Maritime Cybersecurity pioneer Cydome has extended its cybersecurity platform with a Third-Party Vendor Compliance and Risk Management solution.
The new platform is designed to help shipowners, fleet managers, shipyards and third-party vendors manage the complexity around mandatory vendor cybersecurity regulatory compliance, certifications and approvals.
Maritime operators need to manage their third-party vendors’ compliance under multiple regulations. For example, IACS Unified Requirement E27 stipulates that shipowners must ensure that all computer-based systems on board comply with the cyber resilience requirements set therein.
Managing and maintaining an up-to-date picture of all 3rd party vendor systems’ compliance with those requirements requires complex coordination and process management. Today, this is mostly done with manual processes involving multiple internal and external stakeholders, using emails and generic spreadsheets, lacking security, without clear governance or an auditable change log, and without a “single source of truth”.
The new Cydome solution simplifies vendor compliance management using a web-based SaaS tool that automates and streamlines processes, serving as a centralized repository for vendor certifications/approvals with a clear dashboard that presents all user types with a clear picture of their compliance posture. This way, shipping companies have an easy tool to manage compliance for vendors used in their fleets and offices; vendors can easily provide documentation that is automatically updated in all their users’ dashboards; and reports can be easily provided to regulators and auditors showing the full compliance picture as needed.
“E27 introduced important rules for mandatory supply-chain cyber resilience,” said Cydome VP R&D and co-founder, Alon Ayalon. “However, this also brings an operational complexity for managing the compliance process. Shipowners may rely on dozens or even hundreds of vendors across a fleet, each with its own devices, certificates, and sub-suppliers. Until now, most of this has been tracked manually using spreadsheets and emails to different stakeholders. Our solution replaces that administrative complexity with a single, structured system that automates the process and reduces overhead for shipping companies, vendors and class societies.”
IACS Unified Requirement E27 targets critical operational and safety computer-based systems (IT and OT) to ensure they are cyber resilient when deployed on board vessels. It aligns maritime tech with commonly adopted industrial cybersecurity frameworks like IEC 62443. However, unlike other compliance processes, there is no single process for approving a system under UR E27, and sometimes systems can be exempt from the requirements.
“In practice, E27 has left shipowners, shipyards and fleet managers trying to work out if their vendor and systems are compliant, as they manually gather information and review in-date and out-of-date certificates from multiple vendors and sub-vendors. This is notoriously time-consuming,” said Ayalon.
Cydome’s new solution addresses this by providing maritime stakeholders with a central repository that shows E27 compliance status - overall, for specific vessels and sites, or specific vendors and systems. The web-based platform provides details of the vendor, vendors’ equipment, certification status and overall compliance score. It also includes items that are missing, unverified, or nearing expiry. When documentation approaches expiry, automated reminders can be issued requesting updated information.
“We’ve already seen cases where customers have two people working full time just to chase and track third-party certifications,” Ayalon noted. “But by digitising that entire process and building in automation, we are freeing up significant time and reducing the risk of gaps or expired certificates slipping through.
“The shipmanager or yard no longer has to keep chasing every vendor, and the vendor does not have to keep supplying the same information separately to different customers,” said Ayalon. “Once the information is being managed in one place, you can see what is compliant, what is missing, what needs attention and what is approaching expiry.
While the initial focus is on IACS UR E27, the platform will be extended in the future to support additional frameworks, such as ISO and national standards.
“The goal is to give maritime stakeholders a single environment in which to manage third-party compliance and risk across multiple regulatory regimes,” said Ayalon.
Robban Assafina is now on WhatsApp channel. Click Here







