FOR MARITIME EQUIPMENT MAKERS AND SHIPYARDS

Maritime equipment cybersecurity
on the code you did not write

FuzzForge tests the GNSS, AIS and NMEA 2000 code inside the systems you integrate, with reproducible proof for IACS UR E26/E27.

Maritime equipment cybersecurity for onboard systems and shipyards
Maritime equipment cybersecurity for onboard systems and shipyards

WHAT MAKES MARITIME EQUIPMENT CYBERSECURITY HARD

And how FuzzForge makes maritime equipment cybersecurity provable

01

Navigation, comms and bridge systems run on code you never opened.

→Test what you integrate, with or without its source.

FuzzForge writes the fuzzing harness itself, then fuzzes, emulates and reverses the supplier code inside your product.

02

The obligation does not stop at delivery.

→Evidence that is still current at the next survey.

Campaigns run continuously on your own capacity, so your proof is never a year old.

03

An inventory is not a proof.

→Findings your engineers can replay.

Every result comes with a reproducible test case, not a list of known CVEs.

PROOF

Our Stats Speak For Us

Selected for GICAN SeaStart.
PWN2OWN
3 Pwn2Own wins.
1,500+ vulnerabilities found.
20+ CVEs published.

REGULATION

Why does this testing not stop at delivery?

IACS UR E26 and IACS UR E27 have been mandatory since 1 July 2024, for newbuild vessels contracted after that date.

IACS UR E27 names third-party equipment suppliers. IACS UR E26 makes the shipyard answer for the cyber resilience of a vessel it integrated but did not code.

The test procedure covers construction and commissioning. Annual surveys then check the records, and tests run again at the renewal survey where systems have changed. So maritime equipment cybersecurity has to be kept current after delivery, not proven once at type approval.

WHY FUZZFORGE

Where inventory stops, FuzzForge starts

For maritime equipment cybersecurity you have three usual options: inventory the components and track known CVEs, book a one-off pentest, or run the campaigns yourself. FuzzForge is the third one, industrialised. It tests the supplier code inside your product and hands your engineers a test case they can replay.

ON ONBOARD EQUIPMENT, CAN IT…
SBOM and CVE scanning
A one-off pentest
FuzzForge
Test the supplier code you integrate, with or without its source

inventory only

sampled

at scale

Find flaws nobody has published yet

known CVEs

if time allows

Hand your engineers a test case they can replay

a report

replayable

Still be current at the next annual survey

re-scan

re-book

continuous

Cover every product in your range

per target

Our researchers published four flaws in RTKLIB, the RTK positioning library used on vessels and autonomous craft. That is the kind of code we test.

FAQ

Questions from maritime equipment makers

Yes. FuzzForge works on the compiled code, not the source. You do not have to obtain the source of the navigation, comms or automation components you buy in, and your team does not have to write a test harness.

Yes. FuzzForge produces reproducible test evidence you can hand to a class surveyor, at construction and commissioning, at type approval, and at the annual surveys that follow.

GNSS, AIS and NMEA 2000, and the wider embedded stack of onboard systems and equipment. Our researchers published four flaws in RTKLIB, the RTK positioning library used on vessels and autonomous craft.

Neither. An SBOM tells you which components sit inside your product and which CVEs are already published against them. Maritime equipment cybersecurity starts where that list stops: FuzzForge looks for the flaws nobody has published yet, and proves which ones are exploitable.

No. The campaigns run without an operator, on your own capacity. Your engineers pick the work up where they want, with the same standard fuzzing and reverse engineering tools they already know.

Prove it before the next survey

A real campaign, on a target close to yours. Findings your engineers can pick up and verify.

MEET US

Meet our researchers at these upcoming events

3 – 6 November 2026
Paris Nord Villepinte

Book a meeting

16 – 19 November 2026
Rennes

Book a meeting

19 – 20 November 2026
Amsterdam

Book a meeting

9 – 10 December 2026
London

Book a meeting