By EJN Labs · 11 Sep 2026 · 7 min read
IACS UR E27 requires equipment suppliers to test the security capabilities of onboard systems against an approved test procedure, but that testing is supplier-run and self-declared, not independently verified. Shipyards increasingly ask suppliers for additional penetration test evidence anyway, because a self-attested test procedure alone does not show a system withstands a real attacker. A CREST-accredited assessment is one way to provide that evidence.
Why do shipyard security questionnaires now cite IACS UR E27?
Shipyard questionnaires cite IACS UR E27 because ships contracted for construction on or after 1 July 2024 cannot get their class certificate unless every onboard computer-based system demonstrates the required security capabilities, and shipyards pass that burden down the supply chain to equipment vendors.
This shows up first in bid documentation. A tender pack or supplier questionnaire asks you to confirm compliance with IACS UR E27, attach your security capability test results, and in many cases provide independent evidence on top. Your own test procedure satisfies the requirement on paper. In our experience, it rarely satisfies a shipyard’s procurement team, because a test you design and run yourself is not independent verification.
Suppliers of navigation, propulsion control, cargo management and communications systems tend to see the question earliest, since these are the categories classification societies have prioritised for type approval. Build any computer-based system for a newbuild vessel and expect the same question, approved or not.
What does IACS UR E27 actually require from equipment suppliers?
IACS UR E27 sets minimum cyber resilience requirements for individual computer-based systems on a ship. The supplier tests these against an approved test procedure, covering access control and malicious code protection. The requirement does not name penetration testing, or require independent testing.
The requirement applies to systems on ships contracted for construction on or after 1 July 2024, focusing on operational technology and systems essential to the vessel’s safety rather than general IT. It draws its individual security requirements from the IEC 62443-3-3 industrial security standard, though only a smaller subset applies at the minimum security profile most newbuild vessels are contracted to.
Classification societies also run a type approval process for onboard systems, where a supplier submits documentation and test evidence up front and receives approval that cuts the paperwork on every future vessel. Many suppliers have not gone through this yet, which is why shipyards fill the gap with their own questionnaires.
What penetration test evidence satisfies a shipyard’s third-party assurance requirements?
Evidence that satisfies a shipyard’s third-party assurance requirements typically combines a CREST-accredited penetration test report covering the same security capabilities IACS UR E27 lists, an attestation letter confirming who tested the system, and a remediation summary showing findings were closed before delivery.
Some shipyards specify this directly, asking for VAPT packaging with a CREST-aligned attestation letter rather than a bare set of findings, because their own compliance file needs a document a class surveyor can sign off, not a raw vulnerability list. Where the buyer references third-party assurance requirements without naming a format, the same combination of report and letter is the safest way to answer it.
| What the questionnaire asks | Where it sits against IACS UR E27 | Evidence that satisfies it |
|---|---|---|
| Confirm the system’s security capabilities have been tested | The supplier’s own approved test procedure | Your existing self-test report, referenced but rarely sufficient alone |
| Provide independent evidence beyond your own testing | Not specified by the requirement itself | CREST-accredited penetration test report plus attestation letter |
| Confirm the system resists network-based attack | Access control, malicious code protection and communications integrity capabilities | Protocol-level testing of the delivered build, not a generic network scan |
| Confirm findings were closed before delivery | Not specified by the requirement itself | Retest report referenced in the evidence pack |
How does a shipyard-ready evidence pack come together?
A shipyard-ready evidence pack starts with identifying exactly which onboard system is in scope, whether it stands alone or forms part of a wider integrated platform, and which security capabilities the shipyard or systems integrator has actually asked to see tested, before any technical work begins.
- Scoping call. We confirm the system’s function, its communication protocols, commonly NMEA 0183, NMEA 2000, Modbus or a proprietary bus, and which security capabilities the questionnaire references.
- Test environment. Most onboard systems are tested on a bench rig or a representative build rather than a live vessel, since testing a ship mid-voyage is rarely practical or safe.
- Technical testing. We test authentication, access control, network segmentation, malicious code protection and logging against the delivered build, using the same categories IACS UR E27 sets out.
- Reporting and attestation. Findings, a remediation summary and a short attestation letter are packaged together, ready for a shipyard’s procurement or class liaison team to file.
What does IACS UR E27 penetration testing cost in the UK market?
A penetration test for a single onboard system typically costs £3,300 to £7,000 in the UK market, based on 3 to 5 days at £1,100 to £1,400 per day. A systems integrator covering several onboard systems on one platform should expect a longer engagement and a wider total.
Scope, not seniority or margin, is what moves the price, and the exact figure depends on how many protocols, interfaces and communication paths the system exposes. Our guide to penetration testing costs in the UK sets out how these ranges are built up across engagement types.
| Scope | Typical effort | Typical UK cost |
|---|---|---|
| Single onboard system, one communication protocol | 3 to 5 days | £3,300 to £7,000 |
| Onboard system with multiple protocols or an integrated HMI | 5 to 7 days | £5,500 to £9,800 |
| Systems integrator covering several onboard systems on one platform | 8 to 12 days | £8,800 to £16,800 |
| Retest after remediation | 1 to 2 days | £1,100 to £2,800 |
These figures are typical UK ranges rather than a quote. The only way to get an exact figure for your system is to scope it through the quote form.
How EJN Labs approaches IACS UR E27 evidence for equipment suppliers
EJN Labs is a UK-based, CREST-accredited penetration testing firm, certified to ISO 27001 and Cyber Essentials Plus, and we scope every onboard-systems engagement around the specific security capabilities a shipyard or systems integrator has asked to see evidenced, rather than running a generic infrastructure test.
In our experience, suppliers move fastest through procurement when they treat the questionnaire as a specification and bring us the actual document before scoping starts. We test against the categories it names, produce a report a class surveyor can reference, and pair it with an attestation letter your commercial team can file without editing. Our infrastructure penetration testing service covers the network and protocol layer most onboard systems expose, and our CREST-accredited testing overview sets out the methodology behind every engagement. Our guide to choosing a UK penetration testing provider covers the questions worth asking any firm, including us.
Frequently Asked Questions
Does IACS UR E27 require penetration testing?
No. IACS UR E27 requires suppliers to test the required security capabilities against an approved test procedure, but that testing is supplier-run and self-declared. It does not name penetration testing as the method, and independent testing is evidence buyers commonly ask for beyond the requirement.
What ships and systems does IACS UR E27 apply to?
IACS UR E27 applies to individual computer-based systems built into ships contracted for construction on or after 1 July 2024, covering operational technology and systems essential to the vessel’s safety. IT systems are not directly covered, though a shipyard may ask for evidence on connected IT systems.
Which equipment suppliers need IACS UR E27 evidence?
Any supplier building a computer-based system for a newbuild vessel, from navigation and propulsion control to cargo and communications equipment, can be asked for IACS UR E27 evidence. Systems integrators assembling several suppliers’ equipment into one platform face the same questionnaire across every system.
What does IACS UR E27 penetration testing cost in the UK market?
A single onboard system typically costs £3,300 to £7,000 in the UK market, based on 3 to 5 days at £1,100 to £1,400 per day. A systems integrator covering several onboard systems on one platform should expect 8 to 12 days, typically £8,800 to £16,800. The exact scope and price come from the quote form.
How quickly can a supplier get shipyard-ready evidence?
Testing for a single onboard system typically takes one to two weeks once scoping is agreed, with the report and attestation letter following shortly after. Suppliers working to a delivery milestone should start at least four to six weeks ahead, leaving room for remediation and a retest before the deadline.
Get shipyard-ready penetration test evidence for your onboard systems
If a shipyard or systems integrator has sent you a questionnaire referencing IACS UR E27, we can scope a penetration test around the exact system and security capabilities it names. Get a CREST pentesting quote and we will come back with a price built on your scope.
Related research
For the OT supplier side of a similar questionnaire, see our guide to what OT security leads ask SCADA suppliers about RIIO. For the wider regulatory picture, see our analysis of critical infrastructure security and the regulatory tightrope. For a comparable embedded-device supplier question, see how device software vendors handle IEC 62304 penetration testing.




Leave a Reply