The United States Coast Guard, which works to proactively adapt to a rapidly changing world, noted that advanced maritime systems and equipment include the increased use of information and operational technology to accelerate and transform the maritime industry.
While these advancements provide operational efficiencies and improvements throughout the Marine Transportation System (MTS), they also introduce increased risks to a critical infrastructure sector. To strengthen national security and enhance economic prosperity, a comprehensive framework of policies, standards, and guidance was needed to govern the cyber resilience of the MTS.
To meet these needs, the Coast Guard recently announced the establishment of the Office of Maritime Cybersecurity Policy (CG-MCP). This new office, created under the Director of Inspections and Compliance (CG-5PC), directly supports Coast Guard Force Design and administration priorities to revitalize American maritime industries and advance emerging technologies. Serving as the Coast Guard’s central authority for maritime cybersecurity policy, the Office will develop and implement policies governing the cyber safety and security of ports, vessels, and facilities. It will also serve as the Coast Guard’s primary liaison for industry partners and government agencies, ensuring the Service maintains its leadership role in the maritime domain.
The Office of Maritime Cybersecurity Policy will be responsible for a wide range of critical functions including, but not limited to:
- Developing domestic policy and collaborating on international standards to ensure alignment with U.S. maritime cybersecurity goals.
- Directing a coordinated cybersecurity compliance and enforcement strategy.
- Engaging with maritime stakeholders, academia, and national laboratories to stay informed of technological advancements and related governance concerns.
- Monitoring and fostering the development of new technologies and techniques to proactively manage cyber risks.
“The Coast Guard must maintain pace with the maritime industry’s continued technological advancements,” said Rear Adm. Robert C. Compher, Assistant Commandant for Prevention Policy. “The creation of the Office of Maritime Cybersecurity Policy establishes a central authority to develop clear policy, direct a unified compliance strategy, and collaborate with our partners. This office will ensure we are not only addressing current cyber threats and vulnerabilities, but are also preparing for the challenges ahead, safeguarding the Marine Transportation System for the future.”
Industry representatives, agencies, and other maritime stakeholders interested in cybersecurity efforts affecting the MTS can find information and resources at the Coast Guard Maritime Industry Cybersecurity Resource Website, https://www.uscg.mil/maritimecyber/, and are encouraged to reach out to the Office of Maritime Cybersecurity Policy at MTSCyberRule@uscg.mil.
Coast Guard Establishes New Cybersecurity Regulations for the Marine Transportation System
On January 17, 2025, the U.S. Coast Guard published a new final rule that establishes baseline cybersecurity requirements to protect the marine transportation system (MTS) from cyber threats. This final rule became effective on July 16, 2025.
The rule addresses current and emerging cybersecurity threats in the MTS by adding minimum cybersecurity requirements to help detect risks and respond to and recover from cybersecurity incidents. These requirements include developing and maintaining a Cybersecurity Plan, designating a Cybersecurity Officer (CySO), and taking various measures to maintain cybersecurity within the MTS.
The final rule can be accessed at Federal Register: Cybersecurity in the Marine Transportation System
In a related action, the Coast Guard issued this Safety Bulletin on August 27, 2026 clarifying the distinction between “Laid Up” and “Inactive” vessel statuses and how MTS cybersecurity requirements apply during nonoperational periods: Marine Safety Information Bulletin (MSIB) 04-26: Applicability of MTSA Cybersecurity Requirements to Inactive Vessels
The new cybersecurity regulations can be found at eCFR :: 33 CFR Part 101 Subpart F — Cybersecurity



