For many maritime organizations, cybersecurity compliance has moved from a future planning item to an immediate business priority. The U.S. Coast Guard’s final rule on cybersecurity in the Marine Transportation System establishes minimum cybersecurity requirements for certain U.S.-flagged vessels, Outer Continental Shelf facilities, and facilities subject to the Maritime Transportation Security Act. The rule became effective on July 16, 2025 and includes requirements to develop and maintain a Cybersecurity Plan, designate a Cybersecurity Officer, and implement measures to detect, respond to, and recover from cyber incidents.
While many organizations understand that the rule exists, not all organizations have a clear view of what readiness should look like in practice. Moreover, there is increased risk in discovering cybersecurity weaknesses during an inspection, operational disruption, or active incident. Below are helpful considerations to keep in mind regarding maritime cybersecurity compliance.
Why Cybersecurity Is Critical for Maritime Organizational Focus
Cybersecurity is a core component of operational resilience, since maritime organizations rely on interconnected information technology (IT) and operational technology (OT) systems to support vessel operations, cargo movement, facility availability, and customer commitments. Cyber incidents are especially detrimental, as cyber impacts can reach far beyond the network. Such disruptions can affect schedules, safety, revenue, reputation, and the ability to meet contractual obligations.
The Coast Guard’s expectations should be viewed as more than an IT requirement since they encompass operational and business risks, as well. Leadership teams should be asking whether cybersecurity responsibilities are clearly assigned, whether critical systems are understood, and whether the organization can demonstrate that its Cybersecurity Plan is tested and ready.
What Maritime Organizations Should Be Prepared to Demonstrate
The U.S. Coast Guard has established the required cybersecurity outcomes, records, and minimum measures, although detailed inspection and enforcement procedures continue to evolve. Organizations should, therefore, prepare to demonstrate not only that required documentation exists, but also that cybersecurity responsibilities, safeguards, and response processes can operate in practice. While each organization’s environment is different, expectations generally focus on these areas:
- Governance and accountability. Organizations should be able to produce a current Cybersecurity Plan, identify the designated Cybersecurity Officer, and explain how cybersecurity responsibilities are assigned across leadership, operational, IT, OT, security, and third-party personnel. They should also be prepared to show that the required Cybersecurity Assessment has been completed, the plan is reviewed and audited, identified deficiencies are corrected, and required records are retained and available.
- Understanding of the operating environment. A defensible view of the organization’s critical IT and OT systems is also important, particularly for systems that could contribute to a transportation security incident if compromised. Supporting evidence may include current asset inventories, approved hardware and software lists, network maps, OT device configuration information, remote access methods, system ownership, vendor dependencies, and the rationale used to determine which systems are critical.
- Implementation and operating evidence. Organizations should be prepared to demonstrate that required safeguards are implemented and maintained. Depending on the environment, evidence may include access-control configurations, multifactor authentication or documented compensating controls, privileged-access reviews, account termination records, vulnerability and patch-management reports, backups and recovery tests, network segmentation, security monitoring, change records, and third-party oversight.
- Incident response and reporting readiness. Clear incident response procedures help show how cyber incidents are detected, evaluated, reported, escalated, contained, and recovered from. This includes clearly defined notification paths, coordination with operational leadership and external parties, required regulatory reporting, recovery priorities, and evidence that response procedures have been used in drills or exercises.
- Training, drills, exercises, and corrective action. Personnel should understand the cybersecurity responsibilities relevant to their roles. Trainings should show that the Cybersecurity Plan, communication and notification procedures, coordination, resource availability, and response capabilities are tested. Results should identify deficiencies, assign owners and due dates, and document corrective actions through completion.
Cybersecurity Compliance Questions for Maritime Leaders
Gaps in maritime cybersecurity compliance can occur in areas where documentation, system visibility, and response procedures have not been tested. Readiness starts with asking practical questions related to this and other operations, such as:
- Which assets fall within the scope of the compliance?
- Can the organization identify its most critical IT and OT systems?
- Are cybersecurity responsibilities clearly assigned?
- Can the organization demonstrate compliance evidence during an inspection?
- Do leaders know how a cyber incident would be reported and managed?
Maritime organizations that consider the above inquiries may connect governance with operational execution, and drive home the importance of treating cybersecurity as part of an organization’s broader resilience strategy.
How Forvis Mazars Can Help
Maritime cybersecurity compliance is becoming a business imperative across the Marine Transportation System, but readiness does not have to start from scratch. Forvis Mazars can help organizations assess where they stand today, identify gaps against Coast Guard expectations, and prioritize practical steps that align cybersecurity compliance with operational resilience.
Our professionals can support cybersecurity readiness assessments, IT and OT risk evaluations, governance and policy development, incident response planning, tabletop exercises, and evidence preparation for regulatory reviews.
By connecting compliance requirements with real-world operations, Forvis Mazars can help maritime organizations build cybersecurity programs that are documented, tested, and ready to stand up to both regulatory scrutiny and operational disruption.
Connect with professionals from Forvis Mazars today to learn more.