New Coast Guard Guidance Released
What the Coast Guard’s New Guidance Means for FSOs, CySOs, and Maritime Cyber Readiness
June 16, 2026 | By Ron Frechette | Founder & Managing Director | CyberSurv

The Maritime Industry is Entering a New Chapter
Just a few weeks ago, we published an article discussing why maritime cybersecurity is no longer a future concern. The first wave of maritime cyber readiness has already begun.
Now, with the Coast Guard’s release of additional guidance supporting 33 CFR Part 101 Subpart F, maritime organizations have gained greater clarity on Cybersecurity Assessments (CSAs), waiver and equivalency requests, and the path toward Cybersecurity Plan development.
For many organizations, this is the guidance they have been waiting for.
But after reviewing the new material, we believe the most important takeaway isn’t about paperwork, plans, or compliance deadlines.
It’s about understanding risk.
The Guidance the Industry Has Been Waiting For
One of the biggest questions we have heard from maritime operators over the past several months has been:
“What exactly should be included in our Cybersecurity Plan?”
The Coast Guard’s new guidance provides valuable insight into that question. More importantly, it reinforces something we’ve been discussing with clients since Subpart F was finalized.
Before organizations decide what belongs in a Cybersecurity Plan, they first need to understand their operational environment.
That means identifying critical functions, inventorying systems, mapping dependencies, understanding third-party relationships, and evaluating how technology supports day-to-day operations.
In other words, readiness starts with awareness.
The CSA Is About More Than Compliance
Many organizations initially view the Cybersecurity Assessment as another compliance requirement. We see it differently.
The CSA provides an opportunity to uncover risks, dependencies, and vulnerabilities that may have gone unnoticed for years.
The Coast Guard’s guidance encourages organizations to look beyond obvious operational technology systems and evaluate supporting applications, cloud services, communications platforms, vendor connections, and business systems that could impact operations if compromised.
That changes the conversation. Instead of asking: “Is this system in scope?“
Organizations should ask: “Could the compromise of this system disrupt operations?”
In our experience, the most significant risks are often discovered in places organizations weren’t looking.
- An undocumented connection.
- A forgotten application.
- A third-party dependency.
- An unsupported system that quietly became critical to operations.
Those discoveries often provide more value than the compliance exercise itself.
Bringing FSOs and CySOs Together
As a U.S. Coast Guard veteran, one thing I’ve learned throughout my career is that security works best when people work together toward a common mission.
Historically, Facility Security Officers (FSOs) have been responsible for protecting maritime facilities from physical threats while ensuring compliance with Facility Security Plans and MTSA requirements.
Cybersecurity teams often operated separately, focused on networks, systems, and technical controls.
Subpart F is changing that.
For perhaps the first time, FSOs and Cybersecurity Officers (CySOs) are being asked to come to the same table, evaluate operational risk together, and develop a shared understanding of what could impact the safety, security, and resilience of maritime operations.
We believe that is one of the most positive developments emerging from the Coast Guard’s cybersecurity requirements.
Cybersecurity is no longer simply an IT issue. It is now part of the broader maritime security mission.
Why CyberSurv Partnered with Seebald & Associates
This evolving relationship between physical security and cybersecurity is one of the reasons CyberSurv partnered with Seebald & Associates.
For decades, Seebald has helped maritime organizations develop and maintain Facility Security Plans, conduct security assessments, and navigate complex maritime security requirements.
At CyberSurv, we bring decades of cybersecurity, risk management, governance, and compliance expertise to the table.
Together, we are helping maritime organizations bridge the gap between physical security and cybersecurity by bringing FSOs, CySOs, operational leaders, and executive leadership together to create a unified approach to risk management.
The strongest security programs are not built in silos.
They integrate physical security, operational security, and cybersecurity into a single strategy focused on protecting the mission.
What Maritime Organizations Should Do Now
The Coast Guard has provided additional clarity, but organizations should not wait for every policy question to be answered before taking action. Now is the time to:
- Begin planning for your Cybersecurity Assessment.
- Build a comprehensive inventory of systems and dependencies.
- Identify operationally critical functions.
- Evaluate third-party and cloud-based risks.
- Bring FSOs and CySOs together to establish a shared understanding of operational risk.
- Align cybersecurity planning with existing Facility Security Plans and security programs.
Organizations that take these steps today will be far better positioned as Coast Guard implementation efforts continue to evolve.
Final Thoughts
The release of this guidance represents an important milestone for the maritime industry. More importantly, it reinforces a simple principle:
You cannot manage risks you have not identified.
The organizations that benefit most from the Cybersecurity Assessment process will not be the ones focused solely on checking a regulatory box.
They will be the ones using the process to better understand their operations, strengthen resilience, and build stronger partnerships between security, operations, and technology teams. Maritime cyber readiness is no longer on the horizon. It is here. And for many organizations, the most important work is just beginning.
Building Readiness Beyond Compliance
CyberSurv helps maritime organizations identify cyber risks, operational dependencies, and compliance gaps through our Maritime Cyber Readiness Assessment (MCRA℠), Cybersecurity Assessments, RiskGuard 365℠ Cyber Hygiene Program and Security Leadership Program (SLP℠).
Working alongside Seebald & Associates, we help organizations integrate physical security, operational security, and cybersecurity into a comprehensive risk management strategy designed to support both compliance and operational resilience.
If your organization is preparing for a Cybersecurity Assessment under 33 CFR Part 101 Subpart F, we’d welcome the opportunity to discuss your readiness journey.
Wishing everyone a safe, secure, and successful summer season.