FOR SHIPYARDS AND ONBOARD EQUIPMENT SUPPLIERS

IACS UR E26 and E27 compliance
you can prove to the surveyor

FuzzForge tests your suppliers’ software without the source code, and gives you proof the surveyor can replay.

IACS UR E26 E27 compliance testing for onboard systems and equipment
IACS UR E26 E27 compliance testing for onboard systems and equipment

OVERVIEW

What are IACS UR E26 and E27?

IACS UR E26 and E27 are the cyber resilience rules that classification societies apply to every ship contracted since 1 July 2024. UR E26 covers the ship, UR E27 each system on board. In practice, IACS UR E26 E27 compliance means an inventory of every system, a secure development lifecycle and security tests witnessed by the class surveyor.

IACS UR E26 E27 key facts: in force for ships contracted for construction on or after 1 July 2024; covers passenger ships and cargo ships of 500 GT and upwards on international voyages, and mobile offshore units; based on IEC 62443-3-3 and IEC 62443-4-1

WHO DOES WHAT

Who answers for what, and where FuzzForge fits

UR E26

Shipyard (systems integrator)

The ship test procedure and commissioning tests.

FUZZFORGE

Flaws beyond the published CVE list.

UR E27

Equipment supplier

A secure development lifecycle and tested updates.

FUZZFORGE

The same campaign, rerun in your CI on every release.

UR E26

Shipowner

Records at every annual survey.

FUZZFORGE

A findings history per system and per version.

FuzzForge does not issue certificates. Your class society assesses compliance.

PROOF

Proof from the code ships run on

GICAN
Selected for GICAN SeaStart.
6 CVEs in GNSS, AIS and NMEA 2000 code.
PWN2OWN
3 Pwn2Own wins.
1,500+ vulnerabilities found.

THE CALENDAR

When does the class society check what?

IACS UR E26 E27 calendar: when the class society checks each step, from design to in-service surveys

FAQ

Questions from shipyards and suppliers on IACS UR E26 and E27

No technique is named. Both rules ask you to demonstrate compliance by “testing and/or analytic evaluation”. Fuzzing, emulation and binary analysis are ways to produce that evidence, for example for the verification phase of the secure development lifecycle in UR E27.

Type approval is voluntary and applies to standard, routinely manufactured systems. With a valid certificate, the supplier submits a reduced set of vessel-specific documents and skips the vessel-specific factory test. The secure development lifecycle still applies to every update of the product.

Yes. FuzzForge works on compiled binaries and firmware images and writes the fuzzing harness itself. It runs on-premise, with an air-gapped option, as well as in SaaS or a private cloud.

Build the evidence your class surveyor will ask for

A real campaign on one of your systems, run inside your environment. Results your engineers can replay in front of the surveyor.

MEET US

Meet our researchers at these upcoming events

3 – 6 November 2026
Paris Nord Villepinte

16 – 19 November 2026
Rennes

16 – 20 November 2026
Amsterdam

7 – 10 December 2026
London