ISPS Code Explained: What Every Seafarer Must Know

ISPS Code: Security Levels, Duties and Training Explained

Most seafarers meet the ISPS Code the same way: a gangway logbook, an ID check, a security drill that interrupts a coffee break. The paperwork is familiar long before the reasoning behind it is. That gap matters, because an ISPS deficiency does not stay with the security officer — it holds the ship, and a held ship affects everyone signed on.

This guide covers what the ISPS Code is, which vessels it applies to, what the three security levels actually change about your working day, and the training you personally need to hold.

What Is the ISPS Code?

The International Ship and Port Facility Security Code (ISPS Code) is the mandatory maritime security framework that entered into force under SOLAS chapter XI-2 on 1 July 2004. It sets minimum security requirements for ships and port facilities on international voyages, defines three escalating security levels, and assigns named security responsibilities to companies, vessels and ports.

It was agreed in December 2002 at a diplomatic conference of SOLAS signatories in London, in the security climate that followed the 11 September 2001 attacks and the bombing of the tanker Limburg. The drafting question was narrow and practical: how do you make ship and port security auditable, rather than a matter of local goodwill?

The answer was a code with two halves.

Part A vs Part B: What’s Mandatory and What’s Guidance

The Code splits into a mandatory part and a guidance part — and the distinction is less clean in practice than it looks on paper.

 

Part A

Part B

Status

Mandatory

Recommendatory guidance

Contains

Detailed maritime and port security requirements

Guidance on how to meet those requirements

In practice

Audited directly

Some flag States and port States treat portions as mandatory

Worth knowing: because certain Contracting Governments apply parts of Part B as binding, “it’s only Part B” is not a safe answer to a port-state control inspector. Check your flag State’s position before you rely on it.

 

The Three ISPS Security Levels ExplainedWhich Ships and Ports Does the ISPS Code Apply To?

SOLAS chapter XI-2 applies to passenger ships and cargo ships of 500 gross tonnage and upwards, including high-speed craft, mobile offshore drilling units, and the port facilities serving those ships on international voyages.

Category

Covered?

Passenger ships on international voyages

Yes

Cargo ships of 500 GT and above, including high-speed craft

Yes

Mobile offshore drilling units (MODUs)

Yes

Port facilities serving the above

Yes

Warships and naval auxiliaries

No

Government ships on non-commercial service

No

Domestic-only vessels below the threshold

Not under SOLAS — national rules may still apply

Only States that are Contracting Governments to SOLAS carry the legal obligation to implement it. In reality, that covers the overwhelming majority of commercial tonnage, so if you are sailing internationally on a merchant vessel, assume you are inside the system.

The Three ISPS Security Levels Explained

 

The ISPS Code defines three security levels: Level 1 is normal, the level at which the ship or port facility normally operates; Level 2 is heightened, applying for as long as there is a heightened risk; Level 3 is exceptional, applying for the period when there is a probable or imminent risk of a security incident.

The level is set by the Administration for ships entitled to fly its flag, and a port facility’s level can differ from the ship’s — when they differ, the higher one governs while you are alongside.

Level

Meaning

What typically changes for you on board

Level 1 — Normal

Minimum protective measures maintained at all times

Gangway watch, ID checks, visitor logging, routine deck rounds, restricted-area signage

Level 2 — Heightened

Additional measures for as long as elevated risk persists

More frequent patrols, tighter escorting of visitors, increased searches of persons and stores, reduced access points

Level 3 — Exceptional

Specific protective measures for a limited period when an incident is probable or imminent

Access may be suspended or restricted to authorised persons only, searches become comprehensive, movements are directed by the authorities

Quotable: Level 3 is not a stronger version of Level 2 — it is a short-duration response to a specific, credible threat, and it is expected to be lifted once that threat passes.

Two habits separate crews who handle level changes well from crews who scramble: knowing where the Ship Security Plan lists your Level 2 and Level 3 tasks before the level changes, and recording the change and the measures taken in the log at the time, not afterwards.

Who Does What: CSO, SSO, PFSO — and You

The Code creates three named officer roles, each charged with assessing, preparing and implementing effective security plans.

Role

Sits where

Core responsibility

Company Security Officer (CSO)

Ashore, at the operating company

Ensures the ship security assessment is carried out, and that the Ship Security Plan is developed, approved, implemented and maintained across the fleet

Ship Security Officer (SSO)

On board

Accountable to the master for the ship’s security: implementing and maintaining the SSP, conducting security inspections, coordinating drills and crew security training

Port Facility Security Officer (PFSO)

At the terminal

Develops, implements and maintains the port facility security plan and liaises with the SSO and CSO

And the fourth role the Code does not name: every other person on board. Restricted-area discipline, challenging unescorted visitors, reporting an unattended bag, keeping the gangway log honest — these are crew duties, not SSO duties. The SSO writes the procedure; the deck and engine ratings are the ones the procedure depends on.

The master’s authority sits above all of it. Under SOLAS regulation XI-2/8 the master retains overriding discretion for decisions necessary to maintain the safety and security of the ship, and that professional judgement cannot be overruled by the company, the charterer or the port facility.

The Paper Trail: SSA, SSP, ISSC and the DoS

ISPS compliance is proved by documents, and port-state control will ask for them in a predictable order.

  • Ship Security Assessment (SSA) — the risk analysis that must be completed before a Ship Security Plan can be written. It identifies the vessel’s vulnerabilities, key shipboard operations and existing protective measures.
  • Ship Security Plan (SSP) — the ship-specific procedures for each security level, covering access control, restricted areas, cargo and stores handling, communications, and the response to a security threat. Parts of it are confidential and are not open to general inspection.
  • International Ship Security Certificate (ISSC) — issued once the flag Administration or a recognised security organisation verifies that the ship complies. If a ship does not have a valid certificate, that ship may be detained in port.
  • Declaration of Security (DoS) — an agreement between a ship and a port facility (or another ship) setting out the security measures each will apply for a specific interface, typically requested when security levels differ or the interface presents a higher risk.
  • Ship Security Alert System (SSAS) — required under SOLAS regulation XI-2/6. It transmits a covert alert identifying the ship and its position to a designated authority ashore, without raising any alarm on board or alerting other ships.

[source: ISSC validity period — ISPS Part A §19.3 sets the maximum period of validity; confirm the exact figure and the intermediate verification window before publishing.]

What the ISPS Code Means for Your Daily Work

Strip out the regulation numbers and shipboard ISPS obligations come down to five behaviours:

  1. Control access. No one crosses the gangway unlogged and unidentified. That includes contractors, surveyors, agents and people who insist they are expected.
  2. Respect restricted areas. Bridge, engine control room, steering gear, store rooms and any space named in the SSP. Locked means locked, not “locked unless it’s inconvenient”.
  3. Report, don’t assess. An unattended bag, a stranger on deck, a small craft holding station alongside — report it to the SSO or the officer of the watch and let them judge it.
  4. Turn up for drills properly. Security drills and exercises are a Code requirement, and they are also the only rehearsal you get.
  5. Write it down. Access logs, level changes, DoS records, drill records. Undocumented compliance reads as non-compliance to an inspector.

ISPS Code Security Levels, Duties and Training Explained

The Security Training Every Seafarer Needs

Security training is where ISPS stops being the company’s problem and becomes an entry on your own certificate record.

The 2010 Manila Amendments to the STCW Convention, in force from 1 January 2012, introduced new requirements for security training for all seafarers, together with provisions on training for piracy and armed robbery. Earlier, the 2006 STCW amendments (resolution MSC.209(81), in force 1 January 2008) had introduced measures covering ship security officers.

In practice this produces a three-tier structure under STCW chapter VI:

Tier

Who needs it

What it covers

Security awareness

All seafarers

Recognizing maritime security threats and understanding the ISPS Code framework — the baseline everyone carries

Proficiency in Designated Security Duties (PDSD)

Seafarers assigned specific security duties under the SSP — gangway watch, searches, restricted-area control

Carrying out assigned security tasks, search and inspection technique, handling security equipment

Ship Security Officer (SSO)

The designated SSO

Maintaining the SSP, security assessment, inspections, drills, incident response

STCW Regulation VI/6 is the provision covering security awareness and designated security duties.

The practical question most seafarers ask is which tier they need. The test is not your rank — it is whether the Ship Security Plan assigns you a named security duty. If it does, awareness training alone is not enough, and PDSD is the certificate that closes the gap.

→ Read next: Seaman Book for Singapore Seafarers: International Alternatives Explained

A port-state control officer finding an ISPS deficiency has options that escalate quickly: additional measures imposed as a condition of entry, restriction of movement within the port, refusal of entry, expulsion, or detention. A missing or invalid ISSC is at the severe end — a ship without a valid certificate may be detained.

The cost lands unevenly. The company pays in off-hire and lost fixtures; the crew pays in cancelled leave, extended port stays and a detention record attached to the vessel. Individual seafarers rarely cause a detention on their own, but an inspector who finds an unlogged visitor, a propped-open restricted-area door, or a rating who cannot describe their Level 2 duties has found exactly the evidence needed to open the file.

Quick ISPS Checklist Before You Join

  • Locate the Ship Security Plan and read the sections naming your duties at each security level
  • Confirm who the SSO is and how to reach them outside working hours
  • Check the current security level of the ship and of the port you are in
  • Verify your own security certificate covers the duties you have actually been assigned
  • Know the restricted areas on your vessel by name, not by guess
  • Know how to report a security concern — and report early rather than accurately

Frequently Asked Questions

What is the ISPS Code in simple terms?

The ISPS Code is the international rulebook for ship and port security. It requires covered vessels and port facilities to assess their security risks, write and follow a security plan, appoint named security officers, and operate at one of three security levels. It has been mandatory under SOLAS since 1 July 2004.

Does the ISPS Code apply to all ships?

No. SOLAS chapter XI-2 covers passenger ships and cargo ships of 500 gross tonnage and above, including high-speed craft and mobile offshore drilling units, on international voyages, plus the port facilities serving them. Warships, naval auxiliaries and government non-commercial ships are excluded.

What are ISPS security levels 1, 2 and 3?

Level 1 is normal operation with minimum protective measures maintained at all times. Level 2 is heightened, applied for as long as an elevated risk persists. Level 3 is exceptional, applied for a limited period when a security incident is probable or imminent. Higher levels add access controls, searches and patrols.

Who sets the security level for a ship?

The flag Administration sets the security level for ships entitled to fly its flag, and Contracting Governments set levels for port facilities in their territory. When a ship and the port facility it is using are at different levels, the higher level applies for the duration of the interface.

What is the difference between the ISM Code and the ISPS Code?

The ISM Code governs safety management and pollution prevention; the ISPS Code governs security against deliberate threats. They run in parallel — ISM produces the Safety Management System and the DOC/SMC, while ISPS produces the Ship Security Plan and the ISSC.

Do I need PDSD or just security awareness training?

It depends on what the Ship Security Plan assigns you. Every seafarer needs security awareness training. If the plan gives you a specific security duty — gangway watch, searching persons or baggage, controlling restricted areas — you need Proficiency in Designated Security Duties (PDSD) as well.

Can a ship be detained for an ISPS deficiency?

Yes. Port-state control can impose conditions, restrict movement, refuse entry, expel a vessel or detain it. A ship without a valid International Ship Security Certificate may be detained in port until the deficiency is resolved.

The Short Version

The ISPS Code turned ship security from a matter of local practice into an auditable, certificated system: mandatory since 1 July 2004, built on SOLAS chapter XI-2, structured around three security levels, three named officer roles and a documented plan for each vessel. For a seafarer, almost all of it reduces to three things — know your duties at each level, know your restricted areas, and keep the record honest.

The one item worth acting on today is the certificate check. If the Ship Security Plan assigns you a named security duty and your record shows only awareness training, that is a gap that surfaces at the worst possible moment.

Not sure whether your security endorsements match the duties you’re signing on for? Talk to the Seamanbooks team — we handle STCW certification and seafarer documentation across seven flag States, and we’ll tell you straight what’s missing.

Prefer it in your inbox? Join the Seamanbooks newsletter for plain-English updates on STCW, flag-State documentation and maritime compliance changes that affect your certificates.

Contact Form

Recent Post