← Back to Blog

Maritime ECDIS and PQC

Maritime ECDIS and PQC - QNSQY post-quantum encryption guide

A modern commercial vessel runs on dozens of digital systems. Electronic Chart Display and Information System (ECDIS) integrates electronic navigational charts with GPS, AIS, radar, and gyro inputs to give the bridge team a unified picture. Voyage Data Recorders (VDR) capture audio, video, and instrument data to a tamper-evident log. Automatic Identification System (AIS) broadcasts position, course, and speed to other vessels and shore stations. Each of these systems has cryptographic touchpoints that will eventually need to migrate from classical algorithms to post-quantum equivalents. The International Maritime Organization (IMO) Resolution MSC.428(98) made cybersecurity a part of the safety management system, and shipping companies are under increasing pressure from class societies, port states, and insurers to manage cyber risk like any other operational risk. This article walks through the cryptographic footprint of ECDIS, VDR, and AIS, the IMO regulatory framework, and how to think about a post-quantum migration program for the maritime sector.

Why Maritime Cryptography Is a Growing Concern

Commercial ships have a 25 to 30 year service life. The ECDIS, VDR, and communication systems installed today will be aboard vessels into the 2050s. Quantum computers will arrive within that window with high probability. Captured maritime communications and navigation data, even if not immediately decryptable, would become readable to a future quantum-equipped adversary. The harvest-now-decrypt-later threat applies to maritime operations exactly as it does to other critical sectors.

The sector also faces specific operational concerns. GPS spoofing incidents in the eastern Mediterranean and the Black Sea have demonstrated that adversaries are prepared to manipulate maritime navigation. AIS spoofing is documented across multiple regions. ECDIS chart authentication is a known concern. The cryptographic protections that exist today are mostly classical, and the quantum threat layered on top of these existing concerns increases the urgency.

For broader background see What Is Post-Quantum Cryptography and Harvest Now, Decrypt Later.

ECDIS and Electronic Chart Authentication

ECDIS is the integrated bridge system that displays Electronic Navigational Charts (ENCs) along with own-ship position, course, and other navigational information. ECDIS replaced paper charts as the primary means of navigation under SOLAS amendments that took effect between 2012 and 2018. Most large commercial vessels now navigate primarily by ECDIS.

ENCs are produced by national hydrographic offices and distributed through chart distributors. The S-63 standard specifies a chart protection scheme using cryptographic signatures and encryption to ensure that ENCs are authentic and that licensing is enforced. S-63 today uses classical cryptography. The International Hydrographic Organization (IHO) is moving to S-100, the next generation chart standard, which will include updated security profiles that need to address post-quantum considerations.

ECDIS receives ENC updates over various channels including USB, internet downloads, and INMARSAT broadcasts. The integrity of the update stream is critical: if an adversary can substitute a modified chart, navigation hazards can be made invisible. Quantum-era forgery of S-63 signatures would compromise this protection. Migration to hybrid post-quantum signatures (Ed25519 + ML-DSA) is the appropriate response.

VDR Data Integrity and Long-Term Sensitivity

The Voyage Data Recorder is the maritime equivalent of an aircraft black box. VDR captures audio from bridge microphones, VHF radio, ECDIS screens, radar, AIS, and various sensor inputs. The recordings are used in incident investigation by flag states and port states. The IMO Performance Standards for VDRs (Resolution A.861(20) and successors) specify the data types and retention requirements.

VDR data integrity is a cryptographic concern. The recordings need to be tamper-evident across the time from incident to investigation, which can be years. If VDR signatures can be forged in the future by quantum computers, the integrity of historical investigations is compromised. Migration to post-quantum signatures preserves the tamper-evidence across the relevant timeline.

For broader regulatory context see PQC for Critical Infrastructure Grid and the NIST FIPS Guide.

AIS Authentication and the Open Broadcast Problem

The Automatic Identification System broadcasts vessel position, course, speed, and identification data on VHF maritime channels. AIS is a cooperative system: vessels broadcast their data and receive other vessels' data. Shore stations and satellites also receive AIS data, providing global vessel tracking. The open broadcast nature of AIS is by design, but it also enables AIS spoofing where an adversary transmits fake AIS messages.

There is no native cryptographic authentication in standard AIS. The ITU R M.1371 specification does not include message signing. AIS spoofing has been documented in multiple incidents, including 2017 GPS-related disruptions in the Black Sea and ongoing reports of vessel "ghosting" in sanctions evasion contexts. Cryptographic authentication of AIS messages is a research area, with proposals for authenticated AIS that would require post-quantum design from the outset.

If and when authenticated AIS is standardized, the design should incorporate hybrid post-quantum signatures. The bandwidth constraints of AIS are tight (the standard 9.6 kbps channel is shared among all vessels in range), so signature size matters. ML-DSA or compact post-quantum signature schemes will need to be profiled for AIS specifically. See Hybrid Encryption for construction discussion.

Vessel Communication and Navigation Systems

Beyond ECDIS, VDR, and AIS, vessels carry a range of communication systems that depend on cryptography. INMARSAT-C and Fleet Broadband provide satellite voice and data. VSAT systems provide broadband connectivity. GMDSS (Global Maritime Distress and Safety System) provides distress communication. NAVTEX provides navigational warnings.

INMARSAT and other satellite providers are working on PQC roadmaps for their commercial offerings. As the satellite ground stations and onboard terminals refresh over the coming decade, hybrid PQC will arrive in maritime satcom. Vessel operators should require PQC commitments in their satcom service agreements during contract renewals.

The integrated bridge system architecture, including ECDIS, conning displays, and communication systems, is increasingly software-defined and connected. The cryptographic touchpoints proliferate as the architecture evolves. PQC migration needs to address each touchpoint, with priority on the systems most exposed to long-term sensitivity (chart authentication, VDR integrity) and systems most exposed to active adversary targeting (satellite communications, navigation systems).

IMO MSC.428(98) and the Cybersecurity Framework

IMO Resolution MSC.428(98) requires cyber risks to be managed in the safety management system under the International Safety Management (ISM) Code starting January 1, 2021. The resolution does not specify cryptographic requirements directly, but it requires shipping companies to assess cyber risks and implement appropriate measures. Class societies including DNV, Lloyd's Register, ABS, and Bureau Veritas have published cyber notations and guidance that operationalize MSC.428(98).

For PQC, the framework means that quantum risk falls inside the ISM Code's cyber risk management expectations. Forward-looking shipping companies are beginning to address quantum risk in their cyber risk assessments and to align their cryptographic refresh cycles with NIST IR 8547 timelines. Class society guidance is moving in the same direction.

Port State Control and Cybersecurity Inspections

Port states (national maritime authorities) inspect vessels that visit their ports, with authority to detain non-compliant vessels. The Tokyo MOU, Paris MOU, and other regional Memoranda of Understanding coordinate port state control. Cybersecurity inspections are increasingly part of the port state control regime, particularly for vessels with elevated risk profiles.

PQC migration is not yet a port state control item as of 2026, but the broader cybersecurity posture is. Vessels with documented PQC migration plans demonstrate disciplined cyber risk management, which favorably affects port state risk profiling. Class notations and certifications that address PQC will support better port state outcomes over time.

Practical Migration Approach for Vessel Operators

A practical migration approach for a shipping company has three layers. Shore-based IT systems including fleet management, voyage planning, port logistics, and commercial systems can move to hybrid PQC on standard enterprise IT timelines (1 to 3 years). Shore-to-ship communications including chart distribution, weather routing, and operational messaging benefit from PQC and can move on a 3 to 5 year timeline as satellite providers and chart distributors update their systems.

Onboard systems are the longest tail. ECDIS, VDR, AIS, and integrated bridge equipment will follow vendor refresh cycles and class society approval timelines. New vessels delivered after 2030 should specify PQC capability in the procurement. Existing vessels will receive PQC capability through equipment upgrades during scheduled refits and major surveys, typically every five years.

The IHO S-100 chart standard rollout is the natural opportunity for chart authentication PQC migration. As S-100 charts replace S-57 over the coming decade, the underlying signature cryptography should move to hybrid post-quantum.

Sanctions Compliance and Crypto-Sensitive Cargo Data

Maritime shipping carries significant sanctions and trade compliance burden. The Office of Foreign Assets Control (OFAC) sanctions, EU sanctions, and UN sanctions all touch maritime trade through prohibited cargo, sanctioned counterparties, and sanctioned destinations. Vessels that visit sanctioned countries or carry sanctioned cargo can face severe penalties.

The cryptographic implications are around AIS data integrity and the broader operational data that documents vessel movements. AIS records, port call records, bill of lading data, and the documentation that supports OFAC compliance are all sensitive across the period during which sanctions enforcement actions can be brought, which can be a decade or more after the underlying transaction. Forward-looking encryption posture, including hybrid post-quantum protection of these records, supports defensible long-term compliance.

Class Society Notations and Cyber Capable Vessels

Major class societies (DNV, Lloyd's Register, ABS, Bureau Veritas, ClassNK, RINA) all offer cyber notations or class certifications that recognize vessels with elevated cybersecurity practices. DNV's Cyber Secure notation, ABS's CyberSafety class notation, and similar offerings from the other societies establish frameworks that can incorporate PQC-readiness as the threat landscape evolves.

Shipowners pursuing class cyber notations should engage with their class society about PQC roadmaps and how forward-looking cryptographic posture maps to notation requirements. As the international shipping community matures its cybersecurity practices, class notations are likely to become differentiating factors in chartering, financing, and insurance, and PQC capability will likely be one of the criteria.

For sector context see PQC for Critical Infrastructure Grid.

Crew Training and Operational Awareness

Cybersecurity awareness on commercial vessels has grown substantially over the past decade, but the deeper cryptographic understanding required for PQC migration is uneven across the sector. Bridge officers and engineers receive cybersecurity training as part of the IMO Standards of Training, Certification and Watchkeeping (STCW) framework, but the training typically covers operational hygiene (password practices, USB media handling, suspicious email recognition) rather than cryptographic algorithm choices.

For PQC migration, the practical implication is that crew training does not need to deeply cover post-quantum mathematics. The migration is largely a vendor and shore-based decision: equipment vendors update firmware, shore IT updates communication infrastructure, and the crew operates the resulting systems. Where crew awareness matters is in the decommissioning of old equipment (ensuring private keys are destroyed properly), the response to alerts that may indicate cryptographic failures (an ENC update that fails signature verification, for instance), and the documentation of incidents that may have cryptographic relevance.

Class society and flag state training programs are the natural delivery channels for this kind of crew awareness. The Nautical Institute, the International Chamber of Shipping, and similar bodies have begun including cybersecurity in their training curricula. PQC-specific content will likely appear in updated curricula over the coming years as the migration progresses.

Frequently Asked Questions

Does the IMO require post-quantum cryptography?

Not by name as of 2026. IMO MSC.428(98) requires cyber risk management in the safety management system. Cryptographic posture falls inside that framework, with class society guidance increasingly addressing quantum considerations.

What is the biggest maritime PQC concern?

ECDIS chart authentication and VDR integrity stand out because of long sensitivity windows and the consequences of forgery. AIS authentication is also a research area where post-quantum design should be incorporated from the outset.

How does S-63 chart protection work today?

S-63 uses classical cryptographic signatures and encryption to authenticate Electronic Navigational Charts and enforce licensing. The IHO is moving to S-100 over the coming decade, and S-100 security profiles need to incorporate post-quantum considerations.

What about AIS spoofing?

AIS does not have native cryptographic authentication in the standard. AIS spoofing has been documented in multiple incidents. Authenticated AIS is a research and standardization area where any future deployment should incorporate hybrid post-quantum signatures.

How long do shipping companies have to migrate?

Vessel lifecycles are 25 to 30 years, so equipment installed today will be aboard ships into the 2050s. Starting now reduces the harvest-now-decrypt-later exposure and aligns with NIST IR 8547 migration timelines. Major equipment refresh cycles every five years provide migration windows.

How does GMDSS factor into the migration?

The Global Maritime Distress and Safety System provides distress and emergency communication services using a mix of VHF, MF/HF radio, and satellite channels. Cryptographic protections in GMDSS today are limited; the system is designed primarily for reliability rather than confidentiality. As GMDSS modernizes through IMO work programs, the opportunity exists to integrate post-quantum cryptography for any new authenticated services.

Are recreational and fishing vessels affected by maritime PQC migration?

The migration concerns primarily commercial vessels under SOLAS (Safety of Life at Sea) regulations and similar international frameworks. Recreational vessels and small fishing vessels typically use simpler navigation systems with less cryptographic infrastructure. Where they receive ENC updates for chart plotters, the same S-63 to S-100 transition will affect them, but the migration cost and complexity is much lower than for SOLAS-class commercial vessels. The leisure marine equipment vendors (Garmin, Raymarine, Furuno consumer line) will update their products as the chart standards evolve.

What does PQC mean for autonomous shipping experiments?

Autonomous and remotely operated vessels are an active area of maritime research. Yara Birkeland (Norway), the Mayflower Autonomous Ship (UK), and various other projects explore vessels with reduced or no crew. The cryptographic requirements for autonomous shipping are stricter than for crewed vessels because the entire operational decision-making relies on cryptographically authenticated data flows from sensors, navigation systems, and shore-based control centers. PQC migration is essentially a prerequisite for serious deployment of autonomous shipping at sea, because the data integrity and authentication requirements span the multi-decade lifecycles that classical cryptography cannot guarantee.

Sources

  • IMO. "Resolution MSC.428(98): Maritime Cyber Risk Management in Safety Management Systems." imo.org.
  • IMO. "Resolution A.861(20): Performance Standards for Voyage Data Recorders." imo.org.
  • IHO. "S-63 Data Protection Scheme." iho.int.
  • IHO. "S-100 Universal Hydrographic Data Model." iho.int.
  • ITU. "Recommendation ITU-R M.1371: Technical characteristics for an automatic identification system." itu.int.
  • NIST. "NIST IR 8547: Transition to Post-Quantum Cryptography Standards." nist.gov.
  • IEC. "IEC 61162-450: Maritime navigation and radiocommunication equipment and systems." iec.ch.
  • BIMCO and ICS. "Guidelines on Cyber Security Onboard Ships." bimco.org.

Related Articles

Protect Your Data Before Q-Day Arrives

QNSQY's NIST-standardized post-quantum encryption protects files against both current and quantum-era threats.

Try QNSQY