Back to Frameworks

US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements

United States (USCG)
v2002 (NVIC 01-20, 2024 updates)
4 domains
4 controls

The US Maritime Transportation Security Act (MTSA, 2002) and subsequent US Coast Guard (USCG) regulations establish security requirements for US maritime facilities and vessels. USCG Navigation and Vessel Inspection Circular (NVIC) 01-20 provides guidance on addressing cyber risks in Facility Security Assessments (FSA) and Facility Security Plans (FSP) per 33 CFR Part 105. NVIC 05-17 addresses cyber risks in Area Maritime Security Plans. The 2024 USCG cyber incident reporting rule establishes mandatory cyber incident reporting for MTSA-regulated facilities. Applies to port facilities, OCS (outer continental shelf) facilities, and vessels operating in US waters.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (4)

Cyber Assessment

1 controls
Controls in the Cyber Assessment domain of US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements1 controls
CodeTitle
USMTSA-2Cybersecurity Assessment and CSO Designation

Incident Reporting

1 controls
Controls in the Incident Reporting domain of US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements1 controls
CodeTitle
USMTSA-3Reportable Suspicious Activity (RSA) and Cyber Incident Reporting

Security Plan

1 controls
Controls in the Security Plan domain of US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements1 controls
CodeTitle
USMTSA-1Facility Security Assessment and Plan

Training

1 controls
Controls in the Training domain of US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements1 controls
CodeTitle
USMTSA-4Training, Drills, Exercises

Your Compliance Coverage

If you comply with US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements, you already cover:

+ 105 more: IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems (50%), IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1) (50%)

See all 108 mapped frameworks ↓

Maps to 108 other frameworks

4 total controls
ISO/IEC 27400:2022
2 source controls mapped|2 target controls covered
50%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
2 source controls mapped|3 target controls covered
50%
FedRAMP Rev 5
2 source controls mapped|2 target controls covered
50%
NIS2 Directive Implementing Acts
2 source controls mapped|2 target controls covered
50%
50%
ISO/IEC 27010:2015
2 source controls mapped|2 target controls covered
50%
UK Gambling Commission - Cyber Resilience Requirements
2 source controls mapped|1 target controls covered
50%
Protective Security Policy Framework (PSPF) Release 2024
2 source controls mapped|2 target controls covered
50%
Papua New Guinea National Cybersecurity Policy & Cybercrime Act (2016)
1 source controls mapped|1 target controls covered
25%
Vietnam Law on Cybersecurity (No. 24/2018/QH14)
1 source controls mapped|1 target controls covered
25%
BSI IT-Grundschutz
1 source controls mapped|3 target controls covered
25%
API 1164
1 source controls mapped|3 target controls covered
25%
ISO/IEC 30111:2019
1 source controls mapped|2 target controls covered
25%
Bahrain PDPL
1 source controls mapped|2 target controls covered
25%
ISO/IEC 29147:2018
1 source controls mapped|1 target controls covered
25%
Barbados Data Protection Act 2019
1 source controls mapped|1 target controls covered
25%
AWS Well-Architected Security Pillar
1 source controls mapped|1 target controls covered
25%
Azure Security Benchmark
1 source controls mapped|1 target controls covered
25%
APRA CPS 234
1 source controls mapped|3 target controls covered
25%
ASD Strategies to Mitigate Cyber Security Incidents
1 source controls mapped|2 target controls covered
25%
COSO Internal Control - Integrated Framework (2013)
1 source controls mapped|1 target controls covered
25%
Canada ITSG-33 - IT Security Risk Management
1 source controls mapped|1 target controls covered
25%
APPI
1 source controls mapped|2 target controls covered
25%
NIST AI Risk Management Framework (AI RMF 1.0)
1 source controls mapped|1 target controls covered
25%
APRA CPS 230 Operational Risk Management
1 source controls mapped|1 target controls covered
25%
NIST SP 800-171
1 source controls mapped|1 target controls covered
25%
FFIEC Cybersecurity Assessment Tool (CAT)
1 source controls mapped|1 target controls covered
25%
ASIS SPC.1-2009 - Organizational Resilience Standard
1 source controls mapped|1 target controls covered
25%
25%
Family Educational Rights and Privacy Act (FERPA)
1 source controls mapped|1 target controls covered
25%
FIRST CSIRT Services Framework and Standards
1 source controls mapped|1 target controls covered
25%
FISMA
1 source controls mapped|2 target controls covered
25%
FTC GLBA Safeguards Rule (16 CFR Part 314)
1 source controls mapped|1 target controls covered
25%
Ghana Cybersecurity Act
1 source controls mapped|3 target controls covered
25%
GLBA
1 source controls mapped|2 target controls covered
25%
HITECH Act
1 source controls mapped|1 target controls covered
25%
HKMA SPM
1 source controls mapped|1 target controls covered
25%
25%
IEEE 1686
1 source controls mapped|1 target controls covered
25%
India CERT-In Cyber Security Directions 2022
1 source controls mapped|1 target controls covered
25%
India DPDP Act
1 source controls mapped|1 target controls covered
25%
Indiana Consumer Data Protection Act
1 source controls mapped|1 target controls covered
25%
Indonesia PDP Law
1 source controls mapped|2 target controls covered
25%
Iowa Consumer Data Protection Act
1 source controls mapped|2 target controls covered
25%
ISMAP (Japan)
1 source controls mapped|1 target controls covered
25%
Jamaica Data Protection Act 2020
1 source controls mapped|2 target controls covered
25%
Japan FSA Cybersecurity Guidelines for Financial Institutions
1 source controls mapped|1 target controls covered
25%
Kentucky Consumer Data Protection Act
1 source controls mapped|2 target controls covered
25%
South Korea PIPA
1 source controls mapped|2 target controls covered
25%
Laos Law on Prevention and Combating Cybercrime (2015)
1 source controls mapped|1 target controls covered
25%
Law No. 172-13 on the Protection of Personal Data
1 source controls mapped|1 target controls covered
25%
Ley Orgánica de Protección de Datos Personales (LOPDP)
1 source controls mapped|1 target controls covered
25%
LGPD
1 source controls mapped|1 target controls covered
25%
Liechtenstein DPA
1 source controls mapped|1 target controls covered
25%
Malaysia PDPA 2010
1 source controls mapped|2 target controls covered
25%
Maryland Online Data Privacy Act of 2024
1 source controls mapped|2 target controls covered
25%
Mauritius DPA
1 source controls mapped|1 target controls covered
25%
Mexico LFPDPPP
1 source controls mapped|1 target controls covered
25%
Minnesota Consumer Data Privacy Act
1 source controls mapped|1 target controls covered
25%
Monetary Authority of Singapore Technology Risk Management Guidelines
1 source controls mapped|1 target controls covered
25%
Montana Consumer Data Privacy Act
1 source controls mapped|1 target controls covered
25%
MTCS (Singapore)
1 source controls mapped|2 target controls covered
25%
Nebraska Data Privacy Act
1 source controls mapped|4 target controls covered
25%
NERC CIP
1 source controls mapped|1 target controls covered
25%
Nevada Gaming Control Board Cybersecurity Requirements
1 source controls mapped|1 target controls covered
25%
New Hampshire Data Privacy Act
1 source controls mapped|1 target controls covered
25%
New Jersey Data Privacy Act
1 source controls mapped|2 target controls covered
25%
Nigeria Data Protection Act 2023 (NDPA)
1 source controls mapped|4 target controls covered
25%
Nigeria Data Protection Regulation (NDPR)
1 source controls mapped|1 target controls covered
25%
Nigeria Open Banking Regulatory Framework (CBN, 2023)
1 source controls mapped|1 target controls covered
25%
NIS2 Directive
1 source controls mapped|2 target controls covered
25%
NIST SP 800-122
1 source controls mapped|1 target controls covered
25%
NIST SP 800-144
1 source controls mapped|1 target controls covered
25%
NIST SP 800-145
1 source controls mapped|1 target controls covered
25%
NIST SP 800-146
1 source controls mapped|1 target controls covered
25%
NRF Cybersecurity and Data Privacy Framework (National Retail Federation)
1 source controls mapped|1 target controls covered
25%
Oman National Cybersecurity Framework
1 source controls mapped|1 target controls covered
25%
Open Banking Security
1 source controls mapped|2 target controls covered
25%
Oregon Consumer Privacy Act
1 source controls mapped|1 target controls covered
25%
OSFI B-13
1 source controls mapped|3 target controls covered
25%
OWASP DevSecOps Maturity Model (DSOMM)
1 source controls mapped|1 target controls covered
25%
Pakistan Personal Data Protection Bill 2023
1 source controls mapped|1 target controls covered
25%
US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements
1 source controls mapped|1 target controls covered
25%
Uruguay DPL
1 source controls mapped|1 target controls covered
25%
UK GDPR (UK General Data Protection Regulation)
1 source controls mapped|1 target controls covered
25%
Turkey KVKK
1 source controls mapped|1 target controls covered
25%
Trinidad and Tobago Data Protection Act 2011
1 source controls mapped|1 target controls covered
25%
TSA Pipeline Cybersecurity Directives
1 source controls mapped|1 target controls covered
25%
Texas Data Privacy Act
1 source controls mapped|1 target controls covered
25%
Tanzania Personal Data Protection Act (Draft)
1 source controls mapped|1 target controls covered
25%
Taiwan PDPA
1 source controls mapped|1 target controls covered
25%
PSD2 SCA
1 source controls mapped|2 target controls covered
25%
Qatar DPL
1 source controls mapped|2 target controls covered
25%
Privacy Act 2020
1 source controls mapped|1 target controls covered
25%
POPIA
1 source controls mapped|1 target controls covered
25%
Peru DPL
1 source controls mapped|2 target controls covered
25%
Personal Data Act (personopplysningsloven)
1 source controls mapped|1 target controls covered
25%
PDPA Thailand
1 source controls mapped|1 target controls covered
25%
PDPA Singapore
1 source controls mapped|1 target controls covered
25%
ISO/IEC 27011:2024
1 source controls mapped|2 target controls covered
25%
ICAO Annex 17 - Aviation Security (AVSEC)
1 source controls mapped|1 target controls covered
25%
NAIC Insurance Data Security Model Law (MDL-668)
1 source controls mapped|1 target controls covered
25%
NIST Privacy Framework
1 source controls mapped|1 target controls covered
25%
TISAX - Trusted Information Security Assessment Exchange
1 source controls mapped|1 target controls covered
25%

Frequently Asked Questions

What is US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements?

US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements is a compliance framework from United States (USCG) with 4 domains and 4 controls. The US Maritime Transportation Security Act (MTSA, 2002) and subsequent US Coast Guard (USCG) regulations establish security requirements for US maritime facilities and vessels. USCG Navigation and Vessel Inspection Circular (NVIC) 01-20 provides guidance on addressing cyber risks in Facility Security Assessments (FSA) and Facility Security Plans (FSP) per 33 CFR Part 105. NVIC 05-17 addresses cyber risks in Area Maritime Security Plans. The 2024 USCG cyber incident reporting rule establishes mandatory cyber incident reporting for MTSA-regulated facilities. Applies to port facilities, OCS (outer continental shelf) facilities, and vessels operating in US waters. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements have?

US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements has 4 controls organised across 4 domains. The largest domains are Cyber Assessment (1 controls), Incident Reporting (1 controls), Security Plan (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements map to?

US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements maps to 108 other compliance frameworks. The top mapping partners are ISO/IEC 27400:2022 (50% coverage), NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements (50% coverage), FedRAMP Rev 5 (50% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements compliance?

Start your US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 4 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.

Get Started Free →

Free forever — no credit card required