Cybersecurity in the Marine Transportation System
Published Date: 1/17/2025
Rule
Summary
The Coast Guard is rolling out new cybersecurity rules for U.S. ships and marine facilities to keep them safe from cyberattacks. Starting July 16, 2025, these places must have a Cybersecurity Plan and a dedicated Cybersecurity Officer to spot and handle threats. Ship owners should watch for a possible delay in when these rules kick in, with a chance to share their thoughts by March 18, 2025.
Analyzed Economic Effects
7 provisions identified: 1 benefits, 6 costs, 0 mixed.
Estimated $1.2B Industry and Government Cost
The Coast Guard estimates this final rule will create approximately $1.2 billion in total costs and $138.7 million annualized (2022 dollars, discounted at 2 percent) for industry and Government. The rule is effective July 16, 2025, and the Coast Guard is requesting comments on a possible 2-to-5-year delay for U.S.-flagged vessel implementation, with comments due March 18, 2025.
Must Create Cybersecurity Plans
If you own or operate a U.S.-flagged vessel, a facility, or an Outer Continental Shelf (OCS) facility that must have a security plan, you must develop and maintain a Cybersecurity Plan and a Cyber Incident Response Plan. The rule is effective July 16, 2025, and Cybersecurity Plans must be submitted to the Coast Guard for review and approval within 24 months of that date (by July 16, 2027).
Designate a Cybersecurity Officer
Owners or operators must designate a Cybersecurity Officer (CySO) to ensure the Cybersecurity Plan and Cyber Incident Response Plan are implemented. The CySO must keep the plan current, arrange cybersecurity inspections, ensure personnel training, perform an annual audit, and record and report cyber incidents.
Cyber Assessments and Penetration Testing
Owners or operators must conduct a cyber assessment within 24 months of the rule's effective date and must complete penetration testing when renewing a Cybersecurity Plan; the CySO must submit a letter verifying the test and list vulnerabilities found. For critical IT and OT systems, owners must patch or implement documented compensating controls for known exploited vulnerabilities (KEVs) without delay.
Two Cybersecurity Drills Per Year
The rule requires two cybersecurity drills every 12 months (revising a prior quarterly phrasing). This becomes effective July 16, 2025 and must follow applicable drill rules in 33 CFR 104.230, 105.220, or 106.225 as appropriate.
New Incident Reporting Rules
Entities not subject to 33 CFR 6.16-1 must report reportable cyber incidents to the National Response Center (NRC) without delay. A "reportable cyber incident" is defined to include events that cause substantial loss of confidentiality, integrity, or availability; major operational disruption; large disclosure of non-public personal information; or incidents that may lead to a transportation security incident.
Waivers, Equivalents, and Temporary Deviations
After completing a Cybersecurity Assessment, an owner or operator may seek a waiver or an equivalence determination for subpart F requirements consistent with waiver and equivalence procedures in 33 CFR parts 104, 105, and 106. Owners must notify the Coast Guard when they must temporarily deviate from requirements rather than when they are simply unable to meet them.
Personalized for You
How does this regulation affect your finances?
Personalize government policy and PRIA will tell you what this federal register document means for your household, plus every other regulation we track. PRIA reads each provision against your financial profile to show you exactly what matters to your wallet.
Key Dates
Related Federal Register Documents
2026-17116, Modifications to the Regulations Implementing the Vietnam Era Veterans' Readjustment Assistance Act of 1974, as Amended
The U.S. Department of Labor publishes this final rule to revise its implementing regulations for the Vietnam Era Veterans' Readjustment Assistance Act of 1974, as amended (VEVRAA). These revisions will align the regulations with Executive Order 14173 and remove the VEVRAA regulations' cross-references to the Executive Order 11246 authority. Executive Order 11246 was revoked by Executive Order 14173 on January 21, 2025. This final rule also makes technical revisions to update the VEVRAA regulations' jurisdictional thresholds, which were adjusted for inflation by the Federal Acquisition Regulation Council on October 1, 2025.
2026-17115, Modifications to the Regulations Implementing Section 503 of the Rehabilitation Act of 1973, as Amended
The U.S. Department of Labor is revising its implementing regulations for Section 503 of the Rehabilitation Act of 1973, as amended (Section 503). The revisions align the regulations with applicable law and recent executive orders, including Executive Order 14173, "Ending Illegal Discrimination and Restoring Merit-Based Opportunity," and Executive Order 14219, "Ensuring Lawful Governance and Implementing the President's `Department of Government Efficiency' Deregulatory Initiative."
2026-17114, Rescission of Executive Order 11246 Implementing Regulations
On January 21, 2025, President Trump issued Executive Order 14173, "Ending Illegal Discrimination and Restoring Merit-Based Opportunity," which revoked Executive Order 11246. Accordingly, the U.S. Department of Labor publishes this final rule to rescind the implementing regulations for Executive Order 11246.
2026-17088, Carboxin; Pesticide Tolerances
This regulation establishes tolerances for residues of carboxin in or on multiple crops that are discussed later in this document. Under the Federal Food, Drug, and Cosmetic Act (FFDCA), UPL Delaware Inc. submitted a petition to EPA requesting that EPA establish a maximum permissible level for residues of this pesticide in or on the identified commodities.
2026-17120, Fisheries of the South Atlantic; 2026 Commercial Closure of Red Snapper in the South Atlantic
NMFS implements an accountability measure for red snapper in the exclusive economic zone (EEZ) of the South Atlantic. NMFS projects that commercial landings of red snapper will reach the commercial annual catch limit (ACL) for the 2026 fishing year. Therefore, NMFS is closing the commercial sector for red snapper in the South Atlantic EEZ. This closure is necessary to protect the red snapper resource.
2026-17113, Fisheries of the South Atlantic; Commercial Closure for Blueline Tilefish in the South Atlantic
NMFS implements an accountability measure for the commercial harvest of blueline tilefish in the exclusive economic zone (EEZ) of the South Atlantic. NMFS estimates that commercial landings of blueline tilefish will reach the commercial annual catch limit (ACL) for the 2026 fishing year. Accordingly, NMFS closes the commercial sector of blueline tilefish in the South Atlantic EEZ to protect the blueline tilefish resource from overfishing.
Previous / Next Documents
Previous: 2025-00703, Procedural Rules
The Federal Mine Safety and Health Review Commission updated its procedural rules to make mine safety cases faster, fairer, and less costly. These changes affect anyone involved in mine safety legal cases and take effect on March 3, 2025. You can still send your comments until February 18, 2025, so don’t miss your chance to weigh in!
Next: 2025-00721, Defense Federal Acquisition Regulation Supplement: Definition of Material Weakness (DFARS Case 2021-D006)
Starting January 17, 2025, the Department of Defense is updating its rules to replace the term “significant deficiency” with “material weakness” when checking contractor business systems. This change affects contractors working with the DoD and helps make evaluations clearer and more consistent. No big cost changes are expected, but contractors should get ready for the new wording in their audits and reports.