Home / Resources / USCG cyber rule readiness checklist
33 CFR 101 Subpart F · Readiness checklist
Coast Guard cyber rule readiness checklist
Fifteen checks for the Facility Security Officer, the Vessel Security Officer, and the Cybersecurity Officer (CySO). Training was due Jan. 12, 2026. The CySO designation, the Cybersecurity Assessment, and the Cybersecurity Plan are due July 16, 2027. Each check carries its CFR cite so the team can go straight to the rule text.
The fifteen checks
Work through them with the FSO or VSO and the CySO. Any check that is not a clear yes is a finding to plan around before July 16, 2027.
Scope
- Each facility, OCS facility, and U.S.-flagged vessel with a security plan under 33 CFR 104, 105, or 106 is listed. 33 CFR 101.605; 104.105, 105.105, 106.105
- Owner or operator is clear for leased docks and terminals. 33 CFR 101.620(a); 90 FR 6310
- Critical IT and OT systems are named for each one. 33 CFR 101.615
People
- A CySO (and alternate) is designated in writing, by name and title, with 24x7 contact. 33 CFR 101.620(b)(3); 101.625
- Jan. 12, 2026 training is complete and recorded, including contractors. 33 CFR 101.650(d)(4)
- New hires and new-system users are trained within 5 days of access. 33 CFR 101.650(d)(4)
Assessment and Plan
- The Cybersecurity Assessment is scheduled with enough time to fix findings before July 16, 2027. 33 CFR 101.650(e)(1); 101.655
- Plan format is chosen: in the FSP or VSP, an annex, or a separate submission. 33 CFR 101.630(a)
- The Plan is handled as Sensitive Security Information. 33 CFR 101.630(b); 49 CFR 1520
Controls
- MFA is on remotely accessible OT, or compensating controls are documented. 33 CFR 101.650(a)(4)
- IT and OT are segmented and every IT to OT connection is logged and monitored. 33 CFR 101.650(h)
- Inventory, network map, and OT configuration records are current. 33 CFR 101.650(b)
Response
- The Cyber Incident Response Plan names roles and decision makers. 33 CFR 101.650(g)(2)
- Staff know how to report to the National Response Center without delay. 33 CFR 101.650(g)(1)
- Drills (twice a year) and an exercise (once a year) are on the calendar. 33 CFR 101.635
Readiness checklist (PDF)
The same fifteen checks on one page, with the CFR cite next to each, for the FSO and CySO to work through.
Summary only, not legal advice; the eCFR text governs. Status as of Oct. 4, 2026: no Federal Register document adopting the proposed delay for U.S.-flagged vessels.
Where Red Tiger fits
Red Tiger does the plant-safe Cybersecurity Assessment on the live terminal and control systems, helps the CySO write the Plan from what the assessment actually found, and fixes the immediate need. The facility keeps the CySO role and files with the Coast Guard.
The assessment is passive on live OT. Nothing on the terminal or the vessel has to go down for it. For more on scope, deadlines, and what the Plan has to cover, see the USCG Regulated Sector page. Refinery and petrochemical docks are covered on Oil & Gas, and fleets on Cruise Lines and Maritime.