
The International Maritime Organization (IMO) has issued a further revision of its Guidelines on Maritime Cyber Risk Management, published as MSC-FAL.1/Circ.3/Rev.4 on 28 May 2026.
The revised Guidelines were approved by the Facilitation Committee at its 50th session (23–27 March 2026) and the Maritime Safety Committee at its 111th session (13–22 May 2026).
The Guidelines continue to provide high-level recommendations for managing cyber risks in the maritime sector, with the overall objective of supporting safe and secure shipping that is operationally resilient to cyber threats and risks.
What Has Changed in Rev.4?
Compared with Rev.3, the latest revision does not introduce a major restructuring of the maritime cyber risk management framework or significant new cybersecurity controls. The most notable substantive change in Rev.4 is the addition of a new reference under Section 4.3 – Additional guidelines and industry best practices.
The revised Guidelines now include IAPH Cyber Resilience Guidelines for Emerging Technologies in the Maritime Supply Chain. This has been added as a fifth reference alongside the existing industry guidance, including the Guidelines on Cyber Security Onboard Ships, IACS Recommendation 166, the NIST Cybersecurity Framework 2.0, and the IAPH Cybersecurity Guidelines for Ports and Port Facilities.
Cyber Onboard has made the newly issued MSC-FAL.1/Circ.3/Rev.4 – Guidelines on Maritime Cyber Risk Management available for readers who would like to review the document in full.


