What you get
An assessment every year. A Plan in fourteen sections, amended whenever the facility, its ownership or its officer changes. Two drills a year and one exercise. Training for everyone with access to your systems. Records of all of it, kept and available for inspection. Incident reports on a deadline. And the known exploited vulnerability catalogue checked against your own equipment, continuously.
Subpart F creates a standing set of obligations. We do all of them.
A named officer. A qualified individual designated in writing for your facility, by name and by title, reachable by the Coast Guard at any hour of any day §101.620(b)(3). They carry the fifteen duties the rule assigns to the role §101.625(d).
The documents. The Cybersecurity Assessment §101.650(e)(1). The Cybersecurity Plan, all fourteen required sections §101.630(c). The Cyber Incident Response Plan §101.620(b)(6). Filed with the Coast Guard for review and approval §101.655, and amended whenever your ownership or your officer changes §101.630(e).
Everything that repeats. The Assessment again each year. Cybersecurity training for everyone with system access §101.650(d). Two drills §101.635(b)(1) and one full exercise §101.635(c)(1). Known exploited vulnerabilities monitored against your equipment and a decision made on each one §101.625(d)(15). Incident reporting to you and to the National Response Center §101.625(d)(10), §101.620(b)(7). Records created, maintained and available for inspection §101.640.
Plan renewal. If you stay with us through Plan renewal, the penetration test is included §101.650(e)(2). For a Plan approved after July 2027 that is around 2032.
Site visits. The walkdown the Assessment depends on, the drills, the exercise. Our officer is there in person. Travel and expenses for the agreed visits are included in the fee.
The annual audit, performed by us. The rule requires it to be performed by someone with no cybersecurity duties at your facility §101.630(f)(4). That is a test on the person, not the firm, so it is done by one of our officers who holds no designation at your site.
Two obligations most facilities cannot fulfill themselves.
How long it takes
Twenty-five weeks from signature to filing.
What stays with you
The rule requires technical measures on your own systems, and those decisions are yours: account, device and data security §101.650(a)–(c); supply chain management, resilience and network segmentation §101.650(f)–(h). Multifactor authentication is required on password-protected IT systems and remotely accessible OT systems §101.650(a)(4).
We tell you exactly what the rule requires, document what you already have, and identify the gap. You decide what to buy and when.
Also outside the fee: the hardware, software and licences your Plan requires. Remediating what the Assessment finds. Your employees’ time in the training, the drills and the exercise. Work beyond the scope agreed at the Assessment, which is quoted in advance and agreed in writing before it starts.
Before you call
Does this move our regulatory liability?
No. The Coast Guard is explicit that the obligation belongs to the owner or operator. Its Federal Register preamble states that it is the responsibility of owners and operators to ensure cybersecurity risks are managed and addressed, whether through in-house resources or through third-party services. We do the work, and the officer we provide holds the designation. The regulatory responsibility stays with you.
What happens to our Plan if we stop working with you?
The Assessment and the Plan belong to your facility and stay valid. Whoever holds the designation next works from them. If the officer changes, Β§101.630(e)(4) requires the Coast Guard to be notified within 96 hours and the Plan amended. We hand over everything needed to do that.
We already have a Facility Security Plan.
The Cybersecurity Plan is a separate requirement with its own contents. Β§101.630(c) lists fourteen sections that a Facility Security Plan does not contain. You may put the Cybersecurity Plan inside your existing FSP, attach it as an annex, or submit it on its own (Β§101.630(a)), but holding an FSP does not satisfy the requirement.
Our operational technology is air-gapped.
The Coast Guard addressed this in its scoping guidance, Policy Letter 01-26. It states that owners and operators may host their systems onsite, in the cloud, or remotely anywhere in the world, and that wherever those systems sit they may still pose risk to the maritime operations of the regulated entity. The assessment is expected to cover systems on that basis rather than on where they are physically located.
What if we deal with it closer to the deadline?
The Assessment has to be completed before the Plan can be written, and both are due 16 July 2027. From signing to filing takes around 25 weeks, and most of that is on your side, returning a facility questionnaire, hosting a site walkdown, reviewing the draft Plan. Starting six months out means finishing around the deadline with nothing in reserve.
Training has been required since 12 January 2026.
We operate more than one facility.
The rule applies to each vessel, facility and OCS facility that holds a security plan, so each is priced separately. One officer can hold the designation for several: Β§101.625(b) permits it, and the Coast Guardβs section-by-section analysis says the same, that the same person may serve as the CySO for more than one U.S.-flagged vessel, facility, or OCS facility (90 FR 6337). The rule also provides for one Plan covering several facilities. Β§101.630(d)(2) sets the condition and the duty: the facilities must be of similar operations, and the Plan must address the specific cybersecurity risks for each. What is open is not whether combination is allowed. It is whether your particular facilities meet the similar-operations test, which the rule does not define, and that is what we would put to your Captain of the Port.
Start with a call
Thirty minutes. We’ll tell you whether the rule reaches your facility, what it requires of you, and what we’d do about it.