---
title: "IACS UR E26 & E27: Cybersecurity Regulations for Superyachts"
description: How IACS UR E26 & E27 make cyber security a core safety requirement for new build superyachts, and what Captains, ETOs and Engineers must do to comply.
image: https://trustanchorpoint.com/hubfs/AI-Generated%20Media/Images/anime%20A%20new%20build%20yacht%20being%20inspected%20for%20cybersecurity%20controls%20in%20the%20rack%20space%20with%20just%20one%20person%20with%20two%20arms%20looking%20closely%20at%20the%20configu.png
---

[Skip to content](https://trustanchorpoint.com/insights/iacs-ur-e26-e27-cybersecurity-regulations-for-superyachts#main-content)

[![Anchorpoint logo black](https://trustanchorpoint.com/hs-fs/hubfs/Black-White.png?width=1100&height=300&name=Black-White.png)Homepage](https://trustanchorpoint.com)

- [What's a virtual CISO?](https://trustanchorpoint.com/whats-a-virtual-ciso)
- Superyacht Cybersecurity
  
    - [Hire a virtual Cybersecurity Officer (vCySO)](https://trustanchorpoint.com/cybersecurity-compliance-for-superyachts)
    - [Cybersecurity Compliance for Superyachts](https://trustanchorpoint.com/cybersecurity-compliance-for-superyachts)
    - [Cybersecurity Awareness Training for Superyacht Crew](https://trustanchorpoint.com/cybersecurity-awareness-training-for-superyacht-crew)
    - [Cybersecurity Threat Intelligence for Superyacht Crew](https://trustanchorpoint.com/cybersecurity-threat-intelligence-for-superyacht-crew)
- [Insights](https://trustanchorpoint.com/insights)
- [About](https://trustanchorpoint.com/about-us)
  
    - [Code of Ethics](https://trustanchorpoint.com/code-of-ethics)

[Contact us](https://trustanchorpoint.com/contact)

- [What's a virtual CISO?](https://trustanchorpoint.com/whats-a-virtual-ciso)
- Superyacht Cybersecurity
  
    - [Hire a virtual Cybersecurity Officer (vCySO)](https://trustanchorpoint.com/cybersecurity-compliance-for-superyachts)
    - [Cybersecurity Compliance for Superyachts](https://trustanchorpoint.com/cybersecurity-compliance-for-superyachts)
    - [Cybersecurity Awareness Training for Superyacht Crew](https://trustanchorpoint.com/cybersecurity-awareness-training-for-superyacht-crew)
    - [Cybersecurity Threat Intelligence for Superyacht Crew](https://trustanchorpoint.com/cybersecurity-threat-intelligence-for-superyacht-crew)
- [Insights](https://trustanchorpoint.com/insights)
- [About](https://trustanchorpoint.com/about-us)
  
    - [Code of Ethics](https://trustanchorpoint.com/code-of-ethics)

[Contact us](https://trustanchorpoint.com/contact)

![inspection of superyacht cybersecurity](https://trustanchorpoint.com/hs-fs/hubfs/AI-Generated%20Media/Images/anime%20A%20new%20build%20yacht%20being%20inspected%20for%20cybersecurity%20controls%20in%20the%20rack%20space%20with%20just%20one%20person%20with%20two%20arms%20looking%20closely%20at%20the%20configu.png?width=1536&height=1024&name=anime%20A%20new%20build%20yacht%20being%20inspected%20for%20cybersecurity%20controls%20in%20the%20rack%20space%20with%20just%20one%20person%20with%20two%20arms%20looking%20closely%20at%20the%20configu.png)

Cybersecurity superyacht new build

# IACS UR E26 & E27: Cybersecurity Regulations for Superyachts

![Matt](https://app.hubspot.com/settings/avatar/618f3d942fdcc567e50ece243104b38b)

 Matt

February 26, 2026

Cyber security for newbuild and refit yachts is quietly moving from “best practice” to “basic safety.” For crew, especially those involved in builds or yard periods, that has some very practical consequences.

### 1. Cyber is now part of “designing a safe yacht”

Regulators and class bodies expect cyber risk to be managed in the same structured way as fire, stability or machinery:

- The **network** must be designed with clear “zones” (e.g. navigation, propulsion, safety, hotel IT, crew Wi‑Fi) and controlled connections (“conduits”) between them.
- There has to be an **asset inventory** of all computer‑based safety‑relevant systems: ECDIS, DP, autopilot, engine control, power management, steering, fire detection, radio, internal comms, etc.
- The design must show how critical systems are **protected from non‑critical ones** (for example, crew internet or guest Wi‑Fi should not be able to directly affect navigation or propulsion).

For crew: expect more questions about “which zone is this system in?” and “what else shares that network?”

### 2. Every safety‑relevant system is being re‑labelled from a cyber point of view

Shipyards and suppliers now have to classify each system roughly as:

- **Out of scope:** Not part of safety for ship control and not connected to those networks (e.g. some hotel systems).
- **Negligible risk:** Very simple, no network, no USBs, often physically locked down (e.g. a purely mechanical system or a fixed‑firmware device in a sealed cabinet).
- **In scope:** Any system that is computer‑based and connected – especially if it can affect propulsion, steering, power, navigation, fire, or emergency response.

Remote access systems are *always* treated as in scope because they provide a path from shore onto the yacht.

For crew: if you’re responsible for a system, you’ll increasingly be asked:

- Does it have network or USB access?
- Who can log in, from where, and with what credentials?
- What happens if it misbehaves or is unavailable?

### 3. Remote access is no longer a casual convenience

Historically, many AV/IT and OT suppliers had always‑on remote access so they could “jump in and fix it.” Under the new mindset:

- Remote access should go through **controlled gateways**, with logs and permissions.
- There should be a **permit‑to‑work style process**: who requested access, for what, when, and when it’s switched off again.
- Permanent “back doors” into navigation, propulsion, or power systems are being phased out or heavily restricted.

For crew: you’ll likely be expected to:

- Know **which vendors have remote access** to which systems.
- Be able to **enable/disable access on demand** and record it.
- Push back if a supplier wants always‑on access without controls.

### 4. Onboard cyber testing becomes a normal part of sea trials

As delivery approaches, there will be formal tests, witnessed by the class or surveyors, to demonstrate that the cyber design actually works. These typically include:

- **Network segregation tests:** 
    - Confirm that a compromise in one zone (e.g. crew internet) cannot directly affect safety‑critical zones.
    - Verify firewalls and VLANs behave as designed.
- **Access control checks:** 
    - User accounts and roles are set correctly (no generic “admin/admin”).
    - Password policies, MFA where appropriate, and account removal upon crew members' departure.
- **Remote access and USB procedures:** 
    - Demonstrate how remote sessions are controlled and logged.
    - Show how USBs are handled (blocked, scanned on a dedicated station, or both).
- **Backup and recovery drills:** 
    - Evidence that critical systems are backed up.
    - A realistic demonstration of how the yacht would recover key functions after a major cyber incident (e.g. corrupted navigation PC, infected automation station).

For crew: think of this like a **fire drill for your IT/OT systems**. You may be involved in:

- Running the tests
- Providing evidence (screenshots, logs, procedures)
- Fixing gaps found during the trial

### 5. Timelines are tight - 2026-27 will be busy

There is a big wave of newbuilds all coming through with similar contractual dates. That means:

- Classification societies and suppliers will be **extremely busy** checking drawings, issuing approvals, and supporting tests.
- Projects that leave cyber to the last minute could face **delays, re‑work and cost overruns** if systems aren’t ready or documentation is incomplete.
- Yachts nearing delivery may discover that missing cyber paperwork or failed tests can **hold up class notation and handover**.

For crew: if you’re on a build or heavy refit, getting cyber right **early** protects your own timelines too – fewer last‑minute crises and fewer “why didn’t anyone tell us?” moments.

### 6. What this means day‑to‑day for superyacht crew

You don’t have to be a cyber engineer, but you will be expected to:

- Treat cyber controls as part of **safety management**, not just “IT stuff.”
- Understand, at a high level, **which systems are critical**, which networks they’re on, and who can touch them.
- Follow and enforce **remote access, password, and USB policies**, even when it’s inconvenient.
- Help keep **asset inventories and documentation up to date** when systems change or new equipment is fitted.
- Participate in **training and drills** around cyber incidents, just as you do for fire, man overboard, or abandon ship.

If you’re a Captain, Chief Engineer, ETO/AVIT, or head of department, this is where you can really add value: by making sure cyber requirements are built into everyday operations, not bolted on at the end.

 

## Share this post

<https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ftrustanchorpoint.com%2Finsights%2Fiacs-ur-e26-e27-cybersecurity-regulations-for-superyachts><https://twitter.com/intent/tweet?url=https%3A%2F%2Ftrustanchorpoint.com%2Finsights%2Fiacs-ur-e26-e27-cybersecurity-regulations-for-superyachts><https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Ftrustanchorpoint.com%2Finsights%2Fiacs-ur-e26-e27-cybersecurity-regulations-for-superyachts><https://pinterest.com/pin/create/button/?url=https%3A%2F%2Ftrustanchorpoint.com%2Finsights%2Fiacs-ur-e26-e27-cybersecurity-regulations-for-superyachts>[mailto:https%3A%2F%2Ftrustanchorpoint.com%2Finsights%2Fiacs-ur-e26-e27-cybersecurity-regulations-for-superyachts](mailto:https%3A%2F%2Ftrustanchorpoint.com%2Finsights%2Fiacs-ur-e26-e27-cybersecurity-regulations-for-superyachts)

## Keep reading

### [![](https://trustanchorpoint.com/hs-fs/hubfs/Newsletter%20Header_large_nologo.png?width=1920&height=1080&name=Newsletter%20Header_large_nologo.png) Cybersecurity Yachting superyacht If Password Managers Aren’t Perfect, Are They Still Worth It?](https://trustanchorpoint.com/insights/if-password-managers-arent-perfect-are-they-still-worth-it)

### [![](https://trustanchorpoint.com/hs-fs/hubfs/Newsletter%20Header_large_nologo.png?width=1920&height=1080&name=Newsletter%20Header_large_nologo.png) Cybersecurity superyacht firewall Is Kerio still a superyacht's favourite firewall?](https://trustanchorpoint.com/insights/is-kerio-still-a-superyachts-favourite-firewall)

[![L-White-White-Tran](https://trustanchorpoint.com/hs-fs/hubfs/L-White-White-Tran.png?width=200&height=56&name=L-White-White-Tran.png "L-White-White-Tran")](https://www.trustanchorpoint.com)

<https://wa.me/+447493651484><https://www.youtube.com/@trustanchorpoint><https://www.linkedin.com/company/trustanchorpoint/><https://www.facebook.com/trustanchorpoint><https://www.instagram.com/trustanchorpoint><https://www.tiktok.com/@trustanchorpoint?is_from_webapp=1&sender_device=pc><https://x.com/yachtcyberguy>

- [Privacy Policy](https://trustanchorpoint.com/hubfs/Privacy%20Policy.pdf)
- [Terms & Conditions](https://trustanchorpoint.com/hubfs/Terms%20and%20Conditions.pdf)
- [Contact Us](https://trustanchorpoint.com/contact)
- [Climate Pledge](https://climate.stripe.com/hLNMmV)

© 2026 Anchorpoint (trading name of Anchorpoint Cyber Limited). Company number 16320713, registered in England. All rights reserved.

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Matt",
    "url" : "https://trustanchorpoint.com/insights/author/matt"
  },
  "dateModified" : "2026-02-26T12:30:16.425Z",
  "datePublished" : "2026-02-26T12:30:04.000Z",
  "headline" : "IACS UR E26 & E27: Cybersecurity Regulations for Superyachts",
  "image" : [ "https://trustanchorpoint.com/hubfs/AI-Generated%20Media/Images/anime%20A%20new%20build%20yacht%20being%20inspected%20for%20cybersecurity%20controls%20in%20the%20rack%20space%20with%20just%20one%20person%20with%20two%20arms%20looking%20closely%20at%20the%20configu.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://trustanchorpoint.com/insights/iacs-ur-e26-e27-cybersecurity-regulations-for-superyachts",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://trustanchorpoint.com/hubfs/Black-White.png"
    },
    "name" : "Anchorpoint Cyber Limited"
  }
}
```