ClassNK has published the Second Edition of its Guidelines for Cyber Security Management System for Ships. The new edition, dated 2nd October 2026, is a full revision of the original guidelines issued in 2019.
The revised Guidelines establish requirements for a Cyber Security Management System (CSMS) covering shipboard IT and OT systems. They address key areas including cyber risk assessment, governance and responsibilities, cybersecurity training, supply chain management, network security, configuration management, monitoring, backup and recovery, emergency preparedness, and internal audits.
A significant addition in the Second Edition is Part 2: Assessment Criteria and Objective Evidence, which provides the criteria used during ClassNK audits and specifies the evidence expected to demonstrate that CSMS requirements have been implemented.
ClassNK also states that the revised Guidelines incorporate references to ISO/IEC 27001 and ISO/IEC 27002, drawing on the Society’s experience gained through its audits since the publication of the first edition.
The Guidelines focus on cybersecurity management and governance for companies and ships, rather than serving as a technical ship cyber-resilience requirement such as IACS UR E26/E27.
The full Second Edition is available below.


