Maritime Cybersecurity
Resource Center
implement, and sustain 33 CFR Part 101 Subpart F cybersecurity compliance.
Countdown to compliance
Maritime Cybersecurity Compliance Series
-
Issue #09 – The Cybersecurity Officer
-
Issue #10 – Preparing for the Cybersecurity Assessment
-
Issue #11 – Creating an Asset Inventory
-
Conducting the Cybersecurity Assessment (CSA)
-
Developing a Cybersecurity Plan (CSP)
-
Required cybersecurity controls
-
Inspection readiness and compliance expectations
Maritime cybersecurity training
Explore general awareness and role-based courses and bundled learning programs designed
to meet the annual cybersecurity training requirements outlined in 33 CFR 101.650(d).
Maritime cybersecurity resources
Understanding the Regulations
Assessments & Planning
Training & Workforce Development
Inspections & Audits
Incident Reporting & Response
Threat Intelligence & Government Resources
Cybersecurity Regulations (33 CFR 101 Subpart F)
Establishes the U.S. Coast Guard's cybersecurity requirements for MTSA-regulated vessels, facilities, and offshore facilities, including requirements for cybersecurity assessments, plans, training, drills and exercises, incident reporting, and cybersecurity officers. Serves as the primary regulatory framework for maritime cybersecurity compliance.
USCG Maritime Cybersecurity Regulations Fact Sheet
A U.S. Coast Guard fact sheet that provides a high-level overview of the maritime cybersecurity final rule, including who is affected, key compliance requirements, reporting obligations, and implementation deadlines. Useful as a quick-reference summary for understanding the scope and timeline of the regulations.
Source: U.S. Coast Guard | Published January 2025
USCG Cybersecurity Final Rule Frequently Asked Questions
Provides Coast Guard answers to common industry questions about the maritime cybersecurity final rule, including training requirements, Cybersecurity Officers (CySOs), cybersecurity plans, assessments, audits, drills and exercises, inspections, and compliance expectations. Valuable for understanding how the Coast Guard interprets and intends to implement the regulations in practice.
Source: U.S. Coast Guard | Updated January 2026
CG-MCP Discussion & Q&A with the Maritime Industry Cybersecurity Coalition (MICC)
Presentation from the U.S. Coast Guard Office of Maritime Cybersecurity Policy (CG-MCP) addressing common questions about the maritime cybersecurity regulations. Covers compliance timelines, landlord-tenant applicability, cybersecurity assessment scoping, critical IT/OT systems, Cybersecurity Plan submissions, waiver and equivalency requests, and other implementation topics.
Source: U.S. Coast Guard Office of Maritime Cybersecurity Policy (CG-MCP) | July 30, 2026
Cybersecurity in the Marine Transportation System Final Rule
Official Federal Register publication for the cybersecurity regulations. Includes regulatory text, preamble, implementation requirements, and supporting information.
USCG Small Entity Compliance Guide for MTSA-Regulated Facilities and OCS Facilities
A U.S. Coast Guard guide that explains the maritime cybersecurity requirements in plain language for small businesses. Provides an overview of compliance obligations, implementation timelines, cyber incident reporting requirements, training obligations, Cybersecurity Plans, Cybersecurity Assessments, and options for waivers or equivalencies.
Source: U.S. Coast Guard | Published January 2025
USCG Small Entity Compliance Guide for MTSA-Regulated U.S.-Flagged Vessels
A U.S. Coast Guard guide that explains the maritime cybersecurity regulations in plain language for vessel owners and operators. Provides an overview of compliance requirements, cyber incident reporting obligations, training requirements, Cybersecurity Plans, Cybersecurity Assessments, waivers, equivalencies, and key compliance deadlines.
Source: U.S. Coast Guard | Published January 2025
USCG Waiver and Equivalency Guidance for 33 CFR Part 101 Subpart F (MCP-WI-002)
Provides Coast Guard guidance for requesting cybersecurity waivers and equivalency determinations under 33 CFR 101.665. Explains when a waiver or equivalency may be appropriate, how requests are evaluated, and the information needed to support a submission. Valuable for owners and operators seeking alternative compliance approaches based on the results of a Cybersecurity Assessment.
Source: U.S. Coast Guard | Published June 2026
USCG Blog: Existing Waivers and Maritime Cybersecurity Compliance
A U.S. Coast Guard article that clarifies how the maritime cybersecurity regulations apply to facilities, vessels, and offshore facilities that currently hold waivers from certain MTSA security requirements. Explains that existing waivers under 33 CFR Parts 104, 105, or 106 do not automatically exempt an owner or operator from the cybersecurity requirements in 33 CFR Part 101 Subpart F and outlines available compliance options.
Source: U.S. Coast Guard | Published July 22, 2026
USCG Blog: USCG Releases Additional Cybersecurity Policy and Guidance
A U.S. Coast Guard article that introduces several important Coast Guard guidance documents that support implementation of the maritime cybersecurity regulations, helping owners and operators conduct cybersecurity assessments, prepare compliance documentation, and navigate waiver and equivalency processes.
Source: U.S. Coast Guard | Published June 4, 2026
USCG DoD SAFE Instructions for Cybersecurity Plan, Assessment, Waiver & Equivalency Submissions (MCP-WI-003)
Provides U.S. Coast Guard guidance for securely submitting Cybersecurity Plans (CSPs), Cybersecurity Assessments (CSAs), and waiver or equivalency requests through the DoD SAFE portal. Explains the Coast Guard's process for transmitting Sensitive Security Information (SSI) and helps organizations properly submit required cybersecurity documentation.
Source: U.S. Coast Guard | Published June 2026
USCG Cybersecurity Assessment Initial Scoping and Process Policy Letter (CG-5PC 01-26)
Provides U.S. Coast Guard guidance for conducting the Cybersecurity Assessment (CSA) required by 33 CFR Part 101 Subpart F. Outlines a structured approach for defining assessment scope, inventorying assets, evaluating cybersecurity risks, identifying critical IT/OT systems, and documenting results to support development of a Cybersecurity Plan.
Source: U.S. Coast Guard | Published June 2026
USCG Cybersecurity Assessment (CSA) Small Business Guide
A Coast Guard-developed guide that provides a simplified, step-by-step approach to conducting a Cybersecurity Assessment (CSA) for small maritime organizations. The guide breaks the assessment process into manageable stages and explains how to identify critical IT/OT systems, evaluate risks, and document findings to support development of a Cybersecurity Plan.
Source: U.S. Coast Guard | Published June 2026
USCG Waiver and Equivalency Guidance for 33 CFR Part 101 Subpart F (MCP-WI-002)
Provides Coast Guard guidance for requesting cybersecurity waivers and equivalency determinations under 33 CFR 101.665. Explains when a waiver or equivalency may be appropriate, how requests are evaluated, and the information needed to support a submission. Valuable for owners and operators seeking alternative compliance approaches based on the results of a Cybersecurity Assessment.
Source: U.S. Coast Guard | Published June 2026
USCG DoD SAFE Instructions for Cybersecurity Plan, Assessment, Waiver & Equivalency Submissions (MCP-WI-003)
Provides U.S. Coast Guard guidance for securely submitting Cybersecurity Plans (CSPs), Cybersecurity Assessments (CSAs), and waiver or equivalency requests through the DoD SAFE portal. Explains the Coast Guard's process for transmitting Sensitive Security Information (SSI) and helps organizations properly submit required cybersecurity documentation.
Source: U.S. Coast Guard | Published June 2026
USCG Maritime Cybersecurity Assessment and Annex Guide (MCAAG)
A U.S. Coast Guard-developed guidance document that provides a voluntary framework for identifying cybersecurity vulnerabilities and developing a cybersecurity annex for Facility Security Plans (FSPs). Includes assessment methodologies, cyber annex templates, NIST Cybersecurity Framework alignment, and practical guidance for integrating cybersecurity into MTSA security programs.
Source: U.S. Coast Guard | Published January 2023
NVIC 01-20: Guidelines for Addressing Cyber Risks at MTSA-Regulated Facilities
A U.S. Coast Guard guidance document that explains how MTSA-regulated facilities can identify, assess, document, and address cybersecurity vulnerabilities within existing Facility Security Assessments (FSAs) and Facility Security Plans (FSPs). Provides practical recommendations for integrating cybersecurity into security programs, training, exercises, communications, and incident response.
Source: U.S. Coast Guard | Published February 2020
USCG Cybersecurity Training Policy Letter (CG-5PC 01-25)
Provides Coast Guard guidance for implementing the maritime cybersecurity training requirements in 33 CFR 101.650(d). Clarifies who must be trained, required training topics, expectations for key personnel, contractor training, recordkeeping, and the management of untrained personnel. Valuable for developing compliant cybersecurity training programs and preparing for Coast Guard inspections.
Source: U.S. Coast Guard | Published January 2025
USCG Cyber Training Verification Inspector Job Aid (MCP-WI-001)
Provides the Coast Guard's inspection checklist for verifying compliance with maritime cybersecurity training requirements. Includes the questions inspectors may use to evaluate training programs, training records, contractor training, and controls for personnel who have not yet completed required cybersecurity training.
Source: U.S. Coast Guard | Published January 2026
Who Needs Maritime Cybersecurity Training Under 33 CFR Part 101 Subpart F?
Explains which personnel are required to receive cybersecurity training under the maritime cybersecurity regulations, including key personnel, employees with access to IT or OT systems, contractors, and untrained personnel. Helps organizations determine who must be trained and understand common compliance questions.
USCG Cyber Training Verification Inspector Job Aid (MCP-WI-001)
Provides the Coast Guard's inspection checklist for verifying compliance with maritime cybersecurity training requirements. Includes the questions inspectors may use to evaluate training programs, training records, contractor training, and controls for personnel who have not yet completed required cybersecurity training.
Source: U.S. Coast Guard | Published January 2026
U.S. Coast Guard Cyber Protection Teams (CPTs)
The U.S. Coast Guard's Cyber Protection Teams provide cybersecurity assessment, threat hunting, and incident response services to Marine Transportation System (MTS) stakeholders. CPT assessments help organizations identify cybersecurity weaknesses, evaluate security controls, and improve resilience through penetration testing, configuration reviews, and other cybersecurity services.
Source: U.S. Coast Guard
Facility Inspector Cyber Job Aid, Revision 2
Provides a U.S. Coast Guard inspection aid designed to help facility inspectors evaluate how cybersecurity is incorporated into Facility Security Assessments, Facility Security Plans, training programs, access controls, maintenance activities, monitoring practices, and facility-vessel interfaces. Valuable for understanding the cybersecurity topics and questions inspectors may consider during MTSA facility inspections.
Source: U.S. Coast Guard | Published January 2023
USCG Maritime Cybersecurity Contact Information
Provides contact information for U.S. Coast Guard offices responsible for maritime cybersecurity policy, compliance, inspections, incident reporting, and regulatory implementation support. Useful for obtaining guidance, submitting questions, and connecting with the appropriate Coast Guard program office.
Maritime Cyber Bulletin 01-26: Awareness for Increased Phishing
A Coast Guard Maritime Cyber Bulletin that highlights the increasing prevalence and sophistication of phishing attacks targeting the Marine Transportation System. Provides threat information, recommended defensive measures, and resources to help organizations strengthen user awareness, access controls, and phishing response capabilities.
Source: U.S. Coast Guard | Published March 2026
USCG Cyber Trends and Insights in the Marine Environment (CTIME) Reports
Published annually by U.S. Coast Guard Cyber Command, the CTIME report analyzes cybersecurity trends, vulnerabilities, incidents, assessments, and threat activity affecting the Marine Transportation System. The reports provide practical lessons learned, recurring findings, threat intelligence, and recommended best practices drawn from Coast Guard cyber operations and industry engagements.
Source: U.S. Coast Guard
Coast Guard Maritime Industry Cybersecurity Resource Center
Coast Guard Maritime Commons Blog
USCG Maritime Cybersecurity Contact Information
Provides contact information for U.S. Coast Guard offices responsible for maritime cybersecurity policy, compliance, inspections, incident reporting, and regulatory implementation support. Useful for obtaining guidance, submitting questions, and connecting with the appropriate Coast Guard program office.
U.S. Coast Guard Cyber Protection Teams (CPTs)
The U.S. Coast Guard's Cyber Protection Teams provide cybersecurity assessment, threat hunting, and incident response services to Marine Transportation System (MTS) stakeholders. CPT assessments help organizations identify cybersecurity weaknesses, evaluate security controls, and improve resilience through penetration testing, configuration reviews, and other cybersecurity services.
Source: U.S. Coast Guard
USCG Cyber Command (CGCYBER)
NVIC 02-24, Change 1: Security and Cyber Incident Reporting Guidance
Provides Coast Guard guidance on when and how maritime stakeholders and MTSA-regulated entities must report security incidents, including breaches of security, suspicious activity, transportation security incidents, and cyber incidents under MTSA regulations and 33 CFR Part 6. Clarifies reporting thresholds and notification requirements, helping organizations ensure timely reporting and maintain regulatory compliance.
Source: U.S. Coast Guard | Updated January 2026
Maritime Cyber Bulletin 01-26: Awareness for Increased Phishing
A Coast Guard Maritime Cyber Bulletin that highlights the increasing prevalence and sophistication of phishing attacks targeting the Marine Transportation System. Provides threat information, recommended defensive measures, and resources to help organizations strengthen user awareness, access controls, and phishing response capabilities.
Source: U.S. Coast Guard | Published March 2026
USCG Maritime Cybersecurity Contact Information
Provides contact information for U.S. Coast Guard offices responsible for maritime cybersecurity policy, compliance, inspections, incident reporting, and regulatory implementation support. Useful for obtaining guidance, submitting questions, and connecting with the appropriate Coast Guard program office.
