Knowledge hub

Coast Guard Maritime Cyber Security Act

The Coast Guard Maritime Cyber Security Act is an unofficial term for the U.S. Coast Guard's modern cybersecurity requirements governing the Marine Transportation System (MTS). Officially established through the Coast Guard's Cybersecurity in the Marine Transportation System final rule, these requirements establish minimum cybersecurity standards for U.S.-flagged vessels, Outer Continental Shelf (OCS) facilities, and facilities subject to the Maritime Transportation Security Act of 2002 (MTSA). The final rule was published on January 17, 2025, and became effective on July 16, 2025, with phased implementation requirements extending through July 2027. The regulation was developed in response to current and emerging cyber threats affecting ports, vessels, operational technology (OT), information technology (IT), and other critical infrastructure supporting maritime commerce and national security.

The regulation significantly expands existing maritime security requirements by establishing specific cybersecurity measures for regulated owners and operators. Organizations must conduct a cybersecurity assessment to identify vulnerabilities and risks affecting IT and OT systems and use the findings to develop and maintain a formal cybersecurity plan. These cybersecurity requirements complement existing vessel security assessment and facility security requirements under MTSA while establishing dedicated processes for identifying and managing cyber risk. By July 16, 2027, regulated owners and operators must designate a cybersecurity officer (CySO), complete the required cybersecurity assessment, and submit the cybersecurity plan for approval. The CySO is responsible for coordinating and overseeing cybersecurity activities, including implementation and maintenance of the cybersecurity plan, cybersecurity audits, cybersecurity drills and exercises, training, recordkeeping, and other required designation and planning activities. The regulation also establishes technical requirements addressing areas such as account security, multifactor authentication (MFA), passwords, IT and OT system inventories, and access controls, making identity and access security an important component of compliance.

The Coast Guard’s cybersecurity regulations also emphasize ongoing operational readiness. Since the rule took effect on July 16, 2025, regulated organizations have been subject to immediate cybersecurity incident reporting requirements, with incidents required to be reported to the National Response Center. Required cybersecurity training for personnel was due by January 12, 2026, with applicable training recurring annually thereafter. Following approval of the cybersecurity plan, organizations must also conduct cybersecurity drills at least twice each calendar year and cybersecurity exercises at least once each calendar year, with no more than 18 months between exercises. Coast Guard enforcement guidelines and inspection activities support evaluation of compliance, while identified cybersecurity deficiencies can require corrective action and, when warranted, additional measures available to the Coast Guard. Together, these requirements provide support for cybersecurity in the marine transportation system by helping organizations identify cyber risk, protect critical systems, prepare personnel, and respond to incidents.

Organizations seeking help with CGMCSA requirements or determining how to be compliant with the Coast Guard cybersecurity act should evaluate their existing cybersecurity program against the rule's requirements and implementation schedule, including controls for authentication, privileged access, third-party access, IT and OT systems, incident response, and cybersecurity governance. Although Cybersecurity in the MTS applies specifically to regulated maritime vessels and facilities, many of its cybersecurity challenges are also relevant to manufacturing organizations operating interconnected IT and OT environments and state and local government agencies responsible for ports, ferries, transportation systems, public safety, emergency management, and other critical infrastructure, when those agencies own, operate, or support regulated maritime infrastructure.

Imprivata Enterprise Access Management helps organizations secure workforce access through capabilities including single sign-on (SSO), multifactor authentication, passwordless authentication, access controls, and analytics, while Imprivata Privileged Access helps protect privileged and third-party access to critical IT and OT resources with granular access controls, credential management, monitoring, audit logs, and session recording. These capabilities can help organizations address identity- and access-related security requirements while improving visibility and accountability without unnecessarily disrupting critical operations. For organizations looking for a cybersecurity partner for Coast Guard-regulated environments, Imprivata State and Local Government and Manufacturing solutions can help strengthen identity security, reduce risks associated with privileged and third-party access, and support broader efforts to meet the cybersecurity objectives established by the Coast Guard.

You are currently browsing

Product availability varies by region. Would you like to choose a different region?

No thank you, I'd like to continue