US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements
Evidence request list. 33 controls, 33 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
33 CFR Part 105 Facility Security
Determine whether the facility, vessel, or outer continental shelf facility is regulated under 33 CFR Parts 104, 105, or 106 based on type, size, cargo, passengers, and operations, and document the applicability and any associated risk based decisions.
- Applicability assessment
- Letter of recognition from cognizant Captain of the Port (COTP)
- Records of communications with USCG
- Vessel or facility characteristics confirming coverage
- No documented applicability decision
- Changes to operations not reassessed
- Outer continental shelf operations omitted
Designate a qualified Facility Security Officer responsible for development, implementation, maintenance, and amendment of the Facility Security Plan, including cybersecurity components and coordination with IT and operational technology personnel.
- FSO designation letter
- FSO training records (USCG approved course)
- Position description including cyber responsibilities
- Coordination evidence with IT and OT teams
- FSO has no cyber background and no IT counterpart designated
- Training expired
- No documented coordination with corporate CISO
Implement security measures appropriate to the prevailing MARSEC level for personnel, access, restricted areas, cargo handling, vessel stores, monitoring, and cyber systems, and step up measures upon notification of elevated MARSEC.
- MARSEC change drill records
- Procedure mapping measures to each MARSEC level for cyber systems
- Notification logs from COTP
- Step up actions taken
- No cyber specific measures defined per MARSEC level
- Drills do not test cyber response
- Notifications not promptly acted upon
Conduct a Facility Security Assessment that identifies critical assets and infrastructure, identifies threats, vulnerabilities, and consequences, and incorporates cybersecurity vulnerabilities of computer systems and networks that could affect MTSA security operations.
- Facility Security Assessment (FSA) including cyber section
- Asset inventory of operational and information technology
- Threat scenarios including cyber and blended attacks
- Consequence analysis
- FSA does not include cybersecurity per NVIC 01 20
- OT systems not inventoried
- Threat list outdated and missing current TTPs
Develop, submit, and maintain a Facility Security Plan approved by the Captain of the Port that addresses all MTSA requirements and includes cybersecurity measures commensurate with the assessed risks, either as an integrated section or as a separate cyber annex.
- Approved FSP with cyber annex
- COTP approval letter
- Annual review records
- Amendment submission and approvals
- FSP submitted without cybersecurity addendum after 2020
- No annual review
- Plan amendments not communicated to COTP
Cyber Assessment
Per 33 CFR 101.105 + NVIC 2024-01: Cybersecurity Assessment + Cybersecurity Officer Designation + integrate cyber into FSP.
- MTSA evidence for USMTSA-2
- FSP + cyber + USCG partial
Cyber Risk Management (NVIC 02-24)
Restrict logical access to systems supporting MTSA security functions through unique user identification, multi factor authentication for privileged or remote access, role based authorization, and periodic recertification.
- Identity provider configuration
- MFA enforcement evidence for OT remote and privileged access
- Access review records
- Removal of access for terminated personnel
- Shared operator accounts in HMIs
- Default vendor credentials still in use
- Remote access without MFA
Implement monitoring and logging of MTSA security related systems including access events, configuration changes, network communications, and anomaly indicators, with retention, review, and integration with incident response.
- Logging standard for OT and IT
- SIEM or log aggregation configuration
- Sample alerts and triage records
- Log retention evidence
- OT logs not collected centrally
- Retention under 90 days
- No detection use cases for OT protocols
Align facility and vessel cybersecurity programs with current USCG cybersecurity policy updates, including any proposed or final rules on cybersecurity in the marine transportation system, by tracking regulatory developments and updating plans accordingly.
- Regulatory tracker
- Gap assessment against current USCG cyber rule proposals
- Implementation plan and milestones
- Briefings to leadership
- No formal tracking of USCG cyber rulemaking
- Gap assessment outdated
- Implementation plan lacks owners and dates
Separate business information technology networks from operational technology networks supporting MTSA security functions using firewalls, demilitarized zones, unidirectional gateways where appropriate, and documented rule sets.
- Network architecture diagrams
- Firewall rule sets between IT and OT zones
- Documented data flows
- Annual rule review evidence
- Flat networks with no segmentation between business and OT
- Permissive any any rules in firewalls
- Engineering workstations dual homed
Maintain an inventory of operational technology and industrial control systems that perform security related functions including cargo handling, vessel monitoring, access control, surveillance, and communications, with criticality ratings and ownership.
- OT asset register with criticality
- Network diagrams of OT environments
- Ownership and support contracts
- Firmware and software versions
- OT inventory absent or incomplete
- No criticality ratings tied to MTSA security operations
- Vendor remote access undocumented
Maintain a process to identify, evaluate, and apply security patches and vendor advisories for systems supporting MTSA security functions, with compensating controls when patching is not feasible and documented risk acceptance.
- Patch and vulnerability management procedure
- Patch deployment records for OT systems
- Vendor advisory tracking (CISA, ICS CERT)
- Compensating control documentation
- No OT specific patch program
- Vendor advisories not monitored
- Compensating controls undocumented
Establish procedures and technical controls to scan, restrict, and monitor the use of removable media and portable devices in operational environments, including USB drives, mobile devices, and contractor laptops connecting to MTSA related systems.
- Removable media policy
- Kiosk based scanning evidence
- USB port restriction configuration on OT endpoints
- Contractor device check procedure
- USB ports unrestricted on HMIs
- No kiosk scanning at facility entry
- Vendor laptops connect without inspection
Apply supply chain risk management to hardware, software, and services that support MTSA security functions, including assessment of providers, integrity verification, and consideration of country of origin and prohibited sources.
- Vendor risk assessments
- Software bill of materials for security related systems
- Compliance with Section 889 and CISA guidance
- Hardware integrity verification procedures
- No SBOM for OT software
- Prohibited country sourced equipment in security systems
- Vendor assessments not performed for OT suppliers
Govern third party and vendor access to systems supporting MTSA security functions through pre approval, time bounded access, MFA, jump hosts or brokered access, session recording, and contractual security obligations.
- Vendor access policy
- Approval workflow records
- Jump host configuration
- Session recording samples
- Always on vendor VPN tunnels
- No session recording for OT vendor access
- Contracts lack security clauses
Incident Reporting
Per MTSA: incident reporting to USCG + NRC + RSA reporting + cooperation with USCG.
- MTSA evidence for USMTSA-3
- FSP + cyber + USCG partial
Incident Response and Reporting
Establish and maintain procedures to detect, contain, eradicate, and recover from cyber incidents affecting MTSA security functions, with predefined roles, communications, evidence preservation, and integration with physical security response.
- Cyber IR plan integrated with FSP
- Tabletop exercise records
- Sample incident records
- Lessons learned documents
- Cyber IR plan separate from facility security response
- No tabletop covering OT scenarios
- Evidence preservation procedures absent
Report breaches of security, suspicious activity, transportation security incidents, and cyber incidents that may affect facility or vessel security to the National Response Center and the Captain of the Port without delay, and follow up with written reports as required.
- Reporting procedure
- NRC call records
- Written reports to COTP
- After action reports
- No 24 hour reporting capability for cyber events
- Reports lack required content
- No coordination with corporate incident response
Security Plan
Per MTSA + 33 CFR Parts 101-106 + USCG NVIC 2024-01 cyber update: Facility Security Assessment + Facility Security Plan (FSP) + Format and Content of FSP.
- MTSA evidence for USMTSA-1
- FSP + cyber + USCG partial
Training
Per MTSA: training + drills + exercises + cybersecurity awareness + USCG approval.
- MTSA evidence for USMTSA-4
- FSP + cyber + USCG partial
Training, Drills, Audit and Records
Conduct an annual audit of the Facility Security Plan and supporting security operations, including cyber controls, with documented scope, methodology, findings, and corrective action plans submitted to facility leadership and the FSO.
- Annual audit report
- Auditor qualifications
- Findings and corrective action plan
- Audit closure evidence
- Audit performed by FSO without independence
- Cyber section omitted from audit scope
- Corrective actions overdue
Conduct quarterly security drills and annual security exercises that test the Facility Security Plan, including scenarios involving cyber compromise of security related systems, with documented results, lessons learned, and corrective actions.
- Drill schedule and execution records
- Annual exercise after action report
- Cyber scenarios injected
- Corrective action tracking
- Drills repeat the same physical scenarios
- No cyber exercise in last 12 months
- Corrective actions not tracked to closure
Maintain records of training, drills, exercises, incidents, MARSEC level changes, declarations of security, audits, and annual reviews for at least two years and protect records from unauthorized disclosure as sensitive security information.
- Records retention schedule
- Access controls protecting SSI marked records
- Sample records for required categories
- Disposal records
- Records dispersed across personal folders
- SSI markings inconsistent
- Less than two year retention
Provide cybersecurity training to facility security personnel, IT and OT operators, and all employees with access to MTSA security systems, with role specific content and refresher frequency aligned to risk.
- Annual training records
- Role specific curricula for FSO, IT, OT, and operators
- Phishing simulation results
- New hire training completion
- Generic awareness without OT scenarios
- No training for OT vendors and contractors
- Records incomplete
USCG Maritime Cybersecurity: Cybersecurity Plan and Measures
Owners and operators must develop and maintain a Cybersecurity Plan submitted to USCG within 24 months.
- Network segmentation diagrams for OT and IT environments
- Facility Security Assessment (FSA) including cybersecurity
- Facility Security Plan (FSP) with cyber annex
- Cyber incident response plan and drill records
- Vendor and contractor access not adequately controlled
- Drills exclude cyber scenarios
- Remote access to OT lacks MFA and logging
- Cybersecurity not integrated into FSA and FSP
Default passwords must be changed, minimum password strength enforced, and MFA implemented on accessible systems.
- Facility Security Assessment (FSA) including cybersecurity
- Cyber incident response plan and drill records
- Facility Security Plan (FSP) with cyber annex
- Cybersecurity Officer (CySO) designation and training records
- Remote access to OT lacks MFA and logging
- Vendor and contractor access not adequately controlled
- Drills exclude cyber scenarios
- Cybersecurity Officer role unfilled or undertrained
IT and OT device security measures must be documented and maintained in the Cybersecurity Plan.
- Network segmentation diagrams for OT and IT environments
- Facility Security Plan (FSP) with cyber annex
- Cyber incident response plan and drill records
- Cybersecurity Officer (CySO) designation and training records
- Remote access to OT lacks MFA and logging
- Cybersecurity not integrated into FSA and FSP
- Cybersecurity Officer role unfilled or undertrained
- Drills exclude cyber scenarios
Measures to protect sensitive operational and business data from unauthorized access must be implemented.
- Cyber incident response plan and drill records
- Penetration test and vulnerability scan reports for facility systems
- Facility Security Plan (FSP) with cyber annex
- Facility Security Assessment (FSA) including cybersecurity
- Vendor and contractor access not adequately controlled
- Cybersecurity not integrated into FSA and FSP
- Cybersecurity Officer role unfilled or undertrained
- Drills exclude cyber scenarios
A separate Cyber Incident Response Plan must be developed covering detection, containment, and recovery procedures.
- Facility Security Plan (FSP) with cyber annex
- Penetration test and vulnerability scan reports for facility systems
- Cybersecurity Officer (CySO) designation and training records
- Cyber incident response plan and drill records
- Remote access to OT lacks MFA and logging
- Cybersecurity Officer role unfilled or undertrained
- Cybersecurity not integrated into FSA and FSP
- Vendor and contractor access not adequately controlled
Vessels and Outer Continental Shelf Facilities
US-flagged vessels subject to MTSA must comply with cybersecurity assessment and plan requirements.
- Cyber incident response plan and drill records
- Penetration test and vulnerability scan reports for facility systems
- Facility Security Plan (FSP) with cyber annex
- Facility Security Assessment (FSA) including cybersecurity
- Cybersecurity not integrated into FSA and FSP
- Vendor and contractor access not adequately controlled
- Cybersecurity Officer role unfilled or undertrained
- Remote access to OT lacks MFA and logging
Outer Continental Shelf facilities must integrate cybersecurity into their security assessments and plans.
- Facility Security Assessment (FSA) including cybersecurity
- Facility Security Plan (FSP) with cyber annex
- Cybersecurity Officer (CySO) designation and training records
- Cyber incident response plan and drill records
- Cybersecurity Officer role unfilled or undertrained
- Vendor and contractor access not adequately controlled
- Remote access to OT lacks MFA and logging
- Drills exclude cyber scenarios
Penetration test results must be documented and available to the Coast Guard upon request.
- Cybersecurity Officer (CySO) designation and training records
- Network segmentation diagrams for OT and IT environments
- Facility Security Assessment (FSA) including cybersecurity
- Penetration test and vulnerability scan reports for facility systems
- Remote access to OT lacks MFA and logging
- Cybersecurity Officer role unfilled or undertrained
- Drills exclude cyber scenarios
- Vendor and contractor access not adequately controlled
Records of cybersecurity assessments, plans, training, and incidents must be retained for audit purposes.
- Cybersecurity Officer (CySO) designation and training records
- Network segmentation diagrams for OT and IT environments
- Cyber incident response plan and drill records
- Penetration test and vulnerability scan reports for facility systems
- Remote access to OT lacks MFA and logging
- Cybersecurity Officer role unfilled or undertrained
- Drills exclude cyber scenarios
- Vendor and contractor access not adequately controlled
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements framework page.