# What happened The U.S. Coast Guard issued cybersecurity regulations that apply to covered U.S.-flagged vessels, facilities and Outer Continental Shelf facilities. The rule became effective July 16, 2025, and includes phased compliance requirements. BroCoTec, a Houston maritime cybersecurity specialist, warns many operators are behind and could face operational and financial consequences if they delay.
# Why this matters now Shipboard connectivity has expanded rapidly because of faster, lower-cost satellite internet. That connectivity often includes crew WiFi and streaming services. BroCoTec's CEO Nat Kemberling says many vessels still run business IT and critical operational technology (OT) on the same network. That configuration turns crew devices into potential entry points for attackers, especially on ships with legacy PLCs and unpatched systems.
The regulation requires specific actions and roles. Missing the July 16, 2027 milestones could lead to penalties up to $43,527 and could affect vessel clearance. BroCoTec calls the upcoming enforcement window a potential bottleneck for companies that delay and will make it harder to find qualified contractors at the last minute.
# What operators need to do immediately Start with an audit of your shipboard network architecture. Identify where IT and OT are combined and map all satellite and internet-connected devices, including crew WiFi and streaming hardware.
Concrete actions recommended by BroCoTec:
- Implement network segmentation and firewall isolation so crew networks cannot reach critical OT systems.
- Apply logical access controls between business IT and OT.
- Review satellite communications and other internet-connected equipment for any pathway into OT networks.
- Assess legacy PLCs and other OT for known vulnerabilities and unpatched software.
- Designate a Cybersecurity Officer who is responsible for compliance and available to the Coast Guard as required.
- Complete a Cybersecurity Assessment and submit a Cybersecurity Plan for Coast Guard approval.
- Establish and document a Cyber Incident Response Plan, with reporting procedures to the National Response Center.
- Schedule required cybersecurity drills twice yearly and exercises annually, plus personnel training.
Start remediation now to avoid a late rush for contractors and to spread the work over weeks or months rather than days.
# Practical sequencing
# Risks if you delay
# Bottom line Treat compliance with 33 CFR Part 101, Subpart F as an immediate priority. The technical work—segmentation, firewall rules, legacy OT mitigation, and plan preparation—can take weeks or months. Begin audits and remediation now, designate the required Cybersecurity Officer, and schedule drills so you meet the July 16, 2027 milestones without a last-minute scramble.