What the Coast Guard’s cybersecurity rule requires

Subpart F of 33 CFR 101 took effect on 16 July 2025. This page sets out what it asks of a regulated facility, with a link to every section so you can read the text yourself.

The cadence

What Subpart F requires, and how often

What Subpart F requires, and how oftenObligations grouped by how often they recur: five continuous, three every year, one twice a year, one as they occur, and two once, then amended. Two dates are already fixed β€” training since 12 January 2026, and the Assessment and Plan due 16 July 2027, under a year away. Two of them begin only when the Plan is approved: the annual audit and the penetration test at renewal.HOW OFTENREQUIREMENTSWHICH ONESCONTINUOUS5Officer, duties, qualifications, incident response plan and recordsEVERY YEAR3Training, Assessment and exerciseTWICE A YEAR1DrillsAS THEY OCCUR1Reportable incidentsONCE, THEN AMENDED2The Plan and its submissionWHEN THE PLAN IS APPROVED2Annual audit and penetration test at renewalDATES ALREADY FIXED2Training since 12 January 2026 Β· Assessment and Plan due 16 July 2027, under a year away
Applicability

Who it applies to

The rule reaches owners and operators of U.S.-flagged vessels, facilities and OCS facilities required to hold a security plan under Parts 104, 105 or 106 §101.605(a). A facility operating under an approved Alternative Security Program is included §105.140.

If you hold a Facility Security Plan, the rule reaches your facility. Nothing in it exempts a facility because its systems are small, isolated or old no exemption, waiver or scaling provision appears in §§101.600 to 101.665.

The officer

The Cybersecurity Officer

The owner or operator designates a Cybersecurity Officer in writing, by name and by title, and the Plan must state how to reach that person at any time §101.620(b)(3). The officer must be accessible to the Coast Guard 24 hours a day, seven days a week.

The rule sets a knowledge bar across twelve areas §101.625(e) and assigns fifteen duties to the role §101.625(d). One person may hold the designation for more than one facility §101.625(b).

The officer does not have to be an employee. In its section-by-section analysis of §101.625 the Coast Guard states that the CySO “may be a full-time, collateral, or contracted position” 90 FR 6337, and in its response to comments that it is for owners and operators to manage cybersecurity risk “whether through in-house resources or through third-party services” 90 FR 6315. The Coast Guard’s published guidance says the same thing to the public today, in a FAQ answering the question directly.

If the officer changes, the Coast Guard must be notified and the Plan amended within 96 hours §101.630(e)(4).

The assessment

The Cybersecurity Assessment

The Assessment must be completed by 16 July 2027 and repeated annually, and sooner than annually on a change of ownership §101.650(e)(1). It analyses the facility’s networks and identifies the risk posed by each digital asset.

The Assessment comes before the Plan, because the Plan is written from what it finds.

The plan

The Cybersecurity Plan

The Plan covers fourteen required sections §101.630(c) and must be filed with the Coast Guard for review and approval by 16 July 2027 §101.655. It may sit inside your Facility Security Plan, be attached as an annex, be included as part of an approved Alternative Security Program, or be filed on its own §101.630(a).

Once approved, a Plan is valid for five years §101.630(d)(3).

When the Plan must be amended

  • On a change of owner or operator, within 96 hours §101.630(e)(3)
  • On a change of Cybersecurity Officer, within 96 hours §101.630(e)(4)
  • When an audit finds the Plan needs it §101.630(f)(5)
  • When the Coast Guard returns the Plan because it no longer meets the requirements — at least 60 days to submit amendments, with temporary measures in the meantime §101.630(e)(1)(ii)
The audit

The annual audit

The Plan and its implementation are audited annually, beginning no later than one year from the date the Plan is approved §101.630(f)(1). An audit is also required on a change of owner or operator, and when the cybersecurity measures are modified §101.630(f)(2).

Whoever performs it must have no regularly assigned cybersecurity duties at the facility being audited, and must be independent of the measures being audited §101.630(f)(4).

The Facility Security Plan audit has an exception: §105.415(b)(4) applies the independence requirement unless impracticable due to the size and nature of the company or the facility. §101.630(f)(4) carries no equivalent clause. The requirement it states is the requirement.

The rule splits responsibility from performance. The officer must ensure the audit happens §101.625(d)(3), and must ensure problems it finds are corrected §101.625(d)(7). But conducting it is closed to anyone with regularly assigned cybersecurity duties at the facility being audited §101.630(f)(4) — and a designated officer has those duties by definition. Arranging the audit is the officer’s job; conducting it at that facility is not.

The certification is the officer’s own. §101.630(f)(1) assigns it to the Cybersecurity Officer by name rather than to the owner or operator: the CySO must ensure the audit is performed, and the CySO must attach a report to the Plan certifying that the Plan meets the applicable requirements of this subpart §101.630(f)(1).

That last requirement is the one facilities find hardest. Whoever holds the officer role cannot audit that facility’s Plan. The test is on the person, not the organisation, so a colleague with no duties at that facility can.

Drills and training

Drills, exercises and training

Drills are held twice each calendar year §101.635(b)(1). A full exercise is held once each calendar year, with no more than 18 months between exercises §101.635(c)(1).

Cybersecurity training has been required since 12 January 2026 and repeats annually §101.650(d). It covers everyone with access to the facility’s systems.

Your systems

Technical measures

The rule requires measures on the facility’s own systems: account security, device security and data security §101.650(a)–(c); supply chain management, resilience and network segmentation §101.650(f)–(h). Multifactor authentication is required on password-protected IT systems and on remotely accessible OT systems §101.650(a)(4).

Where a measure is not feasible, the rule accepts documented compensating controls §101.650(a)(2), §101.650(a)(4), §101.650(e)(3)(i).

These are decisions about your own equipment and budget. We tell you what the rule requires and when, and document what you have.

Reporting

Reporting and records

Reportable cyber incidents are reported to the owner or operator §101.625(d)(10), and to the National Response Center where 33 CFR 6.16-1 reporting does not already apply §101.620(b)(7). A Cyber Incident Response Plan must be developed, approved and exercised §101.620(b)(6), §101.625(d)(4).

Records of training, drills, exercises, cybersecurity threats, reportable cyber incidents and audits of the Cybersecurity Plan are created, maintained and made available to the Coast Guard on request §101.640, §105.225.

Dates

What has already passed, and what is coming

  • 16 July 2025 — the rule took effect. Incident reporting has applied since that date.
  • 12 January 2026 — cybersecurity training required, and annually thereafter.
  • 16 July 2027 — the Cybersecurity Assessment completed and the Cybersecurity Plan filed.

As at 10 August 2026, the Coast Guard is not approving Cybersecurity Plans yet. Its published FAQ states that it is not currently approving plans for these regulations and is still developing the review and approval procedures. Plans are filed by the deadline regardless.

Failure to comply is subject to civil penalty under 46 U.S.C. 70119 §101.415(b).

Two obligations therefore have no start date yet: the annual audit runs from approval, and the penetration test attaches to Plan renewal §101.650(e)(2). Both begin once your Plan is approved.

Next step

This page is the whole rule. The Check is only your part of it

Ten questions, about two minutes. It runs in your browser and your answers are not sent to us unless you choose to send them.

Which of these apply to you Or schedule a call →