There’s big news in the marine industry as the first round of new mandatory cybersecurity regulations from the U.S. Coast Guard are going into effect for U.S.-flagged vessels, facilities, and offshore platforms.
If you’re in the marine industry, here’s what you need to know, why you should care, and how KVH can help.
What’s Happening?
The Coast Guard is rolling out new mandatory cybersecurity regulations for the U.S. Marine Transportation System (MTS). These rules are all about protecting ships, ports, and offshore facilities from the growing threat of cyberattacks. As more of our industry relies on digital tech—think IoT, navigation, cargo handling, communications—the risks have gotten real.
Hackers aren’t just after your email anymore; they threaten the safety and security of entire operations, and a successful attack can cost you millions in operational losses, put your crews and ships at risk, and damage your fleet’s brand and reputation.
First of All, Who’s Subject to These Mandatory Cybersecurity Regs?
You are subject to these new requirements if you own or operate:
- U.S.-flagged vessels (cargo ships >100 GT, passenger vessels with >150 passengers, OSVs, MODUs, big towing vessels, cruise ships on international routes)
- Facilities (container, chemical, petroleum, cruise, LNG/LPG terminals, barge fleeting with dangerous cargo, etc.)
- Outer Continental Shelf (OCS) facilities (offshore oil/gas platforms, wind farms, FPSOs, deepwater ports)
These new regs don’t apply to foreign-flagged vessels but do offer an excellent roadmap for improved cybersecurity for anyone.
What’s the Timing?
The initial effective date for the initial round of regulations is July 16, 2025. The deadline for full compliance is 24 months after that (so, July 2027).
What Do You Have to Do Now and What Comes Later?
Here’s the rundown (don’t worry, we’ll keep it simple):
Reporting – Effective July 16, 2025
- Have you experienced a cyber incident? You are now required to report it to the National Response Center immediately.
Training – Effective January 12, 2026
- All appropriate personnel must participate in cybersecurity training that “encompasses recognition and detection of cybersecurity threats and all types of cyber incidents, techniques used to circumvent cybersecurity measures, and procedures for reporting a cyber incident,” by January 12, 2026, and every year after.
- Plus, you need to establish a Cyber Incident Response Plan that lays out how you’ll respond to a cyber incident, who does what, and when, and then ensure your crews and personnel understand their roles
Cybersecurity Officer – Effective July 16, 2027
- Vessels and platforms covered by these regulations will need to designate, in writing, their Cybersecurity Officer (or CySO). The function of the CySO is to develop and maintain your vessel or fleet cybersecurity plan, arrange audits, coordinate training, and handle incident reporting.
Cybersecurity Plan – Required No Later than July 2027
- Within 24 months of the effective date for these rules, your CySO will need to submit a written cybersecurity plan for USCG approval. An effective plan should cover such areas as:
- Account security – Potential components include:
- – Automatic lockouts after failed logins
- – Strong passwords
- – Multifactor authentication
- – Least privilege for admins
- – Separate credentials for critical systems
- – Access removal when an employee or crew member leaves or is dismissed
- Device security – Potential features include:
- – Maintaining a list of approved hardware/software
- – The ability to disable executable code by default on critical systems
- – An up-to-date inventory of all network-connected devices
- – Documenting network maps and device configs
- Data security, including:
- – Secure logging (only privileged users get access)
- – Encryption of sensitive data and network traffic, where possible
Drills and Exercises – Upon USCG Approval of Your Cybersecurity Plan
- Get ready to carry out at least two cybersecurity drills and one exercise per year (no more than 18 months between exercises)
Assessments and Audits – Initial Assessment Due by July 16, 2027
- You’ll be required to complete your first in-depth cybersecurity assessment by July 16, 2027, followed by new assessments on an annual basis (or sooner if ownership changes)
- Plus, your CySO must arrange annual audits of your cybersecurity plan
Why does this matter?
The era of “optional” cybersecurity on U.S.-flagged vessels is over. With the July 16, 2025, effective date, these are now legal requirements, not just best practices. These also aren’t simply window dressing. The real-world consequences of a cyberattack include shutting down your operations, endangering lives, or causing an environmental disaster.
It’s also vital to recognize that these U.S. Coast Guard regulations reflect similar moves in this direction throughout the global maritime industry.
What Should You Do Now and How Can KVH Help?
Start prepping! These new regs are being phased in over time and the USCG is putting enforcement programs in place.
- We can help you review your security, identify gaps, and train your team.
- Talk to us about our CommBox Edge Secure Suite, delivering advanced network and bandwidth management along with robust cybersecurity protections powered by Cisco Talos and SNORT.
Appoint your CySO and ensure they have the authority (and resources) to do the job. Not sure what this entails or if you have someone on your team who can take on this role?
- Talk to us about how a virtual CySO can save you time and money while ensuring you have a viable, realistic cybersecurity plan and oversight for training, assessments, and audits.
Document everything. Upon request, the Coast Guard will want your plans, training records, penetration test results, and drill results.
- We’re ready to help with your compliance needs, record keeping, and regulatory submissions to the USCG.
The bottom line: Cybersecurity is now just as critical as physical security for U.S.-flagged vessels and facilities. The clock is ticking—talk to our team here at KVH, and don’t wait until the last minute to get compliant!
Talk to a KVH Team Member about Managed IT
Let us know how we can help.