Home M-SOC Shipcrawler Haris
Other Services Web Development Networking Mobile App Development
Contact Blog Free Fleet Scan
RESEARCH BRIEF 04 Port State Control · Compliance Verification

PSC cyber requirements, ready before the inspection.

What Port State Control inspections will actually check, what evidence counts, and how to build it without a year-long compliance project.

Compliance Framework IACS UR E26/E27 Audit Scope
Fleets with unverified paper-only policies 82%
Evidence export turnaround via M-SOC telemetry < 5 mins
IACS & IMO MSC.428(98) alignment 100%
REGIME: PORT STATE CONTROL 2026 / STANDARD: IACS UR E26/E27 / REPORT TIME: 5 MINUTES / READ TIME: 6 MIN
01 · The regime

What changed for 2026

Port State Control inspections increasingly include a cybersecurity component, aligned with IACS UR E26/E27 and the IMO's MSC.428(98) guidance. The direction is clear: regulators want to see that cyber risk management is a documented, working process on the vessel, not a binder on a shelf.

The practical consequence for fleet managers: inspection now asks for evidence of cyber controls, incident readiness, and continuous monitoring.

02 · What inspectors check

The short list

1. A documented cyber risk assessment. Current, vessel-specific, and signed off.

2. Access control evidence. Who can reach bridge systems, and how that is enforced.

3. Monitoring records. Logs showing the vessel is watched, anomalies are detected, and responses are documented.

4. Incident response readiness. A plan, and crew who can demonstrate they know it.

03 · The evidence gap

Where most fleets fail

Most fleets fail the evidence test, not the policy test. They have procedures on paper but no data trail proving the procedures run. An inspector cannot verify a monitoring process from a PDF.

The fix is telemetry: continuous logs from the vessel's own network, structured so an export answers the inspector's questions in minutes. This is exactly the gap M-SOC and the Haris edge node are built to close.

04 · The plan

How to get ready without a project

1. Baseline now. Run a passive exposure scan so you know your current state.

2. Instrument the fleet. Collect and store monitoring logs continuously, retrofits are cheaper than you expect.

3. Document the loop. Assessment, controls, monitoring, review, with timestamps.

4. Rehearse once. A single drill that produces the evidence an inspector would request.

05 · Related research

Continue reading field notes.

Shodan & Ships

An empirical breakdown of the queries and satellite ASN ranges that surface exposed vessels.

Read Brief (6 min) →

VSAT Security Essentials

What a VSAT terminal is, why it keeps showing up in scans, and the checklist to run before port calls.

Read Brief (5 min) →

ECDIS Vulnerabilities

Electronic chart display risks explained without jargon: what can go wrong, and what bridge teams should know.

Read Brief (5 min) →

Walk into your next PSC visit audit-ready.

Automated evidence from your own fleet telemetry.

Request a Briefing →