Superba Knowledge — Bridging Regulations and Operations Beta
IT/EN
Download
Operational Guide · Registers & Logbooks

Ship Security Plan and the ISPS Code

Since 2025 a Ship Security Officer without a valid certificate is, in itself, grounds for detention: security has moved out of the 'documentary' area and become a full PSC inspection priority.

ISPS CodeShip Security PlanSSOsecurity level

Operational Explanation

The ISPS Code (International Ship and Port Facility Security Code), made mandatory by SOLAS Chapter XI-2, requires every ship subject to it to have a Ship Security Plan (SSP) detailing operational and physical security measures for each of the three security levels (Security Level 1, 2, 3), access control, security of cargo handling, and communication protocols in the event of a security incident.

Every ship must have a designated Ship Security Officer (SSO), responsible for implementing the SSP on board: security drills, access control, record-keeping, and incident reporting. The SSO must hold a valid certificate of competence under STCW Regulation VI/5.

The PSC procedures revised in 2025 (Resolution A.1206(34)) now dedicate a specific appendix to security inspections (Appendix 20): for the first time, PSC inspectors work alongside Duly Authorized Officers (DAO) to conduct security assessments, and the absence of a valid SSO certificate is, in itself, grounds for detention.

Regulatory Reference

ISPS Code, made mandatory by SOLAS Chapter XI-2; SSO certification under STCW Regulation VI/5; PSC security inspection procedures updated by Resolution A.1206(34) (2025), which introduces the dedicated Appendix 20 and collaboration with Duly Authorized Officers.

Scope of Application

Every ship subject to SOLAS Chapter XI-2 (passenger ships, cargo ships ≥500 GT, mobile offshore units) engaged on international voyages.

Procedure / How to Complete It

  1. Verify that the designated SSO holds a valid certificate of competence under STCW Regulation VI/5.
  2. Verify consistency between the declared security level (Security Level 1, 2 or 3) and the measures actually applied on board.
  3. Conduct the security drills required by the SSP, documenting them in the onboard records.
  4. Verify access control and cargo handling security per the SSP procedures.
  5. Prepare for possible collaboration between the PSCO and a Duly Authorized Officer during a security inspection, per the procedures updated in 2025.

Practical Example

Example verification: before arrival in port, the SSO verifies that their STCW VI/5 certificate is currently valid, checks that the current security level of the destination port is consistent with the measures in place on board, and prepares documentation of recent security drills in view of a possible inspection.

Real Cases

The introduction, in the 2025 PSC procedures, of the rule that the absence of a valid SSO certificate is in itself grounds for detention represents a concrete raising of the attention threshold on security: before this update, a documentary shortcoming on the SSO was treated more as an administrative deficiency than as grounds for detention.

Common Mistakes Mistake Library

MistakeConsequenceHow to avoid it
SSO certificate expired or nearing expiry not renewed in timeDirect detention per the 2025 PSC procedures, no longer a simple deficiencyMonitor the SSO certificate expiry with the same rigour as the main statutory certificates
Onboard security measures not updated when the port's declared security level changesInconsistency detectable during the security inspection, with PSCO and DAOPromptly update operational security measures whenever the declared level changes
Security drills conducted rarely or not adequately documentedInability to demonstrate real preparedness during a security inspectionSystematically conduct and document the security drills required by the SSP

PSC Observations

Since 2025, security inspections follow a dedicated procedure (Appendix 20 of Resolution A.1206(34)) with the possible participation of a Duly Authorized Officer alongside the PSCO; the absence of a valid SSO certificate is grounds for direct detention.

Operational Tips

Checklist

FAQ

What happens if the SSO's certificate has expired?
Per the PSC procedures updated in 2025, the absence of a valid SSO certificate is in itself grounds for detention, no longer a simple documentary deficiency.
What is a Duly Authorized Officer (DAO)?
A role introduced in the 2025 PSC procedures (Resolution A.1206(34), Appendix 20) that works alongside the PSCO in conducting security assessments during an inspection dedicated to security.
How many security levels does the ISPS Code provide for?
Three: Security Level 1 (minimum measures always in force), Security Level 2 (enhanced measures for a period of heightened risk) and Security Level 3 (exceptional measures in response to a specific, imminent threat).
🎬 Additional photos, videos and interactive diagrams for this topic will be available in a future version of the platform.

Related Topics