EXPLORATION
Maritime Cyber Resilience Brief ② — U.S. Coast Guard Cybersecurity Rule
Part 2 — U.S. Coast Guard 2025 Cybersecurity Rule: Scope, Compliance Path, and Technical Controls

Part 2 — U.S. Coast Guard 2025 Cybersecurity Rule: Scope, Compliance Path, and Technical Controls
In July 2025, the United States Coast Guard’s groundbreaking “Cybersecurity in the Marine Transportation System” rule came into effect, marking the first mandatory federal cybersecurity standards for the U.S. maritime sector. This rule, codified at 33 CFR Part 101 Subpart F, extends the Maritime Transportation Security Act (MTSA) framework into the cyber domain.It introduces enforceable cybersecurity requirements for a broad range of maritime stakeholders — including U.S.-flagged vessels, vessels on the U.S. Outer Continental Shelf (e.g. offshore rigs/platforms), and MTSA-regulated facilities such as ports, terminals, and refineries. In essence, any vessel or facility already required to have a security plan under 33 CFR Parts 104–106 must now address cyber risks within that plan. The rule arrives in response to escalating cyber threats to maritime operations and aims to enhance the resilience of the Marine Transportation System (MTS) as a whole. Below we analyze the rule’s scope and structure, the phased compliance timeline, key technical and organizational controls required, and how the Coast Guard will enforce these new standards through plan approvals and inspections.
Scope and Structure of the USCG Maritime Cybersecurity Rule
Who is covered: The USCG rule has a wide reach. It explicitly covers U.S.-flag vessels (commercial vessels subject to MTSA, such as cargo ships, tankers, passenger vessels), Outer Continental Shelf (OCS) facilities (like offshore oil/gas platforms under U.S. jurisdiction), and MTSA-regulated shore facilities (major ports, marine terminals, certain industrial facilities by the water) These are essentially the “critical infrastructure owners and operators” of the maritime domain. Entities in these categories are termed “covered entities” in the rule. Notably, foreign-flag vessels are not directly required to have a USCG-approved cyber plan; however, their cyber preparedness will be examined during Port State Control using existing IMO cyber guidelines and USCG’s own inspection procedures. So even foreign ships visiting U.S. ports face indirect scrutiny. By focusing on MTSA-regulated entities, the rule brings cybersecurity into the same regime as physical security — leveraging the existing requirement for Vessel Security Plans (VSPs) or Facility Security Plans (FSPs). The Coast Guard has integrated cyber into these frameworks, guided by updated Navigation and Vessel Inspection Circulars (NVICs) For instance, NVIC 02–24 (2024) provides direction on incorporating cyber risk management into VSPs/FSPs, complementing earlier guidance (NVIC 05–17)
Structurally, the rule is performance-based rather than overly prescriptive. This means it sets forth objectives and minimum outcomes (e.g. “implement network segmentation to protect critical systems”) but allows operators flexibility in how to achieve them. The Coast Guard intentionally avoided a one-size technical checklist; instead, each covered organization must assess its own systems and implement appropriate measures, subject to USCG review and approval. The rule is organized around major requirements: developing a Cybersecurity Plan (and an Incident Response Plan), designating a Cybersecurity Officer, conducting cyber risk assessments, training personnel, and reporting incidents. It aligns with the lifecycle approach by requiring continuous evaluation and updates (e.g. annual drills, periodic reassessment). Importantly, the rule’s language was crafted to harmonize with existing definitions of security incidents and avoid conflicts with other laws, but some complexities remain (for example, the reporting requirements differ slightly from the federal CISA reporting law, leading to potentially overlapping obligations) Overall, this final rule embeds cybersecurity into the day-to-day compliance regime for maritime operators, akin to how physical security and safety management are embedded via ISPS and ISM codes.
Phased Compliance Timeline and Plan Submission
Recognizing the significant effort required to meet the new standards, the Coast Guard has implemented a phased timeline for compliance, stretching out to 2027. Key milestones include:
- July 16, 2025 (Effective Date) — Cyber Incident Reporting begins. From day one of the rule, all covered entities must report certain cyber incidents to the National Response Center (NRC) “without delay.” This immediate requirement was imposed to improve visibility of maritime cyber threats. A “reportable cyber incident” is defined broadly (any incident likely to lead to significant loss of system integrity or loss of ability to operate, safety impacts, large data breaches, or other events that could cause a Transportation Security Incident) In practice, this means if a port facility suffers a ransomware attack that disrupts cargo operations, or a vessel experiences a GPS spoofing event affecting navigation, these must be reported to the NRC immediately. (This NRC report is in addition to any other existing notifications like to local Captain of the Port or to CISA — a point of some confusion that industry commenters have noted)
- By January 12, 2026 (6 months in) — Personnel Training requirements kick in. All personnel with access to the company’s IT or OT systems must complete basic cybersecurity awareness training by this date. This training should cover recognizing and detecting cyber threats, safe practices to avoid introducing risks, and how to report incidents. In addition, key personnel with security duties (for example, the Vessel Security Officer, or facility security staff) must receive role-specific, advanced training on cyber risk management relevant to their duties. After this initial push, training must be conducted annually and for all new hires within 30 days of hiring. The rule does allow training to be delivered in various formats (not necessarily classroom) as long as it meets the content requirements and is documented. Also by early 2026, operators were expected to at least begin developing their Cybersecurity Plans (if not already done), since the rule requires that once a plan is approved it must be fully implemented within 60 days.
- By July 16, 2027 (2 years grace) — Cybersecurity Plan submission and full compliance. This is the major deadline by which each covered owner/operator must designate a qualified Cybersecurity Officer, complete a cybersecurity assessment of their systems, and submit their formal Cybersecurity Plan to the Coast Guard for review and approval. In other words, the rule grants up to two years (from mid-2025 to mid-2027) for entities to do a thorough evaluation of cyber risks in their operations and to develop a comprehensive plan to address those risks. The Cybersecurity Officer (CySO) — which may be an existing employee with added duties, a new hire, or even a contracted role — is responsible for overseeing this process and maintaining the plan. The plan must be submitted to the cognizant Coast Guard office (likely the local Captain of the Port for facilities or the Marine Safety Center or similar for vessels) where it will be reviewed against the regulatory requirements. If deficiencies are found, the Coast Guard can require revisions. Once a plan is approved, the company needs to implement all measures in it within 60 days and keep it updated. Failure to meet the 2027 deadline could result in enforcement actions — vessels could be denied entry to U.S. ports or detained, and facilities could face operations suspensions or civil penalties.
This phased approach underscores the compliance path: immediate incident reporting, rapid attention to training, and methodical development of plans and assessments over a two-year period. It’s worth noting the Coast Guard showed some flexibility for U.S.-flagged vessels — after publishing the final rule, they solicited comments on possibly extending the implementation period for U.S.-flag vessels by 2–5 years. Many industry commenters supported a delay for vessels, citing challenges in retrofitting older ships with new cyber measures. As of mid-2025, no official extension has been announced, so the above timeline remains in force, but the Coast Guard is aware of the concerns.
Key Requirements and Technical Controls under the Rule
The core of the USCG cyber rule is the requirement for each covered entity to establish a robust Cybersecurity Program documented in a Cybersecurity Plan. This plan is analogous to the existing vessel or facility security plan but focused on cyber. It must detail the policies, procedures, and defenses in place to protect the entity’s critical systems from cyber attacks, detect incidents, respond, and recover. Some of the key components mandated include:
- Designation of a Cybersecurity Officer (CySO): Each vessel or facility must appoint a CySO responsible for cyber preparedness. This person’s duties include maintaining the cybersecurity plan, ensuring crew/staff training, coordinating security measures, and managing incident response and recovery efforts. A CySO can cover multiple ships or facilities if appropriate, but their authority and resources must be sufficient for the role. The rule envisions the CySO similar to the role of a Facility Security Officer or Company Security Officer, but specialized in IT/OT security. They need general knowledge of cybersecurity principles, threat trends, regulations, and drills/exercise procedures. The creation of this role elevates cybersecurity leadership within maritime organizations, making it clear who is accountable for compliance.
- Cybersecurity Assessment: Before finalizing the plan, companies must conduct a comprehensive cybersecurity assessment of their systems and operations. This is essentially a risk assessment identifying vulnerabilities, potential attack impacts, and the current state of their network and control system security. The assessment should evaluate both IT and OT systems that could affect maritime operations or safety. For example, an assessment might reveal that a port’s container management system is accessible from the corporate network without proper segmentation, posing a risk of operational disruption — a gap that the plan then needs to address. The rule requires this assessment to be completed and documented by the 2027 deadline, and presumably kept updated thereafter. The findings directly inform what protective measures are needed.
- Cybersecurity Plan — Protective Measures and Policies: The plan must outline the controls to protect critical systems, detect cyber threats, and respond to incidents. While not an exhaustive list, the Coast Guard provided guidance on expected technical controls, which closely mirror industry best practices. These include:
- Network Segmentation: Separating networks to prevent a compromise in one area from spreading. For vessels, this might mean isolating navigation and propulsion control networks from administrative networks. For facilities, it could mean isolating operational control systems from enterprise IT. The rule expects covered entities to implement segmentation as appropriate.
- Access Control and Authentication: This includes implementing multifactor authentication (MFA) for remote or sensitive access, enforcing least privilege for user accounts, and managing user access to systems securely. For example, logging into a cargo handling system might require a second factor if done from an external network.
- Secure Device Configuration & Patching: Entities are expected to maintain an inventory of devices and apply risk-based patch management. High-risk vulnerabilities in critical systems should be patched promptly, or compensating controls applied if patching is not possible. Secure configuration (disabling unused ports/services, changing default passwords) is also implied.
- Backup and Recovery: Regular backups of critical system data and configurations should be performed, and offline storage of backups is encouraged to prevent ransomware from encrypting everything.The plan should detail a backup strategy and ensure that systems can be restored in a timely manner after an incident.
- Continuous Monitoring and Detection: The rule highlights the need for continuous asset visibility and anomaly detection on networks. This suggests that organizations should deploy tools to monitor network traffic and system behavior (like an intrusion detection system or security information and event management software) to catch suspicious activity. Real-time threat detection capabilities are expected, whether via automated systems or managed security services.
- Incident Response Procedures: The plan must include a Cyber Incident Response Plan (somewhat like an annex) detailing how to respond to different cyber scenarios. This includes immediate actions (e.g. isolating affected systems, notifying authorities), investigation steps, recovery steps, and communication protocols. Regular drills and exercises are mandated to test these procedures: at least two cybersecurity drills per year and one full-scale exercise every 18 months to simulate a cyber incident and practice the response.For instance, a drill might involve a mock malware infection on the cargo system to see how staff react and contain it.
- Supply Chain Security: Though not always highlighted in summaries, the rule expects operators to consider third-party and supply chain cybersecurity. This means vetting vendors, requiring secure practices of contractors, and ensuring service providers with remote access (like equipment maintainers) follow strict security controls. For example, if an HVAC technician remotely connects to a cruise ship’s systems, that access must be secured and monitored.
- Training and Awareness: As noted earlier, all personnel must receive basic cybersecurity training (by early 2026, then annually). The plan should describe the training program and content. Additionally, the rule requires cybersecurity drills and exercises as part of the security program, effectively integrating cyber into the existing drill regime that facilities/vessels already do for physical security. Drills can be small-scale (like a table-top scenario or a test of backup systems), whereas exercises are larger simulations involving multiple stakeholders.
- Incident Reporting: The regulation codifies the requirement that significant cyber incidents be reported to the National Response Center (NRC) immediately. The NRC acts as the central point of contact to involve relevant agencies. The rule’s definition of a “reportable cyber incident” is intentionally broad (as mentioned above) to err on the side of reporting. The plan should include procedures for incident reporting — who makes the call, what information to provide, and any parallel notifications (Captain of the Port, FBI, CISA, etc., as required by other regs)The Coast Guard wants timely awareness so they can advise or assist, and to track patterns in threats.
In summary, the USCG cybersecurity rule mandates that maritime operators adopt a holistic cyber risk management program. It blends organizational measures (governance, training, designated officers) with technical measures (segmentation, MFA, monitoring, etc.) to safeguard maritime operations. The rule aligns with broader national security objectives — it supports the National Maritime Cybersecurity Plan’s goals of improving cyber readiness and incident response across the sector.
Inspection and Enforcement Regime
The Coast Guard will enforce these requirements through a combination of plan review/approval and on-site inspections. By July 2027, every covered vessel or facility must submit their Cybersecurity Plan for approval. The review will likely be done by Coast Guard headquarters or district units specialized in security (similar to how they review facility security plans). If a plan meets the requirements (which might include an accompanying letter certifying the plan adheres to 33 CFR 101.630, as hinted in the rule), the Coast Guard will approve it. If not, they will require revisions. A key question raised by industry is whether the Coast Guard might delegate plan review or accept class society (Recognized Organization) approvals as evidence. At this time, the Coast Guard retains authority, but coordination with class isn’t ruled out, especially if class-certified cyber programs (like IACS-based) overlap with the rule’s content.
Once plans are approved and in effect, enforcement will mirror traditional MTSA enforcement:
- Annual/periodic inspections: Coast Guard inspectors (for facilities) and Marine Inspectors or Port State Control officers (for vessels) will verify implementation during their normal inspection cycles. They will likely check records (training logs, drill logs, cybersecurity assessment reports, etc.), interview the CySO or crew about cyber procedures, and potentially observe technical measures. For example, an inspector might verify that backup systems are in place or ask for a demonstration of network segregation (such as showing that an ECDIS on the bridge cannot connect to the internet). They may also review logs or evidence of continuous monitoring as claimed in the plan.
- Enforcement actions: Non-compliance can lead to deficiencies or penalties. A vessel without an approved plan by 2027 could be detained or denied entry to port. A facility that hasn’t trained staff or conducted required drills could face fines or suspension of its operations until issues are fixed. The rule explicitly notes that non-compliance will be treated seriously, as cybersecurity is now deemed a “business-critical function” tied to safety and security.
The Coast Guard has also set up a Cybersecurity Assistance Team and industry resource center. They publish guidance (e.g., a USCG Cybersecurity fact sheet) and maintain a Maritime Cybersecurity Resource Center. This helps operators find tools and best practices to comply. The rule’s performance-based nature means the onus is on companies to show effectiveness. The Coast Guard will expect to see evidence that the implemented measures actually work to safeguard operations. This could even include results from penetration testing or vulnerability assessments, which, while not explicitly mandated, are strongly encouraged as part of the required cybersecurity assessment. In fact, industry experts interpret the rule as effectively requiring penetration testing of critical systems to validate their security — an extension of the idea that you must identify vulnerabilities and test your defenses.
For maritime organizations, the USCG cyber rule represents a seismic shift in regulatory expectations. Cyber risk is no longer a voluntary or secondary concern; it is now baked into legal compliance akin to safety drills and security watches. Shipping companies, port operators, and offshore companies will need to invest in cyber expertise (hiring or training a CySO), upgrade legacy systems (installing firewalls, etc.), and maintain vigilance through monitoring and drills. The benefit, however, is a more resilient maritime infrastructure. The rule aims to create consistency and accountability, addressing what was previously an ad-hoc approach to cyber. It complements international efforts (like IMO’s guidelines) by adding teeth in the form of enforcement. In the next section, we will explore how these USCG requirements align or diverge from the IACS standards discussed in Part 1, and how a unified approach can ease the burden of compliance while enhancing security.