← Back to Channel 16

MARSEC Levels 1, 2 and 3: What They Mean for an International Port Call

Mar 3, 2026, 9:00:00 AM6 min read

Analysis by Dryad Global’s intelligence team

Reviewed: 22 August 2026

The phrase “MARSEC level” is widely used in maritime conversation, but it can blur two related systems.

Internationally, the International Ship and Port Facility Security Code uses security levels 1, 2 and 3. In the United States, the Coast Guard uses the term Maritime Security, or MARSEC, Levels 1, 2 and 3 under US maritime-security regulations.

Both systems scale protective security as the threat changes. The authority, applicable plan and instructions still matter. A US MARSEC notice should not be treated as the source for the security level at a port in another country.

The ISPS Code connects ship and port security

The ISPS Code forms part of SOLAS chapter XI-2 and has supported the international security regime for ships and port facilities since 1 July 2004. It requires security assessments and approved plans, along with designated security responsibilities for companies, ships and port facilities.

The Code is built around risk management. Contracting Governments use security levels to communicate the degree of protective security that ships and port facilities need to maintain, while the detailed measures sit in the approved Ship Security Plan or Port Facility Security Plan.

The IMO overview of SOLAS XI-2 and the ISPS Code and its maritime-security questions and answers provide the primary international reference.

What security levels 1, 2 and 3 mean

Security level 1 is the normal level at which minimum appropriate protective security measures are maintained.

Security level 2 applies while additional protective security measures are maintained because the risk of a security incident is heightened.

Security level 3 applies for a limited period when a security incident is probable or imminent, even if the specific target may not be identified. Further specific measures are then maintained.

The level communicates the degree of security required. It does not publish every protective action to the wider public, and it does not mean that every ship or port implements an identical checklist. The approved plans determine how the organisation responds.

Who sets the level

Under SOLAS XI-2, security levels can be set only by a SOLAS Contracting Government. In its role as an Administration, a Contracting Government sets the level for ships entitled to fly its flag. It also sets levels for port facilities and for ships prior to entering or while within ports in its territory.

If the port’s Contracting Government sets a higher level than the ship’s Administration, the ship follows the higher level before entry and while in that port. The ship cannot reduce the applicable level because its own assessment is less concerned.

The IMO’s guidance on setting and responding to security levels explains these responsibilities.

UKMTO, MSCHOA, MDAT-GoG and other reporting or information centres do not set ISPS security levels. They may distribute information relevant to a threat assessment, but the formal level comes from the competent government authority.

MARSEC is the US term

The US Coast Guard maintains the MARSEC system for the US Marine Transportation System. MARSEC Level 1 is the baseline, Level 2 reflects heightened risk requiring additional measures, and Level 3 applies when an incident is probable, imminent or has occurred and further specific measures are required for a limited time.

The structure aligns with the three-tier international approach, but it operates through US law, authorities and approved plans. Current US status and notices should be checked through the US Coast Guard’s MARSEC resources and official local communications.

Outside the United States, “ISPS security level” is the more accurate general term. Using MARSEC as a global label risks suggesting that the Coast Guard sets the position elsewhere.

A higher level can change the port call before the ship arrives

A change in level can affect more than activity at the gangway. The ship and port facility may need to confirm how their respective measures will work together before arrival, and any difficulty implementing the required measures may need to be resolved with the relevant security officers and authorities.

Depending on the approved plans and instructions, the change can affect access control, restricted areas, watchkeeping, searches, cargo or stores handling, communications and the movement of people. It may require more preparation, personnel or time and can alter whether the call proceeds as expected.

For an operator, the immediate questions concern readiness and safe compliance. A charterer or trader may be concerned with delay and performance, while an insurer or financier may need to understand whether the change alters the exposure or the basis on which the call was approved.

The level itself does not calculate those consequences. It tells the ship and facility that a different security posture applies; the plans, port instructions and commercial arrangements determine what follows.

Security level does not describe the whole threat

A port operating at security level 1 is not certified free from crime, conflict, cyber disruption or every other maritime risk. It means the baseline ISPS measures apply under the competent authority’s current determination.

Likewise, a higher level does not explain the full cause or consequence for a particular vessel. The relevant risk may involve civil unrest near the port, a threat to a specific nationality, an incident on the approaches or another development requiring consideration beyond the formal level.

This is why the port-call assessment should show both the known security level and the wider conditions around the call, including when each was last checked. “Unknown” or “not verified” should remain visible rather than being turned into a reassuring default.

Where Verihelm contributes

Verihelm port assessments can include ISPS or MARSEC information where it is available, together with relevant incidents, local context and the risks around the port call. The assessment shows its status and review information so customers can see what was known and when it was checked.

To examine the wider conditions around a port call, see Beyond the Pin: Verihelm Port Intelligence.

Information is blended across multiple sources, with Dryad Global’s intelligence team applying judgement where reporting is unclear or the consequence could be significant. Completed assessments pass through internal quality control and carry a visible approval status. They can also be downloaded as structured PDF reports for use across the vessel and shore organisation.

Verihelm is not the authority that sets the security level, and the assessment does not replace official port instructions, the Ship Security Plan, the Port Facility Security Plan or the professional judgement of the Master and security officers.

The level tells the ship and port which security posture applies. The assessment helps the customer understand what the change could mean for the call.

This article provides general information and analysis. It is not legal, regulatory, port-entry or vessel-specific operational advice. Confirm the current level and instructions through the competent authority, port and company security channels before relying on them.

New Channel 16 analysis by email

Receive new analysis when it is published.

See the risk behind the headline.

Verihelm brings incidents, assessments, actors and threat areas together so you can understand what is changing, what it could disrupt and where you still have choices.