Skip to content

Evidence request lists

US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements

Evidence request list. 33 controls, 33 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

33 CFR Part 105 Facility Security

MTSA-101.105
Applicability Determination

Determine whether the facility, vessel, or outer continental shelf facility is regulated under 33 CFR Parts 104, 105, or 106 based on type, size, cargo, passengers, and operations, and document the applicability and any associated risk based decisions.

Artefacts an auditor will ask for
  • Applicability assessment
  • Letter of recognition from cognizant Captain of the Port (COTP)
  • Records of communications with USCG
  • Vessel or facility characteristics confirming coverage
Where this commonly fails
  • No documented applicability decision
  • Changes to operations not reassessed
  • Outer continental shelf operations omitted
MTSA-105.200
Facility Security Officer Responsibilities

Designate a qualified Facility Security Officer responsible for development, implementation, maintenance, and amendment of the Facility Security Plan, including cybersecurity components and coordination with IT and operational technology personnel.

Artefacts an auditor will ask for
  • FSO designation letter
  • FSO training records (USCG approved course)
  • Position description including cyber responsibilities
  • Coordination evidence with IT and OT teams
Where this commonly fails
  • FSO has no cyber background and no IT counterpart designated
  • Training expired
  • No documented coordination with corporate CISO
MTSA-105.255
Maritime Security (MARSEC) Level Implementation

Implement security measures appropriate to the prevailing MARSEC level for personnel, access, restricted areas, cargo handling, vessel stores, monitoring, and cyber systems, and step up measures upon notification of elevated MARSEC.

Artefacts an auditor will ask for
  • MARSEC change drill records
  • Procedure mapping measures to each MARSEC level for cyber systems
  • Notification logs from COTP
  • Step up actions taken
Where this commonly fails
  • No cyber specific measures defined per MARSEC level
  • Drills do not test cyber response
  • Notifications not promptly acted upon
MTSA-105.305
Facility Security Assessment

Conduct a Facility Security Assessment that identifies critical assets and infrastructure, identifies threats, vulnerabilities, and consequences, and incorporates cybersecurity vulnerabilities of computer systems and networks that could affect MTSA security operations.

Artefacts an auditor will ask for
  • Facility Security Assessment (FSA) including cyber section
  • Asset inventory of operational and information technology
  • Threat scenarios including cyber and blended attacks
  • Consequence analysis
Where this commonly fails
  • FSA does not include cybersecurity per NVIC 01 20
  • OT systems not inventoried
  • Threat list outdated and missing current TTPs
MTSA-105.405
Facility Security Plan with Cybersecurity Annex

Develop, submit, and maintain a Facility Security Plan approved by the Captain of the Port that addresses all MTSA requirements and includes cybersecurity measures commensurate with the assessed risks, either as an integrated section or as a separate cyber annex.

Artefacts an auditor will ask for
  • Approved FSP with cyber annex
  • COTP approval letter
  • Annual review records
  • Amendment submission and approvals
Where this commonly fails
  • FSP submitted without cybersecurity addendum after 2020
  • No annual review
  • Plan amendments not communicated to COTP

Cyber Assessment

USMTSA-2
Cybersecurity Assessment and CSO Designation

Per 33 CFR 101.105 + NVIC 2024-01: Cybersecurity Assessment + Cybersecurity Officer Designation + integrate cyber into FSP.

Artefacts an auditor will ask for
  • MTSA evidence for USMTSA-2
Where this commonly fails
  • FSP + cyber + USCG partial

Cyber Risk Management (NVIC 02-24)

MTSA-Access-Control
Access Control for Security Related Systems

Restrict logical access to systems supporting MTSA security functions through unique user identification, multi factor authentication for privileged or remote access, role based authorization, and periodic recertification.

Artefacts an auditor will ask for
  • Identity provider configuration
  • MFA enforcement evidence for OT remote and privileged access
  • Access review records
  • Removal of access for terminated personnel
Where this commonly fails
  • Shared operator accounts in HMIs
  • Default vendor credentials still in use
  • Remote access without MFA
MTSA-Monitoring
Continuous Monitoring and Logging

Implement monitoring and logging of MTSA security related systems including access events, configuration changes, network communications, and anomaly indicators, with retention, review, and integration with incident response.

Artefacts an auditor will ask for
  • Logging standard for OT and IT
  • SIEM or log aggregation configuration
  • Sample alerts and triage records
  • Log retention evidence
Where this commonly fails
  • OT logs not collected centrally
  • Retention under 90 days
  • No detection use cases for OT protocols
MTSA-NVIC-02-24
Alignment with Updated USCG Cyber Policy

Align facility and vessel cybersecurity programs with current USCG cybersecurity policy updates, including any proposed or final rules on cybersecurity in the marine transportation system, by tracking regulatory developments and updating plans accordingly.

Artefacts an auditor will ask for
  • Regulatory tracker
  • Gap assessment against current USCG cyber rule proposals
  • Implementation plan and milestones
  • Briefings to leadership
Where this commonly fails
  • No formal tracking of USCG cyber rulemaking
  • Gap assessment outdated
  • Implementation plan lacks owners and dates
MTSA-Network-Segmentation
Network Segmentation Between IT and OT

Separate business information technology networks from operational technology networks supporting MTSA security functions using firewalls, demilitarized zones, unidirectional gateways where appropriate, and documented rule sets.

Artefacts an auditor will ask for
  • Network architecture diagrams
  • Firewall rule sets between IT and OT zones
  • Documented data flows
  • Annual rule review evidence
Where this commonly fails
  • Flat networks with no segmentation between business and OT
  • Permissive any any rules in firewalls
  • Engineering workstations dual homed
MTSA-OT-Inventory
Operational Technology Asset Inventory

Maintain an inventory of operational technology and industrial control systems that perform security related functions including cargo handling, vessel monitoring, access control, surveillance, and communications, with criticality ratings and ownership.

Artefacts an auditor will ask for
  • OT asset register with criticality
  • Network diagrams of OT environments
  • Ownership and support contracts
  • Firmware and software versions
Where this commonly fails
  • OT inventory absent or incomplete
  • No criticality ratings tied to MTSA security operations
  • Vendor remote access undocumented
MTSA-Patch-Management
Patch and Vulnerability Management

Maintain a process to identify, evaluate, and apply security patches and vendor advisories for systems supporting MTSA security functions, with compensating controls when patching is not feasible and documented risk acceptance.

Artefacts an auditor will ask for
  • Patch and vulnerability management procedure
  • Patch deployment records for OT systems
  • Vendor advisory tracking (CISA, ICS CERT)
  • Compensating control documentation
Where this commonly fails
  • No OT specific patch program
  • Vendor advisories not monitored
  • Compensating controls undocumented
MTSA-Removable-Media
Removable Media and Portable Device Controls

Establish procedures and technical controls to scan, restrict, and monitor the use of removable media and portable devices in operational environments, including USB drives, mobile devices, and contractor laptops connecting to MTSA related systems.

Artefacts an auditor will ask for
  • Removable media policy
  • Kiosk based scanning evidence
  • USB port restriction configuration on OT endpoints
  • Contractor device check procedure
Where this commonly fails
  • USB ports unrestricted on HMIs
  • No kiosk scanning at facility entry
  • Vendor laptops connect without inspection
MTSA-Supply-Chain
Supply Chain Risk Management for Security Systems

Apply supply chain risk management to hardware, software, and services that support MTSA security functions, including assessment of providers, integrity verification, and consideration of country of origin and prohibited sources.

Artefacts an auditor will ask for
  • Vendor risk assessments
  • Software bill of materials for security related systems
  • Compliance with Section 889 and CISA guidance
  • Hardware integrity verification procedures
Where this commonly fails
  • No SBOM for OT software
  • Prohibited country sourced equipment in security systems
  • Vendor assessments not performed for OT suppliers
MTSA-Vendor-Remote-Access
Third Party and Vendor Remote Access

Govern third party and vendor access to systems supporting MTSA security functions through pre approval, time bounded access, MFA, jump hosts or brokered access, session recording, and contractual security obligations.

Artefacts an auditor will ask for
  • Vendor access policy
  • Approval workflow records
  • Jump host configuration
  • Session recording samples
Where this commonly fails
  • Always on vendor VPN tunnels
  • No session recording for OT vendor access
  • Contracts lack security clauses

Incident Reporting

USMTSA-3
Reportable Suspicious Activity (RSA) and Cyber Incident Reporting

Per MTSA: incident reporting to USCG + NRC + RSA reporting + cooperation with USCG.

Artefacts an auditor will ask for
  • MTSA evidence for USMTSA-3
Where this commonly fails
  • FSP + cyber + USCG partial

Incident Response and Reporting

MTSA-Cyber-Incident-Response
Cyber Incident Response Procedures

Establish and maintain procedures to detect, contain, eradicate, and recover from cyber incidents affecting MTSA security functions, with predefined roles, communications, evidence preservation, and integration with physical security response.

Artefacts an auditor will ask for
  • Cyber IR plan integrated with FSP
  • Tabletop exercise records
  • Sample incident records
  • Lessons learned documents
Where this commonly fails
  • Cyber IR plan separate from facility security response
  • No tabletop covering OT scenarios
  • Evidence preservation procedures absent
MTSA-Incident-Reporting
Reporting of Breaches of Security and Suspicious Activity

Report breaches of security, suspicious activity, transportation security incidents, and cyber incidents that may affect facility or vessel security to the National Response Center and the Captain of the Port without delay, and follow up with written reports as required.

Artefacts an auditor will ask for
  • Reporting procedure
  • NRC call records
  • Written reports to COTP
  • After action reports
Where this commonly fails
  • No 24 hour reporting capability for cyber events
  • Reports lack required content
  • No coordination with corporate incident response

Security Plan

USMTSA-1
Facility Security Assessment and Plan

Per MTSA + 33 CFR Parts 101-106 + USCG NVIC 2024-01 cyber update: Facility Security Assessment + Facility Security Plan (FSP) + Format and Content of FSP.

Artefacts an auditor will ask for
  • MTSA evidence for USMTSA-1
Where this commonly fails
  • FSP + cyber + USCG partial

Training

USMTSA-4
Training, Drills, Exercises

Per MTSA: training + drills + exercises + cybersecurity awareness + USCG approval.

Artefacts an auditor will ask for
  • MTSA evidence for USMTSA-4
Where this commonly fails
  • FSP + cyber + USCG partial

Training, Drills, Audit and Records

MTSA-Audit
Annual Audit of the Security Plan

Conduct an annual audit of the Facility Security Plan and supporting security operations, including cyber controls, with documented scope, methodology, findings, and corrective action plans submitted to facility leadership and the FSO.

Artefacts an auditor will ask for
  • Annual audit report
  • Auditor qualifications
  • Findings and corrective action plan
  • Audit closure evidence
Where this commonly fails
  • Audit performed by FSO without independence
  • Cyber section omitted from audit scope
  • Corrective actions overdue
MTSA-Drills-Exercises
Drills and Exercises Including Cyber

Conduct quarterly security drills and annual security exercises that test the Facility Security Plan, including scenarios involving cyber compromise of security related systems, with documented results, lessons learned, and corrective actions.

Artefacts an auditor will ask for
  • Drill schedule and execution records
  • Annual exercise after action report
  • Cyber scenarios injected
  • Corrective action tracking
Where this commonly fails
  • Drills repeat the same physical scenarios
  • No cyber exercise in last 12 months
  • Corrective actions not tracked to closure
MTSA-Recordkeeping
Recordkeeping and Records Protection

Maintain records of training, drills, exercises, incidents, MARSEC level changes, declarations of security, audits, and annual reviews for at least two years and protect records from unauthorized disclosure as sensitive security information.

Artefacts an auditor will ask for
  • Records retention schedule
  • Access controls protecting SSI marked records
  • Sample records for required categories
  • Disposal records
Where this commonly fails
  • Records dispersed across personal folders
  • SSI markings inconsistent
  • Less than two year retention
MTSA-Training-Cyber
Cybersecurity Training and Awareness

Provide cybersecurity training to facility security personnel, IT and OT operators, and all employees with access to MTSA security systems, with role specific content and refresher frequency aligned to risk.

Artefacts an auditor will ask for
  • Annual training records
  • Role specific curricula for FSO, IT, OT, and operators
  • Phishing simulation results
  • New hire training completion
Where this commonly fails
  • Generic awareness without OT scenarios
  • No training for OT vendors and contractors
  • Records incomplete

USCG Maritime Cybersecurity: Cybersecurity Plan and Measures

CYB-1
Cybersecurity Plan Development

Owners and operators must develop and maintain a Cybersecurity Plan submitted to USCG within 24 months.

Artefacts an auditor will ask for
  • Network segmentation diagrams for OT and IT environments
  • Facility Security Assessment (FSA) including cybersecurity
  • Facility Security Plan (FSP) with cyber annex
  • Cyber incident response plan and drill records
Where this commonly fails
  • Vendor and contractor access not adequately controlled
  • Drills exclude cyber scenarios
  • Remote access to OT lacks MFA and logging
  • Cybersecurity not integrated into FSA and FSP
CYB-2
Account Security Measures

Default passwords must be changed, minimum password strength enforced, and MFA implemented on accessible systems.

Artefacts an auditor will ask for
  • Facility Security Assessment (FSA) including cybersecurity
  • Cyber incident response plan and drill records
  • Facility Security Plan (FSP) with cyber annex
  • Cybersecurity Officer (CySO) designation and training records
Where this commonly fails
  • Remote access to OT lacks MFA and logging
  • Vendor and contractor access not adequately controlled
  • Drills exclude cyber scenarios
  • Cybersecurity Officer role unfilled or undertrained
CYB-3
Device Security Measures

IT and OT device security measures must be documented and maintained in the Cybersecurity Plan.

Artefacts an auditor will ask for
  • Network segmentation diagrams for OT and IT environments
  • Facility Security Plan (FSP) with cyber annex
  • Cyber incident response plan and drill records
  • Cybersecurity Officer (CySO) designation and training records
Where this commonly fails
  • Remote access to OT lacks MFA and logging
  • Cybersecurity not integrated into FSA and FSP
  • Cybersecurity Officer role unfilled or undertrained
  • Drills exclude cyber scenarios
CYB-4
Data Security Measures

Measures to protect sensitive operational and business data from unauthorized access must be implemented.

Artefacts an auditor will ask for
  • Cyber incident response plan and drill records
  • Penetration test and vulnerability scan reports for facility systems
  • Facility Security Plan (FSP) with cyber annex
  • Facility Security Assessment (FSA) including cybersecurity
Where this commonly fails
  • Vendor and contractor access not adequately controlled
  • Cybersecurity not integrated into FSA and FSP
  • Cybersecurity Officer role unfilled or undertrained
  • Drills exclude cyber scenarios
CYB-5
Cyber Incident Response Plan

A separate Cyber Incident Response Plan must be developed covering detection, containment, and recovery procedures.

Artefacts an auditor will ask for
  • Facility Security Plan (FSP) with cyber annex
  • Penetration test and vulnerability scan reports for facility systems
  • Cybersecurity Officer (CySO) designation and training records
  • Cyber incident response plan and drill records
Where this commonly fails
  • Remote access to OT lacks MFA and logging
  • Cybersecurity Officer role unfilled or undertrained
  • Cybersecurity not integrated into FSA and FSP
  • Vendor and contractor access not adequately controlled

Vessels and Outer Continental Shelf Facilities

VES-1
US-Flagged Vessel Cybersecurity

US-flagged vessels subject to MTSA must comply with cybersecurity assessment and plan requirements.

Artefacts an auditor will ask for
  • Cyber incident response plan and drill records
  • Penetration test and vulnerability scan reports for facility systems
  • Facility Security Plan (FSP) with cyber annex
  • Facility Security Assessment (FSA) including cybersecurity
Where this commonly fails
  • Cybersecurity not integrated into FSA and FSP
  • Vendor and contractor access not adequately controlled
  • Cybersecurity Officer role unfilled or undertrained
  • Remote access to OT lacks MFA and logging
VES-2
OCS Facility Cybersecurity

Outer Continental Shelf facilities must integrate cybersecurity into their security assessments and plans.

Artefacts an auditor will ask for
  • Facility Security Assessment (FSA) including cybersecurity
  • Facility Security Plan (FSP) with cyber annex
  • Cybersecurity Officer (CySO) designation and training records
  • Cyber incident response plan and drill records
Where this commonly fails
  • Cybersecurity Officer role unfilled or undertrained
  • Vendor and contractor access not adequately controlled
  • Remote access to OT lacks MFA and logging
  • Drills exclude cyber scenarios
VES-3
Penetration Testing

Penetration test results must be documented and available to the Coast Guard upon request.

Artefacts an auditor will ask for
  • Cybersecurity Officer (CySO) designation and training records
  • Network segmentation diagrams for OT and IT environments
  • Facility Security Assessment (FSA) including cybersecurity
  • Penetration test and vulnerability scan reports for facility systems
Where this commonly fails
  • Remote access to OT lacks MFA and logging
  • Cybersecurity Officer role unfilled or undertrained
  • Drills exclude cyber scenarios
  • Vendor and contractor access not adequately controlled
VES-4
Recordkeeping Requirements

Records of cybersecurity assessments, plans, training, and incidents must be retained for audit purposes.

Artefacts an auditor will ask for
  • Cybersecurity Officer (CySO) designation and training records
  • Network segmentation diagrams for OT and IT environments
  • Cyber incident response plan and drill records
  • Penetration test and vulnerability scan reports for facility systems
Where this commonly fails
  • Remote access to OT lacks MFA and logging
  • Cybersecurity Officer role unfilled or undertrained
  • Drills exclude cyber scenarios
  • Vendor and contractor access not adequately controlled
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements framework page.