A 5-Minute Maritime Cyber Readiness Check, Mapped to IMO and NIS2

Maritime cyber readiness is now tied to regulatory and industry expectations. The A9X Maritime Cyber Readiness Check turns IMO, BIMCO, IAPH, and NIS2 guidance into ten plain-language questions for fleet teams.

Maritime cyber readiness is no longer only a technical question.

It is increasingly a regulatory, contractual, insurance, and operational question.

Ship managers and fleet IT teams are being asked to show how cyber risk is governed, how onboard systems are identified, how basic protections are applied, how incidents are detected and reported, and how recovery is handled after something goes wrong.

That is a lot to answer from a standing start.

So we built the A9X Maritime Cyber Readiness Check as a short first step.

It is not an audit.

It is not legal advice.

It is a practical scoping aid: ten plain-language questions that help you see where your current controls may line up with the expectations already appearing in maritime cyber guidance and regulation.


What the check is based on

The check is compiled from a small set of maritime cyber references that many operators already recognize:

  • IMO Resolution MSC.428(98), which brings cyber risk management into the Safety Management System context under the ISM Code
  • IMO MSC-FAL.1/Circ.3/Rev.3, the IMO's updated guidelines on maritime cyber risk management
  • BIMCO's Guidelines on Cyber Security Onboard Ships
  • IAPH's Cybersecurity Guidelines for Ports and Port Facilities
  • EU Directive (EU) 2022/2555, better known as NIS2

Those documents do not all do the same job.

IMO sets the maritime baseline and connects cyber risk to existing safety management practice. BIMCO gives ship-focused operational guidance. IAPH brings in the port and port facility perspective. NIS2 introduces broader EU cybersecurity obligations for in-scope essential and important entities, including risk management measures and incident reporting duties.

Together, they point in the same general direction:

cyber risk needs to be owned, understood, controlled, monitored, responded to, and recovered from.

That is the structure behind the check.


Why we mapped it by function

The readiness check groups the answers across six functions:

  • Govern
  • Identify
  • Protect
  • Detect
  • Respond
  • Recover

This keeps the result useful.

A single score can be interesting, but it does not tell a fleet team where to start. A vessel operator may have reasonable endpoint protection but weak incident reporting. Another may have good informal knowledge of critical systems but no current inventory. Another may have a policy for removable media that is not actually enforceable onboard.

Function-by-function scoring makes those differences visible.

It also mirrors the way maritime cyber risk is normally discussed: governance, asset understanding, protective measures, detection, incident handling, and recovery are separate capabilities. They reinforce each other, but weakness in one area can still leave a real gap.


The questions are deliberately plain

The check does not ask whether you have "implemented Article 21 controls" or "completed a full cyber risk management assessment under MSC-FAL.1/Circ.3/Rev.3."

That language has its place, but it is not always the best way to start a useful conversation.

Instead, the check asks practical questions such as:

  • Is one specific person accountable for cyber risk across the fleet?
  • Do you have an up-to-date list of digital systems and network connections on each vessel?
  • Can crew or visitors plug in a USB drive without it being checked or logged?
  • Are Windows security updates tracked and applied with vessel bandwidth limits in mind?
  • Would you know within a day if a vessel PC picked up malware or started behaving unusually?
  • Do you have a written plan for reporting and handling a cyber incident?

Those questions are easier to answer honestly.

They are also closer to the work fleet teams actually need to do.


The important caveat

The check should not be treated as a compliance determination.

Flag state implementation matters. The way a company is structured matters. The ports you call at may matter. Whether NIS2 applies directly to your organization depends on entity classification, Member State transposition, establishment, services, and other legal details.

That is why the result page includes a clear warning: use this as a scoping aid, then confirm applicability and obligations with the right legal or compliance advice.

The value of the check is not that it replaces that work.

The value is that it helps you prepare for it.


Where A9X fits

A readiness check is only useful if it points toward practical next steps.

Some gaps are process gaps: ownership, documentation, training, reporting, and recovery planning.

Some gaps need tools that work in the real conditions found onboard vessels:

  • asset visibility across vessel PCs
  • removable media approval and logging
  • Windows update management that accounts for limited connectivity
  • endpoint protection and detection that does not assume every vessel has perfect cloud access
  • application control for shared and operationally sensitive PCs

Those are the kinds of vessel-focused controls A9X is built around.

The check helps connect the regulatory language to the onboard control problem: what needs to be governed, what needs to be visible, what needs to be blocked or logged, and what needs to be recoverable.


Take the check

The Maritime Cyber Readiness Check takes about five minutes.

There is no download and no login. Your answers stay in the browser unless you choose to send the result.

Use it as a first pass before an internal review, insurer conversation, customer request, audit preparation, or compliance discussion.

Take the Maritime Cyber Readiness Check

For a more detailed discussion, email sales@a9x.com.


Source references

Interactive demo

Try USB Manager Local Edition in the browser.

Walk through USB blocking, temporary unblock, Secure Copy, ECDIS media, Defender update USB creation, settings, license, and updates.