The headline four

The frameworks every operator is asked about.

Every fleet we work with faces these four — usually in the same year, sometimes the same week. Navis Arca answers all four with the same live evidence base, exportable as a polished PDF in two clicks. Per-class-society notations, port-state regimes, vetting bodies and underlying standards are covered in the matrix below.

IACS UR E26 / E27

Cyber Resilience of Ships & Onboard Systems

The International Association of Classification Societies' Unified Requirements for cyber resilience of new-build ships (UR E26) and the systems aboard them (UR E27). Mandatory for vessels contracted on or after 1 July 2024 across IACS member societies — DNV, ABS, Lloyd's Register, Bureau Veritas, ClassNK, RINA, KR and others.

Asset inventory Network segregation evidence Patch management Incident response logs Tamper-proof audit

TMSA 3 — Element 13

Maritime Security & Cyber Risk Management

OCIMF's Tanker Management & Self-Assessment, third edition. Element 13 is the cyber-risk element scored against by oil-major vetting inspectors before a tanker is chartered. Stage-1 and Stage-2 questions cover policy, training, technical controls and audit — the same areas Navis Arca generates evidence for automatically.

Endpoint protection Access control Removable media Vulnerability management Audit log

BIMCO Guidelines V5

Cyber Security Onboard Ships

The fifth edition of the industry-wide guidelines published by BIMCO together with ICS, INTERTANKO, INTERCARGO, OCIMF and other maritime associations. Practical, operationally grounded, and directly referenced by class societies — Navis Arca implements the technical controls the guidance calls for.

Identify Protect Detect Respond Recover

IMO MSC-FAL.1/Circ.3 · Resolution MSC.428(98)

Maritime Cyber Risk Management in SMS

The International Maritime Organization's resolution requiring cyber risk to be addressed within a vessel's Safety Management System under the ISM Code. In effect since the first annual DOC verification after 1 January 2021. Navis Arca produces the operational evidence flag-state and port-state inspectors look for.

Risk assessment Procedures Roles & responsibilities Drills & review
The full coverage matrix

Beyond the headline four. Everything else operators face.

Every framework below is reachable from the same agent telemetry that powers the headline four. We use three coverage tiers so you know exactly what arrives turnkey, what's ready on request, and what's a documented alignment.

● Live · pre-mapped ● Coverage-ready · evidence on request ● Aligned · controls map cleanly
Class society notations

Per-society cyber notations

Beyond the IACS unified requirements, each society publishes its own optional notation. Navis Arca produces evidence that maps to the technical control elements of each.

  • DNV — Cyber Secure (Basic / Essential / Advanced) Coverage-readyClass notation under DNV-RU-SHIP Pt.6 Ch.5.
  • ABS — CyberSafety® (CS1 / CS2 / CS3) & CyberSecurity Notation Coverage-readyABS Guide for Cybersecurity Implementation.
  • Lloyd's Register — Cyber-secure descriptive note Coverage-readyLR ShipRight Cyber-secure provisions.
  • Bureau Veritas — Cyber Managed / Cyber Secure / Cyber Resilient Coverage-readyBV NR 659 Rules on cyber security.
  • ClassNK — Cyber Security Approach (CSA) AlignedGuidelines for Designing Cyber Security Onboard Ships.
  • RINA — Cyber Resilience notation AlignedRINA Rules for Classification of Ships, Pt F Ch 14.
  • Korean Register (KR) — Cyber Resilience & CR(S+) AlignedKR Guidance for Maritime Cyber Resilience.
Charterer & vetting

Industry vetting bodies

The questions vetting inspectors ask before your tonnage is accepted on a charter — answered with evidence, not assertions.

  • OCIMF TMSA 3 — Element 13 LiveMaritime Security & Cyber Risk Management.
  • OCIMF SIRE 2.0 — cyber question set Coverage-readyShip Inspection Report Programme, 2.0 framework.
  • CDI — Chemical Distribution Institute, cyber sections Coverage-readyFor chemical / parcel tankers and terminals.
  • RightShip — Cyber Risk & SAFE Score inputs Coverage-readyDry-bulk vetting; CSA cyber assessment.
  • INTERTANKO / INTERCARGO guidance AlignedSector-specific guidance, often via BIMCO V5.
Regulatory & port-state

Flag-state, port-state & regional regulation

Where Navis Arca produces the operational evidence inspectors expect during boarding, audit, or regulatory verification.

  • USCG NVIC 01-20 — Cyber Risk Management at MTSA-regulated facilities Coverage-readyNow extending to vessels via NVIC 02-24 / Subchapter H.
  • Paris MoU — port-state cyber inspection regime AlignedCyber concentrated inspection campaigns.
  • Tokyo MoU — Asia-Pacific port-state regime AlignedConcentrated inspections incl. cyber-risk verification.
  • EU NIS 2 Directive AlignedFor maritime operators in scope; supports operator notification & risk-management evidence.
  • UK DfT Code of Practice — Cyber Security for Ships AlignedDepartment for Transport, voluntary code.
  • Singapore MPA — maritime cyber guidance AlignedMaritime Port Authority cyber framework.
  • India DGS / Indian Ports Act guidance AlignedFor Indian-flag operators & Indian ports.
Underlying technical standards

The standards your auditors recognise

Every maritime framework above leans on these underlying technical standards. Navis Arca's controls implement them directly so the same evidence satisfies multiple frameworks at once.

  • NIST CSF 2.0 — Identify · Protect · Detect · Respond · Recover · Govern Coverage-readyThe framework BIMCO V5 and most class societies reference.
  • IEC 62443 — Industrial Automation & Control Systems Security AlignedFor IT-side controls; deeper OT scope through partners.
  • CIS Controls v8 & CIS Benchmarks Live600+ benchmark checks scored per host.
  • ISO/IEC 27001 / 27002 AlignedParent company is ISO 27001 certified; platform controls map to Annex A.
  • MITRE ATT&CK — for threat modelling & SOC integration AlignedTelemetry exportable for SIEM / SOC consumption.
Insurance & P&I

Underwriter & P&I-club expectations

The cyber clauses your hull, cargo and P&I underwriters increasingly require evidence of — to bind cover, to defend a claim, or to negotiate premium.

  • IG of P&I Clubs — cyber risk circulars AlignedInternational Group P&I cyber expectations.
  • LMA CL380 — cyber attack exclusion clause posture AlignedLloyd's Market Association; evidence supports affirmative cover negotiations.
  • JCC cyber endorsements — Joint Cargo Committee AlignedCargo-side cyber coverage expectations.
IMO & SMS

IMO & Safety Management System

The international baseline that sits behind every flag-state cyber expectation under the ISM Code.

  • IMO Resolution MSC.428(98) — Maritime Cyber Risk Mgmt in SMS LiveIn effect from first DOC verification after 1 Jan 2021.
  • IMO MSC-FAL.1/Circ.3 (Rev.2) — Guidelines on Maritime Cyber Risk LiveOperational guidelines referenced by flag states.
  • ISM Code — cyber elements within SMS AlignedProcedural side remains operator's; we produce the technical evidence.
  • SOLAS Ch. IX — implications via ISM Code AlignedIndirect cyber implications through safety management.

Tier definitions — Live · pre-mapped: turnkey export of an inspection-ready PDF in two clicks. Coverage-ready: evidence base is in place; a framework-formatted report is produced on request during onboarding. Aligned: Navis Arca controls map cleanly to the framework; we work with your team and inspector to produce the format the audience expects. Trademarks belong to their respective owners and are referenced for factual descriptive purposes only.

How the evidence works

Telemetry → control → coverage PDF.

Every control in every framework is wired to the agent telemetry that proves it is operating. When an inspector arrives, the proof is already collected — no scramble, no spreadsheet, no screenshots taken at midnight.

Live telemetry

Agent posts posture, scan results, audit events and policy state to the platform continuously.

Control mapping

Each framework's controls are pre-mapped to telemetry signals — no manual mapping work for your team.

Coverage scoring

Per-vessel and fleet-wide scores update as posture changes. Gaps are visible before an inspector points them out.

Two-click PDF

Pick a framework, pick a vessel (or fleet), download a polished, signed coverage report ready for the surveyor.

25+
frameworks & standards covered
600+
CIS hardening checks
2-click
coverage PDF export
7 yrs
tamper-proof audit retention
Frequently raised in surveys

What inspectors actually ask.

A quick read of the questions class-society and charterer auditors most commonly bring to a Navis Arca-protected fleet — and where the answer lives.

"Show me your asset inventory for this vessel."

Each enrolled endpoint reports OS, hostname, role, last-seen timestamp and software inventory — visible per vessel and exportable as the asset register IACS UR E27 expects. No spreadsheet to maintain by hand.

"How do you know which CVEs are open right now?"

Continuous vulnerability assessment matches installed software against authoritative CVE feeds (NVD and vendor advisories). Each finding is shown with severity, the affected device, and the vendor-published remediation. The detection date and the date you closed it are both retained.

"Show me the hardening posture against CIS for this server."

Per-host CIS benchmark report — 600+ checks, scored, with the corrective action against each failed check. Score is tracked over time so you can show trend, not just snapshot.

"Show me a removable-media incident from the last 12 months."

USB events are recorded per device, per vessel, with timestamp and operator (if applicable). The cryptographically chained audit trail makes the record defensible — no one can quietly remove an event after the fact.

"Who can log in and how is access controlled?"

Role-based access with mandatory MFA, session controls, and a per-action audit log. Operator activity is queryable per vessel and per timeframe.

Bring an inspector. We'll bring the evidence.

Walk through a live coverage report against IACS UR E26 / E27, TMSA 3, BIMCO V5 and IMO MSC-FAL — using a real fleet of demo vessels.

Book the compliance demo →