US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements
The US Maritime Transportation Security Act (MTSA, 2002) and subsequent US Coast Guard (USCG) regulations establish security requirements for US maritime facilities and vessels. USCG Navigation and Vessel Inspection Circular (NVIC) 01-20 provides guidance on addressing cyber risks in Facility Security Assessments (FSA) and Facility Security Plans (FSP) per 33 CFR Part 105. NVIC 05-17 addresses cyber risks in Area Maritime Security Plans. The 2024 USCG cyber incident reporting rule establishes mandatory cyber incident reporting for MTSA-regulated facilities. Applies to port facilities, OCS (outer continental shelf) facilities, and vessels operating in US waters.
US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements is a compliance framework from United States (USCG) with 10 domains and 33 controls that map to 204 other frameworks. The largest domains are Cyber Risk Management (NVIC 02-24) (9 controls), 33 CFR Part 105 Facility Security (5 controls), USCG Maritime Cybersecurity: Cybersecurity Plan and Measures (5 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (10)
33 CFR Part 105 Facility Security
| Code | Title |
|---|---|
| MTSA-101.105 | Applicability Determination |
| MTSA-105.200 | Facility Security Officer Responsibilities |
| MTSA-105.255 | Maritime Security (MARSEC) Level Implementation |
| MTSA-105.305 | Facility Security Assessment |
| MTSA-105.405 | Facility Security Plan with Cybersecurity Annex |
Cyber Assessment
| Code | Title |
|---|---|
| USMTSA-2 | Cybersecurity Assessment and CSO Designation |
Cyber Risk Management (NVIC 02-24)
| Code | Title |
|---|---|
| MTSA-Access-Control | Access Control for Security Related Systems |
| MTSA-Monitoring | Continuous Monitoring and Logging |
| MTSA-NVIC-02-24 | Alignment with Updated USCG Cyber Policy |
| MTSA-Network-Segmentation | Network Segmentation Between IT and OT |
| MTSA-OT-Inventory | Operational Technology Asset Inventory |
| MTSA-Patch-Management | Patch and Vulnerability Management |
| MTSA-Removable-Media | Removable Media and Portable Device Controls |
| MTSA-Supply-Chain | Supply Chain Risk Management for Security Systems |
| MTSA-Vendor-Remote-Access | Third Party and Vendor Remote Access |
Incident Reporting
| Code | Title |
|---|---|
| USMTSA-3 | Reportable Suspicious Activity (RSA) and Cyber Incident Reporting |
Incident Response and Reporting
| Code | Title |
|---|---|
| MTSA-Cyber-Incident-Response | Cyber Incident Response Procedures |
| MTSA-Incident-Reporting | Reporting of Breaches of Security and Suspicious Activity |
Security Plan
| Code | Title |
|---|---|
| USMTSA-1 | Facility Security Assessment and Plan |
Training
| Code | Title |
|---|---|
| USMTSA-4 | Training, Drills, Exercises |
Training, Drills, Audit and Records
| Code | Title |
|---|---|
| MTSA-Audit | Annual Audit of the Security Plan |
| MTSA-Drills-Exercises | Drills and Exercises Including Cyber |
| MTSA-Recordkeeping | Recordkeeping and Records Protection |
| MTSA-Training-Cyber | Cybersecurity Training and Awareness |
USCG Maritime Cybersecurity: Cybersecurity Plan and Measures
| Code | Title |
|---|---|
| CYB-1 | Cybersecurity Plan Development |
| CYB-2 | Account Security Measures |
| CYB-3 | Device Security Measures |
| CYB-4 | Data Security Measures |
| CYB-5 | Cyber Incident Response Plan |
Vessels and Outer Continental Shelf Facilities
Your Compliance Coverage
If you comply with US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements, you already cover:
NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security
15%
5 controls mapped
Compare →Oman National Cybersecurity Framework
12%
4 controls mapped
Compare →NIS2 Directive Implementing Acts
12%
4 controls mapped
Compare →+ 201 more: IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems (12%), FedRAMP Rev 5 (12%)
See all 204 mapped frameworks ↓Maps to 204 other frameworks
What is US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements and who does it apply to?
US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements is a compliance framework from United States (USCG) with 10 domains and 33 controls. The US Maritime Transportation Security Act (MTSA, 2002) and subsequent US Coast Guard (USCG) regulations establish security requirements for US maritime facilities and vessels. USCG Navigation and Vessel Inspection Circular (NVIC) 01-20 provides guidance on addressing cyber risks in Facility Security Assessments (FSA) and Facility Security Plans (FSP) per 33 CFR Part 105. NVIC 05-17 addresses cyber risks in Area Maritime Security Plans. The 2024 USCG cyber incident reporting rule establishes mandatory cyber incident reporting for MTSA-regulated facilities. Applies to port facilities, OCS (outer continental shelf) facilities, and vessels operating in US waters. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements actually require?
US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements has 33 controls organised across 10 domains. The largest domains are Cyber Risk Management (NVIC 02-24) (9 controls), 33 CFR Part 105 Facility Security (5 controls), USCG Maritime Cybersecurity: Cybersecurity Plan and Measures (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements do I already cover?
US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements maps to 204 other compliance frameworks. The top mapping partners are NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security (15% coverage), Oman National Cybersecurity Framework (12% coverage), NIS2 Directive Implementing Acts (12% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements?
Start your US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 33 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required