The ISPS Code is the global framework that protects ships, ports, and the people within them from security threats — and as of the IMO's revised Procedures for Port State Control adopted in December 2025, security inspections have undergone their most significant change in years. For the first time, a dedicated appendix addresses ship security issues under ISPS, with PSC officers now working alongside Duly Authorized Officers (DAOs) to conduct security assessments. A missing or expired ISSC, an unqualified SSO, or a vessel operating at a lower security level than the port can all trigger detention. Yet ISPS compliance is also one of the most straightforward areas to maintain — with a valid certificate, a trained Ship Security Officer, up-to-date drills, and proper documentation, the security element of any inspection is routine. This guide covers the ISPS Code structure, the three security levels, the certification cycle, what inspectors actually check, and how to prepare for both PSC security inspections and ISSC audits. Operators strengthening their security compliance can sign up for Marine Inspection or schedule a demo to see how security drills, ISSC tracking, and audit readiness connect in one platform.
ISPS Code Compliance: Key Reference Numbers
SOLAS XI-2
Legal Basis
Mandatory under SOLAS Chapter XI-2 since July 2004
≥500 GT
Applicability
Cargo ships on international voyages + all passenger ships
3 Levels
Security Levels
Normal (1) · Heightened (2) · Imminent Threat (3)
≤3 months
Drill Interval
Security drills required at least every 3 months
The 3 Security Levels Explained
The ISPS Code operates on a scalable system of three security levels. Each level requires progressively more intensive measures — and your vessel must be capable of operating at all three at any time.
Security Level 1 — Normal
Minimum Protective Security Measures at All Times
The baseline level at which all ships and port facilities operate continuously. Standard measures include: access control (gangway watch, visitor identification and logging), monitoring of restricted areas, cargo and stores security checks, and security communications readiness. The Ship Security Plan defines the specific measures required at Level 1 for your vessel.
Security Level 2 — Heightened
Additional Protective Measures for Elevated Risk
Activated when intelligence indicates a heightened risk of a security incident. Measures escalate: enhanced access control (additional ID verification, bag searches), increased frequency of security patrols, restricted deck access, additional CCTV monitoring, and tightened cargo/stores supervision. Set by the Contracting Government — the vessel must comply immediately when notified.
Security Level 3 — Exceptional
Maximum Protective Measures — Threat Imminent or Probable
Activated for a limited period when a security incident is probable or imminent. Requires specific instructions from the Contracting Government. All access may be restricted, crew confined to secure areas, vessel searches conducted, and coordination with naval/coast guard authorities established. Level 3 is rarely activated but the SSP must contain detailed procedures for it.
Who: A designated officer onboard — usually a senior officer serving dual duties. Responsibilities: Implements and maintains the Ship Security Plan daily, conducts security drills and crew training, performs regular security inspections onboard, reports security incidents, and coordinates with the CSO and port facility security officers. Qualification: Must hold a valid certificate of proficiency per STCW Regulation VI/5. An unqualified SSO is clear grounds for detention under the 2025 revised PSC procedures.
Onboard — implements the SSP daily
CSO
Company Security Officer
Who: A shore-based person designated by the company. Responsibilities: Develops and maintains the company's Ship Security Plans for all vessels, arranges security assessments, coordinates security training for ship and shore personnel, oversees internal audits, liaises with flag state authorities and port facility security officers, and ensures SSOs are properly trained and supported. Must have direct contact details registered with the flag state.
Who: Designated by the port facility operator. Responsibilities: Develops and implements the Port Facility Security Plan, coordinates security measures between the port and visiting vessels, manages access control and surveillance for the facility, and liaises with SSOs for ship-port interface operations. Declaration of Security (DoS): When required, the PFSO and SSO jointly complete a DoS — an agreement specifying which party is responsible for specific security measures during the ship-port interface.
Port-side — coordinates security during ship-port interface
The ISSC Certificate Cycle
The International Ship Security Certificate is the proof of compliance that inspectors verify first. Understanding the certification cycle prevents the administrative failures that lead to detention.
ISSC Certification: Key Milestones
1
Ship Security Assessment (SSA) — Risk assessment identifying vulnerabilities. Basis for developing the Ship Security Plan.
2
Ship Security Plan (SSP) — Detailed procedures for all 3 security levels. Approved by flag state or RSO. Confidential document.
3
Interim ISSC — Valid up to 6 months. Issued after interim verification confirms SSP elements are implemented onboard.
4
Initial Verification & Full ISSC — Issued after comprehensive onboard verification. Valid for 5 years.
5
Intermediate Verification — Required between 2nd and 3rd anniversary. Endorsement on the ISSC confirms ongoing compliance.
6
Renewal — Before ISSC expires. New 5-year certificate issued upon successful renewal verification. Extension up to 3 months only.
Never Miss an ISSC Milestone
Marine Inspection tracks ISSC validity, intermediate verification dates, SSO certificate expiry, and drill schedules — alerting you before any deadline becomes a compliance gap.
ISSC or Interim ISSC valid and onboard — Invalid or expired certificate = clear grounds for detention. Intermediate verification must be endorsed. Company details consistent.
SSO holds valid certificate of proficiency — Per STCW Regulation VI/5. No valid SSO certificate = clear grounds for detention under 2025 procedures.
Crew with security duties hold appropriate certificates — Advance Security Certificate for crew assigned specific security responsibilities.
Operational Security Assessment
Security level correct — Ship must operate at least at the security level set by the port. Operating at a lower level than the port = clear grounds for detention.
Drill and exercise records — Evidence of security drills at intervals not exceeding 3 months and full-scale exercises annually. Records must show varied scenarios, documented participation, and lessons learned.
Security records maintained for 3 years — Drill records, security incident reports, Declarations of Security, and security-related communications must be retained onboard for minimum 3 years.
Physical Security Measures
Access control measures in place — Gangway watch active, visitor log maintained, restricted areas secured. PSCO observes whether crew are actually implementing access control — or just have procedures on paper.
Ship Security Alert System (SSAS) operational — Minimum 2 activation points. System must be able to transmit a covert security alert to the flag state identifying the ship, location, and that the ship's security is under threat. PSCOs may verify the system is functional.
Critical: SSP Confidentiality
The Ship Security Plan is a confidential document. PSC officers are not permitted to access the SSP during routine inspections. They can verify the existence of an approved plan and a valid ISSC — but cannot review plan contents. Only qualified maritime security auditors or the RSO that certifies the ship can review the SSP. If a PSCO requests access, the Master should politely decline and offer to demonstrate compliance through the ISSC and other non-confidential documentation. In rare cases where the only way to resolve a specific concern is by showing a relevant SSP section, the Master may show only that specific section — never the entire plan. Book a demo to see how Marine Inspection manages SSP documentation securely.
Security Drills & Exercises: What Inspectors Expect
Full exercise report with debrief and corrective actions
Best Practice
Vary timing, include surprise drills, cover all security levels
Include realistic scenarios: boarding, bomb, cyber, stowaway
Clear Grounds for Detention: The Lines You Must Not Cross
Under the 2025 revised PSC procedures, these findings constitute clear grounds for detention in the security area.
ISPS Clear Grounds for Detention (2025 Procedures)
ISSC or Interim ISSC invalid or expired — No valid security certificate = vessel cannot demonstrate compliance. Detention until valid certificate obtained.
SSO does not hold valid certificate of proficiency — Per STCW 1978, Regulation VI/5. The person responsible for implementing shipboard security is unqualified.
Ship operating at lower security level than the port — Vessel must operate at least at the security level set by the port. Operating below this indicates failure to comply with Contracting Government directions.
Evidence of use of interim certificate to avoid full compliance — If the PSCO judges the ship or company is using an Interim ISSC to avoid completing full certification beyond the initial interim period.
ISSC valid with endorsements — Intermediate verification current. Certificate onboard, accessible for presentation.
2
SSO certificate valid — Current proficiency certificate per STCW VI/5 for the designated SSO onboard.
3
Security level correct — Verify destination port security level. Ensure vessel operates at or above that level.
4
Drill records current — Security drills within last 3 months documented with scenarios, participation, and lessons.
5
Security records for 3 years — Drills, DoS, incidents, and communications accessible and organized.
6
SSAS operational — Ship Security Alert System tested and functional. Minimum 2 activation points confirmed.
7
Access control active — Gangway watch posted, visitor log ready, restricted areas secured, CCTV operational.
8
SSP secured — Stored in locked location. Not accessible to unauthorized persons. Ready but not for PSC review.
9
Crew knows their security duties — SSO and crew with security roles can explain their responsibilities when asked.
Security Compliance That Runs Continuously
Marine Inspection tracks ISSC validity, SSO certification, drill schedules, security records, and audit readiness — so your security compliance is always current, not assembled before port calls.
No. The SSP is a confidential document. PSC officers can verify the existence of an approved plan and a valid ISSC, but they are not permitted to access the SSP contents during routine inspections. Only qualified maritime security auditors or the Recognized Security Organization (RSO) that certifies the ship can review the document. If a PSCO specifically requests access, the Master should politely decline. In rare cases where showing a specific section is the only way to resolve a particular concern, only that relevant section should be shown — never the entire plan.
How often must security drills be conducted?
Security drills must be conducted at intervals not exceeding 3 months. Full-scale security exercises should be conducted at least annually. Drills should test individual elements of the Ship Security Plan — such as access control procedures, bomb threat response, or unauthorized boarding — and records must document the date, scenario, participants, and lessons learned. Varying drill timing and scenarios, including surprise drills, demonstrates genuine readiness rather than routine compliance.
What is a Declaration of Security (DoS)?
A Declaration of Security is a formal agreement between a ship and a port facility (or between two ships during ship-to-ship activity) that specifies which party is responsible for specific security measures during the interface period. It clarifies security arrangements for activities like cargo operations, passenger embarkation, or bunkering. The DoS is completed jointly by the SSO and PFSO (or the SSO of the other vessel) and must be retained onboard as part of the security records for at least 3 years.
How long is an ISSC valid?
A full-term ISSC is valid for 5 years, subject to at least one intermediate verification between the 2nd and 3rd anniversary dates. An Interim ISSC is valid for up to 6 months (extendable by a further 6 months in special cases). The ISSC may be extended up to 3 months beyond its expiry to allow the vessel to reach a port where verification can be carried out — but the vessel cannot leave that port without a new ISSC once the extension period is used.
What changed in the 2025 revised PSC procedures for security?
The most significant change is the introduction of a dedicated appendix (Appendix 20) specifically addressing security inspections under the ISPS Code. Security inspections now involve PSCOs working with Duly Authorized Officers (DAOs) — a DAO being an official of the Contracting Government authorized to carry out security compliance measures. Clear grounds for detention have been consolidated, and specific detention triggers are now defined — including invalid ISSC, unqualified SSO, operating below port security level, and misuse of interim certification.