Don’t do SECURITY. Do business SECURELY.

US Coast Guard maritime cybersecurity rule takes effect

New US Coast Guard rules require US-flagged vessels and regulated facilities to appoint cybersecurity officers and report cyber incidents.

The US Coast Guard’s maritime cybersecurity final rule (33 CFR Part 101, Subpart F) takes effect today for US-flagged vessels, Outer Continental Shelf facilities and regulated port facilities.

Key points

  • Reportable cyber incidents must be reported to the National Response Center without delay.
  • Owners and operators must appoint a cybersecurity officer.
  • Cybersecurity assessments and plans are required, with phased deadlines.
  • Training, drills, account security, device and data security, and supply-chain measures are required.

UK shipping, port technology and maritime service providers working with US operators should expect these requirements to shape contracts and assessments.

Source: Cybersecurity in the Marine Transportation System final rule (Federal Register)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights