US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements
The US Maritime Transportation Security Act (MTSA, 2002) and subsequent US Coast Guard (USCG) regulations establish security requirements for US maritime facilities and vessels. USCG Navigation and Vessel Inspection Circular (NVIC) 01-20 provides guidance on addressing cyber risks in Facility Security Assessments (FSA) and Facility Security Plans (FSP) per 33 CFR Part 105. NVIC 05-17 addresses cyber risks in Area Maritime Security Plans. The 2024 USCG cyber incident reporting rule establishes mandatory cyber incident reporting for MTSA-regulated facilities. Applies to port facilities, OCS (outer continental shelf) facilities, and vessels operating in US waters.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (5)
Cybersecurity Officer and Personnel
| Code | Title |
|---|---|
| CSO-1 | Cybersecurity Officer Designation |
| CSO-2 | Cybersecurity Training |
| CSO-3 | Cybersecurity Drills and Exercises |
| CSO-4 | Personnel Awareness |
Cybersecurity Plan Requirements
| Code | Title |
|---|---|
| CYB-1 | Cybersecurity Plan Development |
| CYB-2 | Account Security Measures |
| CYB-3 | Device Security Measures |
| CYB-4 | Data Security Measures |
| CYB-5 | Cyber Incident Response Plan |
Facility Security Assessment and Planning
| Code | Title |
|---|---|
| 33CFR101.105 | Cybersecurity Assessment |
| 33CFR105.305 | Facility Security Assessment |
| 33CFR105.400 | Facility Security Plan (FSP) |
| 33CFR105.405 | Format and Content of FSP |
Incident Reporting and Monitoring
| Code | Title |
|---|---|
| IR-1 | Reportable Cyber Incident Notification |
| IR-2 | Incident Documentation |
| IR-3 | USCG Inspection and Audit |
| IR-4 | Continuous Monitoring |
Vessel and OCS Facility Requirements
| Code | Title |
|---|---|
| VES-1 | US-Flagged Vessel Cybersecurity |
| VES-2 | OCS Facility Cybersecurity |
| VES-3 | Penetration Testing |
| VES-4 | Recordkeeping Requirements |
Maps to 479 other frameworks
Frequently Asked Questions
What is US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements?
US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements is a compliance framework from United States (USCG) with 5 domains and 21 controls. The US Maritime Transportation Security Act (MTSA, 2002) and subsequent US Coast Guard (USCG) regulations establish security requirements for US maritime facilities and vessels. USCG Navigation and Vessel Inspection Circular (NVIC) 01-20 provides guidance on addressing cyber risks in Facility Security Assessments (FSA) and Facility Security Plans (FSP) per 33 CFR Part 105. NVIC 05-17 addresses cyber risks in Area Maritime Security Plans. The 2024 USCG cyber incident reporting rule establishes mandatory cyber incident reporting for MTSA-regulated facilities. Applies to port facilities, OCS (outer continental shelf) facilities, and vessels operating in US waters. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements have?
US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements has 21 controls organised across 5 domains. The largest domains are Cybersecurity Plan Requirements (5 controls), Cybersecurity Officer and Personnel (4 controls), Facility Security Assessment and Planning (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements map to?
US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements maps to 479 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (43% coverage), FedRAMP Rev 5 (43% coverage), TISAX — Trusted Information Security Assessment Exchange (43% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements compliance?
Start your US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 21 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required