Call
Ask an Expert
Tel: +1-281-673-2800
Find an Office
Email
Email Us

Maritime Cybersecurity Compliance to Industry Regulations

Maritime Cybersecurity Compliance


As cyber threats targeting maritime critical systems grow increasingly frequent and sophisticated, vessel owners, shipyard operators, and MTSA-regulated facilities must understand and comply with evolving regulations to help ensure the resilience of their operations, protect critical assets, and support the safety and security of the maritime industry.

Updates to the Maritime Transportation Security Act (MTSA) Cyber Regulations issued by the United States Coast Guard (USCG) in February 2024 and the International Association of Classification Societies (IACS) E26 and E27 Cyber Regulations are reshaping how maritime stakeholders must address cyber risks.

Guiding Maritime Cybersecurity Compliance:

MTSA Cyber Regulations

In February 2024, USCG updated maritime security regulations to establish minimum cybersecurity requirements for U.S.-flagged vessels, Outer Continental Shelf facilities, and MTSA-regulated facilities. The new rule addresses cybersecurity threats by requiring entities to develop a Cybersecurity Plan, designate a Cybersecurity Officer, and implement measures to detect, respond to, and recover from cybersecurity incidents. These updates are designed to strengthen the maritime sector’s resilience against cyber risks and help ensure the safety of operations.

Milestone Dates: The final rule on MTSA Cyber Regulations published by the USCG goes into effect July 16, 2025, which includes a cybersecurity training deadline on January 12, 2026 and a full compliance deadline of July 2027.

Cybersecurity Solutions to Support MTSA Compliance


IACS E26 and E27 Cyber Regulations

IACS E26 regulations establish cybersecurity requirements for vessels and shipbuilding processes. These standards ensure that vessels are designed, constructed and operated with robust cybersecurity measures to protect onboard systems from cyber threats.

IACS E27 regulations address cyber resilience of individual systems and equipment installed on the ship, with particular emphasis on the security of third-party equipment and systems.

Milestone Date: The IACS E26 and E27 regulations are mandatory for new ships contracted for construction on or after July 1, 2024, and are strongly recommended for consideration by ship owners in their existing fleets to improve cyber security preparedness.

Cybersecurity Solutions to Support IACS Compliance

Why Are These Regulations Important?

Non-compliance with these regulations can result in operational disruptions, financial losses due to cyber incidents and Regulatory penalties and reputational damage.

By proactively addressing these regulations, maritime stakeholders can:

  • Protect operations from cyber risks.
  • Enhance safety of passengers and crew.
  • Ensure compliance with evolving industry standards.
  • Build trust with customers, regulators and partners.

From the Knowledge Center

 

Managing Maritime Cyber Risk – Rising to USCG's New Maritime Security Directive

The USCG's new directive mandates cybersecurity measures for US-flagged vessels and facilities. Discover how to prepare your organization to meet these challenges head-on.
Read More
 

Operationalizing Maritime Cybersecurity: A Strategic Approach for the Cruise Industry

Explore how the cruise industry can leverage specific operational readiness principles as a framework for building cybersecurity resilience, enhancing guest experiences and safeguarding operations.
Read More
 

Reducing Cybersecurity Risks in MTSA-Regulated Facilities

Discover how we increased visibility and reduced cybersecurity risks in MTSA-Regulated Facilities by conducting vulnerability assessments and creating a mitigation plan and roadmap to enhance cyber posture.
Read More
Back to top