What the ISPS Code is
The International Ship and Port Facility Security Code is the security half of SOLAS. It sits under SOLAS Chapter XI-2, Special measures to enhance maritime security, and it has been in force since 1 July 2004. Where the rest of SOLAS is concerned with a ship surviving a fire or a flood, the ISPS Code is concerned with a ship being interfered with on purpose: unauthorised boarding, stowaways, weapons and explosives brought over the gangway, tampering with the ship or its cargo.
It works by asking three things of every ship in scope. Assess your own vulnerabilities. Write a plan that answers them. Then prove, in records, that the plan is what actually happens. Almost every argument anyone has about the Code is an argument about that third part.
Why it exists
The Code was drafted after the attacks of 11 September 2001, when it became clear that international shipping had a comprehensive safety regime and nothing equivalent for deliberate acts. A Conference of Contracting Governments to the SOLAS Convention adopted the new Chapter XI-2 and the ISPS Code in December 2002, and gave the industry eighteen months to implement it. It took effect on 1 July 2004. That is unusually fast for an IMO instrument, and it is the reason the Code reads as a framework rather than a rulebook: it tells you what outcomes to achieve and leaves the method to your plan.
Who it applies to
Chapter XI-2 applies, on international voyages, to:
- Passenger ships, including high-speed passenger craft
- Cargo ships of 500 GT and over, including high-speed craft
- Mobile offshore drilling units
- The port facilities that serve those ships
Two consequences follow that people miss. The first is that scope is a function of tonnage and trade, not of what the vessel looks like: a commercially registered yacht of 500 GT and over on an international voyage is a cargo ship for these purposes and is in scope. The second is that being out of scope does not put you outside the regime. If you berth at an ISPS-regulated port facility, that facility’s approved plan governs the interface, and it may ask you for a Declaration of Security, control access to your berth and expect you to control access to your gangway. The Code reaches vessels through the ports they visit as much as through their own flag.
Part A and Part B
Part A is mandatory. It sets out the requirements: the security assessment, the plan, the officers, the records, the verification and certification regime. When a surveyor says "the Code requires", they mean Part A.
Part B is guidance. It explains how to meet Part A, and it is where most of the practical detail lives, including the drill frequencies and the measures suggested at each security level. Part B is recommendatory in the Code itself, but several flag administrations have made parts of it mandatory for their ships, and approved Ship Security Plans routinely commit to it. Check what your flag has done before treating Part B as optional, because once your plan adopts a Part B measure, that measure is auditable.
Who does what
The Code names three roles and leaves one authority undisturbed.
- Company Security Officer (CSO) — ashore. Owns the ship security assessment, gets the plan written, approved and kept current, and arranges training and internal audits. One person may cover several ships.
- Ship Security Officer (SSO) — aboard, named in the plan, and accountable to the Master. Implements and maintains the plan, runs the drills, keeps the security records, and reports deficiencies to the CSO. On yachts this is very often the Chief Officer.
- Port Facility Security Officer (PFSO) — ashore, at the facility. Your counterpart when a Declaration of Security is raised or the level changes.
- The Master keeps overriding authority. SOLAS XI-2 is explicit that the Master’s professional judgement on the safety and security of the ship is not to be constrained by the Company, the charterer or anyone else, and that where safety and security conflict the Master applies safety first.
The documents
Six things are worth knowing by name, because these are what get asked for.
- Ship Security Assessment (SSA) — the risk work that comes first. It identifies the ship’s key shipboard operations, the threats against them, and the existing weaknesses, including the human ones.
- Ship Security Plan (SSP) — the approved document the SSA produces. It states the measures in force at each security level, defines the restricted areas, and sets out access control, searches, drills, communications and reporting. It is confidential, and access to it is itself controlled.
- International Ship Security Certificate (ISSC) — issued after verification, valid for a maximum of five years, with at least one intermediate verification between the second and third anniversary. An Interim ISSC covers a new ship, a change of flag or a change of company, and runs for six months.
- Declaration of Security (DoS) — an agreement between a ship and a port facility, or between two ships, recording who is responsible for which security measures during an interface. It is required in the situations your flag or the facility specifies, and typically when the two parties are operating at different security levels.
- Continuous Synopsis Record (CSR) — the ship’s biography, issued by the flag under SOLAS XI-1: names, owners, registered operators, class and flag, right back through every change.
- Ship Security Alert System (SSAS) — the covert alert required by SOLAS XI-2, which sends a signal ashore identifying the ship and its position without alerting anyone on board or raising an alarm on any other ship. It is tested, and the test is recorded.
The three security levels
Security levels are set by the Contracting Government, not by the ship, and a ship must be able to operate at the level in force at the port facility it is using. The plan has to say what the ship does differently at each one, which is the point of the table below: Level 2 is not "be more careful", it is a defined set of additional measures your plan already committed to.
| Level | What it means | What typically changes at the gangway |
|---|---|---|
| Level 1 Normal |
The minimum protective measures, maintained at all times. | Identity checked and the reason for boarding confirmed. Restricted areas defined and marked. Sample searching of persons and their effects. |
| Level 2 Heightened |
Additional measures, for as long as the heightened risk lasts. | A higher proportion of people searched. Access points reduced and manned. Escorting of visitors. Deck and overside watches increased. |
| Level 3 Exceptional |
A security incident is probable or imminent. Not a routine state, and usually accompanied by instructions from the authorities. | Search of every person seeking to board. Access limited to a single controlled point, or suspended. Movement on board restricted and supervised. |
Two practical points. A change of level has to reach the people standing the gangway watch within minutes, not at the next handover, and the change itself is a record. And the level in force is one of the first things an inspector establishes, because everything they check afterwards is judged against it.
Restricted areas
Every SSP defines restricted areas and how they are controlled at each level. On a merchant ship that is the bridge, the machinery spaces, the steering gear compartment, spaces holding security and surveillance equipment, ventilation and air-conditioning, spaces with access to potable water, and any space holding dangerous goods. On a yacht it is the same list plus the owner’s and guests’ accommodation, the tender garage and the crew mess.
The measure that matters is the one that is easiest to skip: a visitor who is not cleared for a restricted area has to be visibly identifiable as such and has to be accompanied. A badge that says Restricted at a glance does more work in a yard period than any amount of written procedure, because the crew member who spots the contractor two decks below the workshop does not have to remember who that person is.
Access control and the visitor record
The Code never uses the phrase "visitor log". What Part A requires is that the plan prevent unauthorised access to the ship and to restricted areas, and Part B describes what that looks like: checking the identity of all persons seeking to board, confirming the reason they are boarding, and searching in proportion to the level in force.
The log is how you demonstrate any of that happened. Practically every approved SSP requires a record of persons boarding at the point of access, so the obligation is real even though it lives in your plan rather than in a numbered paragraph. A record that stands up shows, for every person who is not crew: who they are and who they represent, why they are aboard or who is hosting them, when they boarded and when they left, and what was checked — identity verified, search carried out, and by whom. There is more on this in ISPS visitor log requirements.
Drills and exercises
These are two different things and inspectors treat them as two different things.
- Drills test individual elements of the plan and are run by the ship. Part B says drills should be carried out at least once every three months. Where more than 25% of the ship’s personnel are changed at one time for people who have not taken part in a drill on that ship in the last three months, a drill should be run within one week of the change — a provision written for merchant crew rotations that lands squarely on a yacht at the start of a season.
- Exercises test the full plan and involve others: the company, the port facility, and where relevant the authorities. They should be carried out at least once each calendar year, with no more than 18 months between them, and may be full-scale, tabletop, simulated, or combined with another exercise.
Subjects worth drilling, because they are the ones that get audited: unauthorised boarding, response to a bomb threat, a suspect package, a breach of a restricted area, a change from Level 1 to Level 2 while alongside, and testing the SSAS.
The records you must be able to produce
Part A of the Code lists the security records to be kept aboard. This is the shortest useful summary of what the Code actually demands of you day to day, and it is worth reading as a checklist rather than as prose.
| Record | What it has to show |
|---|---|
| Training, drills and exercises | Date, what was drilled, who took part. |
| Security threats and incidents | What happened, when, what was done, who was told. |
| Breaches of security | The same, for breaches specifically. |
| Changes in security level | The level, the time it changed, and on whose instruction. |
| Security communications | Communications relating directly to the security of the ship. |
| Internal audits and reviews | Audits of security activities and what they found. |
| Review of the SSA | That the assessment has been reviewed periodically. |
| Review of the SSP | The same for the plan, with amendments recorded. |
| Amendments to the plan | That approved amendments were actually implemented. |
| Security equipment | Maintenance, calibration and testing, including the SSAS test. |
Retention and format. The Code requires records to be kept for the minimum period specified by the ship’s Administration, so the number is a flag matter rather than a single global figure. Where nothing is specified, the common practice is to keep them for the life of the certificate, which is five years. Records may be kept in electronic format, and must be protected from unauthorised access and disclosure — which is a requirement on the storage, not an argument against it.
Verification, audits and inspection
The ISSC is issued after an initial verification and kept alive by an intermediate one. Between those, the Company runs internal audits of its own security activities, and Port State Control may look at security during any inspection.
What a PSC officer or a PFSO asks about security is nearly always concrete. Who is the SSO. What level are you at. Show me the record of the last drill. Who was aboard on this date. Who searched this person. When was the SSAS last tested. Show me a Declaration of Security from this call. What they are testing is not whether you own a plan — everybody owns a plan — but whether the plan is practised or laminated. If clear control measures are not demonstrated, a PSC officer has powers under Chapter XI-2 ranging from inspection to detention or denial of entry to port.
The ISPS charge
Worth clearing up because it sends a lot of people to this page. The ISPS charge, or ISPS surcharge, is a commercial fee, not a legal requirement of the Code. Compliance costs money — the SSO, the plan, the equipment, the audits ashore and the terminal’s own access control and surveillance — and carriers and terminals recover it as a line item, usually split into a carrier security fee and a terminal security charge. It is normally paid by whoever pays the freight. It has nothing to do with whether your ship is compliant, and it will not appear on a yacht’s berthing invoice as such, though the marina’s own security costs are in the rate somewhere.
ISPS on a yacht
The Code was written with container terminals in mind and then applied to vessels where the "cargo" is the owner’s family, the "crew change" is a seasonal turnover, and the port facility is a marina in the middle of a town. A few things follow.
- Scope turns on commercial registration and 500 GT. A commercially registered yacht of 500 GT and over on international voyages carries an SSP, an SSO and an ISSC. A private yacht not engaged in trade sits outside the mandatory regime. Below 500 GT the Code does not bite directly. Your flag’s yacht code and your management company’s standards may still ask for equivalent measures, so the honest answer to "does ISPS apply to us" always starts with your flag and your commercial status.
- Out of scope still means controlled. Private yachts routinely run visitor control anyway, because the marina expects it, the owner expects it, and knowing who is aboard is a safety question before it is a compliance one. It is also the difference between a muster that accounts for everybody and one that does not.
- The gangway is the whole game. A yacht has one access point, a watchkeeper who is often alone at it, and in a yard period more contractors over it in a week than a merchant ship sees in a year. Almost every ISPS finding on a yacht is an access control finding.
- Guests are not visitors. The owner’s party do not get processed like a surveyor. They still have to be accounted for — counted on the muster roster, with the details the flag asks for — but putting them through a visitor sign-in flow is the wrong answer to the right question.
- Season start is a drill trigger. The 25% crew change provision is written for merchant rotations, and it catches yachts hardest in April.
Where it usually goes wrong
The findings repeat, across flags and across vessel types.
- The visitor log has arrivals and no departures, so the ship cannot say who was aboard.
- The plan commits to searching a proportion of people at Level 1, and nothing on board records that any search was ever carried out or by whom.
- The level went up for a port call and there is no record of when it changed or who was told.
- Drills are logged as a line in a book with no detail of what was drilled or who attended.
- Restricted areas are defined in the plan and unmarked in reality, and contractors move unaccompanied.
- The SSAS test is overdue, or was done and not written down.
- The record exists but lives in one book at the gangway, so a question about last March takes twenty minutes of page-turning in front of the inspector.
Every one of those is a record-keeping failure rather than a security failure. The measures were mostly being taken. Nothing was capturing them.