is confirmed that it falls back to a safe state (minimal risk condition) (Part X, 5.4.5(4)).

Note that if equivalent tests were successfully conducted by the supplier (manufacturer) during the approval process for Part X, Chapter 4 (UR E27), the tests on board may be omitted.

Category
Ch5 Part X(E26)
Tag
Test, Dos, Protect
Update date
2026/01/20
Q122 Is it acceptable to submit a conventional electric cable wiring diagram as the "Zone and Conduit Diagram" required by Part X Chapter 5?
Integrator

In principle, submitting a conventional electric cable wiring diagram as a "Zone and Conduit Diagram" without modification is not acceptable. There are two main reasons for this:

1. Difference in Information Requirements The "Zone and Conduit Diagram" must clearly visualize the configuration of security zones, communication between zones (conduits), and connections to untrusted networks (refer to Part X, 5.4.3(1)(d)i)2)). Conventional wiring diagrams primarily show physical connections and power distribution. They typically lack the necessary information for evaluating cybersecurity measures, such as "logical grouping (zones)" and "data flows (conduits)," or are often too cluttered to be legible for this purpose.

2. Consistency with Other Documents The names of systems and equipment used in the "Zone and Conduit Diagram" must be fully consistent with those in other submitted documents, such as the "Ship Asset Inventory." The names and symbols used in conventional wiring diagrams often do not match these documents, making it difficult to verify consistency from a cybersecurity perspective.

Category
Ch5 Part X(E26)
Tag
Document, Protect
Update date
2026/02/10
Q123 Is the installation of an Intrusion Detection System (IDS) mandatory?
IntegratorSupplier

No, it is not mandatory.
However, if an IDS is implemented for computer-based systems within the scope of Chapter 4/5 of Part X, it must comply with the following requirements based on the Rules (5.4.4(1)(c)ii), Part X):
-The IDS must be qualified by the suppliers of the respective computer-based systems.
-The IDS must be passive and not activate protection functions that may affect the performance (intended operation) of the computer-based systems.
-The users of the IDS should be trained and qualified personnel.

Furthermore, the implemented IDS must be verified by the Society (5.4.4(1)(d)iii)2), Part X). Specifically, the following actions are required:
-Submission of relevant documents: While no special documents dedicated to the IDS are required, information regarding the IDS (including the information mentioned above) must be included in documents such as the "Cybersecurity design description (CSDD)".
-Surveys/tests onboard: Technical tests, such as demonstrating the passive nature of the IDS, may be omitted if they have already been performed during the certification tests under Chapter 4 of Part X (5.4.4(1)(d)iii)1), Part X). However, the final onboard survey to verify that the IDS is correctly implemented and appropriately connected to the network as designed (e.g., checking the installation status and configuration) cannot be omitted.

Category
Ch5 Part X(E26)
Tag
Test, Detect
Update date
2026/02/20
Q124 Part X, 5.4.4
Is the installation of an NMS (Network Monitoring System) mandatory?
Integrator

No, it is not mandatory.
An NMS generally means a system that continuously monitors the status of onboard networks and connected devices, including communication conditions and alarms. However, Chapter 5 of Part X does not require the installation of a specific item of equipment or system called an “NMS.”
On the other hand, it is required that networks within the scope of Chapter 5 of Part X are monitored and that alarms are generated in the event of failure or degraded functionality. Therefore, some means to achieve these functions is necessary, but it does not have to be an NMS.

Category
Ch5 Part X(E26)
Tag
Detect
Update date
2026/03/13
Q125 Part X, 5.4.3(6)(d)iii)

Regarding the onboard tests for "Control of remote access and communication with untrusted networks" required during the commissioning phase, is it impossible to conduct the tests until the ship's satellite communication system is contracted and activated?
Integrator

Tests can be conducted even if the satellite communication system is not yet contracted or activated, provided that compliance with the requirements can be demonstrated based on the approved test procedures.
Instead of the actual satellite communication line, a dummy line (e.g., a temporary shore network or mobile router) can be connected to simulate an "untrusted network" and establish an external communication environment for testing.

However, even when using a dummy line, the rules and network settings of the zone boundary devices (e.g., firewalls) installed on board must reasonably represent the actual production environment intended for satellite communication (i.e., settings based on the approved "Cybersecurity design description"). Furthermore, it is necessary to demonstrate that the regulatory requirements (such as multi-factor authentication for remote users and explicit access approval) are satisfied.

Category
Ch5 Part X(E26)
Tag
Test
Update date
2026/03/27
Q126 What is the difference between a security zone and a network segment?
ShipownerIntegrator

A security zone is a grouping of systems to which the same security requirements and access control policy are applied.
A network segment, on the other hand, is a communication division within the network architecture.
Accordingly, a zone is a security-based classification, whereas a segment is a network design-based classification.
They may coincide in some cases, but they are not necessarily the same.
For example, a single security zone may include multiple network segments.
Conversely, dividing a network into segments does not automatically mean that separate security zones have been established.

In practice, the distinction may be understood as follows:
-Zone: a classification showing which systems are subject to the same security requirements and access control policy
-Segment: a classification showing how the network is actually arranged or separated to implement that design

Category
Ch5 Part X(E26)
Tag
Term
Update date
2026/04/09
Q131 For a ship to which UR E26/E27 are not applicable, such as an existing ship whose contract for construction was concluded before 1 July 2024, is compliance with UR E26/E27 newly required due to a change of shipowner or ship management company?
Shipowner

No. Compliance with UR E26/E27 (Part X, Chapters 5/4 of the Rules) is not required solely due to a change of shipowner or ship management company. UR E26/E27 generally apply to applicable ships contracted for construction on or after 1 July 2024, and are not applied to existing ships or non-applicable ships due to a change of shipowner or ship management company.

Category
Ch5 Part X(E26)
Tag
Existing ships
Update date
2026/06/08
Q133 What should a ship management company do if a ship to be newly managed appears to be subject to E26/E27 but has not been brought into compliance?
Shipowner

For ships for which E26/E27 (Part X, Chapters 4 and 5 of the Rules) compliance is mandatory, the required plan approval and surveys are carried out, and the “CybR” notation is assigned. Therefore, it is not normally expected that such a ship would be found non-compliant at the time management is taken over. When taking over management, please first confirm whether the ship is subject to E26/E27 and whether the “CybR” notation has been assigned. If the ship appears to be subject to E26/E27 but the “CybR” notation or compliance status cannot be confirmed, the shipowner should consult the Society.

Category
Ch5 Part X(E26)
Tag
Existing ships
Update date
2026/06/22
Q134 For a ship subject to E26/E27, if the ship management company changes, is a new Ship Cyber Security and Resilience Program required to be prepared and approved? By when must approval be obtained from the Society?
Shipowner

In principle, the new management company is required to prepare a new Ship Cyber Security and Resilience Program and obtain approval from the Society.
However, if the Society-approved Program is taken over from the previous management company and the new management company continues to manage the ship in accordance with the Program, preparation and approval of a new Program are not required.
If the new management company does not have such a Society-approved Program, the Program is to be submitted to the Society and approved by the next periodical survey (Annual Survey, Intermediate Survey or Special Survey). During the survey, records demonstrating that cyber resilience management has been implemented in accordance with the approved Program are to be verified.

Category
Ch5 Part X(E26)
Tag
Existing ships
Update date
2026/06/26
Ch4 Part X(E26) 1 items
Q17 What is the existing class notation "CybR-G"?
ShipownerIntegrator

The notation "CybR" (abbreviated of Cyber Resilience) is affixed to the ships that are subject to the application of Chapter 4 and Chapter 5 of Part X which incorporate IACS UR E26 Rev.1 and E27 Rev.1.

On the other hand, the notation "CybR-G" (abbreviated of Cyber Resilience-Guideline) is affixed to ships that conform to our non-mandatory guideline "Cybersecurity Design Guidelines for Ships".

Category
Ch5 Part X(E26)
Tag
Applicable ship, Notation
Update date
2024/08/28
Ch4 Part X(E26 & E27) 16 items
Q10 4.1.2-2., Part X of the Rules

Are the following (Example) systems considered outside the scope of the requirements?

(Example)
Packaged air conditioner
Food refrigeration unit
Passenger elevator
EGCS (Exhaust Gas Cleaning System)
SCR
EGR
BWTS
Incinerator
Bilge alarm
Bilge separator
FO/LO purifier
Sewage treatment plant
Fresh Water Generator (excl. main boiler vessel)
Anemometer / Wind speed and direction meter (excl. DPS vessel)
Provision crane
E/R crane
ShipownerIntegratorSupplier

These systems are not considered OT systems under 4.1.2-2, Part X, so they are basically not applicable. However, they may still be subject to the requirements depending on the system and/or network configuration of the system and/or the ship.
For the details, please refer to the attached file.
(Q10_reference.pdf)

Category
Ch4 Part X(E26 & E27)
Tag
Applicable system
Update date
2024/09/27
2025/01/17
2025/02/13
Q13 4.1.2-1., Part X of the Rules

Are the requirements mandatory to ships not engaged in international voyages?
ShipownerIntegrator

The requirements are not mandatory for ships not engaged in international voyages.

Category
Ch4 Part X(E26 & E27)
Tag
Applicable ship
Update date
2024/08/28
Q14 4.1.2-1.(1)(e), Part X of the Rules

Do CTVs fall under the category of "Self-propelled mobile offshore units engaged in construction"?
ShipownerIntegrator

We consider that CTVs do not fall under the category of "Self-propelled mobile offshore units engaged in construction.

Category
Ch4 Part X(E26 & E27)
Tag
Applicable ship
Update date
2024/08/28
Q15 4.1.2-1., Part X of the Rules

Are the requirements mandatory to CTVs?
ShipownerIntegrator

We consider that the requirements are mandatory for CTVs of 500 GT and upwards engaged in international voyages.

Category
Ch4 Part X(E26 & E27)
Tag
Applicable ship
Update date
2024/08/28
Q64 In 4.1.2(2), Part X, "other systems" are defined as "any other systems connected to OT systems, either permanently or temporarily (e.g. during maintenance)". Does this include a work PC that a service engineer of an OT system supplier brings on board and connects to the OT system to perform maintenance? For this reason, is the OT system considered to be connected to an untrusted network?
Supplier

The work PC that a service engineer from an OT system supplier brings on board and connects to the OT system to perform maintenance is not considered to be an "other systems".
-It is not necessary to obtain E27 approval for the work PC itself. (However, the supplier is responsible for ensuring appropriate cybersecurity management of the work PC.)
-Subjected OT system is not considered to be connected to an untrusted network.

Category
Ch4 Part X(E26 & E27)
Tag
Applicable system, Type approval
Update date
2025/01/31
Q77 Is E27 approval required for PMS Software (Planned Machinery Maintenance Scheme Management Software)?
Shipowner

In principle, E27 approval is not required for PMS software itself or for PCs with PMS software installed.

However, if it is placed in the same security zone as a system subject to E26 (Applicable OT system), the PMS software must also meet E27 requirements. (See E26 4.2.1.3 / 5.4.3(1)(c)i), Part X)

Category
Ch4 Part X(E26 & E27)
Tag
Applicable system
Update date
2025/04/15
Q78 Is a system that incorporates a logic IC considered a computer based system?
IntegratorSupplier

Simply integrating a logic IC is not considered a system as a “computer based system” as defined in UR E26 and UR E27.

Category
Ch4 Part X(E26 & E27)
Tag
Applicable system
Update date
2025/04/15
Q85 Are E26 and E27 specifically intended for autonomous ships (such as Maritime Autonomous Surface Ships (MASS), etc.)? Furthermore, were these URs developed with the future operation of autonomous ships in mind?
ShipownerIntegrator

As of Revision 1, UR E26 and UR E27 do not establish requirements specifically for autonomous ships (including MASS, etc.). It is understood that these URs are not designed with the application to ships utilizing specific advanced technologies in mind, but rather they define general minimum requirements for cyber resilience on board ships.

Category
Ch4 Part X(E26 & E27)
Tag
Applicable ship
Update date
2025/05/19
Q86 4.1.2-1., Part X of the Rules

Do IACS UR E26/E27 apply to ships subject to the IP Code?

(IP Code = International Code of Safety for Ships Carrying Industrial Personnel)
ShipownerIntegrator

The application of the IP Code itself is not a direct condition for the applicability of E27 (Chapter 4, Part X) and E26 (Chapter 5 Part X).

However, if the said ship subject to the IP Code meets all of the following conditions, the requirements apply:
-The ship's contract for construction is dated on or after July 1, 2024.
-The ship is engaged on international voyages.
-The ship has a gross tonnage of 500 or upwards.

Category
Ch4 Part X(E26 & E27)
Tag
Applicable ship
Update date
2025/05/26
Q90 Is CCTV considered an applicable OT system under UR E26/E27?
ShipownerIntegratorSupplier

The applicability of CCTV is considered to depend on its intended purpose.

Case 1: For general monitoring purposes.
CCTV installed for general purposes such as ship security or work monitoring is not considered an applicable OT system. (However, if it is placed in the same security zone as an applicable OT system, it must meet the E26/27 (Chapter 5/4, Part X) requirements.)

Case 2: When installed as an alternative means of bridge visibility.
CCTV installed as an essential alternative equipment to ensure the field of vision from the bridge as required by the SOLAS Convention is considered an applicable OT system. (However, it can be exempted from the application if it satisfies the exclusion requirements in Part X, 5.5 / E26 Section 6.)

When used for fire detection please see Q108.

Category
Ch4 Part X(E26 & E27)
Tag
Applicable system, CCTV
Update date
2025/06/16
2025/06/17
2025/10/20
Q93 4.1.2-1., Part X of the Rules

Are tugboats subject to the application of Part X Chapter 4/5(UR E27/E26)?
ShipownerIntegrator

Tugboats that meet all of the following conditions are considered to be subject to the application:

-The ship is contracted for construction on or after 1 July 2024.
-The ship is engaged in international voyages.
-The gross tonnage is 500 GT or upwards.

Category
Ch4 Part X(E26 & E27)
Tag
Applicable ship
Update date
2025/07/08
Q103 Is the control system for a wind-assisted propulsion system, to which the "Guidelines for Wind-Assisted Propulsion Systems for Ships (Edition 2.2)" apply, subject to the cyber resilience requirements (Rules for the Survey and Construction of Steel Ships, Part X, Chapters 4 and 5)?
IntegratorSupplier

The control system for a wind-assisted propulsion system installed based on the "Guidelines for Wind-Assisted Propulsion Systems for Ships (Edition 2.2)" is, in principle, outside the scope of application of Chapter 4 (UR E27) and Chapter 5 (UR E26) of Part X of the Rules.

However, if it is installed in the same security zone as an applicable computer-based system (applicable OT system), it must comply with the requirements of E26/27 (Part X, Chapters 5/4).

Category
Ch4 Part X(E26 & E27)
Tag
Applicable system, WAPS
Update date
2025/09/16
Q107 Is it necessary for a maintenance PC used by a user (e.g., crew) to have approval under Chapter 4 of Part X (UR E27)? Also, if this PC is connected to an OT system, is the OT system considered to be connected to an untrusted network?
Supplier

Under certain conditions, Chapter 4 of Part X (E27) approval for the PC is not required, and it is not considered a "connection to an untrusted network."

[Conditions]
-Limited Purpose: The connection is strictly limited to maintenance and servicing tasks, such as software updates, configuration changes, or log retrieval.
-PC Management: The PC is under the shipowner's control and is operated under appropriate security policies, including malware protection.
-OT System Countermeasures: The target OT system implements the security capabilities required by Table X4.1, No. 10 "Use control for portable and mobile devices " in Part X, and has functions to allow connection only from authorized devices, including the said PC.

Please note that this applies only to temporary connections for maintenance and servicing purposes. Permanent connections or use for purposes other than maintenance are not covered by this interpretation.

Category
Ch4 Part X(E26 & E27)
Tag
Applicable system, Untrusted network
Update date
2025/10/14
Q108 Is CCTV used for early fire detection considered an applicable OT system under UR E26/E27?
ShipownerIntegratorSupplier

Generally, it is considered that CCTV is mostly installed and used within the scope of Case 1 in Q90 (for general monitoring purposes).

However, if CCTV is installed as an alternative design, approved by the flag administration, to substitute for a fire detection system required by conventions such as SOLAS, it effectively functions as a fire detection system (Part X, 4.1.2-2.(1)(e) / E26 1.3.2 a)). In this case, it is considered an applicable OT system. (However, it can be exempted from the application if it satisfies the exclusion requirements in Part X, 5.5 / E26 Section 6.)

Category
Ch4 Part X(E26 & E27)
Tag
Applicable system, CCTV
Update date
2025/10/20
Q132 For determining the applicability of Part X, Chapters 4 and 5 of the Rules (UR E27/E26), what contract date does the “date of contract for construction” refer to?
Shipowner

The “date of contract for construction” generally means the date on which the contract to build the ship is signed between the prospective owner or other relevant contracting party and the shipbuilder. It does not mean the date of a ship management agreement, charter party, equipment purchase contract, or delivery of the ship. The Society confirms the applicability of the Rules based on the date of contract for construction declared by the applicant for classification and stated in the application for classification or other relevant documents. If the ship management company or other relevant party is not aware of this date, please confirm the date stated in such documents with the shipowner or shipbuilder. For the treatment of the date of contract for construction for a series of ships, optional ships, additional ships, or changes in ship type, please also refer to the ClassNK Technical Information TEC-0704.
(Q132_reference(TEC-0704).pdf)

Category
Ch4 Part X(E26 & E27)
Tag
Applicable ship
Update date
2026/06/11
Q136 Is E27 (Chapter 4, Part X) approval required for an electronic inclinometer?
IntegratorSupplier

An electronic inclinometer is navigational equipment required by SOLAS regulation V/19.2.12, as amended by resolution MSC.532(107), for container ships and bulk carriers of 3,000 gross tonnage and upwards constructed on or after 1 January 2026. An electronic inclinometer installed in accordance with this requirement falls under applicable OT systems subject to Chapters 4 and 5, Part X (UR E27 and E26); therefore, if it is equipped with a computer, E27 (Chapter 4, Part X) approval is required.
(However, if the exclusion requirements in 5.5, Part X / E26 Section 6 are satisfied, it may be excluded from application and E27 (Chapter 4, Part X) approval is not required.)

Category
Ch4 Part X(E26 & E27)
Tag
Applicable system
Update date
2026/07/08
Ch4 Part X(E27) / Ch5 Part X(E26) 15 items
Q25 What should the integrator (shipyard) do when equipment that has not have type approval certificate of IACS UR E27 is installed on a ship?
Integrator

The first step is to conduct network isolation, etc., and consider exemptions based on risk assessment to exclude the application. (5.5, Part X)

If exemptions are not possible, approval for individual products must be obtained, the manufacturer must submit the documents required in E27, and the manufacturer must undergo a witnessed survey before shipment.

Category
Ch4 Part X(E27) / Ch5 Part X(E26)
Tag
Compliance process
Update date
2024/10/02
Q35 Are the applicable systems common between UR E22 (Chapter 3 of Part X) and UR E26/E27 (Chapter 4/5 of Part X)?
IntegratorSupplier

Some systems are subject to both UR E22 and UR E26/E27, but they are basically different.

In UR E22 rev.3, the applicable equipment and systems will be determined by the integrator. For details, please refer to NK Technical Information TEC-1348.

Category
Ch4 Part X(E27) / Ch5 Part X(E26)
Tag
Applicable system
Update date
2024/10/29
2025/06/19
Q37 Is it correct that the alarm function triggered by excessive bandwidth is not required by UR E27?
IntegratorSupplier

In addition to the requirements of E27 (Part X, Chapter 4), the following provisions exist, so it is considered necessary to consider them in the design.
- The requirements in 5.4.4(1)(c)i), Part X of the Rules:
i) Measures to monitor networks in the scope of applicability of this Chapter are to have the following capabilities:
5) generate alarm if utilization of the network’s bandwidth exceeds a threshold specified as abnormal by the supplier (see 3.7.2-1).
- The requirements in 3.7.2-1, Part X of the Rules for Category II or III products:
Data links are to comply with following (1) to (5). In addition, loss of a data link is to be specifically addressed in risk assessment analysis / FMEA (see 3.4.2-3).
(3) Data links are to be provided with means for preventing or coping with excessive communication rates.
(5) Detected failures are to initiate alarms.

Category
Ch4 Part X(E27) / Ch5 Part X(E26)
Tag
Detect
Update date
2024/10/29
Q41 Part X, Chapter 5 requires the preparation of a Ship Cyber Security and Resilience Program. However, it is my understanding that this program has not yet been created at the time of ship completion. (I understand that the shipowner creates it and obtains NK approval after the ship enters service and before the first annual survey.) Even in this case, is it correct to understand that the notation "CybR" will be affixed to the Classification Characters at the time of completion?
ShipownerIntegrator

Your understanding is correct. Part X, Chapter 5 requires that the Ship Cyber Security and Resilience Program be created by shipowner and approved by ClassNK by the first annual survey. At the time of ship completion, the notation of “Cyber Resilience” (abbreviated to CybR) will be affixed to the Classification Characters even if the program is not yet available.

Category
Ch4 Part X(E27) / Ch5 Part X(E26)
Tag
Compliance process, Notation
Update date
2024/11/01
Q55 Do existing vessels (those with construction contracts concluded before July 1, 2024) need to comply with E26/E27?
Shipowner

No action is required.

Category
Ch4 Part X(E27) / Ch5 Part X(E26)
Tag
Existing ships
Update date
2024/12/13
Q60 Is E27 (Chapter 4 of Part X) approval necessary for the following products?

-Rate-of-turn indicator
-Engine telegraph
IntegratorSupplier

Since those products fall under the applicable OT systems, it is necessary to obtain approval under E27 (Chapter 4, Part X) if they are computer-based systems.
(However, if the exclusion provisions of E26 Section 6 (5.5, Part X) are satisfied, these products will be excluded from the application and approval under E27 (Chapter 4, Part X) will not be required.)

Category
Ch4 Part X(E27) / Ch5 Part X(E26)
Tag
Applicable system, Risk assessment
Update date
2025/01/17
Q61 ・Is it necessary to have a qualified person to comply with E26/E27(Chapter 4/5 of Part X)?
・Are there any qualifications required to carry out the tests required by E26/E27(Chpater 4/5 of Part X)?
・Is it necessary to request tests or evaluations by an accredited testing laboratory, etc. to carry out the tests required by E26/E27(Chapter 4/5 of Part X)?
ShipownerIntegratorSupplier

It is not required to use a qualified person or a certified testing organization.

Category
Ch4 Part X(E27) / Ch5 Part X(E26)
Tag
Test
Update date
2025/01/24
Q70 Even if an applicable OT system communicates P2P with a system that has not obtained E27 approval, can the OT system be treated as having no communication with an untrusted network by installing a firewall on the communication path?
IntegratorSupplier

When an applicable OT system communicates P2P (Peer to Peer) with a system that has not obtained E27 approval (a computer-based system on an untrusted network), the OT system is considered to have communication with an untrusted network, even if there is a firewall with E27 approval on the communication path.

Therefore, the OT system must obtain E27 approval for connection with an untrusted network, or the communicating system must obtain E27 approval.
(Q70_reference.pdf)

Category
Ch4 Part X(E27) / Ch5 Part X(E26)
Tag
Network configuration, Applicable system, Type approval, Untrusted network
Update date
2025/03/10
Q74 If an OT system subject to UR E26/E27 is replaced or newly installed on an existing ship (a ship for which the shipbuilding contract was concluded before July 1, 2024), is compliance with UR E26/E27 required?
Shipowner

No, it is not required.

Category
Ch4 Part X(E27) / Ch5 Part X(E26)
Tag
Existing ships, Modification
Update date
2025/04/03
Q79 In a network configuration shown in the attachment (Q79_reference.pdf), what kind of operations possible from the Remote PC would lead to the OT system being considered as having a connection to an untrusted network?
IntegratorSupplier

If the remote PC can perform any operations on the OT system, it implies that the remote PC has access to the OT system. Therefore, in such cases, the OT system is considered to have a connection to an untrusted network.

Category
Ch4 Part X(E27) / Ch5 Part X(E26)
Tag
Network configuration, Untrusted network
Update date
2025/04/22
Q89 What is the relationship between IACS URs E26, E27 and the Rules for the Survey and Construction of Steel Ships?
ShipownerIntegratorSupplier

The IACS (International Association of Classification Societies) Unified Requirements (URs) E26 and E27 are incorporated into Part X of Nippon Kaiji Kyokai's (ClassNK) Rules for the Survey and Construction of Steel Ships.

The specific correspondence is as follows:
UR E27 corresponds to Part X, Chapter 4, "CYBER RESILIENCE OF ON-BOARD SYSTEMS AND EQUIPMENT" of the Steel Ship Rules.
UR E26 corresponds to Part X, Chapter 5, "CYBER RESILIENCE OF SHIPS" of the Steel Ship Rules.

(Q89_reference.pdf)

Category
Ch4 Part X(E27) / Ch5 Part X(E26)
Tag
Term
Update date
2025/06/10
Q106 Are the requirements based on UR E26 and E27 (Part X, Chapters 5 and 4 in ClassNK rules) different among IACS member societies?
ShipownerIntegratorSupplier

Basically, the minimum requirements based on each UR are consistent across all IACS member societies.

UR E26 and E27 are Unified Requirements (URs) established by the International Association of Classification Societies (IACS). All member societies are required to incorporate these URs into their own rules.

However, it is possible for an individual classification society to impose additional requirements on top of the URs, or for interpretations and operational details to differ. For specific details regarding a particular society's rules, please contact that society directly.

For instance, ClassNK has incorporated UR E27 into Part X, Chapter 4 and UR E26 into Part X, Chapter 5 of our rules. While there may be minor differences in structure or phrasing, the technical requirements are fully aligned with the respective URs.

Category
Ch4 Part X(E27) / Ch5 Part X(E26)
Tag
General
Update date
2025/10/01
Q120 Is compliance with Chapters 4 and 5 of Part X (UR E27 and E26) unnecessary for systems classified as Category I or considered outside the scope of Chapter 3 of Part X (UR E22)? Also, is a risk assessment for exemption unnecessary in such cases?
IntegratorSupplier

Compliance may be required, as the classification under Chapter 3 of Part X (UR E22) and the scope of applicability for Chapters 4 and 5 of Part X (UR E27 and E26) are determined based on different criteria.

Chapters 4 and 5 of Part X apply to OT systems and other relevant systems specified in 4.1.2-2 of Part X. Even if a system is classified as Category I or is outside the scope of Chapter 3 of Part X, it falls within the scope of Chapters 4 and 5 if it meets the criteria in 4.1.2-2.
Furthermore, if you wish to exclude a system that falls within the scope of 4.1.2-2 from the requirements of the Rules, the system must meet the exclusion criteria in 5.5 of Part X (UR E26 Section 6), regardless of its category under Chapter 3. In such cases, the system needs to be included in the "Risk assessment for the exclusion of computer-based systems" prepared by the shipyard (integrator).

Category
Ch4 Part X(E27) / Ch5 Part X(E26)
Tag
Applicable system, Risk assessment
Update date
2026/01/27
Q121 Part X, Table X4.1 / 5.5.4-2.(2)

Can assigning an incorrect or random IP address to an unused interface be accepted for the following purposes?
1. To be considered "logical disabling" as required by Part X, 5.5.4-2.(2).
2. To treat security capability requirements (e.g., Table X4.1) for that interface as "Not Applicable (N/A)".
IntegratorSupplier

No, it is not accepted in either case.
Merely changing the IP address leaves the interface electrically and logically active. Risks such as discovery via scanning tools and exploitation remain, so it is still considered part of the attack surface.
"Logical disabling" under the Rules refers to stopping the function of the interface itself through OS or firmware settings.

Note that this does not preclude changing IP addresses as part of defense-in-depth measures, for instance, to prevent accidental connection.

Category
Ch4 Part X(E27) / Ch5 Part X(E26)
Tag
Type approval, Risk assessment
Update date
2026/02/06
Q128 Do the requirements of E26/E27 (Part X, Chapters 5/4 of the Rules) include countermeasures against GPS spoofing or jamming?
Shipowner

No. E26/E27 do not directly require countermeasures against GPS spoofing or jamming themselves.
These requirements mainly address cyber risks related to on-board computer-based systems and equipment, and their interfaces, including measures such as network protection, access control, response, and recovery.
GPS spoofing and jamming concern the authenticity or availability of satellite positioning signals received from outside the ship, and are not direct subjects of these requirements.

Category
Ch4 Part X(E27) / Ch5 Part X(E26)
Tag
Spoofing, Jamming, GPS
Update date
2026/04/24