IMO Resolution MSC.428(98) brought cyber risk into the shipping company’s existing safety-management framework. The deadline was the first annual Document of Compliance verification after 1 January 2021; for an Indian-flag operator, the practical implementation details sit in DGS Engineering Circular No. 06 of 2017, as corrected.
What does IMO Resolution MSC.428(98) actually say?
Read the resolution’s language alongside the flag-state implementation.
The resolution, adopted on 16 June 2017, runs to four operative paragraphs. It affirms that an approved safety management system should take cyber risk management into account in accordance with the objectives and functional requirements of the ISM Code. It then encourages Administrations — flag states — to ensure that cyber risks are appropriately addressed in safety management systems “no later than the first annual verification of the company’s Document of Compliance after 1 January 2021.”
MSC.428(98) does not create a standalone cybersecurity code addressed directly to shipowners. Instead, it places cyber risk within the existing ISM and flag-state compliance framework. Cyber risk belongs in the same Safety Management System that already addresses fire, collision and pollution risk, and it appears in the same audit trail — so it is not a checkbox an IT contractor can tick beside the safety case. Operators must read the resolution together with the ISM Code and the requirements issued by their flag Administration.
Where does cyber compliance actually get checked?
Primarily through the company-level Document of Compliance verification expressly identified in MSC.428(98), with vessel-level implementation also capable of being examined during Safety Management Certificate audits. These audits are conducted by the flag Administration or by a Recognised Organisation acting on its behalf. Under the Indian implementation procedure, later SMC intermediate or renewal audits are linked to evidence of compliance recorded in the preceding DOC audit. A material gap can therefore affect certification rather than merely produce a warning after the event.
What an auditor looks for is not a list of installed firewalls. It is evidence that cyber risk has been identified and assessed the way any other operational risk would be, that there is a documented procedure for detecting and responding to an incident, and that the people who would be on watch know their part in it.
Which IMO guidelines should the SMS reference?
Use MSC-FAL.1/Circ.3/Rev.4, dated 28 May 2026, when reviewing the current IMO guidance, and record the revision in the SMS reference register. IMO maritime cyber-risk guidelines, Revision 4
The guidance accompanying the resolution describes practical areas for managing maritime cyber risk. Check the current revision alongside your flag Administration’s requirements and record which version your assessment uses. The accountability, training and IT/OT points below should be reflected in the operating evidence, not only in a policy reference.
The six functional elements are Govern, Identify, Protect, Detect, Respond and Recover. Governance includes an accountable person or entity with the authority, support and expertise to organise cybersecurity work. The elements operate together continuously; an SMS should connect ownership, risk assessment, protective measures, detection, response and recovery to the vessel’s actual systems.
Use the listed controls as a starting point for evaluating the vessel’s risks, then check whether additional measures are needed for its systems, connections and operating profile. Record how a control is implemented and how its effectiveness is checked.
The guidance addresses annual basic cybersecurity training, OT-specific training for relevant users, familiarisation for joining crew and occasional testing through exercises. Plan those activities around the roles people actually perform on board. Keep attendance records alongside evidence of the decisions participants could make during a drill.
Why does the IT/OT split catch operators out?
A vessel can have IT services such as email and administration alongside OT for navigation, propulsion or cargo operations. Determine the real interfaces and operating consequences with the people responsible for those systems.
A compromised email account may initially present as an information-security or fraud incident, but it can also expose credentials or provide a route into connected systems. A compromised ECDIS — the Electronic Chart Display and Information System used for navigation on many SOLAS vessels — or engine control system can become a safety problem, potentially a life-safety one. IT and OT therefore need risk assessments and response procedures suited to their different operational consequences.
Treat the IT/OT boundary explicitly in the risk assessment. Identify the systems involved, permitted connections, remote maintenance routes and the consequences of losing availability or integrity. Check the current guidance on segmentation and protective measures with people who understand the vessel’s operational constraints.
What does India add on top of MSC.428(98)?
The step that turns an encouragement into a requirement.
DGS Engineering Circular No. 06 of 2017 (6 November 2017), read with its corrigendum of 20 November 2017, implements the requirement for Indian-flag ships and adds a specific review step. Cyber risk mitigation procedures included in the SMS manuals must be reviewed by a Recognised Organisation. Indian Register of Shipping Technical Circular No. 141/2017 is a useful industry summary of the DGS instrument, but it is not itself a DG Shipping circular. DGS Circular 06/2017, original document hosted by IRS
The sequence ran like this. New DOC applicants requesting an initial audit on or after 1 January 2018 had to include RO-reviewed cyber risk management procedures in their SMS risk mitigation manuals. Existing DOC holders could demonstrate compliance early at any point before 1 January 2021. From 1 January 2021, no request for a DOC annual or renewal audit is accepted unless RO-reviewed risk mitigation procedures are already in the SMS manuals. DGS corrigendum, 20 November 2017, hosted by IRS
Schedule the required RO review and retain its record with the SMS evidence. Confirm the current flag and RO procedure for the company and vessel rather than treating an internally signed risk assessment as the entire audit package.
Newbuild projects also need to assess applicable class requirements for cyber resilience, including IACS E26 and E27. Confirm the relevant versions, scope and contract dates with the class society and yard. This is a design and procurement question alongside the operating SMS, rather than a substitute for it.
What should you check before the next audit?
Use the following preparation questions; their order is a suggested workflow, not a ranking of common audit failures.
- Is cyber risk a named line in the SMS risk register, rather than a passing reference inside a general IT policy?
- Is the incident response procedure specific to the vessel, rather than a generic corporate one?
- Is there a named, empowered owner, evidence of annual basic cybersecurity training, OT-specific training for relevant users and familiarisation for joining crew — together with occasional testing through drills or exercises?
- Does all of it leave a dated, current paper trail an auditor can review, rather than something assembled the week before?
For an Indian-flag vessel there is a fifth: has a Recognised Organisation actually reviewed those procedures, and can you produce the review?
The primary instruments are public: IMO Resolution MSC.428(98), the current Guidelines on maritime cyber risk management, and India’s DGS Engineering Circular No. 06 of 2017. The practical task is to translate their high-level expectations into current, vessel-level controls and evidence. The same preparation matters ashore on a far shorter clock: CERT-In gives an Indian organisation six hours to report certain cyber incidents, and most of what makes timely reporting possible has to be established beforehand.
This article explains the resolution, the guidelines and the circular in general terms. It is not a substitute for guidance from your flag state, class society or legal counsel on your specific fleet.
An SMS evidence map for the next review
- Governance: connect the named accountable owner to the SMS risk register, decisions and action tracking. Suggested evidence: authority, open risks and dated reviews. Distinguish recommended governance practice from a specific flag-state requirement.
- System understanding: connect the inventory to vessel functions, IT/OT interfaces and maintenance routes. Suggested evidence: a current dependency map with operational sign-off, limitations and responsibility for updates.
- People and response: connect familiarisation and exercises to actual watchkeeping and shore-support duties. Suggested evidence: scenario, participants, decisions observed and corrective actions, alongside attendance.
- Recovery: identify the safe fallback and restoration process for the selected operational scenario. Suggested evidence: controlled test results and unresolved dependencies. Do not conduct a live-system exercise without the appropriate operational authorisation.

