The USCG Maritime Cyber Rules Texas Operators Keep Missing

Short version. The Coast Guard’s 2025 cybersecurity rule superseded NVIC 01-20. It did not change 33 CFR Part 105. Texas facility operators now carry 2 separate cyber obligations, 1 that has lived inside the Facility Security Plan since 2003 and 1 that arrives as a new Cybersecurity Plan due July 16, 2027. Most Gulf Coast operators are tracking only the second one.

The USCG cybersecurity rule for maritime facilities is now 2 rules, not 1. 33 CFR Part 101 Subpart F added a Cybersecurity Plan due July 16, 2027. 33 CFR Part 105 has required cyber content in your Facility Security Assessment and Facility Security Plan since 2003, and it never went away.

Every conversation we have about maritime and logistics IT support in Houston lands on the same date. July 16, 2027. That’s the day the Cybersecurity Plan is due, and it’s the only date most facility teams can name. Then ask about the cyber section of the Facility Security Plan that’s already approved. The room goes quiet. That silence is the expensive part, and it shows up long before 2027.

This one is for Facility Security Officers, plant managers and the finance people who sign their budgets, at facilities on the Houston Ship Channel, in Texas City, Freeport, Beaumont, Port Arthur and Corpus Christi. It’s about the regulations. Not what a vendor wants them to say.

Whiteboard split into two columns headed Facility Security Plan and Cybersecurity Plan while a worker in a safety vest holds a marker

What the USCG cybersecurity rule requires of a Texas maritime facility

The USCG cybersecurity rule for maritime facilities is a stack of 2 obligations. Part 105 requires your Facility Security Assessment to analyze computer system and network vulnerabilities and your Facility Security Plan to address every one it finds. Part 101 Subpart F adds a Cybersecurity Assessment, a Cybersecurity Officer and a Cybersecurity Plan on top of that.

People hear “the new Coast Guard cyber rule” and picture 1 document with 1 deadline. It isn’t 1 document. The Coast Guard built Subpart F as a parallel structure that follows the applicability of Parts 104, 105 and 106 rather than replacing anything inside them. Two obligations. Two clocks. A facility can satisfy 1 and fail the other without ever noticing, which is roughly what we find when we open a plan that hasn’t been touched since its last physical security audit.

 FSP cyber content, 33 CFR 105Cybersecurity Plan, 33 CFR 101 Subpart F
In force since2003July 16, 2025
Where it livesIn the FSA and FSP, or a cyber annex to the FSPA separate plan, or folded into the FSP
Submission deadlineAlready passedJuly 16, 2027
Who owns itFacility Security OfficerCybersecurity Officer
1 officer across multiple sitesSame COTP zone, no more than 50 miles apartNo distance limit
Audit cycleAnnual FSP auditAnnual Cybersecurity Plan audit
Checked byYour COTP at the facility’s annual auditCoast Guard inspectors, timing set by the COTP

Read both columns as 2 jobs. Because they are.

The 2025 rule superseded NVIC 01-20, but left 33 CFR 105 untouched

Here’s where it trips people. In the final rule published at 90 FR 6298 on January 17, 2025, commenters asked the Coast Guard directly whether Subpart F would supersede NVIC 01-20, the 2020 guidance on cyber risks at MTSA-regulated facilities. The answer was yes. “This final rule will supersede NVIC 01-20,” the Coast Guard wrote.

Plenty stopped reading there. That’s the mistake.

NVIC 01-20 was never the source of the requirement. It was guidance interpreting regulations that already existed, and the Coast Guard said so in the same document, noting the NVIC “is not enforceable as a legislative rule” and that its guidance “relates to the requirements in 33 CFR part 105 that predate this rulemaking.” A few pages earlier, responding to a request to amend the assessment sections, the agency was blunter. “We are not making changes to existing regulatory requirements in 33 CFR parts 104 and 105.”

So the interpretive layer went away. The regulation underneath it didn’t.

The 3 sections that carry the obligation

In the 2020 Federal Register notice at 85 FR 16108, the Coast Guard footnoted its own citation chain for facility cyber. Three sections. Worth knowing by number.

  • 33 CFR 105.305(c)(1)(v) requires the FSA analysis to consider “measures to protect radio and telecommunication equipment, including computer systems and networks” as a vulnerability found during the on-scene survey.
  • 33 CFR 105.400(a)(3) requires the FSP to address each vulnerability identified in the FSA. Not most of them. Each.
  • 33 CFR 105.405(a)(17) requires the FSA report to be a section of the FSP itself, so cyber findings travel with the plan wherever it goes.

All 3 date to the 2003 rulemaking at 68 FR 39322. That’s not new. The Coast Guard’s position has been consistent and public for years. “This requirement has been in place since 2003,” it wrote in 2020. “It is not limited to physical threats.”

There’s a second artifact most facilities forget. Under 105.405(c), Form CG-6025, the Facility Vulnerability and Security Measures Summary, has to be completed using the vulnerabilities from the FSA and the mitigations from the FSP. So a cyber vulnerability in your assessment belongs on that summary line. Leave it off and an inspector reading the summary sees a facility that found nothing.

Texas Gulf Coast nautical chart on an office wall with red pins at coastal facilities and a ruler measuring the distance between two of them

Why so many Texas operators think cyber starts in 2027

Because for about 20 years, almost nothing happened.

The enforcement history is thin, and we can put a number on it. In GAO-25-107244, released February 11, 2025, the Government Accountability Office reviewed Coast Guard inspection data from fiscal year 2019 through June 2024 and found the Coast Guard had identified 145 facility deficiency records “deemed to be cybersecurity-related.” Set that against a regulated population the Coast Guard itself puts at 3,718 facilities. Roughly 29 findings a year, nationwide.

GAO also found the data can’t be trusted to be complete. Its wording is careful. “Coast Guard’s cybersecurity-related deficiency data are likely not complete,” the report says, because vessel inspectors weren’t following the documentation guidance and facility inspections had no guidance to follow at all. The agency can’t pull complete cyber deficiency information out of its own system of record on demand either.

Then add the staffing picture. GAO counted 8 vacant cybersecurity specialist positions and 23 vacancies across Coast Guard cyber protection teams, and noted that “the position descriptions for Coast Guard’s facility and vessel inspectors do not include competencies related to mitigating cyber risks.” An inspector whose job description never mentioned cyber wasn’t likely to write a cyber deficiency. That’s not a criticism. It’s arithmetic.

Here’s the honest read. A facility that skipped cyber in its FSP between 2003 and 2024 probably never heard a word about it, and concluding that nothing was required was a reasonable inference from lived experience. It was still wrong. And it’s expiring, because verification has been sharpening since October 1, 2021, when the Coast Guard’s 18-month NVIC implementation window closed and COTPs began checking cyber content during annual facility audits. The 2025 rule pushed further. So did the training verification job aid the Coast Guard issued for 2026 inspections.

What changed isn’t the requirement. It’s the odds of detection. That shift is also reshaping how facilities pick providers, which we broke down in our review of the best IT providers for Houston Ship Channel and port logistics firms.

5 things Texas facility operators keep missing

These come from actual conversations at Gulf Coast facilities. Not from a compliance checklist somebody sells.

1. Treating the 2027 Cybersecurity Plan as a replacement for the FSP cyber annex

It isn’t a replacement. It’s an addition. Part 105 still demands cyber vulnerabilities in the FSA and mitigations in the FSP, and your annual FSP audit under 105.415(b)(1) still covers that content. Shelve the FSP cyber annex while you build a Cybersecurity Plan for 2027 and you’ve opened a gap in the plan that’s approved right now. The Coast Guard does allow the Cybersecurity Plan to be incorporated into an existing FSP, which is worth considering. It warned in the same analysis that merging them doesn’t make the work smaller.

2. Hiring 2 officers when the distance rules are different

This one is a real planning advantage and almost nobody talks about it. Under 105.205(a)(2), 1 person can serve as FSO for more than 1 facility only if those facilities sit in the same COTP zone and are no more than 50 miles apart. Under 101.625(b), the Cybersecurity Officer has no such limit. The rule asks only that each covered facility be listed in the Cybersecurity Plan of the others.

Run the map. An operator with docks in Deer Park and Corpus Christi needs 2 FSOs, because that’s well past 50 miles and past the zone boundary. That same operator can appoint 1 CySO for both. For multi-site Texas companies the asymmetry is worth real money, and it’s a design decision you make once.

3. Treating a network change as a non-event

Section 105.415(b)(2) requires an FSP audit “if there have been modifications to the facility, including but not limited to physical structure, emergency response procedures, security measures, or operations.” Now hold that next to the Coast Guard’s own position that computer systems and networks are facility security systems covered by the rule. The two fit together in a way most change tickets never account for.

A terminal operating system migration is a modification to operations. A new remote access path for your TOS vendor is a modification to security measures. So is a firewall replacement. So is a cloud cutover for the yard management system, or collapsing 2 VLANs into 1. The relief sits in the next paragraph of the regulation. Under 105.415(b)(3), an audit triggered by a modification “may be limited to those sections of the FSP affected.” You aren’t redoing the whole plan. You are supposed to look. And if the audit produces an amendment, an owner-initiated change has to reach the COTP at least 30 days before it takes effect.

Most IT projects at MTSA facilities skip this entirely. Put it in change control. Next to the rollback plan.

Marine terminal network cabinet with separated blue and orange cable bundles running to different patch panels while a technician documents the layout

4. Storing the Facility Security Plan like an ordinary PDF

Section 105.400(c) says the FSP is sensitive security information protected under 49 CFR part 1520. That’s not a formality. It lands squarely on IT.

Under 1520.9(a), a covered person has to take reasonable steps to safeguard SSI, store it in a secure container when not in physical possession, and disclose it only to covered persons with a need to know. Under 1520.13(d), non-paper records “including electronic and magnetic records” have to carry the protective marking and the distribution limitation statement. There’s a rule for receiving unmarked SSI too. You mark it. Then you tell the sender it should have arrived marked.

So ask where your FSP actually lives. In our experience it’s a shared drive folder with inherited permissions, an email thread with the consultant who wrote it, and somebody’s laptop. Section 105.400(d) adds that an FSP kept electronically needs procedures preventing unauthorized deletion, destruction or amendment, which in practice means versioning, an immutable backup copy and an access log you can produce on request rather than reconstruct after the fact.

DocumentWhat the regulation saysWhat that means for IT
FSA reportProtected from unauthorized access or disclosure, 105.305(e)Restricted folder, named access list, no open link sharing
Facility Security PlanSensitive security information under 49 CFR 1520, 105.400(c)SSI marking on the file, need-to-know access, secure storage
FSP held electronicallyProcedures preventing unauthorized deletion, destruction or amendment, 105.400(d)Version history, immutable backup, change audit log
Security recordsKept 2 years, electronic copies protected the same way, 105.225Retention policy, tamper-evident storage, retrieval on request
Cybersecurity PlanSubmitted and approved under 105.410, same path as the FSPSame handling as the FSP, no looser

5. Believing the vendor carries the finding

We’ll be direct, because this cuts against our own interest. You can hire out almost all of this work. Section 105.300(c) is explicit that third parties may be used in any aspect of the FSA if they have the appropriate skills and the FSO reviews and accepts their work. Section 105.205(a)(3) lets the FSO assign security duties to other personnel. Section 101.625(c) says the same for the CySO.

Now read the second half of both sentences. The FSO “retains the responsibility for these duties.” The CySO “retains ultimate responsibility.” A deficiency gets written against the facility, never against the company that drew its network diagram. That’s the right way to think about any provider you bring in, us included. We can do the assessment work, write the technical sections and sit in the audit. The name on the finding is still yours.

One more independence detail. Under 105.415(b)(4), personnel conducting the internal audit of the FSP must not have regularly assigned security duties and must be independent of the measures being audited. So if the same engineer who built your segmentation is also auditing it, that’s a problem on its face.

What the paperwork actually costs

The Coast Guard published its own hour estimates in the 2025 final rule, drawn from OMB Information Collection Request 1625-0077 and from agency subject matter experts. These are averages, not quotes. A complex terminal will run past them. They’re still the best public anchor available.

TaskHoursAt the rule’s $84.14 loaded rate
Develop the Cybersecurity Plan, including the assessment100$8,414
Annual audit of the plan40$3,366
Annual maintenance and amendments10$841
Revise and resubmit after a correction50$4,207
Resubmit at the 5 year renewal15$1,262

Look at the fourth row. The Coast Guard expects roughly 10 percent of plans to come back for revision in year 2, which is the current resubmission rate for Facility Security Plans. So budget for a 1 in 10 chance of a second pass rather than treating first-time approval as the plan.

Scale matters here in a way the averages hide. The rule affects 3,718 facilities and OCS facilities but only about 1,372 owners and operators, so the average owner runs close to 3 sites. Multi-site operators feel this as 3 assessments, 3 audits and 3 sets of records, which is exactly why the single-CySO allowance in 101.625(b) is worth using. Pricing the IT side against normal managed services spend is a separate exercise. Our Texas freight brokerage and 3PL IT cost guide shows how the per-seat math shifts with a desk-heavy headcount.

A 90 day sequence if your facility is behind

Start with what exists. Not with a clean sheet. Most facilities are further along than they think, because the physical security program already built the bones.

  1. Pull the current FSA and FSP and find the cyber content. Search for the phrase “computer systems and networks.” If the only hit is boilerplate copied out of 105.305, you have a gap, and now you know its size.
  2. Check the CG-6025. Confirm whether any cyber vulnerability appears on the Facility Vulnerability and Security Measures Summary. Ten minutes. It tells you what an inspector sees first.
  3. Inventory what a compromise could actually reach. Gate and access control, cameras, tank gauging, the terminal operating system, the scale house, the PLCs on the loading arms. Write down where each one touches the office network.
  4. Decide the document structure before writing anything. Cyber annex to the FSP, integrated FSP, or a standalone Cybersecurity Plan. Ask your COTP office what they prefer to review. That call saves a resubmission.
  5. Name your CySO and map the multi-site question. Running more than 1 Texas facility? Check whether 1 CySO covers all of them under 101.625(b) before you hire.
  6. Fix SSI handling now. Cheapest item on the list. Also the one most likely to be visibly wrong today.
  7. Put a security review step into IT change control. Any change to a system in your inventory gets a 105.415(b)(2) check before it ships, not after somebody notices in an audit.
  8. Schedule the training evidence. The annual cyber training requirement under 101.650 has been running since January 12, 2026, and inspectors now work from a standard job aid when they verify it.

None of that waits for 2027. Most of it makes the 2027 submission shorter.

Printed document marked Sensitive Security Information resting on a locked steel filing cabinet in a secure records room

Questions Texas maritime operators actually ask us

Does the 2025 Coast Guard cyber rule cancel my FSP cyber annex?

No. The rule superseded NVIC 01-20, which was guidance, but it explicitly did not change 33 CFR Part 105. Your FSA still has to analyze computer system and network vulnerabilities and your FSP still has to address them, audited annually under 105.415(b)(1).

My facility has never had a cyber deficiency written. Are we fine?

Probably not, and the absence of findings is weak evidence. GAO counted only 145 cyber-related facility deficiency records from fiscal 2019 through June 2024, then concluded the data are “likely not complete,” partly because facility inspectors had no documentation guidance for cyber findings.

Can 1 person be the Cybersecurity Officer for facilities in Houston and Corpus Christi?

Yes. Section 101.625(b) sets no distance or zone limit for the CySO, requiring only that each facility be listed in the others’ Cybersecurity Plans. The Facility Security Officer role works differently. Under 105.205(a)(2), 1 FSO covers multiple facilities only within the same COTP zone and within 50 miles.

Do we have to tell the Coast Guard when we replace a firewall?

Not automatically, but you do have to look. Section 105.415(b)(2) triggers an FSP audit after modifications to security measures or operations, and 105.415(b)(3) lets that audit cover only the affected sections. If it produces an amendment, submit it at least 30 days before the change takes effect.

Where is our Facility Security Plan allowed to be stored?

Somewhere that satisfies 49 CFR 1520. The FSP is sensitive security information under 105.400(c), so it needs the protective marking and distribution limitation statement, need-to-know access, and secure storage. Kept electronically, 105.400(d) also requires procedures preventing unauthorized deletion, destruction or amendment.

Can our IT provider be the Cybersecurity Officer?

Outside help is allowed, and 105.300(c) permits third parties in any aspect of the assessment when the FSO reviews and accepts the work. Accountability doesn’t transfer. Both 105.205(a)(3) and 101.625(c) keep ultimate responsibility with your officer, and 105.415(b)(4) bars whoever built a control from auditing it.

Where to go from here

Is your facility on the Ship Channel or anywhere along the Texas coast, with nobody sure whether the FSP has real cyber content in it? That’s a 1 hour answer, not a project. Pull the plan. Search it. What turns up decides whether the next 90 days are cleanup or a build.

Uprite runs the network and security side of that work for Texas maritime and logistics operators out of 2 Houston offices, at $138 per user per month fully managed and $100 co-managed alongside your own IT staff, published rather than quoted. We’ll do the assessment work, write the technical sections, separate terminal and yard networks from the office, and sit with your FSO through the audit. Your officer still signs. That’s how the regulation is built, and we’d rather say so up front than discover it together in an audit.

Start with our cybersecurity solutions for the full control set, the maritime and logistics practice page for the vertical view, or vessel to shore connectivity on the Gulf Coast if your compliance problem starts at the dock and ends somewhere out on the water.

About Author

Learn More