DPA & CSO

What Does a Company Security Officer (CSO) Do, and Why Does Location Matter?

If your vessel needs a Designated Person Ashore under the ISM Code, it almost certainly needs a Company Security Officer under the ISPS Code too. Most operators know they need one. Fewer have thought through what the role actually involves, who is allowed to hold it, or what happens to a vessel's security coverage when the vessel is operating a long way from the people who manage it.

What the ISPS Code actually requires

The ISPS Code is direct: the Company shall designate a Company Security Officer. A single CSO can cover multiple vessels, provided it is clearly documented which vessels they are responsible for, and a Company may designate more than one CSO on the same basis.

The CSO's core duties are to ensure a Ship Security Assessment is carried out for each vessel, to develop and submit the Ship Security Plan for approval, to ensure the plan is properly implemented and maintained on board, and to act as the liaison point between the ship, the Port Facility Security Officer and the Ship Security Officer. Security incident reports from the vessel go to the CSO, and any amendment to an approved Ship Security Plan has to be submitted through them.

The CSO must also have the knowledge to do the job: security assessment, current security threats and patterns, recognition and detection of weapons, the security equipment and systems on board, and the requirements of the ISPS Code itself.

Who can be a CSO?

The Code does not prescribe a single qualification, but it does require the CSO to be genuinely competent. Most Administrations look for training built on the IMO model course for Company Security Officers and the competencies set out in IMO guidance. We hold that training and certification through Lloyd's Maritime Institute.

But there is a second question most articles skip, and it matters more than the first: who the CSO is allowed to be.

In most flag state cases, the CSO must be an employee of the Company — the Document of Compliance holder that has assumed responsibility for operating the vessel — and not a third-party contractor. Some registries state this expressly. The Marshall Islands, for example, does not accept the CSO function being entrusted to a third party, on the reasoning that the CSO is part of the Company and shares its obligation to protect the integrity of the Ship Security Plan. Other Administrations are less prescriptive in their wording, but the working assumption a Recognised Security Organisation brings to an audit is the same.

What is widely permitted is more than one designated officer. A number of Administrations expressly contemplate additional, alternate or deputy CSOs — designated by the Company in the same way as the primary — covering particular geographical areas or groups of ships within a fleet, precisely to remove a single point of failure and to make twenty-four hour cover real rather than notional. Where that is the structure, the Ship Security Plan identifies which officer covers which vessels, with contact details held on board.

Read those two paragraphs together, because the distinction governs everything below. What is restricted is who may hold the appointment. What is widely permitted is regional cover. They are different things, and confusing them is how operators end up with an arrangement their flag will not accept.

So the first question on any vessel is not "can we get a CSO". It is "what does this flag require, and what does it permit". The answer differs between Administrations, and it is worth establishing before anything is agreed.

Not fully ISPS-bound? Security oversight still matters

In yacht industry practice, ISPS bites once a vessel is operating commercially, trading internationally and crosses 500GT — the same line that pulls in full ISM compliance, and no coincidence: it is why an entire generation of yachts is deliberately designed to sit at 499GT, just under the threshold. Carrying more than 12 fare-paying guests reclassifies a yacht as a passenger vessel, which can bring ISPS into play depending on how the flag state applies it, but 500GT remains the threshold that does most of the real work. Smaller private vessels and mini-ISM operations often sit outside the mandatory requirement altogether, in the same way they can sit outside ISM.

The same logic applies here as it does to safety management: a lack of legal obligation is not a lack of risk. This region also is not quite the same proposition as coastal cruising in the Mediterranean. Ports across the South Pacific and Papua New Guinea are more remote, further from immediate outside assistance, and more variable in local infrastructure. A voluntary, properly resourced security point of contact ashore is one of the more straightforward pieces of risk management to put in place for that kind of cruising ground, and for an owner planning a move toward commercial certification later, it is a head start rather than a cost.

Domestic commercial vessels in Australia and New Zealand carry their own security obligations distinct from ISPS, a topic detailed enough that we will cover it properly in a future article.

Why location matters

A vessel's security arrangements are written in one place and tested in another. For a superyacht or boutique cruise vessel operating in New Zealand, Australia, Papua New Guinea or the wider South Pacific, the people who manage it are very often somewhere else entirely. That gap shows up in three ways, and time zone is only one of them.

Availability

This is arithmetic, not a criticism of anybody's service. A vessel arriving in Auckland at 1500 on a summer afternoon, needing help from its Company Security Officer is calling at 0200 UTC. That is the small hours in London and across Europe, early morning in Dubai, and the previous evening on the US East Coast. Midday in Fiji falls between late evening and the middle of the night for almost every major yacht management centre in the northern hemisphere.

Most managers advertise 24-hour response, and most of them deliver it. But a phone answered at three in the morning is not the same as a working day. Decisions get deferred, documents wait, and a situation that could have been dealt with in an afternoon runs into the next one.

Knowledge of place

The ISPS Code is the same everywhere. The ports it is applied in are not. Port facilities across the Pacific differ in size, infrastructure and local procedure, and remote anchorages across the South Pacific and Papua New Guinea sit a long way from outside assistance. On a typical Pacific circuit, a vessel moves routinely between port States, each with its own arrangements, and arrives from ports operating at different security levels.

New Zealand and Australia add their own emphasis: Port State Control in both countries checks ISPS compliance closely. Having someone informed, on the ground and answering the phone during the vessel's working day can make a real difference if questions arise.

That kind of local knowledge comes from having operated in these waters, and it is the part of regional support that is hardest to replicate from a distance.

Presence

Some things are simply better done in person: attending a vessel during a Port State Control inspection, running a security drill on board before a first arrival, walking through a Ship Security Plan with a new Ship Security Officer, or sitting down with the Master after an incident. An appointed CSO can arrange any of these from anywhere. It is faster, simpler and usually cheaper to arrange them from here.

What regional security support looks like

Regional support works alongside the vessel's appointed CSO, not in place of them. The statutory structure stays where the flag requires it to be. What is added is a regional arm of that function.

A properly structured arrangement is a formal agreement, not a loose understanding. It sets out which vessels are covered and which Ship Security Plan applies to each; the contact arrangements and expected response times; the liaison procedures with PFSOs and local authorities at the ports the vessel is actually using; and the scope of involvement in assessments, drills and plan reviews.

Critically, it sets out the escalation path back to the appointed CSO — who is contacted, in what order, and how quickly. The value of regional cover is that something gets dealt with at the moment it happens. The discipline of it is that the appointed officer is never out of the loop.

Tasman's role in that arrangement is regional security support, not a statutory appointment. The appointed CSO, and any alternate or deputy the Company designates, stays within the Company, as the flag requires. What we provide works alongside them: active participation in the vessel's security while it operates in this region.

How our regional maritime security and ISPS shore support works →

Summary

If your vessel is subject to the ISPS Code, a reachable, properly trained CSO is a Code requirement with an explicit 24-hour contact standard, not a discretionary extra. How that is made to work when the vessel is operating far from its management — across time zones, in unfamiliar ports, a long way from anyone who can attend — is a practical problem the Code does not solve for you, and how it may be structured depends on what your flag permits. And if your vessel does not legally require a CSO at all, genuine security oversight ashore is still worth having before an incident makes the case for you.

Get in touch if you would like to talk through what your flag requires and where the gaps are for a vessel operating in this region.

Frequently asked questions

Does every superyacht need a Company Security Officer?

In practice, once a superyacht is operating commercially, trading internationally and crosses 500GT — the same line that triggers full ISM compliance. Carrying more than 12 fare-paying guests reclassifies a yacht as a passenger vessel, which can bring ISPS into play depending on the flag state, but 500GT is what does most of the real work. Vessels outside these thresholds are not legally required to carry a CSO, though arriving at an ISPS-regulated port without one when you should have one can mean delays, detention or refused entry.

Does a CSO really need to be contactable 24 hours a day?

Yes. The ISPS Code requires the Ship Security Plan to list the CSO's 24-hour contact details, not just their name.

Can an external consultant be appointed as our CSO?

In most flag state cases, no. The CSO is normally required to be an employee of the Company and not a third-party contractor, and some registries state that expressly. Many Administrations allow the Company to designate alternate or deputy CSOs for particular geographical areas, but those officers are normally within the Company too. What an external consultant can provide is regional support alongside them. Establishing what your flag requires is the first step, and we would rather confirm it than assume it.

Can the DPA and CSO be the same person?

Often, yes. Nothing in the ISM or ISPS Codes prevents one person holding both roles, and in smaller operations it is common, provided the dual role is documented in both the Safety Management System and the Ship Security Plan. Where the flag requires the CSO to be a Company employee, an external DPA can still provide regional security support alongside the Company's appointed CSO. For more on the DPA's side, see our companion article on what a Designated Person Ashore does under the ISM Code.

Why would a vessel use regional security support in New Zealand, Australia or the South Pacific?

Because a vessel operating here is often a long way from its management — in hours, in miles and in local knowledge. Regional support adds availability in the vessel's operating day, familiarity with the ports it is actually using, and the ability to attend in person, without replacing the existing structure or the appointed officer.

Does regional support mean replacing our management company or our CSO?

No. Your appointed CSO stays exactly where your flag requires. Regional support works within your existing Ship Security Plan and reporting lines, alongside your appointed officer, as support rather than a statutory appointment.

How does handover and escalation work?

It is written down before it is needed. The agreement sets the hours covered, expected response times, the contact order back to your appointed CSO, and what may and may not be done without their authority. Anything requiring their decision goes to them immediately.

Share this article

Share on LinkedIn Share by email

Have a question about this topic?

Book a free 15-minute call with Craig Hopkins — practical answers, no jargon.