The ISPS Code is the International Ship and Port Facility Security Code. It requires ships and the port facilities serving them to assess threats, appoint security officers and follow approved security plans. Compliance is proved through certification.
This guide is written for deck officers, ship security officers, cadets and port staff. It explains who the Code applies to, how the three security levels work, what the plans contain, and what inspectors check.
What Is the ISPS Code?
The ISPS Code is IMO’s security framework for ships and port facilities. Adopted in December 2002 after the 11 September attacks, it became mandatory on 1 July 2004 through SOLAS Chapter XI-2.
The Code treats security as a shared job at the ship-port interface. Governments set the threat level, companies and port facilities write plans for it, and named officers carry those plans out.
| ISPS Code at a glance | |
|---|---|
| Full title | International Ship and Port Facility Security Code |
| Legal basis | SOLAS Chapter XI-2, Special measures to enhance maritime security |
| Adopted | December 2002, by a SOLAS diplomatic conference |
| Mandatory since | 1 July 2004 |
| Structure | Part A, mandatory requirements; Part B, guidance |
| Applies to | Passenger ships, cargo ships of 500 GT and above and MODUs on international voyages, and the port facilities serving them |
| Certificate | International Ship Security Certificate (ISSC), valid up to 5 years |
| Security levels | 1 (normal), 2 (heightened), 3 (exceptional) |
What Is the Difference Between Part A and Part B?
Part A is mandatory. It sets the duties of governments, companies, ships and port facilities. Part B is guidance on how to meet Part A, such as what a security assessment should look at.
Some flag states and port states treat parts of Part B as binding in their own law. The European Union, for example, made several Part B paragraphs mandatory for its member states.
Which Ships and Port Facilities Does the ISPS Code Apply To?
The Code applies to passenger ships, cargo ships of 500 GT and above, and mobile offshore drilling units on international voyages. High-speed craft are included, and so are the port facilities serving these ships.
- Excluded: warships, naval auxiliaries and other government ships used only on non-commercial service.
- Outside the threshold: cargo ships under 500 GT, fishing vessels and private yachts.
- Domestic trade: not covered by the Code itself, though many states apply similar national rules.
Each government decides which of its port facilities serve international ships and must comply. Those facilities need an approved port facility security assessment and plan.
Who Are the ISPS Security Officers?
The Code names three officers. The Company Security Officer works ashore for the company. The Ship Security Officer serves on each ship, and the Port Facility Security Officer runs security at each port facility.
| Officer | Where | Main duties |
|---|---|---|
| Company Security Officer (CSO) | Company office | Arranges the ship security assessment, develops the plan, submits it for approval, and arranges audits and drills |
| Ship Security Officer (SSO) | On board | Implements the plan, runs inspections and drills, trains crew, reports incidents and liaises with the PFSO |
| Port Facility Security Officer (PFSO) | Port facility | Implements the port facility security plan and coordinates with visiting SSOs |
On most ships the SSO is the master or the chief officer. One CSO may cover a whole fleet, but each ship must know who its CSO is and how to reach them at any hour.
What Training Do Ship Security Officers Need?
Security training is set by the STCW Code, Chapter VI. Three levels apply on board:
- Ship Security Officer: a certificate of proficiency under STCW Regulation VI/5.
- Designated security duties: training for crew with security tasks under Section A-VI/6.
- Security awareness: basic training for every seafarer, also under Section A-VI/6.
These are issued as an STCW certificate of proficiency. PSC officers check that the named SSO actually holds one.
What Are the Three ISPS Security Levels?
Security level 1 is normal, level 2 is heightened, and level 3 is exceptional. The government sets the level for its ports and for ships flying its flag, and the plan sets the measures for each.
| Level | Meaning | What typically changes on board |
|---|---|---|
| 1 Normal | Minimum protective measures maintained at all times | Gangway watch, ID checks for all visitors, restricted areas locked, stores checked |
| 2 Heightened | Additional measures for a period of increased risk | Fewer access points, escorts for visitors, more frequent rounds, waterside watch |
| 3 Exceptional | Further specific measures while an incident is probable or imminent | Single access point, full searches, operations may stop, instructions from authorities followed |
A ship must be at least at the level set by the port she is in. If the flag sets a higher level, the ship follows the higher one. The SSO and PFSO agree how the difference is handled.

In my experience, the level change at the pilot station is where crews slip. The port has gone to level 2, the ship is still running level 1, and the gangway watch hears about it from the agent.
What Is the Ship Security Plan?
The Ship Security Plan (SSP) sets out the measures the ship takes at each security level. It is based on a ship security assessment and approved by the flag Administration or a recognized security organization.
The plan must cover at least these points:
- Measures to stop weapons and dangerous substances being brought on board.
- Restricted areas and how unauthorized access is prevented.
- Responses to security threats and breaches, including evacuation.
- Duties of crew with security tasks, and of the SSO and CSO by name or position.
- Training, drills, audits, record keeping and plan review.
- Ship security alert system activation points and procedures.
The SSP is confidential. Inspectors may see only limited sections without the flag state’s consent. A recognized security organization may approve the plan, but never one it prepared itself.
How Often Are Security Drills and Exercises Held?
Part B guidance calls for security drills at least every three months. Exercises involving the company, port or authorities are held at least once each calendar year, with no more than 18 months between them.
Drills must test a real part of the plan, such as a bomb search, an unauthorized boarding or a stowaway search. A drill log that says only “security drill carried out” is a finding waiting to happen.
What Is a Declaration of Security?
A Declaration of Security (DoS) is a signed agreement between a ship and a port facility, or another ship. It sets out who handles each security measure during their interface. Both sides keep a copy.
A ship may request a DoS. Common triggers include:
- The ship is at a higher security level than the port facility or the other ship.
- The interface is with a ship or port facility not covered by the Code.
- There is a security threat or incident involving the ship or the port.
- The flag state or port state requires one, for example for passenger ships or dangerous cargoes.
The SSO signs for the ship and the PFSO for the port facility. Declarations are kept for the period set by the flag state and the port state, and appear in the record of recent port calls.
What Is the Ship Security Alert System?
The Ship Security Alert System (SSAS), required by SOLAS regulation XI-2/6, sends a covert alert ashore when the ship is under attack. It gives the ship’s identity and position and keeps transmitting until deactivated.
- The alert goes to a competent authority named by the flag state, which may include the company.
- It does not alert other ships or sound an alarm on board, so attackers do not know it has been sent.
- At least two activation points are fitted, one of them on the bridge, and they are protected against accidental use.
The system is tested at intervals set by the flag state, after telling the company and the competent authority. Where pirates are the threat, the SSAS is one layer of defence; the wider picture is covered in do pirates still exist.
What Is the International Ship Security Certificate?
The International Ship Security Certificate (ISSC) shows that a ship’s security system and plan comply with the Code. It is issued after an initial verification on board and is valid for up to five years.
| Verification | When |
|---|---|
| Initial | Before the ISSC is first issued |
| Intermediate | At least one, between the second and third anniversary dates |
| Renewal | Before the five-year certificate expires |
| Additional | When the flag state or RSO decides one is needed |
| Interim ISSC | Up to 6 months for a new ship, a new company or a change of flag; cannot be extended |
The ISSC lapses if a verification is missed, when a new company takes over the ship, or on a change of flag. Verifications are usually carried out alongside the other statutory surveys carried out on ships.
What Is the Continuous Synopsis Record?
The Continuous Synopsis Record (CSR), required by SOLAS regulation XI-1/5, is the ship’s ID history. It lists the flag, owners, managers, registered names and certifying bodies over the ship’s life.

What Do PSC Officers Check Under the ISPS Code?
Under SOLAS regulation XI-2/9, port state control officers first check for a valid ISSC. If there are clear grounds to doubt compliance, they go further, but they cannot demand the full plan.
- Certificate: a valid ISSC or interim ISSC matching the ship’s name and flag.
- SSO: named, certified, and able to explain the plan and the current security level.
- Port call records: the last ten port calls, with the security level at each and any Declarations of Security.
- Access control: visitors identified, logged and escorted; the gangway watch alert.
- Restricted areas: bridge, engine room and steering gear room locked or monitored.
- Drills and SSAS: drills recorded at the required interval, and SSAS tests logged.
The fastest test is the gangway. An inspector who walks up unchallenged and finds the watchman on his phone has already written the first deficiency.
Can a Ship Be Denied Entry for ISPS Non-Compliance?
Yes. Before entry, a port state may ask for security information, such as the ISSC, the security level and the last ten port calls. If it is not satisfied, it may set conditions or refuse entry.
In port, control measures range from inspection and delayed operations to detention or expulsion. Serious failures are grounds for ship detention, and the pre-arrival information usually passes through the ship’s agent.
How Does the ISPS Code Relate to SOLAS, ISM, the MTSA and Piracy?
The ISPS Code sits inside SOLAS Chapter XI-2. It runs alongside the ISM Code’s safety system, is implemented in the United States through the MTSA, and is one layer of defence against piracy.
- ISM Code: safety management, with its own DOC and SMC. ISPS is a separate system, but many companies audit the two together and the SSO often sits within SMS procedures.
- MTSA: the US law that applies the ISPS Code in US ports and adds rules such as the TWIC card and MARSEC levels.
- Piracy: the Code covers access control and plans, but armed guards and Best Management Practices sit outside it. See modern-day pirates and maritime crime.
- MLC 2006: security measures must not block seafarers’ right to shore leave and welfare access.
The ISPS Code is written for physical threats. Cyber risks are handled mainly through the safety management system, though many companies now cover them in their security assessments too.
For the full text, the IMO publication ISPS Code contains SOLAS Chapter XI-2 and both parts of the Code. The official overview is on the IMO maritime security page.
Related Topics
Frequently Asked Questions
What are the three ISPS security levels?
Level 1 is normal, with minimum measures at all times. Level 2 is heightened, for a period of increased risk. Level 3 is exceptional, while an incident is probable or imminent.
Who is the Ship Security Officer?
The person on board responsible for the ship security plan, named by the company. On most ships it is the master or chief officer, holding an STCW Regulation VI/5 certificate.
What is the difference between the ISPS Code and the ISM Code?
The ISM Code covers safety management and pollution prevention. The ISPS Code covers security against deliberate threats such as terrorism, stowaways and theft. Each has its own plan, officer and certificate.
Does the ISPS Code apply to yachts and fishing vessels?
Not under SOLAS. It applies to passenger ships, cargo ships of 500 GT and above and mobile offshore drilling units on international voyages. Some flags apply security rules to large commercial yachts.
What is a Declaration of Security?
A signed agreement between a ship and a port facility, or another ship, setting out who handles each security measure. It is often used when the two are at different security levels.
How long is an ISSC valid?
Up to five years, with at least one intermediate verification between the second and third anniversary dates. An interim ISSC is valid for up to six months and cannot be extended.
What is SSAS on a ship?
The Ship Security Alert System sends a covert alert ashore if the ship is under attack. It does not alert nearby ships or sound an alarm on board.
Can a ship be denied entry for ISPS non-compliance?
Yes. A port state can ask for security information before arrival and refuse entry if it is not satisfied. In port, non-compliance can lead to detention or expulsion.
- What Is the ISPS Code? Security Levels, Plans and the ISSC – October 8, 2026
- What Is the Load Line Convention? Freeboard and Marks Guide – October 8, 2026
- What Is the MLC 2006? Maritime Labour Convention Explained – October 8, 2026



