Maritime security

The ISPS Code.

What it is, who it applies to, what actually changes at Security Levels 1, 2 and 3, and the records a ship has to be able to put in front of an inspector. Written for the people who keep them.

Last reviewed August 2026 · sources: IMO, SOLAS Chapter XI-2 and the ISPS Code Parts A and B.

The ISPS Code explained

What the ISPS Code is

The International Ship and Port Facility Security Code is the security half of SOLAS. It sits under SOLAS Chapter XI-2, Special measures to enhance maritime security, and it has been in force since 1 July 2004. Where the rest of SOLAS is concerned with a ship surviving a fire or a flood, the ISPS Code is concerned with a ship being interfered with on purpose: unauthorised boarding, stowaways, weapons and explosives brought over the gangway, tampering with the ship or its cargo.

It works by asking three things of every ship in scope. Assess your own vulnerabilities. Write a plan that answers them. Then prove, in records, that the plan is what actually happens. Almost every argument anyone has about the Code is an argument about that third part.

Why it exists

The Code was drafted after the attacks of 11 September 2001, when it became clear that international shipping had a comprehensive safety regime and nothing equivalent for deliberate acts. A Conference of Contracting Governments to the SOLAS Convention adopted the new Chapter XI-2 and the ISPS Code in December 2002, and gave the industry eighteen months to implement it. It took effect on 1 July 2004. That is unusually fast for an IMO instrument, and it is the reason the Code reads as a framework rather than a rulebook: it tells you what outcomes to achieve and leaves the method to your plan.

Who it applies to

Chapter XI-2 applies, on international voyages, to:

  • Passenger ships, including high-speed passenger craft
  • Cargo ships of 500 GT and over, including high-speed craft
  • Mobile offshore drilling units
  • The port facilities that serve those ships

Two consequences follow that people miss. The first is that scope is a function of tonnage and trade, not of what the vessel looks like: a commercially registered yacht of 500 GT and over on an international voyage is a cargo ship for these purposes and is in scope. The second is that being out of scope does not put you outside the regime. If you berth at an ISPS-regulated port facility, that facility’s approved plan governs the interface, and it may ask you for a Declaration of Security, control access to your berth and expect you to control access to your gangway. The Code reaches vessels through the ports they visit as much as through their own flag.

Part A and Part B

Part A is mandatory. It sets out the requirements: the security assessment, the plan, the officers, the records, the verification and certification regime. When a surveyor says "the Code requires", they mean Part A.

Part B is guidance. It explains how to meet Part A, and it is where most of the practical detail lives, including the drill frequencies and the measures suggested at each security level. Part B is recommendatory in the Code itself, but several flag administrations have made parts of it mandatory for their ships, and approved Ship Security Plans routinely commit to it. Check what your flag has done before treating Part B as optional, because once your plan adopts a Part B measure, that measure is auditable.

Who does what

The Code names three roles and leaves one authority undisturbed.

  • Company Security Officer (CSO) — ashore. Owns the ship security assessment, gets the plan written, approved and kept current, and arranges training and internal audits. One person may cover several ships.
  • Ship Security Officer (SSO) — aboard, named in the plan, and accountable to the Master. Implements and maintains the plan, runs the drills, keeps the security records, and reports deficiencies to the CSO. On yachts this is very often the Chief Officer.
  • Port Facility Security Officer (PFSO) — ashore, at the facility. Your counterpart when a Declaration of Security is raised or the level changes.
  • The Master keeps overriding authority. SOLAS XI-2 is explicit that the Master’s professional judgement on the safety and security of the ship is not to be constrained by the Company, the charterer or anyone else, and that where safety and security conflict the Master applies safety first.

The documents

Six things are worth knowing by name, because these are what get asked for.

  • Ship Security Assessment (SSA) — the risk work that comes first. It identifies the ship’s key shipboard operations, the threats against them, and the existing weaknesses, including the human ones.
  • Ship Security Plan (SSP) — the approved document the SSA produces. It states the measures in force at each security level, defines the restricted areas, and sets out access control, searches, drills, communications and reporting. It is confidential, and access to it is itself controlled.
  • International Ship Security Certificate (ISSC) — issued after verification, valid for a maximum of five years, with at least one intermediate verification between the second and third anniversary. An Interim ISSC covers a new ship, a change of flag or a change of company, and runs for six months.
  • Declaration of Security (DoS) — an agreement between a ship and a port facility, or between two ships, recording who is responsible for which security measures during an interface. It is required in the situations your flag or the facility specifies, and typically when the two parties are operating at different security levels.
  • Continuous Synopsis Record (CSR) — the ship’s biography, issued by the flag under SOLAS XI-1: names, owners, registered operators, class and flag, right back through every change.
  • Ship Security Alert System (SSAS) — the covert alert required by SOLAS XI-2, which sends a signal ashore identifying the ship and its position without alerting anyone on board or raising an alarm on any other ship. It is tested, and the test is recorded.

The three security levels

Security levels are set by the Contracting Government, not by the ship, and a ship must be able to operate at the level in force at the port facility it is using. The plan has to say what the ship does differently at each one, which is the point of the table below: Level 2 is not "be more careful", it is a defined set of additional measures your plan already committed to.

The three ISPS security levels and what each one means in practice
LevelWhat it meansWhat typically changes at the gangway
Level 1
Normal
The minimum protective measures, maintained at all times. Identity checked and the reason for boarding confirmed. Restricted areas defined and marked. Sample searching of persons and their effects.
Level 2
Heightened
Additional measures, for as long as the heightened risk lasts. A higher proportion of people searched. Access points reduced and manned. Escorting of visitors. Deck and overside watches increased.
Level 3
Exceptional
A security incident is probable or imminent. Not a routine state, and usually accompanied by instructions from the authorities. Search of every person seeking to board. Access limited to a single controlled point, or suspended. Movement on board restricted and supervised.

Two practical points. A change of level has to reach the people standing the gangway watch within minutes, not at the next handover, and the change itself is a record. And the level in force is one of the first things an inspector establishes, because everything they check afterwards is judged against it.

Restricted areas

Every SSP defines restricted areas and how they are controlled at each level. On a merchant ship that is the bridge, the machinery spaces, the steering gear compartment, spaces holding security and surveillance equipment, ventilation and air-conditioning, spaces with access to potable water, and any space holding dangerous goods. On a yacht it is the same list plus the owner’s and guests’ accommodation, the tender garage and the crew mess.

The measure that matters is the one that is easiest to skip: a visitor who is not cleared for a restricted area has to be visibly identifiable as such and has to be accompanied. A badge that says Restricted at a glance does more work in a yard period than any amount of written procedure, because the crew member who spots the contractor two decks below the workshop does not have to remember who that person is.

Access control and the visitor record

The Code never uses the phrase "visitor log". What Part A requires is that the plan prevent unauthorised access to the ship and to restricted areas, and Part B describes what that looks like: checking the identity of all persons seeking to board, confirming the reason they are boarding, and searching in proportion to the level in force.

The log is how you demonstrate any of that happened. Practically every approved SSP requires a record of persons boarding at the point of access, so the obligation is real even though it lives in your plan rather than in a numbered paragraph. A record that stands up shows, for every person who is not crew: who they are and who they represent, why they are aboard or who is hosting them, when they boarded and when they left, and what was checked — identity verified, search carried out, and by whom. There is more on this in ISPS visitor log requirements.

Drills and exercises

These are two different things and inspectors treat them as two different things.

  • Drills test individual elements of the plan and are run by the ship. Part B says drills should be carried out at least once every three months. Where more than 25% of the ship’s personnel are changed at one time for people who have not taken part in a drill on that ship in the last three months, a drill should be run within one week of the change — a provision written for merchant crew rotations that lands squarely on a yacht at the start of a season.
  • Exercises test the full plan and involve others: the company, the port facility, and where relevant the authorities. They should be carried out at least once each calendar year, with no more than 18 months between them, and may be full-scale, tabletop, simulated, or combined with another exercise.

Subjects worth drilling, because they are the ones that get audited: unauthorised boarding, response to a bomb threat, a suspect package, a breach of a restricted area, a change from Level 1 to Level 2 while alongside, and testing the SSAS.

The records you must be able to produce

Part A of the Code lists the security records to be kept aboard. This is the shortest useful summary of what the Code actually demands of you day to day, and it is worth reading as a checklist rather than as prose.

Security records required by Part A of the ISPS Code
RecordWhat it has to show
Training, drills and exercisesDate, what was drilled, who took part.
Security threats and incidentsWhat happened, when, what was done, who was told.
Breaches of securityThe same, for breaches specifically.
Changes in security levelThe level, the time it changed, and on whose instruction.
Security communicationsCommunications relating directly to the security of the ship.
Internal audits and reviewsAudits of security activities and what they found.
Review of the SSAThat the assessment has been reviewed periodically.
Review of the SSPThe same for the plan, with amendments recorded.
Amendments to the planThat approved amendments were actually implemented.
Security equipmentMaintenance, calibration and testing, including the SSAS test.

Retention and format. The Code requires records to be kept for the minimum period specified by the ship’s Administration, so the number is a flag matter rather than a single global figure. Where nothing is specified, the common practice is to keep them for the life of the certificate, which is five years. Records may be kept in electronic format, and must be protected from unauthorised access and disclosure — which is a requirement on the storage, not an argument against it.

Verification, audits and inspection

The ISSC is issued after an initial verification and kept alive by an intermediate one. Between those, the Company runs internal audits of its own security activities, and Port State Control may look at security during any inspection.

What a PSC officer or a PFSO asks about security is nearly always concrete. Who is the SSO. What level are you at. Show me the record of the last drill. Who was aboard on this date. Who searched this person. When was the SSAS last tested. Show me a Declaration of Security from this call. What they are testing is not whether you own a plan — everybody owns a plan — but whether the plan is practised or laminated. If clear control measures are not demonstrated, a PSC officer has powers under Chapter XI-2 ranging from inspection to detention or denial of entry to port.

The ISPS charge

Worth clearing up because it sends a lot of people to this page. The ISPS charge, or ISPS surcharge, is a commercial fee, not a legal requirement of the Code. Compliance costs money — the SSO, the plan, the equipment, the audits ashore and the terminal’s own access control and surveillance — and carriers and terminals recover it as a line item, usually split into a carrier security fee and a terminal security charge. It is normally paid by whoever pays the freight. It has nothing to do with whether your ship is compliant, and it will not appear on a yacht’s berthing invoice as such, though the marina’s own security costs are in the rate somewhere.

ISPS on a yacht

The Code was written with container terminals in mind and then applied to vessels where the "cargo" is the owner’s family, the "crew change" is a seasonal turnover, and the port facility is a marina in the middle of a town. A few things follow.

  • Scope turns on commercial registration and 500 GT. A commercially registered yacht of 500 GT and over on international voyages carries an SSP, an SSO and an ISSC. A private yacht not engaged in trade sits outside the mandatory regime. Below 500 GT the Code does not bite directly. Your flag’s yacht code and your management company’s standards may still ask for equivalent measures, so the honest answer to "does ISPS apply to us" always starts with your flag and your commercial status.
  • Out of scope still means controlled. Private yachts routinely run visitor control anyway, because the marina expects it, the owner expects it, and knowing who is aboard is a safety question before it is a compliance one. It is also the difference between a muster that accounts for everybody and one that does not.
  • The gangway is the whole game. A yacht has one access point, a watchkeeper who is often alone at it, and in a yard period more contractors over it in a week than a merchant ship sees in a year. Almost every ISPS finding on a yacht is an access control finding.
  • Guests are not visitors. The owner’s party do not get processed like a surveyor. They still have to be accounted for — counted on the muster roster, with the details the flag asks for — but putting them through a visitor sign-in flow is the wrong answer to the right question.
  • Season start is a drill trigger. The 25% crew change provision is written for merchant rotations, and it catches yachts hardest in April.

Where it usually goes wrong

The findings repeat, across flags and across vessel types.

  • The visitor log has arrivals and no departures, so the ship cannot say who was aboard.
  • The plan commits to searching a proportion of people at Level 1, and nothing on board records that any search was ever carried out or by whom.
  • The level went up for a port call and there is no record of when it changed or who was told.
  • Drills are logged as a line in a book with no detail of what was drilled or who attended.
  • Restricted areas are defined in the plan and unmarked in reality, and contractors move unaccompanied.
  • The SSAS test is overdue, or was done and not written down.
  • The record exists but lives in one book at the gangway, so a question about last March takes twenty minutes of page-turning in front of the inspector.

Every one of those is a record-keeping failure rather than a security failure. The measures were mostly being taken. Nothing was capturing them.

The Muster App

Set the level. The gangway changes.

The ship side of ISPS runs on an iPad at the gangway and in the admin ashore. You define what Levels 1, 2 and 3 mean for this vessel, and the check-in enforces it — from automatic sign-in to a mandatory search of every visitor.

Core
The admin security level page. Level 1 Normal is active with its search threshold set to search every 20 visitors, and switches for contact details, ID verification, the search notice and the restricted step. Level 2 Heightened sits below it, set to search every 5 visitors.
Admin · what each level means for this vessel

The level is stated before anything else

The iPad names the vessel, states the level in force, and tells the visitor they may be asked for identification and to submit to search — before a single field is filled in. Access at the Master’s discretion, on the screen, in writing.

The change reaches the watch instantly

Raise the level in the admin and every iPad and every crew phone has it. No handover briefing, no laminated card to swap, and the change is on the record with its time.

Searches happen, and are attributed

At the frequency each level sets, the check-in holds and alerts a crew member by push or WhatsApp with the visitor’s name and photo. A PIN clears the hold, and the crew member signs as search officer against that visit.

A typical setup. Search frequency, ID checks and the restricted step are yours to define per level. The whole flow is on the security page.

What the Code asks for.
Where it lives in the app.

The Code is not software and no app makes a vessel compliant. What software can do is stop the evidence depending on somebody remembering to write it down.

ISPS obligations and the part of The Muster App that produces the record
What the Code asks of the ship What produces the record
Prevent unauthorised access to the shipGangway check-in on the iPad, with a photo, a named host and a signed agreement before boarding
Check identity and confirm reason for boardingID document scanned and read, with whether the name matched, and the host recorded per visit
Search in proportion to the level in forcePer-level search frequency, a hold at the kiosk, and the crew member named as search officer
Record changes in security levelThe active level is set in the admin and carried to every iPad and crew phone
Control access to restricted areasA red Restricted badge printed at check-in for anyone who must stay accompanied
Know who is on board at any momentThe live board: everyone aboard now, crew and visitors, with time on board counting
Account for everybody in an emergencyRoll call called from the crew board, ending in a PDF of who was accounted for and how long it took
Record drills: date, subject, attendanceEmergency scenarios you define, including a security incident, each drill logged with its attendance and notes
Record security equipment checksChecklists built or imported, run on the phone in the space, with fails becoming tracked follow-ups
Produce the record on demandSearchable by name, company, host or date range, and exported as a PDF with both signatures

The Muster App is not a Ship Security Plan and does not replace one. It is where the measures your plan commits to get carried out and recorded.

Badges, drills and the rounds in between.

A Restricted badge, printed at the gangway

Visitor badges print at check-in on a label printer, and a visitor who must stay accompanied prints a red Restricted badge. The crew member who sees them two decks from where they should be does not have to know who they are. What you need at the gangway.

A security drill, recorded like any other

Emergencies are yours to define, so Security Incident — Level 2 or 3 response, restricted area lockdown, crew accounting — sits alongside Fire and Man Overboard with its own alarm signal, stations and duties. The drill is called from who is actually aboard and ends in a PDF. Building emergency scenarios.

Security rounds that leave evidence

Restricted area checks, SSAS tests, gangway equipment: import the laminated card you already run or build the check in the admin, and crew complete it on their own phones in the space being checked. Anything that fails becomes a job with a name and a due date against it. Checklists and inspections.

The visitor log itself, and what it holds, is on the visitors page. Coming from an office sign-in app? What changes aboard.

ISPS questions we get asked.

What does ISPS stand for?

International Ship and Port Facility Security Code. It sits under Chapter XI-2 of the SOLAS Convention and has been in force since 1 July 2004.

Does the ISPS Code apply to my yacht?

If the yacht is commercially registered, 500 GT or over and trading internationally, yes: you carry a Ship Security Plan, a named Ship Security Officer and an International Ship Security Certificate. A private yacht not engaged in trade is outside the mandatory scope, and a commercial yacht below 500 GT is not caught directly. Your flag’s yacht code and the port facilities you use may still require equivalent measures, so confirm it with your flag rather than with tonnage alone.

What are the three ISPS security levels?

Level 1 is normal operation and the minimum measures maintained at all times. Level 2 is heightened, with additional measures for as long as the raised risk lasts. Level 3 is exceptional, applied when a security incident is probable or imminent. The level is set by the Contracting Government, and your plan has to state what the ship does differently at each one.

How often are ISPS security drills required?

Part B of the Code says drills should be run at least once every three months, and additionally within one week whenever more than a quarter of the ship’s personnel are changed at one time for people who have not drilled on that ship in the previous three months. Exercises, which test the whole plan and involve the company and the port facility, should be run at least once each calendar year with no more than 18 months between them.

Does the ISPS Code require a visitor log?

Not in those words. The Code requires the Ship Security Plan to prevent unauthorised access and to check the identity and purpose of everyone seeking to board. Nearly every approved plan meets that with a record of persons boarding at the access point, so the obligation is real but it lives in your plan. There is more in ISPS visitor log requirements.

Can ISPS records be kept electronically?

Yes. The Code allows security records in any format and requires them to be protected from unauthorised access and disclosure. How long you keep them is set by your Administration; where nothing is specified, five years, the life of the certificate, is the usual practice.

What is an ISPS charge?

A commercial surcharge carriers and terminals use to recover the cost of complying with the Code — the security officer, the plan, the equipment, the audits and the terminal’s access control. It is usually split into a carrier security fee and a terminal security charge and paid by whoever pays the freight. It is not a requirement of the Code itself.

Who is the Ship Security Officer?

The person named in the Ship Security Plan and accountable to the Master for implementing it: running the drills, keeping the security records, inspecting the ship and reporting deficiencies to the Company Security Officer. On yachts it is very often the Chief Officer.

Does The Muster App make a vessel ISPS compliant?

No, and nothing sold as software does. Compliance comes from an approved Ship Security Plan and from the ship following it. What the app does is carry out and record the parts of the plan that happen at the gangway and on the deck — access control, ID checks, searches, restricted badges, the level in force, drills and security rounds — so the evidence is a by-product of the work rather than a writing-up job.

Try it at your gangway.

Visitor check-in and the ISPS security levels are on every plan.

14-day free trial. Refund policy