Coast Guard Subpart F Compliance Package

A named Cybersecurity Officer for your facility, and every piece of compliance work the rule assigns to that role, for one flat monthly fee.

$5,000 a month

Everything in the package is one flat monthly rate. The officer, the documents, every recurring obligation, and the annual audit the rule requires to be performed independently. Billing starts at signature and the first payment is due before work begins. No deposit, no setup fee, no per-document charge. Minimum term 24 months.

Schedule a call Does this apply to you

The package

What you get

An assessment every year. A Plan in fourteen sections, amended whenever the facility, its ownership or its officer changes. Two drills a year and one exercise. Training for everyone with access to your systems. Records of all of it, kept and available for inspection. Incident reports on a deadline. And the known exploited vulnerability catalogue checked against your own equipment, continuously.

Subpart F creates a standing set of obligations. We do all of them.

A named officer. A qualified individual designated in writing for your facility, by name and by title, reachable by the Coast Guard at any hour of any day §101.620(b)(3). They carry the fifteen duties the rule assigns to the role §101.625(d).

The documents. The Cybersecurity Assessment §101.650(e)(1). The Cybersecurity Plan, all fourteen required sections §101.630(c). The Cyber Incident Response Plan §101.620(b)(6). Filed with the Coast Guard for review and approval §101.655, and amended whenever your ownership or your officer changes §101.630(e).

Everything that repeats. The Assessment again each year. Cybersecurity training for everyone with system access §101.650(d). Two drills §101.635(b)(1) and one full exercise §101.635(c)(1). Known exploited vulnerabilities monitored against your equipment and a decision made on each one §101.625(d)(15). Incident reporting to you and to the National Response Center §101.625(d)(10), §101.620(b)(7). Records created, maintained and available for inspection §101.640.

Plan renewal. If you stay with us through Plan renewal, the penetration test is included §101.650(e)(2). For a Plan approved after July 2027 that is around 2032.

Site visits. The walkdown the Assessment depends on, the drills, the exercise. Our officer is there in person. Travel and expenses for the agreed visits are included in the fee.

The annual audit, performed by us. The rule requires it to be performed by someone with no cybersecurity duties at your facility §101.630(f)(4). That is a test on the person, not the firm, so it is done by one of our officers who holds no designation at your site.

Two obligations most facilities cannot fulfill themselves.

One week of hours: the 40 an IT team covers, against the 168 the rule requiresA grid of one week. Each square is one hour; hours of the day run across, days of the week run down. The Cybersecurity Officer must be reachable by the Coast Guard at every hour on the grid. all 168 of them. The filled squares are the 40 hours a week when IT staff are normally at work; the other 128 are the hours when the officer must still be reachable and they are not there. Reachable, not on site and not on shift. the rule requires the officer be CONTACTABLE, it does not require the facility to staff anyone. Separately, programme: section 101.630(f)(4) bars personnel with regularly assigned cybersecurity duties at the facility being audited, so a second qualified person is needed every year.CONSTRAINT 1Your officer must be reachable by the Coast Guard at every hour on this grid.12am6am12pm6pm12amMONTUEWEDTHUFRISATSUNHours your IT staff is normally at work. 40Hours the officer must still be reachable. 128CONSTRAINT 2The annual audit cannot be done by whoever runs your cybersecurity.RUNS THE PROGRAMMEAUDITS ITΒ§101.630(f)(4) requires the audit to be done by an independent officer.A second qualified person is needed every year.
The timeline

How long it takes

Twenty-five weeks from signature to filing.

How long the work takes, against 16 July 2027Upper panel, a calendar: signing in one, three or six months, each with the 4.5 to 8 month planning range to submission, against 16 July 2027 drawn 11.3 months from 2026-08-08. Lower panel, a separate scale: the 25 weeks the contract schedules from signature, of which 14 are the client’s and 11 are ours.IF YOU SIGN … YOU SUBMITAug 26OctDecFebAprJunAugOctDecFeb16 JUL 2027Sign next monthsubmittedSign in three monthssubmittedSign in six monthssubmitteddarker = the 4.5-month end Β· lighter = the 8-month endELAPSED WEEKS FROM SIGNATURETHE 25 WEEKSthe contract setsKickoffYour questionnaireSite walkdownAssessmentDraft PlanYour reviewSubmission0510152025weeksAND THENEvery year after approval: the Assessment again, an audit by personnel independent ofthe measures audited, two drills and one exercise. The elapsed cost does not stop at submission.Β§101.650(e)(1) Β· Β§101.630(f)(1), (f)(4) Β· Β§101.635(b)(1), (c)(1)your timeoursPlanning estimate from the contract schedule, not a commitment.
The boundary

What stays with you

The rule requires technical measures on your own systems, and those decisions are yours: account, device and data security §101.650(a)–(c); supply chain management, resilience and network segmentation §101.650(f)–(h). Multifactor authentication is required on password-protected IT systems and remotely accessible OT systems §101.650(a)(4).

We tell you exactly what the rule requires, document what you already have, and identify the gap. You decide what to buy and when.

Also outside the fee: the hardware, software and licences your Plan requires. Remediating what the Assessment finds. Your employees’ time in the training, the drills and the exercise. Work beyond the scope agreed at the Assessment, which is quoted in advance and agreed in writing before it starts.

Questions

Before you call

Does this move our regulatory liability?

No. The Coast Guard is explicit that the obligation belongs to the owner or operator. Its Federal Register preamble states that it is the responsibility of owners and operators to ensure cybersecurity risks are managed and addressed, whether through in-house resources or through third-party services. We do the work, and the officer we provide holds the designation. The regulatory responsibility stays with you.

What happens to our Plan if we stop working with you?

The Assessment and the Plan belong to your facility and stay valid. Whoever holds the designation next works from them. If the officer changes, Β§101.630(e)(4) requires the Coast Guard to be notified within 96 hours and the Plan amended. We hand over everything needed to do that.

We already have a Facility Security Plan.

The Cybersecurity Plan is a separate requirement with its own contents. Β§101.630(c) lists fourteen sections that a Facility Security Plan does not contain. You may put the Cybersecurity Plan inside your existing FSP, attach it as an annex, or submit it on its own (Β§101.630(a)), but holding an FSP does not satisfy the requirement.

Our operational technology is air-gapped.

The Coast Guard addressed this in its scoping guidance, Policy Letter 01-26. It states that owners and operators may host their systems onsite, in the cloud, or remotely anywhere in the world, and that wherever those systems sit they may still pose risk to the maritime operations of the regulated entity. The assessment is expected to cover systems on that basis rather than on where they are physically located.

What if we deal with it closer to the deadline?

The Assessment has to be completed before the Plan can be written, and both are due 16 July 2027. From signing to filing takes around 25 weeks, and most of that is on your side, returning a facility questionnaire, hosting a site walkdown, reviewing the draft Plan. Starting six months out means finishing around the deadline with nothing in reserve.

Training has been required since 12 January 2026.

We operate more than one facility.

The rule applies to each vessel, facility and OCS facility that holds a security plan, so each is priced separately. One officer can hold the designation for several: Β§101.625(b) permits it, and the Coast Guard’s section-by-section analysis says the same, that the same person may serve as the CySO for more than one U.S.-flagged vessel, facility, or OCS facility (90 FR 6337). The rule also provides for one Plan covering several facilities. Β§101.630(d)(2) sets the condition and the duty: the facilities must be of similar operations, and the Plan must address the specific cybersecurity risks for each. What is open is not whether combination is allowed. It is whether your particular facilities meet the similar-operations test, which the rule does not define, and that is what we would put to your Captain of the Port.

Start with a call

Thirty minutes. We’ll tell you whether the rule reaches your facility, what it requires of you, and what we’d do about it.

Schedule a call