| CySO designation | July 16, 2027 (USCG timeline) | Owner designates a named person. Red Tiger does not serve as the CySO. | CySO advisory: role description, duty list, and coaching through the Assessment and Plan. |
| Cybersecurity Assessment | July 16, 2027, then annually | Owner or CySO ensures it is completed. | Plant-safe OT assessment (CVA) of the terminal, dock, and control systems, passive on live OT, mapped to the § 101.650(e)(1) content and the FSA. |
| Cybersecurity Plan | Submitted by July 16, 2027 | Owner submits to the COTP, OCMI, or MSC. | Plan and policy writing support (compliance, standards and framework consulting): the fourteen sections drafted from the assessment findings for the CySO to adopt and sign. |
| Account security, MFA, device security | In the Plan | Owner implements and documents. | Remediation of the immediate need: MFA and secure remote access for OEMs and integrators, hardening, asset inventory and network map. |
| IT/OT segmentation and monitored connections | In the Plan | Owner implements and documents. | IT/OT network architecture review and IEC 62443 zone design; plant firewall and sensor where the finding calls for it. |
| Monitoring of IT to OT and third-party connections | In the Plan | Owner ensures monitoring. | 24x7 MSP + Metrics and Reports on the assets just assessed. Cadence as agreed with the operator. |
| Cyber Incident Response Plan and NRC reporting | Reporting in force since July 16, 2025 | Owner reports without delay. | Incident response planning (the CIRP and reporting procedure) and an optional IR retainer for surge support. |
| Drills and exercises | Twice and once each calendar year | CySO participates. | Tabletop exercises and drill support with operations, the FSO, and the CySO in the room, built on the assessment findings. |
| Training | Jan. 12, 2026, then annually | Owner ensures and records. | Training through CambiOS Academy (on-demand OT plus virtual labs), coordinated with site-specific content. |
| Penetration test at Plan renewal | With renewal (Plan valid 5 years) | Owner ensures; letter goes in the FSA. | OT / ICS penetration testing, on staging or approved windows only, plus IT testing of the IT to OT path. |
| Annual Plan audit | Within 1 year of approval, then annually | Auditor must be independent of the cyber duties audited. | Independent audit support from outside the facility's own cyber staff. |
| Supply chain | In the Plan | Owner documents. | Vendor and integrator remote-access review and contract language as part of the assessment and roadmap. |