UFEED
← Back to list

CMA CGM 8212 — DNV Cyber Security SP0 Certification Achieved for 13,000 TEU Container Carrier

· UFEED
cyber-resilience

## Overview


UFEED supported the on-board cyber security test campaign for **HSHI Hull Nos. 8212**, a series of **13,000 TEU class container carriers**, toward achieving **DNV Cyber Secure (SP0)** notation under **DNV-RU-SHIP Pt.6 Ch.5 Sec.21**. The test procedure and results document (Dwg. No. 6N-7000-505) defines the full scope of testing required across the vessel's Systems under Consideration (SuC), and the on-board test itself was executed over a four-day window from March 6–12, 2025.


DNV's Cyber Secure notation framework is built on **IEC 62443-3-3** security requirements, and SP0 represents the baseline security profile applied to this vessel class.


## Systems Under Consideration (SuC)


The test procedure identifies ten systems in scope, each supplied by a different maker:


| System | Maker |

|---|---|

| Navigation & Communication | Furuno |

| Auto Telephone System | MRC |

| M/E Control System | HHI-EMD |

| ICMS (incl. ESDS) | HD Hyundai Marine Solution (HMS) |

| G/E Control System | HHI-EMD |

| VRCS & Anti-heeling System | Hoppe |

| Shaft Generator System | ABB |

| GAS Detection System | Consilium |

| Fire Detection System | Consilium |

| Bridge Maneuvering System (BMS) | Kongsberg |


Each system's test procedure follows a common structure derived from IEC 62443-3-3 requirements — covering user identification and authentication, use control for portable/mobile devices, auditable events, communication integrity, malicious code protection, session integrity, information confidentiality, denial-of-service protection, and backup/recovery capability.


## Four-Day On-Board Test Schedule


The on-board test was scheduled as a rolling, multi-vendor campaign, with each supplier's engineers attending their assigned slots:


| Day | Date | Morning | Afternoon |

|---|---|---|---|

| Day 1 | 3/6(Thu) | BMS(Kongsberg) | Negligilble System | VRCS & Anti-heeling System(Hoppe) | GAS, Fire Detection(HMS) |

| Day 2 | 3/7(Fri) | Shaft Generator(ABB) | AutoTel(MRC) |

| Day 3 | 3/11(Tue) | ICMS(in ECR) | ICMS(in WH) |

| Day 4 | 3/12(Wed) | Generator Engine(HHI) | Main Engine(HHI) |


Coordinating this many suppliers within a fixed on-board window required close scheduling discipline — each system needed its own test setup, equipment, and in some cases supplier-specific procedures (e.g., the main engine, shaft generator, and BMS test packages were each governed by separate maker-approved test programs referenced as appendices to the main procedure).


## Three Layers of Verification


The test procedure structures compliance demonstration into three distinct categories:


**1. System Testing** — Each SuC is tested individually against its applicable IEC 62443-3-3 security requirements, verifying that the specific system behaves as required (e.g., confirming physical port blockers are in place, reviewing audit logs, and validating DoS resilience through controlled traffic-flood testing using tools such as hping3).


**2. Integration Testing** — Beyond individual system compliance, the vessel's overall network architecture is verified for **network segmentation** and **zone boundary protection**, confirming that OT and IT systems, and safety-critical systems, are properly separated into distinct security zones, and that any communication crossing a zone boundary is controlled through a firewall following a "deny by default, allow by exception" policy.


**3. Negligible Risk Systems** — Systems meeting all three of DNV's negligible-risk criteria (no IP-based network connection, located in a restricted area, and software/configuration changeable only by the manufacturer using proprietary tools) may be exempted from full security testing, subject to on-board visual verification. For this vessel series, over 40 systems — ranging from navigation aids (gyro compass, magnetic compass, NAVTEX) to power distribution panels and machinery auxiliaries — qualified under this category, each verified individually against the exemption criteria.


## Why It Matters


This project illustrates the operational complexity behind a single cyber security notation on a modern container carrier: ten actively-tested systems from ten different suppliers, a network architecture verified for proper zone segmentation, and dozens of additional systems individually screened for exemption eligibility — all coordinated within a four-day on-board window.


For UFEED, managing this scale of multi-vendor, multi-system coordination — across engine control, navigation, communication, and safety systems simultaneously — builds directly on the testing methodology developed through earlier UR E26/E27 and Bureau Veritas Cyber Managed Prepared work, and reflects the kind of large-scale test orchestration UFEED brings to DNV-classed newbuildings.

Delivering DNV Cyber Secure (SP0) Certification Testing for a 13,000 TEU Container Carrier Series | UFEED