An official website of the United States government
A .mil website belongs to an official U.S. Department of Defense organization in the United States.
A lock (lock ) or https:// means you’ve safely connected to the .mil website. Share sensitive information only on official, secure websites.

Maritime Commons banner

    HOME    |    ABOUT    |    MARINE SAFETY LEADERS    |    CONTACT US   


33 Code of Federal Regulations, Part 101, Subpart F – Cybersecurity, information for regulated entities with existing waivers of certain requirements of 33 CFR Parts 104, 105, or 106

July 22, 2026

On July 16, 2025, the regulations in 33 CFR Part 101, Subpart F – Cybersecurity, became effective. This subpart set minimum cybersecurity requirements for U.S.-flagged vessels, facilities, and Outer Continental Shelf facilities to safeguard the security and resilience of the Marine Transportation System.   

Prior to the implementation of cybersecurity regulations under 33 CFR Part 101 Subpart F, the Coast Guard issued waivers or exemptions to certain MTSA-regulated entities based on risk assessments related to the prevalent security threats at the time. These waivers often relieved the MTSA-regulated entity from certain requirements of 33 CFR Part 104, 105, or 106 due to the low physical security risk of a Transportation Security Incident (TSI). However, the threat landscape has changed significantly since the inception of MTSA regulations, making it premature to assume that low physical security risk of a TSI equates to low cybersecurity risk, before such an evaluation is made through a Cybersecurity Assessment (CSA). 

Entities that were granted a waiver in the past from the requirement to have a security plan under 33 CFR Part 104, 105, or 106 are not automatically exempt from cybersecurity regulations in 33 CFR Part 101, Subpart F. These entities must complete a CSA as detailed in 33 CFR 101.650(e)(1), and following completion of the CSA and pursuant to 33 CFR 101.665, request a waiver from all or individual requirements under Subpart F, no later than July 16, 2027. A notice letter outlining this information will also be sent to affected entities.

Guidance on requesting a waiver from all or some requirements may be found in Coast Guard CG-MCP Work Instruction MCP-WI-002, Waiver and Equivalency Guidance for Requirements of 33 CFR Part 101, Subpart F – Cybersecurity, located at Coast Guard Maritime Industry Cybersecurity Resource Website: https://www.uscg.mil/maritimecyber/

For any questions not addressed in these documents or regarding the recent regulations, please reach out to the Coast Guard at MTSCyberRule@uscg.mil .

 

 


 

This blog is not a replacement or substitute for the formal posting of regulations and updates or existing processes for receiving formal feedback of the same. Links provided on this blog will direct the reader to official publications, such as the Federal Register, Homeport and the Code of Federal Regulations. These publications remain the official source for regulatory information published by the Coast Guard.