Ship Security Plan and the ISPS Code
Since 2025 a Ship Security Officer without a valid certificate is, in itself, grounds for detention: security has moved out of the 'documentary' area and become a full PSC inspection priority.
Operational Explanation
The ISPS Code (International Ship and Port Facility Security Code), made mandatory by SOLAS Chapter XI-2, requires every ship subject to it to have a Ship Security Plan (SSP) detailing operational and physical security measures for each of the three security levels (Security Level 1, 2, 3), access control, security of cargo handling, and communication protocols in the event of a security incident.
Every ship must have a designated Ship Security Officer (SSO), responsible for implementing the SSP on board: security drills, access control, record-keeping, and incident reporting. The SSO must hold a valid certificate of competence under STCW Regulation VI/5.
The PSC procedures revised in 2025 (Resolution A.1206(34)) now dedicate a specific appendix to security inspections (Appendix 20): for the first time, PSC inspectors work alongside Duly Authorized Officers (DAO) to conduct security assessments, and the absence of a valid SSO certificate is, in itself, grounds for detention.
Regulatory Reference
ISPS Code, made mandatory by SOLAS Chapter XI-2; SSO certification under STCW Regulation VI/5; PSC security inspection procedures updated by Resolution A.1206(34) (2025), which introduces the dedicated Appendix 20 and collaboration with Duly Authorized Officers.
Scope of Application
Every ship subject to SOLAS Chapter XI-2 (passenger ships, cargo ships ≥500 GT, mobile offshore units) engaged on international voyages.
Procedure / How to Complete It
- Verify that the designated SSO holds a valid certificate of competence under STCW Regulation VI/5.
- Verify consistency between the declared security level (Security Level 1, 2 or 3) and the measures actually applied on board.
- Conduct the security drills required by the SSP, documenting them in the onboard records.
- Verify access control and cargo handling security per the SSP procedures.
- Prepare for possible collaboration between the PSCO and a Duly Authorized Officer during a security inspection, per the procedures updated in 2025.
Practical Example
Example verification: before arrival in port, the SSO verifies that their STCW VI/5 certificate is currently valid, checks that the current security level of the destination port is consistent with the measures in place on board, and prepares documentation of recent security drills in view of a possible inspection.
Real Cases
Common Mistakes Mistake Library
| Mistake | Consequence | How to avoid it |
|---|---|---|
| SSO certificate expired or nearing expiry not renewed in time | Direct detention per the 2025 PSC procedures, no longer a simple deficiency | Monitor the SSO certificate expiry with the same rigour as the main statutory certificates |
| Onboard security measures not updated when the port's declared security level changes | Inconsistency detectable during the security inspection, with PSCO and DAO | Promptly update operational security measures whenever the declared level changes |
| Security drills conducted rarely or not adequately documented | Inability to demonstrate real preparedness during a security inspection | Systematically conduct and document the security drills required by the SSP |
PSC Observations
Operational Tips
- Monitor the SSO certificate expiry with the same rigour reserved for the main statutory certificates.
- Promptly update operational security measures whenever the port's declared security level changes.
- Systematically document every security drill conducted, not just the most recent ones.
Checklist
- Valid SSO certificate under STCW Regulation VI/5
- Current security level consistent with the measures applied on board
- Security drills conducted and documented regularly
- Access control and cargo security compliant with the SSP
- Security records ready for a possible PSCO/DAO inspection