Cybersecurity in the Marine Transportation System
Published Date: 1/17/2025
Rule
Summary
The Coast Guard is rolling out new cybersecurity rules for U.S. ships and marine facilities to keep them safe from cyberattacks. Starting July 16, 2025, these places must have a Cybersecurity Plan and a dedicated Cybersecurity Officer to spot and handle threats. Ship owners should watch for a possible delay in when these rules kick in, with a chance to share their thoughts by March 18, 2025.
Analyzed Economic Effects
7 provisions identified: 1 benefits, 6 costs, 0 mixed.
Estimated $1.2B Industry and Government Cost
The Coast Guard estimates this final rule will create approximately $1.2 billion in total costs and $138.7 million annualized (2022 dollars, discounted at 2 percent) for industry and Government. The rule is effective July 16, 2025, and the Coast Guard is requesting comments on a possible 2-to-5-year delay for U.S.-flagged vessel implementation, with comments due March 18, 2025.
Must Create Cybersecurity Plans
If you own or operate a U.S.-flagged vessel, a facility, or an Outer Continental Shelf (OCS) facility that must have a security plan, you must develop and maintain a Cybersecurity Plan and a Cyber Incident Response Plan. The rule is effective July 16, 2025, and Cybersecurity Plans must be submitted to the Coast Guard for review and approval within 24 months of that date (by July 16, 2027).
Designate a Cybersecurity Officer
Owners or operators must designate a Cybersecurity Officer (CySO) to ensure the Cybersecurity Plan and Cyber Incident Response Plan are implemented. The CySO must keep the plan current, arrange cybersecurity inspections, ensure personnel training, perform an annual audit, and record and report cyber incidents.
Cyber Assessments and Penetration Testing
Owners or operators must conduct a cyber assessment within 24 months of the rule's effective date and must complete penetration testing when renewing a Cybersecurity Plan; the CySO must submit a letter verifying the test and list vulnerabilities found. For critical IT and OT systems, owners must patch or implement documented compensating controls for known exploited vulnerabilities (KEVs) without delay.
Two Cybersecurity Drills Per Year
The rule requires two cybersecurity drills every 12 months (revising a prior quarterly phrasing). This becomes effective July 16, 2025 and must follow applicable drill rules in 33 CFR 104.230, 105.220, or 106.225 as appropriate.
New Incident Reporting Rules
Entities not subject to 33 CFR 6.16-1 must report reportable cyber incidents to the National Response Center (NRC) without delay. A "reportable cyber incident" is defined to include events that cause substantial loss of confidentiality, integrity, or availability; major operational disruption; large disclosure of non-public personal information; or incidents that may lead to a transportation security incident.
Waivers, Equivalents, and Temporary Deviations
After completing a Cybersecurity Assessment, an owner or operator may seek a waiver or an equivalence determination for subpart F requirements consistent with waiver and equivalence procedures in 33 CFR parts 104, 105, and 106. Owners must notify the Coast Guard when they must temporarily deviate from requirements rather than when they are simply unable to meet them.
Personalized for You
How does this regulation affect your finances?
Personalize government policy and PRIA will tell you what this federal register document means for your household, plus every other regulation we track. PRIA reads each provision against your financial profile to show you exactly what matters to your wallet.
Key Dates
Related Federal Register Documents
2026-20447, Transparency in Coverage
Starting soon, health plans and insurers must share clearer, easier-to-understand price info for medical services and drugs. This helps you see what in-network and out-of-network costs really look like, with more details and better updates. These changes affect most group and individual health plans and kick in with new reporting rules to make healthcare pricing more transparent and fair.
2026-20469, Privacy Act Exemptions
The Department of the Treasury is creating a new system to handle tips and complaints about waste, fraud, and abuse in federal programs. To keep investigations safe and effective, this system will be partly exempt from some Privacy Act rules starting November 5, 2026. This change helps protect sensitive info while fighting fraud, with no extra costs to the public.
2026-20441, Medical Devices; Cardiovascular Devices; Classification of the Hyperoxia Monitoring Device Adjunct to Pulse Oximetry
The FDA is officially putting the hyperoxia monitoring device that works with pulse oximeters into a safer, easier-to-manage category called Class II. This change, effective October 6, 2026, means the device will have special safety rules but fewer regulatory hurdles, helping patients get access to this cool tech faster. Medical device makers and healthcare providers will feel the impact, with smoother approval processes and no big new costs expected.
2026-20448, Medical Devices; Exemptions From Premarket Notification: Class II Devices; Certain Clinical Toxicology Test Systems
Starting October 6, 2026, the FDA is letting certain clinical toxicology test systems skip the usual premarket approval step, cutting red tape and saving money for medical device makers. This change means these devices can get to market faster without extra paperwork, helping labs and patients get quicker results. If you make or sell these test systems, this update is a big win for your business and the healthcare world!
2026-20440, Medical Devices; General and Plastic Surgery Devices; Classification of the Focused Ultrasound System for Non-Thermal, Mechanical Tissue Ablation
The FDA is officially classifying the focused ultrasound system for non-thermal, mechanical tissue ablation as a Class II device, meaning it has special safety rules but fewer hurdles than the strictest category. This change helps make the device safer and easier to get to patients, boosting innovation and cutting red tape. The new classification is effective October 6, 2026, but has been in effect since October 6, 2023, affecting manufacturers and patients alike.
2026-20443, Medical Devices; Immunology and Microbiology Devices; Classification of the High Throughput DNA Sequencing for Hereditary Cancer Predisposition Assessment Test System
The FDA is officially putting high throughput DNA tests for hereditary cancer risk into a safer, easier-to-access category called Class II. This change means these tests will have special rules to keep them safe and effective, while also making it simpler for patients to get these life-saving tools. The new classification took effect on October 6, 2026, helping speed up innovation without extra costs for companies or patients.
Previous / Next Documents
Previous: 2025-00703, Procedural Rules
The Federal Mine Safety and Health Review Commission updated its procedural rules to make mine safety cases faster, fairer, and less costly. These changes affect anyone involved in mine safety legal cases and take effect on March 3, 2025. You can still send your comments until February 18, 2025, so don’t miss your chance to weigh in!
Next: 2025-00721, Defense Federal Acquisition Regulation Supplement: Definition of Material Weakness (DFARS Case 2021-D006)
Starting January 17, 2025, the Department of Defense is updating its rules to replace the term “significant deficiency” with “material weakness” when checking contractor business systems. This change affects contractors working with the DoD and helps make evaluations clearer and more consistent. No big cost changes are expected, but contractors should get ready for the new wording in their audits and reports.