Change description : 2026-08-14 10:44:00: Replaced references to the Maritime Security and MLC Branch with the Audit and Verification Operations branch and updated contact details. [Guidance and regulation]
The maritime community has a series of special measures to enhance maritime security. These are contained in the International Convention for Safety of Life at Sea (SOLAS) Chapter XI-2 and the International Ship and Port Facility (ISPS) Code.
This guide explains how maritime security is managed in the UK, how security measures are applied and how you should comply with them. It also provides guidance on how to deal with stowaways and deter acts of violence against merchant ships, such as piracy and armed robbery.
You can find guidance and information on maritime security training. It also explains how Ship Identification Numbers (SINs) and Continuous Synopsis Records (CSRs) work.
Maritime security management
The AuditMaritimeSecurityand VerificationMLC OperationsBranch branch is part of the Maritime and Coastguard Agency (MCA) and co-ordinates a series of special measures to ensure security in the maritime community.
The branchBranch provides technical advice and guidance to make sure that SOLAS Chapter XI-2 and the ISPS Code are consistently applied and maintained.
The Department for Transport and the AuditMaritimeSecurityand VerificationMLC Operations branchBranch
Department for Transport (DfT) is responsible for security across all forms of transport, including maritime.
As policy leaders and advisers, DfT implements measures in UK ports that security arrangements meet UK standards.
The MCA is responsible to DfT for:
implementing the ISPS Code for all UK-registered ships
undertaking security aspects of Port State Control (PSC) inspections of foreign vessels in UK ports, including passenger ships where this is a logical extension of the PSC inspection
receiving and handling ship security alerts in line with agreed standard operating procedures
approving and auditing training providers for Ship Security Officer (SSO) and Company Security Officer (CSO) courses
The ISPS Code is a comprehensive set of measures designed to strengthen the security of ships and port facilities.
It was historically implemented in UK through the EU regulation on enhancing ship and port facility security (725/2004). The Ship and Port Security (Amendment etc.) (EU Exit) Regulations 2019 came into force on EU exit day. At this time, SI 2019 No. 0308 amends 2004/0725 (Regulation), SI 2004 No. 1495, SI 2009 No. 2048 and revokes 2008/0324 (Regulation).
The code takes the approach that ensuring the security of ships and port facilities is a risk management activity and that, to determine what security measures are appropriate, an assessment of the risks must be made in each particular case.
The purpose of the code is to provide a standardised, consistent framework for evaluating risk. This enables governments to counteract changes in threat with changes in vulnerability for ships and port facilities by adopting the appropriate security levels and corresponding security measures.
This duty surveyor number must not be used for anyurgent or routine enquiriesenquires during normal office hours.
Ship Security Plans
To comply with the ISPS Code requirements, every companycompany/ship or ship must have a Ship Security Plan (SSP). As a minimum, this must address the requirements in paragraphsparagraph A/9.4 and B/9.2.
The purpose of an SSP is to:
help prevent illegal acts against the ship, crew and passengers
minimise damage to the marine environment and port facilities
SSPs for for UK-registered vessels must be approved by the the MCA or by a Recognised Security Organisation (RSO) when ISSC certification for those EAS vessels isare delegated to RSOs.
When you submit an SSP it must be accompanied by a Ship Security Assessment (SSA). The SSA is an essential and integral part of the process of developing and updating an SSP. In addition,addition MCA form MSF5611 mustto be completed by the CSO and submitted along with the SSP.
While formulating an SSP, CSOsCSO shouldto take guidance onfor UK ship security requirements from Maritime Security Measures (MSM),(MSM) which areis available from theMaritime AuditSecurity and VerificationMLC Operationsbranch Branch or CSM. MSMsMSM show CSOs for UK-registered ships what must be contained within SSPs.
For further information please email hq_maritimesecurity@mcga.gov.uk.YoucancalltheMCASecurityandMLCbranchduringofficehourson+44(0)2039085178.
You should send your SSP to hq_maritimesecurity@mcga.gov.uk for approval. There is currently no charge applicablefor approving SSPs.atpresent.
Ship Security Alert Systems (SSAS)
The SSAS is part of the ISPS Code. It is a system that contributes to the International Maritime Organization’s (IMO’s) efforts to strengthen maritime security and suppress acts of terrorism and piracy against shipping.
The SSAS for UK-registered ships should be programmed to send an alert to a nominated 24-hour24hourcontact and to the UK Joint Rescue Coordination Centre (UK-JRCC).
To notify the MCA of changes in contact details of the nominated contact or ofthe CSO, the CSO should complete MSF5608 and send it to the address detailed on the form.
SSAS is not required to be fitted on board ships where the ISPS Codecode doesis not apply.applicable. However, if a shipowner decides to fit a SSAS on board those ships, the masterMaster and key crew membersonboardmust receiveget training and familiarisation on activating, deactivating and limiting false alertsalert from the SSAS unit fitted on board. MSF5608 (ISPS Code Contact Details) must be completed and sent to the MCA for recording the details of the CSO and vessel.
For further information please email HQ_maritimesecurity@mcga.gov.uk.YoucancalltheMCASecurityandMLCBranchduringofficehourson+44(0)2039085178.
Ships that must comply with maritime security requirements
The SOLAS Chapter XI-2 and the ISPS Code apply to the following types of ships engaged on international voyages:
passenger ships, including high-speed passenger craft
cargo ships, including high-speed craft, of 500 gross tonnage and upwards
mobile offshore drilling units
The UK has extended the ISPS Code to include:
domestic Class‘Class AA’ passenger ships (domestic ships which travel more than 20 miles from a place of refuge)
domestic Class‘Class BB’ passenger ships certified to carry more than 250 passengers and tankers
For further information please email HQ_maritimesecurity@mcga.gov.uk.YoucancalltheMCASecurityandMLCBranchduringofficehourson+44(0)2039085178.
Your application for ISPS Code verification (survey of ship security systems)system) will usually be undertaken at the same time as an International Safety Management Code audit and MLC 2006 inspection.
To apply for an ISPS Code verification, you should complete and send an application form to your local Marine Office.
There is no fee for undertaking the ISPS verification.
For further information please email HQ_maritimesecurity@mcga.gov.uk.YoucancalltheMCASecurityandMLCbranchduringofficehourson+44(0)2039085178.
Deter piracy, armed robbery and other acts of violence against merchant ships
TheDfT has responsibility for counter-piracypolicy policy.oncounterpiracy.
Marine Guidance Note (MGN) 440 (M) Amendment 1 aims to help ship owners, operators,operators(companies),masters and seafarers understand the risks posed by piracy, armed robbery and other acts of violence against merchant shipping. DfT has identified steps you can take to reduce the risk of such acts and advises on how to deal with and report them if they occur.
This MGN and associated linksofnational and international guidance covers:coverthefollowing:
specific guidance for Somalia, the Northwest Indian Ocean, the Gulf of Aden and the Gulf of Guinea
recommended practices to deter acts of piracy
recommended practices to deter acts of armed robbery
jurisdiction and intervention
the role of the port and coastal state
reporting incidents
Key points include:
planning the voyage by- carryingcarry out a risk assessment and assessingmakeanassessmentofthe measures required when transiting high-riskhighriskareas
training and planning,planning as- many attempted piracy and armed robbery attacks‘attacks’ are unsuccessfulunsuccessful, becausecountered crewsbyships’crewwhohave planned and trained in advance
being vigilant
maintaining a high speed where possible in high-risk areas
using effectivegood communications with relevant authorities and- reportingreport incidentstotherelevantauthoritiesbefore, during or after an attack
High threat of piracy in the Gulf of Aden and off the coast of Somalia
There is a growing need for CSOs to remain aware of piracyhigh threats ofpiracyin the Gulf of Aden,Adenandoff the coast of Somalia and elsewhere in the world. If your vessel will be passing through the area, you should:
Report frequently to the UK Maritime Trade Organisation in Dubai (UKMTO Dubai) and email info@ukmto.orgthem for the latest informationatinfo@ukmto.org.
UKMTO Dubai can provide advice and information on other maritime security issues in the Gulf of Aden, theStraits Strait of Hormuz and thegeneral wider Gulf area, including information on knownnaval operations and exercises.exercises,andpossibleinteractionbetweenthemandvesselsonpassage.
For further information, email the Maritime Security Division of the Department for Transport at maritimesecurity@dft.gov.uk.
Stowaways
The UK Border Agency has responsibility for dealing with stowaways.
MarineMaritime Guidance Note (MGN)) 70 70(M) (M), as amended,amended offers guidanceguidelines to ship owners, operators, charterers, managers, shipping agents, port authorities, masters and ship’s officers on managinghow stowawayto incidents.dealwithstowawaysonvessels.It also provides practical advice on the procedures to follow if you find a stowaway on board.
MGN 70 (M) reminds you of the need:
for continuous vigilance against stowaways
to carry out adequate searches, especially when a hold is to be sealed orand/or fumigated
to provide feedback on the guidelines’practical effectiveness of the guidance
Always refer to the latest IMO guidancelatestguidelineson the allocation of responsibilities fortoseekthe successful resolution of stowaway cases.
For further information please email HQ_maritimesecurity@mcga.gov.uk.YoucancalltheMCASecurityandMLCBranchduringofficehourson+44(0)2039085178.
Ship Identification Numbers and Continuous Synopsis Records
SINs and CSRs are special measures to ensure maritime safety contained in theSOLAS Chapter XI-1. They are also closely associated with the application of the ISPS Code.
SOLAS Chapter XI-1 Regulation 3/4.1 requires that a SIN be permanently marked in visible places on the vessel,vessel as applicable:applicable,eg:
on the stern
on either side of the hull, amidships port and starboard, above the deepest assigned load line
on either side of the superstructure, port and starboard
on the front of the superstructure
inthecaseofpassengerships,on a horizontal surface visible from the air, in the case of passenger shipsair
Identification for large commercial yachts
UK-registered large commercial yachts are authorised to display the SIN on a horizontal‘horizontal surface visible from the air,air’, in the same way as passenger ships.
Continuous Synopsis Record
The CSR is intended to provide an onboardon-board record of the ship’shistory history.oftheship.Every ship tothat which SOLAS Chapter I applies tomust have an updated CSR containing specified information, including:
the name of the state whosefor flagwhich the ship is entitled to flytheflag
the date of ship registration
the SIN
the port ofit registryisregisteredat
the name, registered address and unique identification number of the owner
For further information please email HQ_maritimesecurity@mcga.gov.uk.YoucancalltheMCASecurityandMLCBranchduringofficehourson+44(0)2039085178.
Training for Company Security Officers and Ship Security Officers
Shipping companies are required to designate a CSO to co-ordinate the security activities of the company and its ships, and to liaise with port facilities and governments. All ships must have a properly trained SSO on board.
CSO training and duties
The ISPS Code defines the CSO as the person designated by the company to make sure that:
a Ship Security Assessment is carried out
a SSP is developed, submitted for approval,approval and thenthereafter implemented and maintained
liaison with port facility security officers and the SSO is maintainedupheld
There is no requirement for these duties to be included in the SSP, but evidence thatof the activities havehaving taken place will be sought during verification visits.
A key requirement of the ISPS Code is thatforthepeople with security responsibilities aretobeappropriately trained.trainedtocarryouttheirduties.The government requires thatCSOs and SSOs associated with UK-registered ships to undergo approved trainingtraining, in accordance with Maritime Safety Committee (MSC)(MSC)/Circular Circular 1154.DownloadMSC/Circular1154fromtheIMOwebsite(PDF,161KB).
You should designate ana SSO on each shipship, and include the SSO’s duties in the SSP.
A key requirement of the ISPS Code is thatforthepeople with security responsibilities aretobeappropriately trained.trainedtocarryouttheirduties.The government requires CSOsthatCSO and SSOs associated with UK-registered ships to undergo approved training.