Home / Industries / USCG Regulated Sector

MTSA facilities · U.S.-flagged vessels · OCS facilities · 33 CFR 101 Subpart F

Your Coast Guard Cybersecurity Plan is due July 16, 2027. Find out now where you stand.

Under ten months to the July 16, 2027 deadline

Ports and terminals, LNG and petrochemical docks, offshore oil and gas facilities, ferries, cruise terminals, and U.S.-flagged vessels now have a cyber rule of their own. By July 16, 2027 each one needs a Cybersecurity Officer, a Cybersecurity Assessment, and a Cybersecurity Plan submitted to the Coast Guard. Red Tiger Security does the plant-safe Cybersecurity Assessment on the live terminal and control systems, helps your CySO write the Plan from what the assessment actually found, and fixes the immediate need. You keep the CySO role and file with the Coast Guard.

Get your Cyber Plan readiness review

A call with the Red Tiger team on where your facility or vessel stands against Subpart F, what is due by July 16, 2027, and what the Cybersecurity Assessment has to cover.

No cost to ask. Red Tiger Security will reply by email to set up the call.

Patrol vessel alongside a container terminal with ship-to-shore cranes
July 16, 2025Rule effective. Reportable cyber incidents go to the National Response Center. [4]
Jan. 12, 2026Training due for all personnel with IT or OT access, then annually. [3]
July 16, 2027CySO designated, Cybersecurity Assessment done, Cybersecurity Plan submitted for approval. [4,3]
5 yearsPlan approval period. A penetration test comes with each Plan renewal. [3]

Who the rule covers

The gate is the security plan the site already has. Subpart F applies to owners and operators of U.S.-flagged vessels, facilities, and OCS facilities required to have a security plan under 33 CFR parts 104, 105, or 106. A waterfront location by itself does not trigger it. [3]

33 CFR 105 · FSP

MTSA facilities

Ports and container terminals; oil and hazardous-material transfer facilities under part 154 (refinery and petrochemical docks); LNG and liquefied hazardous gas terminals under part 127; dangerous-cargo facilities under part 126; cruise and ferry terminals that receive vessels certificated for more than 150 passengers; terminals receiving foreign or U.S. cargo vessels over 100 gross register tons; and certain barge fleeting facilities. [7]

33 CFR 104 · VSP

U.S.-flagged vessels

Vessels that must carry a Vessel Security Plan: SOLAS cargo and passenger vessels and MODUs, self-propelled U.S. cargo vessels over 100 gross register tons, tankships, passenger vessels certificated for more than 150 passengers (including large ferries), certain barges, and towing vessels over eight meters towing regulated barges. Foreign-flagged vessels are excluded from Subpart F. [6,3]

33 CFR 106 · OCS FSP

Outer Continental Shelf facilities

Fixed and floating oil, gas, and mineral facilities on the OCS that host more than 150 people for 12 hours a day for 30 days or more, or produce more than 100,000 barrels of oil or 200 million cubic feet of gas a day. OCS facilities report cyber incidents to the NRC under Subpart F. [8,1]

Marine terminal with storage tanks, a loading dock, and pipe manifold valves
Tank farm, dock, and manifold. The dock PLCs, loading arms, and tank gauging are OT the Assessment has to cover.

How the rule got here, and what is due when

Dates are from the Federal Register, the eCFR, and the Coast Guard's implementation timeline. [12,11,13,1,4]

Feb 26, 2020NVIC 01-20cyber in FSA / FSPFeb 21, 2024EO 14116COTP cyber authorityFeb 22, 2024Proposed rule89 FR 13404Jan 17, 2025Final rule90 FR 6298Mar 18, 2025Comments dueon vessel delayJul 16, 2025Rule effectiveNRC reporting startsJan 12, 2026Training duethen annuallyJul 16, 2027CySO, Assessment,Plan submittedPlan renewalPen testPlan valid 5 years
Solid accent line: the window the rule is in now. Dashed: Plan renewal and the penetration test, five years after approval.

Status of the proposed delay for U.S.-flagged vessels (as of Oct. 4, 2026): the Coast Guard asked for comments, due March 18, 2025, on a possible 2 to 5 year delay of the implementation periods for U.S.-flagged vessels only. The Federal Register docket USCG-2022-0802 lists only the 2024 proposed rule, its comment extension, and the January 2025 final rule; no document adopting the delay has been published. The eCFR still sets July 16, 2027 for the Assessment and the Plan. Facilities and OCS facilities were never part of the proposed delay. [1,14,3,15]

What Subpart F asks for

The owner or operator is responsible for compliance (§ 101.620(a)). This is the short version; the eCFR text governs. [3]

33 CFR 101.620(b)(3), 101.625

Cybersecurity Officer (CySO)

Designated in writing, by name and title, reachable by the Coast Guard 24 hours a day. May also serve as FSO, VSO, or CSO, and may cover more than one facility or vessel if each Plan lists them.

33 CFR 101.650(e)(1)

Cybersecurity Assessment

Analyze all networks for vulnerabilities to critical IT and OT systems, validate the Plan, document recommendations in the VSA, FSA, or OCS FSA, and patch or compensate for known exploited vulnerabilities without delay. Due by July 16, 2027, then annually, and sooner on a change of ownership.

33 CFR 101.630, 101.655

Cybersecurity Plan

Fourteen required sections, from organization and training through monitoring, unresolved vulnerabilities, and incident reporting. Can sit inside the FSP or VSP, as an annex, or as a separate submission. Submitted to the COTP or OCMI (facilities) or the Marine Safety Center (vessels) by July 16, 2027; valid five years. Sensitive Security Information.

33 CFR 101.650(d)

Training

All personnel with access to IT or OT, including contractors, by Jan. 12, 2026 and annually after that: threat recognition, techniques used to get around controls, how to report to the CySO, and OT-specific training for anyone whose duties include OT. Key personnel get incident roles on top. Plan-specific training within 60 days of Plan approval.

33 CFR 101.620(b)(7), 101.650(g)(1)

Incident reporting

Reportable cyber incidents go to the National Response Center without delay, in force since July 16, 2025. Waterfront facilities and vessels also report under 33 CFR 6.16-1 to the FBI, CISA, and the COTP.

33 CFR 101.635

Drills and exercises

Cyber drills at least twice each calendar year. An exercise at least once each calendar year, no more than 18 months apart, with substantial and active participation of the CySO. Tabletop, live, combined, or port-wide all count.

33 CFR 101.650(a)

Account security and MFA

Lockout after failed logins, default passwords changed, minimum password strength, multifactor authentication on password-protected IT and remotely accessible OT, least privilege, separate credentials on critical systems, and access removed when people leave.

33 CFR 101.650(b), (c)

Device and data security

Approved hardware and software list, an accurate inventory of network-connected systems with critical IT and OT designated, a network map and OT configuration records, protected logs, and encryption where it is technically feasible.

33 CFR 101.650(h)

Network segmentation

Segmentation between IT and OT networks, and every IT to OT connection logged and monitored for suspicious activity, breaches, and cyber incidents.

33 CFR 101.650(f)

Supply chain and third parties

Cyber capability considered in IT and OT procurement, vendors required to report vulnerabilities and incidents without delay, and third-party remote connections monitored and documented.

33 CFR 101.620(b)(6), 101.650(g)

Resilience and incident response plan

A Cyber Incident Response Plan that is developed, exercised, and maintained, periodic validation of the Plan, and tested backups of critical IT and OT.

33 CFR 101.650(e)(2), 101.630(f)

Penetration testing and audits

A penetration test in conjunction with Plan renewal, with a certifying letter and the findings in the security assessment. An annual Plan audit by people without regularly assigned cyber duties for that facility or vessel.

Not sure you will be ready by July 16, 2027?

Get a Cyber Plan readiness review. The Red Tiger team will go over your scope, your gaps, and what the Assessment and the Plan need, with your FSO or CySO on the call.

FSA, FSP, NVIC 01-20, MARSEC, and Executive Order 14116

FSA and FSP. The cyber work does not start a second security program. Assessment recommendations are documented in the existing VSA, FSA, or OCS FSA, and the Cybersecurity Plan can live inside the FSP or VSP, as an annex, or as a separate submission. The penetration test letter also goes into the security assessment. [3]

NVIC 01-20. Since 2020, NVIC 01-20 asked MTSA facilities to assess cyber vulnerabilities in the FSA and address them in the FSP. The Coast Guard said the final rule supersedes NVIC 01-20 as of July 16, 2025; its principles can still inform compliance. Many facilities already have a cyber annex from that work. It is a starting point. [12,1]

MARSEC levels. MARSEC Levels 1 to 3 are set by the Coast Guard under 33 CFR 101 Subpart C, and the FSP already spells out what changes at each level. Subpart F does not add a separate cyber measure for each MARSEC level. It does require the CySO to have a way to tell personnel about changes in cybersecurity conditions, which should line up with how the FSP handles a MARSEC change. [9,3]

Executive Order 14116. Signed Feb. 21, 2024, it amended 33 CFR part 6 so the Captain of the Port can act on cyber threats to vessels, harbors, ports, and waterfront facilities, and it made actual or threatened cyber incidents reportable to the FBI, CISA, and the COTP under § 6.16-1. Under Coast Guard guidance, a report to the NRC is shared with CISA and the FBI. [11,10,1]

CISA, NIST, and IEC 62443. The technical requirements were benchmarked on CISA's Cybersecurity Performance Goals, which are informed by the NIST CSF. IEC 62443 is not incorporated by reference, but zones and conduits remain the clearest way to design the segmentation the rule asks for. [1,18,19,20]

Each requirement, and where Red Tiger fits

Red Tiger does the work and writes the documents your CySO can adopt. You designate the CySO, sign, and submit. The Coast Guard approves.

RequirementDeadlineWhat stays with the ownerHow Red Tiger helps
CySO designationJuly 16, 2027 (USCG timeline)Owner designates a named person. Red Tiger does not serve as the CySO.CySO advisory: role description, duty list, and coaching through the Assessment and Plan.
Cybersecurity AssessmentJuly 16, 2027, then annuallyOwner or CySO ensures it is completed.Plant-safe OT assessment (CVA) of the terminal, dock, and control systems, passive on live OT, mapped to the § 101.650(e)(1) content and the FSA.
Cybersecurity PlanSubmitted by July 16, 2027Owner submits to the COTP, OCMI, or MSC.Plan and policy writing support (compliance, standards and framework consulting): the fourteen sections drafted from the assessment findings for the CySO to adopt and sign.
Account security, MFA, device securityIn the PlanOwner implements and documents.Remediation of the immediate need: MFA and secure remote access for OEMs and integrators, hardening, asset inventory and network map.
IT/OT segmentation and monitored connectionsIn the PlanOwner implements and documents.IT/OT network architecture review and IEC 62443 zone design; plant firewall and sensor where the finding calls for it.
Monitoring of IT to OT and third-party connectionsIn the PlanOwner ensures monitoring.24x7 MSP + Metrics and Reports on the assets just assessed. Cadence as agreed with the operator.
Cyber Incident Response Plan and NRC reportingReporting in force since July 16, 2025Owner reports without delay.Incident response planning (the CIRP and reporting procedure) and an optional IR retainer for surge support.
Drills and exercisesTwice and once each calendar yearCySO participates.Tabletop exercises and drill support with operations, the FSO, and the CySO in the room, built on the assessment findings.
TrainingJan. 12, 2026, then annuallyOwner ensures and records.Training through CambiOS Academy (on-demand OT plus virtual labs), coordinated with site-specific content.
Penetration test at Plan renewalWith renewal (Plan valid 5 years)Owner ensures; letter goes in the FSA.OT / ICS penetration testing, on staging or approved windows only, plus IT testing of the IT to OT path.
Annual Plan auditWithin 1 year of approval, then annuallyAuditor must be independent of the cyber duties audited.Independent audit support from outside the facility's own cyber staff.
Supply chainIn the PlanOwner documents.Vendor and integrator remote-access review and contract language as part of the assessment and roadmap.

Assess, fix the immediate need, then stay

Lined up with the Coast Guard dates.

The door
1

Cybersecurity Assessment

Plant-safe assessment of the terminal, dock, and control systems, from the perimeter as it touches business IT, cloud, and vendor networks down to the field devices. Passive on live OT. Findings written so they drop into the FSA and the Plan.

The plant-safe assessment →
The fix
2

Plan and remediation

Plan and CIRP drafts for the CySO, plus the fixes that close the biggest gaps first: segmentation, MFA on remote access, vendor connections, inventory and network map. Tabletop exercise with the CySO in the room before the Plan goes in.

Fix the immediate need →
The close
3

24x7 MSP + Metrics and Reports

Monitoring of the IT to OT and third-party connections the rule asks the operator to watch, with Metrics and Reports the CySO can use for the annual audit and the next Assessment.

24x7 MSP + Metrics and Reports →

Coast Guard cyber rule readiness checklist

Fifteen checks that show quickly whether a facility or vessel is on track for July 16, 2027.

Scope

  • Each facility, OCS facility, and U.S.-flagged vessel with a security plan under 33 CFR 104, 105, or 106 is listed.
  • Owner or operator is clear for leased docks and terminals.
  • Critical IT and OT systems are named for each one.

People

  • A CySO (and alternate) is designated in writing, by name and title, with 24x7 contact.
  • Jan. 12, 2026 training is complete and recorded, including contractors.
  • New hires and new-system users are trained within 5 days of access.

Assessment and Plan

  • The Cybersecurity Assessment is scheduled with enough time to fix findings before July 16, 2027.
  • Plan format is chosen: in the FSP or VSP, an annex, or a separate submission.
  • The Plan is handled as Sensitive Security Information.

Controls

  • MFA is on remotely accessible OT, or compensating controls are documented.
  • IT and OT are segmented and every IT to OT connection is logged and monitored.
  • Inventory, network map, and OT configuration records are current.

Response

  • The Cyber Incident Response Plan names roles and decision makers.
  • Staff know how to report to the National Response Center without delay.
  • Drills (twice a year) and an exercise (once a year) are on the calendar.
Download

Readiness checklist (PDF)

The same fifteen checks on one page, with the CFR cite next to each, for the FSO and CySO to work through.

Download the checklist (PDF)

Frequently asked questions

Does the rule apply to foreign-flagged vessels?

No. § 101.605(b) says Subpart F does not apply to foreign-flagged vessels subject to 33 CFR part 104. It applies to U.S.-flagged vessels, MTSA facilities, and OCS facilities that must have a security plan under parts 104, 105, or 106. [3]

Was the proposed delay for U.S.-flagged vessels adopted?

Not as of Oct. 4, 2026. With the final rule, the Coast Guard asked for comments, due March 18, 2025, on a possible 2 to 5 year delay of the implementation periods for U.S.-flagged vessels only. The Federal Register docket USCG-2022-0802 shows no later document adopting it, and the eCFR still carries the July 16, 2027 dates. If a delay is published, it will need its own Federal Register notice. [1,14,3]

Can Red Tiger serve as our CySO?

No. The owner or operator designates the CySO in writing, by name and title, and stays responsible for compliance. Red Tiger supports the CySO: the assessment, Plan drafts, remediation, monitoring, tabletop exercises, and coaching. The owner signs and submits.

Does following IEC 62443 or NIST CSF satisfy the rule?

Not by itself. The Coast Guard says the rule is benchmarked on CISA's Cybersecurity Performance Goals, which are informed by NIST CSF, and that owners may use NIST or other frameworks to help inform how they meet the mandatory requirements. Subpart F does not incorporate IEC 62443 by reference. [1,18,19,20]

Is a penetration test required with the first Plan?

No. § 101.650(e)(2) ties the penetration test to Plan renewal. Plans are valid for five years. [3]

The training deadline passed. What now?

Training under § 101.650(d) was due Jan. 12, 2026 and is annual after that. Plan-specific training is due within 60 days of Plan approval; MSIB 04-26 notes it may be deferred until Plan approval or July 16, 2027, whichever is earlier. If staff or contractors are not trained yet, untrained people with system access must be accompanied or monitored by someone who is. [3,16]

What does the rule replace?

The Coast Guard said the final rule supersedes NVIC 01-20 as of the effective date, while owners may still use NVIC 01-20 principles to inform compliance. Existing FSA, FSP, and MARSEC requirements stay in place. [1,12]

Who reviews the Plan?

The Coast Guard. Facilities and OCS facilities submit to the cognizant COTP or OCMI; U.S.-flagged vessels submit to the Marine Safety Center. The preamble says the Coast Guard does not plan to delegate review to third parties. [3,1]

Get your Cyber Plan readiness review

Plant-safe, on the live terminal and control systems, with operations, the FSO, and the CySO in the room. Then the Plan, the fixes, and 24x7 MSP + Metrics and Reports if you want the team to stay.

Under ten months to the July 16, 2027 deadline

Prefer to call? +1.877.387.7733 · info@redtigersecurity.com

Download the readiness checklist (PDF) →

Book your readiness call

First name, work email, and company. That is all it takes.

No cost to ask. Red Tiger Security will reply by email to set up the call.

References

Numbers match the bracketed citations on this page. Sources checked Oct. 4, 2026. This page is a summary, not legal advice; the eCFR text governs.

  1. Federal Register, 90 FR 6298, "Cybersecurity in the Marine Transportation System," final rule, Jan. 17, 2025 (docket USCG-2022-0802). https://www.federalregister.gov/documents/2025/01/17/2025-00708/cybersecurity-in-the-marine-transportation-system
  2. GPO, official PDF of the final rule, 90 FR 6298-6453. https://www.govinfo.gov/content/pkg/FR-2025-01-17/pdf/2025-00708.pdf
  3. eCFR, 33 CFR Part 101 Subpart F, Cybersecurity (§§ 101.600-101.670). https://www.ecfr.gov/current/title-33/chapter-I/subchapter-H/part-101/subpart-F
  4. USCG Maritime Commons, "Final Rule: Cybersecurity in the Marine Transportation System, Implementation Timeline," July 16, 2025. https://www.news.uscg.mil/maritime-commons/Article/4247529/final-rule-cybersecurity-in-the-marine-transportation-system-implementation-tim/
  5. U.S. Coast Guard, Maritime Industry Cybersecurity Resource Website (FAQs, Policy Letters 01-25 and 01-26, small entity guides, job aids). https://www.uscg.mil/MaritimeCyber/
  6. eCFR, 33 CFR Part 104, Maritime Security: Vessels (applicability at § 104.105). https://www.ecfr.gov/current/title-33/chapter-I/subchapter-H/part-104
  7. eCFR, 33 CFR Part 105, Maritime Security: Facilities (applicability at § 105.105). https://www.ecfr.gov/current/title-33/chapter-I/subchapter-H/part-105
  8. eCFR, 33 CFR Part 106, Marine Security: Outer Continental Shelf (OCS) Facilities (applicability at § 106.105). https://www.ecfr.gov/current/title-33/chapter-I/subchapter-H/part-106
  9. eCFR, 33 CFR Part 101 Subpart C, Maritime Security (MARSEC) Levels. https://www.ecfr.gov/current/title-33/chapter-I/subchapter-H/part-101/subpart-C
  10. eCFR, 33 CFR 6.16-1, Reporting of sabotage, subversive activity, or an actual or threatened cyber incident. https://www.ecfr.gov/current/title-33/chapter-I/subchapter-A/part-6/subpart-6.16/section-6.16-1
  11. Federal Register, Executive Order 14116, "Amending Regulations Relating to the Safeguarding of Vessels, Harbors, Ports, and Waterfront Facilities of the United States," signed Feb. 21, 2024, 89 FR 13971 (Feb. 26, 2024). https://www.federalregister.gov/documents/2024/02/26/2024-04012/amending-regulations-relating-to-the-safeguarding-of-vessels-harbors-ports-and-waterfront-facilities
  12. Federal Register, notice of availability, NVIC 01-20, "Guidelines for Addressing Cyber Risks at MTSA Regulated Facilities," Mar. 20, 2020 (NVIC dated Feb. 26, 2020). https://www.federalregister.gov/documents/2020/03/20/2020-05823/navigation-and-vessel-inspection-circular-nvic-01-20-guidelines-for-addressing-cyber-risks-at
  13. Federal Register, notice of proposed rulemaking, 89 FR 13404, Feb. 22, 2024. https://www.federalregister.gov/documents/2024/02/22/2024-03075/cybersecurity-in-the-marine-transportation-system
  14. Regulations.gov, docket USCG-2022-0802. https://www.regulations.gov/docket/USCG-2022-0802
  15. USCG Cyber Regulations Fact Sheet (hosted by UK P&I Club). https://www.ukpandi.com/fileadmin/uploads/ukpandi/Documents/uk-p-i-club/articles/2025/USCG_Cyber_Regulations_Fact_Sheet.pdf
  16. USCG NAVCEN, national Marine Safety Information Bulletins (MSIB 04-26, Aug. 19, 2026). https://navcen.uscg.gov/msib-national
  17. National Response Center. https://nrc.uscg.mil/
  18. CISA, Cross-Sector Cybersecurity Performance Goals. https://www.cisa.gov/cross-sector-cybersecurity-performance-goals
  19. NIST, Cybersecurity Framework. https://www.nist.gov/cyberframework
  20. ISA, ISA/IEC 62443 series of standards. https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.