NewMeet the Virtual Facility: your terminal, live in real time.See it in action
Logo Stowlog
ISPS & Maritime Compliance

MARSEC Levels Explained: Operating at Security Levels 1, 2 and 3

The three ISPS security levels decide which protective measures a port facility applies, and how fast. Here is what each level means in practice.

Security fence with razor wire at a port facility

Maritime security operates on a deceptively simple principle: a port facility must be able to adjust its protective posture to match the threat it faces. The International Ship and Port Facility Security (ISPS) Code, adopted under chapter XI-2 of the SOLAS Convention and administered by the International Maritime Organization (IMO), gives that principle a structure. It defines three security levels, and every port facility within scope of the Code must be able to operate at each of them.

For a Port Facility Security Officer (PFSO), the MARSEC level is not an abstract designation. It dictates how many access points stay open, how vehicles and persons are screened, how often patrols run, and how restricted areas are controlled. Understanding the levels, and more importantly the movement between them, is fundamental to the role. This article explains where the three security levels come from, who sets and communicates them, what the Port Facility Security Plan (PFSP) must specify for each, and how to manage the transitions that cause most operational friction.

Where the security levels come from in the ISPS Code

The ISPS Code entered into force in 2004 as the maritime industry's structured response to the need for a consistent, risk-based security regime across ships and port facilities. Part A of the Code is mandatory; Part B contains guidance. Together they establish that security is managed through a graduated system of three levels, applied uniformly so that a ship and a port facility interacting with one another share a common understanding of the prevailing threat.

The three security levels are defined in the Code as follows:

  • Security Level 1: the level at which minimum appropriate protective security measures are maintained at all times.
  • Security Level 2: the level at which appropriate additional protective security measures are maintained for a period of time as a result of a heightened risk of a security incident.
  • Security Level 3: the level at which further specific protective security measures are maintained for a limited period of time when a security incident is probable or imminent, although it may not be possible to identify the specific target.

Two ideas are built into these definitions and worth holding onto. First, the levels are cumulative. Level 2 measures are applied in addition to Level 1, and Level 3 in addition to both. A facility does not switch off its baseline when it escalates. Second, Levels 2 and 3 are explicitly time-bound. They describe a temporary posture, not a new normal. Level 3 in particular is reserved for situations where an incident is probable or imminent, and is expected to be invoked rarely and for the shortest period necessary.

The Code also makes clear that the security level is a description of threat, not a prescription of every action. The detailed actions belong in the facility's own documentation, which is where the PFSP enters the picture.

Who sets the security level and who communicates it

A recurring point of confusion is the question of who decides the MARSEC level. The answer in the ISPS Code is unambiguous: the security level is set by the Contracting Government. A PFSO does not select the level. A facility operator does not select the level. The decision rests with the national authority, which assesses threat information available to it and determines the applicable level for ships and port facilities under its jurisdiction.

In practice, national administrations have built the communication mechanisms that carry that decision down to the facility. The terminology and the channels vary by jurisdiction, but the structure is consistent:

  • In the United States, the Coast Guard administers the regime and uses the term MARSEC Level, communicated through maritime security directives and broadcast notices.
  • In the European Union, Regulation (EC) No 725/2004 incorporates the ISPS Code into Union law, and member states designate competent authorities responsible for setting and communicating security levels nationally.
  • In the United Kingdom, the Department for Transport acts as the designated authority and communicates security levels to port facilities through its established channels.

Whatever the national label, the chain is the same: the Contracting Government determines the level, the designated or competent authority communicates it to port facilities (and to ships flying its flag or operating in its waters), and the PFSO is responsible for ensuring the facility implements the corresponding measures. The PFSO is the point at which national direction becomes operational reality. For a fuller treatment of where this responsibility sits, see our guide on the PFSO role and responsibilities at a port facility.

It is also worth noting that a facility can face a security level set higher than the surrounding port. If a Contracting Government raises the level for a specific facility, or a ship arrives operating at a higher level than the facility, the higher of the two levels generally governs the interaction. This is one of the situations the Declaration of Security exists to resolve, covered later in this article.

What the Port Facility Security Plan must specify for each level

The ISPS Code requires every port facility within scope to have an approved Port Facility Security Plan, developed on the basis of a Port Facility Security Assessment. The PFSP is the operational backbone of the facility's security regime, and the Code is specific that it must address measures for all three security levels.

In other words, the PFSP cannot describe only how the facility operates day to day. It must set out, in advance and in approved form, what changes when the level rises to 2 and what changes again at Level 3. When an authority communicates a level change, the PFSO is not improvising. The PFSO is activating a pre-approved set of measures already documented, rehearsed, and resourced.

For each security level, a PFSP typically specifies measures across a consistent set of functional areas:

  • Access control to the port facility, including the number and management of access points, identification checks, and credentialing.
  • Restricted areas within the facility, their designation and the controls applied to them.
  • Handling of cargo, including measures to detect tampering and to verify that cargo accepted into the facility matches documentation.
  • Delivery of ship's stores and bunkers.
  • Monitoring and surveillance of the facility, its access points, restricted areas, and the areas surrounding it.
  • Screening and searching of persons, baggage, vehicles, and unaccompanied items.

The PFSP also identifies the PFSO and the means by which the facility will communicate with authorities, ships, and the Company Security Officer. Crucially, it specifies the procedures for responding to a change in security level, including escalation, de-escalation, and the activities that must continue regardless of level. A plan that lists Level 2 measures but does not say how to reach them is incomplete.

Because the PFSP is approved by, or on behalf of, the Contracting Government, changes to it follow a formal process. This is one reason the planning work matters: the time to decide what a Level 2 access regime looks like is during plan development, not during an active escalation. For the audit dimension of this, see preparing for an ISPS audit: a port facility checklist.

Security Level 1: normal operations and baseline measures

Security Level 1 is the default. It is the level at which a compliant port facility operates the overwhelming majority of the time, and it is the foundation on which Levels 2 and 3 are built. The objective at Level 1 is to maintain minimum appropriate protective measures at all times, in a manner that is sustainable indefinitely without exhausting personnel or resources.

Concrete Level 1 measures across the core functional areas typically include the following.

Access control at Level 1

  • A defined and limited set of active access points, each staffed or controlled.
  • Verification of the identity of persons seeking entry, and confirmation of their reason for being at the facility.
  • Checking of credentials for facility personnel, contractors, visitors, port workers, and ship's crew.
  • Control and logging of vehicle access.

Restricted areas at Level 1

Restricted areas are designated portions of the facility where access is limited to authorized persons. At Level 1 the facility maintains clear demarcation, signage, and controls so that only those with a legitimate need enter. The principles of designating and controlling these zones are covered in detail in restricted areas and access control under the ISPS Code.

Monitoring, searching, and patrols at Level 1

  • Routine monitoring of the facility, including access points and restricted areas, by personnel, lighting, and surveillance equipment as set out in the PFSP.
  • A defined proportion of persons, vehicles, and items subject to search, applied consistently.
  • Routine security patrols at intervals established by the plan.
  • Standard procedures for the handling of cargo and ship's stores, including documentation checks.

The defining characteristic of Level 1 is sustainability. Every measure is calibrated to run continuously. This matters because it sets the baseline from which escalation is measured. If Level 1 measures are already being applied inconsistently, a move to Level 2 will not deliver the intended increase in protection.

See how Stowlog handles this on a live facility

Book a focused 30-minute consultation, mapped to your terminal's workflows.

Book a consultation

Security Level 2: heightened measures for increased risk

Security Level 2 applies when a Contracting Government determines that the risk of a security incident has increased. It is a heightened posture, maintained for a period of time, and it requires the facility to apply additional protective measures on top of everything already in place at Level 1.

The PFSP specifies what those additional measures are. While the exact content is facility-specific, Level 2 measures generally intensify the same functions managed at Level 1.

Access control at Level 2

  • Reducing the number of active access points and more tightly controlling those that remain.
  • Increasing the frequency and detail of identity and credential checks.
  • Escorting or supervising waterside access.
  • Limiting or denying access to visitors who cannot provide a verified reason for entry.

Restricted areas and searches at Level 2

  • Increasing the proportion of persons, vehicles, baggage, and unaccompanied items searched.
  • Expanding or more tightly controlling restricted areas, and increasing the supervision applied to them.
  • Increasing scrutiny of cargo, ship's stores, and deliveries, including more frequent verification against documentation.

Monitoring and patrols at Level 2

  • Increasing the frequency, coverage, and duration of patrols.
  • Assigning additional security personnel.
  • Increasing the intensity and continuity of monitoring and surveillance.
  • Coordinating more closely with ships at the interface and with port authorities.

The operational reality of Level 2 is resource intensity. Heightened measures consume more personnel hours, slow throughput, and add coordination overhead. Because Level 2 is time-bound, the facility must be able to sustain the posture for the duration while continuing to function as a working terminal. A well-built PFSP recognizes this and identifies the resources, including mutual aid or contracted support, needed to hold Level 2 without degradation.

Security Level 3: exceptional measures for a probable or imminent incident

Security Level 3 is exceptional. It is set when a security incident is probable or imminent, even if the specific target cannot be identified, and it is maintained only for the limited period that the threat persists. Operating at Level 3 is not a routine extension of Level 2. It is a response to a credible, immediate danger, and it will frequently involve direct coordination with, or direction from, national authorities and responders.

At Level 3, the facility implements the further specific measures set out in its PFSP, which may include:

  • Restricting access to a single, tightly controlled point, or suspending access altogether.
  • Limiting facility operations to those essential to responding to the incident or threat.
  • Granting access only to those responding to the incident.
  • Suspending cargo operations and the movement of certain vehicles or vessels.
  • Conducting comprehensive searches of the facility, or specific parts of it.
  • Preparing for, or executing, the evacuation of the facility.
  • Directing the positioning or movement of ships and other measures in coordination with authorities.

A defining feature of Level 3 is that the Contracting Government may issue specific instructions that go beyond, or differ from, the measures pre-approved in the PFSP. Because Level 3 responds to a probable or imminent incident, the national authority may direct actions tailored to the particular threat. The PFSO's task at Level 3 is therefore twofold: implement the plan's Level 3 measures and act on the additional direction received, while keeping accurate records of both.

Level 3 also carries a heavy burden on continuity and life safety. Suspending operations, evacuating personnel, and coordinating with emergency services all sit within the PFSO's responsibilities at this level. The plan must address them, and exercises should test them, because Level 3 is precisely the level a facility has the least opportunity to rehearse in live conditions.

The real challenge: transitions between levels

If the three levels are the theory, the transitions are the practice. The hardest part of operating across MARSEC levels is not running steadily at any one of them. It is the move from one to the next, performed under time pressure, often with incomplete information, and the equivalent move back down when the threat recedes.

The escalation process

When a Contracting Government raises the security level, the facility must acknowledge the change and bring the corresponding measures into effect. A sound escalation process addresses, at minimum:

  1. Acknowledgement: confirming receipt of the level change from the communicating authority.
  2. Notification: passing the change to security personnel, facility management, tenants, contractors, ships at the interface, and the Company Security Officer.
  3. Activation: implementing the pre-approved measures for the new level, including opening or closing access points, adjusting search rates, repositioning personnel, and changing patrol patterns.
  4. Confirmation: verifying that the measures are actually in place, not merely instructed, and reporting completion.
  5. Recording: documenting what changed, when, on whose authority, and who carried it out.

The Code expects facilities to be able to respond to a level increase within a defined timeframe. A facility that cannot demonstrate a prompt, orderly, and complete escalation has a compliance gap, regardless of how well it operates at Level 1.

The de-escalation process

De-escalation receives less attention than escalation, and that is a mistake. Returning to a lower level is also a security event. It must be directed by the Contracting Government, communicated through the same chain, and recorded with the same rigor. The PFSO must verify that the facility steps down in a controlled way, that any temporary resources are released appropriately, and that nothing introduced at the higher level, a temporary barrier, a closed gate, an altered route, is left in an inconsistent state. Stepping down without a controlled process can leave the facility in an undocumented posture that is neither fully Level 2 nor cleanly Level 1.

The 24/7 communication chain

Level changes do not observe working hours. A Contracting Government may raise the level overnight, on a weekend, or during a holiday, and the facility must still respond within the expected timeframe. This means the communication chain has to function continuously:

  • A means for the authority to reach the facility at any hour, with verified contact points.
  • A duty PFSO or deputy reachable around the clock, with documented succession if the primary contact is unavailable.
  • An internal cascade that reaches on-shift security personnel, management, and tenants regardless of time.
  • A path to notify ships at the interface and the relevant Company Security Officers.

A communication chain that depends on a single individual or a single channel is fragile. The PFSP should document redundancy, and exercises should test the chain at inconvenient times, because that is when it will be needed.

The Declaration of Security (DoS) is the formal agreement between a ship and a port facility, or between two ships, that records the security measures each will undertake during their interface and the responsibilities of each party. Security levels and the DoS are directly linked.

A DoS is more likely to be required, and a Contracting Government may specifically require one, when the prevailing security level is elevated, or when a ship and a facility are operating at different security levels. The DoS becomes the instrument that resolves a mismatch: it records which measures apply, who is responsible for each, and for how long. The PFSO should know the conditions under which the facility's Contracting Government requires a DoS, and completed Declarations should be retained as part of the facility's security records.

Recording level changes and keeping the audit trail

The ISPS Code requires port facilities to keep records of the security activities addressed in the PFSP, and changes in security level sit squarely within that requirement. Whenever the level changes, the facility should be able to produce a clear, contemporaneous record covering:

  • The level before and after the change.
  • The date and time the change took effect.
  • The authority or instruction that directed the change, and the channel through which it was received.
  • The specific measures activated or stood down.
  • The personnel who implemented them and confirmed completion.
  • Any Declaration of Security raised, and any specific instruction received from the Contracting Government.
  • The de-escalation, recorded with the same detail when the facility returns to a lower level.

These records serve several purposes at once. They demonstrate compliance to auditors and to the Contracting Government. They give the PFSO a defensible account of decisions and actions if an incident is later investigated. And they feed continuous improvement, because reviewing past transitions is how a facility learns where its escalation process is slow or unclear. For the wider context of how level records fit into the inspection regime, see the ISPS Code compliance guide for Port Facility Security Officers.

The practical difficulty is that level changes are exactly the moments when record-keeping is hardest to do well. Personnel are focused on implementing measures, the situation is fluid, and information arrives in fragments. Records reconstructed after the fact from memory and scattered notes are weaker, harder to defend, and slower to produce when an auditor asks for them.

How Stowlog supports operating across MARSEC levels

Stowlog is built for the operational side of port facility security: turning the requirements of the ISPS Code and the PFSP into structured, recorded, repeatable practice. Operating across MARSEC levels is one of the areas where that structure makes a measurable difference.

When a security level changes, Stowlog gives the PFSO a single place to record the transition: the level before and after, the time it took effect, the directing authority, and the measures activated. The escalation becomes a guided sequence rather than an improvised one, with each step acknowledged and timestamped as it is completed, so the facility can show not only that it changed level but how promptly and how completely.

The platform keeps the resulting record complete and retrievable. Level changes, the personnel who implemented them, any Declaration of Security raised, and the corresponding de-escalation are held in one auditable trail, available immediately when a Contracting Government or auditor asks for evidence of how the facility has operated across all three levels. The same record gives the PFSO the raw material to review past transitions and tighten the process over time.

Because the underlying measures, restricted areas, access control, patrols, searches, and monitoring, are managed in the same system, the picture stays consistent as the facility moves up and down the levels. The result is what the ISPS Code ultimately asks for: a facility that can operate at Security Levels 1, 2, and 3, move between them in a controlled way, and prove it.

For more on the regulatory framework behind these requirements, explore our ISPS and maritime compliance resources.

Sources and further reading

Frequently asked questions

How many MARSEC security levels are there under the ISPS Code?

The ISPS Code defines three security levels. Level 1 is normal, Level 2 is heightened, and Level 3 is exceptional. A port facility within scope of the Code must be able to operate at all three.

Who sets the MARSEC security level for a port facility?

The security level is set by the Contracting Government, the national authority responsible for the jurisdiction. The PFSO and the facility operator do not choose the level; they implement the measures that correspond to the level communicated to them.

What is the difference between Security Level 2 and Security Level 3?

Security Level 2 applies when the risk of a security incident has increased, and it adds protective measures for a period of time. Security Level 3 applies when an incident is probable or imminent, and it adds further specific measures for a limited period, often under direct national direction.

Does the Port Facility Security Plan have to address all three security levels?

Yes. The ISPS Code requires the PFSP to specify the protective measures for Security Levels 1, 2, and 3. This means the facility activates pre-approved, documented measures when the level changes rather than improvising.

How quickly must a port facility respond to a security level increase?

A facility must be able to implement the measures for a higher level within the timeframe expected by its Contracting Government and set out in its PFSP. This is why the escalation process and a 24/7 communication chain must be tested in advance, since level changes can arrive at any hour.

How does the Declaration of Security relate to MARSEC levels?

The Declaration of Security records the security measures a ship and a port facility will each undertake during their interface. It is more likely to be required when the security level is elevated or when a ship and facility are operating at different levels, since it resolves which measures apply and who is responsible.

Does a port facility apply Level 1 measures when it is at Level 2 or 3?

Yes. The security levels are cumulative. Level 2 measures are applied in addition to Level 1, and Level 3 measures in addition to both, so the baseline protection is never switched off when the facility escalates.

What records should a facility keep when the security level changes?

The facility should record the level before and after the change, the date and time it took effect, the directing authority, the measures activated or stood down, the personnel who carried them out, and any Declaration of Security raised. The de-escalation back to a lower level should be recorded with the same detail.

Can a port facility be at a higher security level than the rest of the port?

Yes. A Contracting Government can set a higher level for a specific facility, and a ship may arrive operating at a higher level than the facility. In an interface, the higher of the two levels generally governs, and a Declaration of Security is often used to record how the mismatch is managed.

From the blog

Latest articles

View all articles