ISPS compliance has an unusual structure that shapes everything about how a fleet manages it. The Ship Security Plan — the document that defines what the vessel actually does to protect itself — is confidential, and a port state control officer is not permitted to read it. They may verify that an approved plan exists and that the certificate is valid, but if they ask to see the contents the master should decline, and where a specific section is genuinely the only way to resolve a concern, only that section is shown. The consequence is that a vessel cannot demonstrate ISPS compliance by producing its plan. It demonstrates compliance through everything surrounding the plan: a valid certificate, properly certificated officers, drill and exercise records, Declarations of Security, security logs, and crew who visibly know their duties. Those records are the compliance artefact, and they are what a port facility check actually examines. That is also why ISPS so often becomes a records problem rather than a security problem — the measures are in place, but the evidence of them is scattered, incomplete, or three months out of date. This guide covers the records regime, the drill cadence, security level changes, keeping the plan current and the verification cycle. To keep that evidence current across your fleet, book a demo or start a free trial.
COMPLIANCE GUIDE · SHIP SECURITY
ISPS Code Security Compliance for Vessel Fleets
The security plan is confidential, so the records prove the compliance. Here is the evidence regime that satisfies a port facility check — drill cadence, Declarations of Security, level changes, plan amendments and the certificate cycle.
Prove It Without Showing It
The confidentiality of the Ship Security Plan is not an inconvenience to be worked around — it is the organising fact of ISPS compliance, and understanding it correctly prevents both over-disclosure and under-preparation.
Not disclosed at a routine check
The contents of the Ship Security Plan
Detailed security measures, access control arrangements and monitoring specifics
Restricted-area definitions and response procedures
Only qualified maritime security auditors or the Recognized Security Organization that certifies the ship may review the plan. If asked, the master should politely decline, and where one section is the only way to resolve a specific concern, only that section is shown.
Shown, and expected
A valid International Ship Security Certificate, with intermediate verification endorsed
Evidence that an approved plan exists, without its contents
Officer and crew security certification
Drill and exercise records, Declarations of Security and security logs
This is the visible half of compliance, and it is where findings arise — because the measures may be sound while the record of them is incomplete.
The practical lesson is that a fleet should invest its ISPS management effort where the verification actually happens. The plan is written once, amended occasionally and reviewed on a cycle; the records accumulate continuously and are checked constantly. To hold that evidence in one place across the fleet, book a demo or start a free trial.
The Records That Do the Proving
Security records are retained for three years, and the categories are specific. Each is a question a port facility check can ask, and a gap in any of them is a finding regardless of how well the vessel is actually run.
Drill and exercise records
Showing varied scenarios rather than the same exercise repeated, documented participation, and the lessons learned from each.
Security incident reports
Including breaches, attempted breaches and near-misses, with the response taken and any resulting change to practice.
Declarations of Security
Each completed declaration retained, evidencing the agreement reached with the port facility or other ship on respective security responsibilities.
Security communications
Security-related correspondence with the company, port facilities and authorities, including notifications of level changes.
Certification records
The certificate of proficiency held by the Ship Security Officer and the appropriate security certificates of crew assigned specific security duties.
Equipment and system tests
Testing of security equipment and the ship security alert system, with results recorded rather than assumed.
Three years, and retrievable
The retention period is three years, which spans multiple crew rotations, at least one intermediate verification and often a change of trading pattern. A record that exists somewhere in a filing system but cannot be produced during a port call is functionally missing, and incomplete drill records are among the specific items that can generate a deficiency. The retention requirement is therefore really a retrieval requirement: the question is not whether the fleet kept the record but whether the vessel can put it in front of an officer while they are standing there.
The Drill and Exercise Cadence
Security training runs on three separate clocks, and each is checked independently. Missing any one of them is visible in the records immediately.
Every 3 months
Security drills at intervals not exceeding three months, testing individual elements of the plan — access control, restricted areas, response to a suspected breach, searches, and similar. Records must show varied scenarios rather than a repeated routine.
Annually
A full-scale security exercise completed each year, potentially involving the Company Security Officer, Port Facility Security Officers, relevant authorities and shore-based personnel alongside the ship's own team.
First week aboard
Crew security familiarisation for all personnel within their first week of joining, so every new joiner understands the security arrangements and their own duties before the next port call, not after it.
The familiarisation requirement is the one that most often slips in practice, because it is triggered by crew movements rather than by a calendar date. On a fleet with active rotations it fires constantly and unpredictably, and a new joiner without documented familiarisation is a straightforward finding. Tying it to the crew-change event rather than to a periodic schedule is the only reliable way to keep it complete.
Security evidence, ready at every port call
Drill schedules on three separate clocks, familiarisation triggered by crew changes, Declarations retained for three years, certificate validity tracked across the fleet — the ISPS burden is a records burden. Marine Inspection captures drills, incidents and security records at the point they happen and keeps certification visible fleet-wide.
Book a demo to see it on your vessels, or
start a free trial.
Security Level Changes
Unlike most compliance obligations, the security level is dynamic and externally set, which makes it the one ISPS requirement that can put a vessel in breach within minutes of arriving somewhere.
Level 1
Minimum protective measures maintained at all times during normal operations. The baseline the vessel operates at unless raised.
Level 2
Additional protective measures applied for a period of heightened risk, typically in response to specific intelligence or conditions at a port.
Level 3
Specific protective measures for a limited period when a security incident is probable or imminent, usually coordinated with authorities.
The rule that matters operationally is that a ship must operate at least at the security level set by the port facility it is entering. Operating at a lower level than the port constitutes clear grounds for detention — so a vessel arriving at Level 1 into a facility at Level 2 is non-compliant the moment it interfaces, unless it raises its own level and implements the corresponding measures from its plan. This has two management consequences. First, security level information needs to reach the vessel before arrival rather than at the gangway, which makes pre-arrival communication with the port facility part of the compliance routine. Second, each level change needs recording — when the change occurred, what measures were implemented, and the communication that prompted it — because the record is what evidences that the ship responded correctly. Level changes also commonly trigger a Declaration of Security, formalising the division of security responsibilities between ship and facility, and each completed Declaration joins the three-year record set.
Keeping the Plan Current
Although the plan itself is not shown at a port check, it still has to be maintained, and the amendment process has a trap in it that catches operators who treat plan updates as internal housekeeping.
The Ship Security Officer identifies shortcomings through normal operations, drills, near-miss incidents, changes in trading area or feedback from security audits, and submits recommendations to the Company Security Officer. The CSO evaluates them, carries out or commissions any supporting security assessment, and submits the proposed amendment to the Administration or the Recognized Security Organization for approval. The critical point is that no amendment takes effect until formal approval is received and documented — a plan revised aboard and put into practice before approval is not a compliant plan, it is a deviation from the approved one. The approved amendment record is held on board alongside the certificate, so the approval trail is itself part of the evidence set.
Three events oblige a review regardless of whether anything has obviously gone wrong: any security incident involving the vessel, any significant change in the ship's operating profile, and the intermediate verification of the certificate. The operating-profile trigger is worth flagging for fleet managers, because a change of trading area or cargo type can shift a vessel's risk picture substantially without anyone treating it as a security event. Building a plan review into the decision to redeploy a vessel avoids discovering the gap at the next verification. To keep amendment approvals and review triggers tracked across a fleet, book a demo or start a free trial.
The Certificate Cycle
Certification runs on a familiar rhythm, with a few conditions that invalidate a certificate outside the normal cycle and catch fleets during corporate change.
5 years
Maximum validity of the International Ship Security Certificate, issued on verification that the plan meets the Code's requirements.
Annual
Verification audits through the certificate's life, with the intermediate verification requiring endorsement — an unendorsed intermediate verification is itself a finding.
6 months
Validity of an Interim certificate, issued for new ships or on a change of flag or company, during which full certification must be achieved.
Invalidated by
A change of flag, a change of the company operating the ship, or significant modifications altering the vessel's security arrangements.
Those invalidation triggers deserve attention during fleet transactions, because they coincide exactly with the periods when administrative attention is elsewhere. A vessel changing management can lose certificate validity while the commercial side is focused on the transfer, and an invalid or expired certificate is clear grounds for detention. Treating flag changes, management transfers and significant modifications as security-certification events, planned alongside the transaction rather than after it, avoids the most predictable ISPS failure a fleet can have. Equally predictable and equally avoidable: an absent or uncertificated Ship Security Officer, since no valid certificate of proficiency is clear grounds for detention on its own. Tracking officer certification alongside vessel certification closes that gap. To keep both visible across every vessel, book a demo or start a free trial.
Frequently Asked Questions
Can a port state control officer read our Ship Security Plan?
No. The Ship Security Plan is a confidential document. A port state control officer may verify that an approved plan exists and that the International Ship Security Certificate is valid, but they are not permitted to access the plan's contents during routine inspections. Only qualified maritime security auditors or the Recognized Security Organization that certifies the ship may review the document. If an officer specifically requests access, the master should politely decline. In rare cases where showing one particular section is the only way to resolve a specific concern, only that relevant section should be shown, never the entire plan. This is why compliance is demonstrated through the surrounding evidence — certificates, officer certification, drill and exercise records, Declarations of Security and security logs — rather than through the plan itself.
How often must security drills and exercises be held?
Three separate clocks run in parallel. Security drills must be held at intervals not exceeding three months, testing individual elements of the plan such as access control, restricted areas, response to a suspected breach and searches. A full-scale security exercise must be completed annually, and may involve the Company Security Officer, Port Facility Security Officers, relevant authorities and shore personnel alongside the ship's team. Separately, crew security familiarisation is required for all personnel within their first week of joining. Records must show varied scenarios rather than the same exercise repeated, with documented participation and lessons learned. The familiarisation requirement slips most often because it is triggered by crew movements rather than a calendar date, so it is best tied to the crew-change event itself.
What happens if our security level is lower than the port's?
It is a compliance breach and constitutes clear grounds for detention. A ship must operate at least at the security level set by the port facility it is entering, so a vessel arriving at Level 1 into a facility operating at Level 2 is non-compliant from the moment it interfaces unless it raises its own level and implements the corresponding measures from its plan. Two management practices prevent this. First, obtain security level information from the port facility before arrival rather than at the gangway, making pre-arrival security communication part of the standard routine. Second, record each level change — when it occurred, what measures were implemented and the communication that prompted it — since that record evidences the correct response. Level changes frequently also trigger a Declaration of Security with the facility.
How long must security records be kept?
Security records are retained for three years. The set includes drill and exercise records, security incident reports, Declarations of Security and security-related communications, alongside certification records and security equipment test results. Three years spans multiple crew rotations, at least one intermediate verification and often a change of trading pattern, which is why the retention requirement is really a retrieval requirement. A record that exists somewhere in the filing system but cannot be produced during a port call is functionally missing, and incomplete drill records are among the specific items that generate deficiencies. The practical test is whether the vessel can put the requested record in front of an officer while they are standing on board, not whether the company believes it is held somewhere.
When does a Ship Security Plan need to be amended or reviewed?
The Ship Security Officer identifies shortcomings through normal operations, drills, near-miss incidents, changes in trading area or security audit feedback, and recommends amendments to the Company Security Officer, who evaluates them, commissions any supporting security assessment and submits the proposal to the Administration or Recognized Security Organization. Crucially, no amendment takes effect until formal approval is received and documented, and the approved amendment record is held on board alongside the certificate. Beyond that, three events oblige a review: any security incident involving the vessel, any significant change in the ship's operating profile, and the intermediate verification of the certificate. The operating-profile trigger matters for fleet managers, since a change of trading area or cargo type can shift the risk picture without being treated as a security event.
What invalidates an International Ship Security Certificate?
The certificate is valid for a maximum of five years subject to annual verification and an intermediate verification that must be endorsed, but it becomes invalid outside that cycle in three situations: a change of flag, a change of the company operating the ship, or significant modifications altering the vessel's security arrangements. These triggers deserve particular attention during fleet transactions, because they coincide with periods when administrative attention is focused on the commercial transfer. A vessel changing management can lose certificate validity while nobody is watching, and an invalid or expired certificate is clear grounds for detention. An Interim certificate valid for six months covers new ships and flag or company changes while full certification is achieved. Treating these events as security-certification milestones, planned alongside the transaction, avoids the most predictable ISPS failure available.
The Records Are the Compliance
Because the security plan stays confidential, everything a port facility check examines is evidence around it — certificate validity, officer certification, drills on three separate clocks, Declarations of Security and level-change logs, all retrievable across a three-year window. Marine Inspection captures those records at the point they happen and keeps certification and drill status visible fleet-wide, so security readiness is current rather than assembled before a port call.
Book a demo or
start a free trial.