The US Coast Guard’s maritime cybersecurity final rule (33 CFR Part 101, Subpart F) takes effect today for US-flagged vessels, Outer Continental Shelf facilities and regulated port facilities.
Key points
- Reportable cyber incidents must be reported to the National Response Center without delay.
- Owners and operators must appoint a cybersecurity officer.
- Cybersecurity assessments and plans are required, with phased deadlines.
- Training, drills, account security, device and data security, and supply-chain measures are required.
UK shipping, port technology and maritime service providers working with US operators should expect these requirements to shape contracts and assessments.
Source: Cybersecurity in the Marine Transportation System final rule (Federal Register)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.