PART 101—MARITIME SECURITY: GENERAL Authority: 46 U.S.C. 70101-70104 and 70124; Executive Order 12656, 3 CFR, 1988 Comp., p. 585; 33 CFR 1.05-1, 6.04-11, 6.14, 6.16, and 6.19; Department of Homeland Security Delegation No. 00170.1, Revision No. 01.4. Source: USCG-2003-14792, 68 FR 39278, July 1, 2003, unless otherwise noted. Editorial Note: Nomenclature changes to part 101 appear by USCG-2008-0179, 73 FR 35009, June 19, 2008. Subpart A—General § 101.100 Purpose. (a) The purpose of this subchapter is: (1) To implement portions of the maritime security regime required by the Maritime Transportation Security Act of 2002, as codified in 46 U.S.C. Chapter 701; (2) To align, where appropriate, the requirements of domestic maritime security regulations with the international maritime security standards in the International Convention for the Safety of Life at Sea, 1974 (SOLAS Chapter XI-2) and the International Code for the Security of Ships and of Port Facilities, parts A and B, adopted on 12 December 2002; and (3) To ensure security arrangements are as compatible as possible for vessels trading internationally. (b) For those maritime elements of the national transportation system where international standards do not directly apply, the requirements in this subchapter emphasize cooperation and coordination with local port community stakeholders, and are based on existing domestic standards, as well as established industry security practices. (c) The assessments and plans required by this subchapter are intended for use in implementing security measures at various MARSEC Levels. The specific security measures and their implementation are planning criteria based on a set of assumptions made during the development of the security assessment and plan. These assumptions may not exist during an actual transportation security incident. [USCG-2003-14792, 68 FR 39278, July 1, 2003, as amended at 68 FR 60470, Oct. 22, 2003] § 101.105 Definitions. Unless otherwise specified, as used in this subchapter: Alternative Security Program Area Commander Area Maritime Security (AMS) Assessment Area Maritime Security (AMS) Committee https://www.dco.uscg.mil/Our-Organization/NVIC/ Area Maritime Security (AMS) Plan Area of Responsibility (AOR) Audit Barge Barge fleeting facility Biometric match Breach of security Bulk in bulk Bunkers Canceled Card List (CCL) Captain of the Port (COTP) Card Holder Unique Identifier (CHUID) Card validity check Cargo Cargo vessel Carry-on item Certain Dangerous Cargo (CDC) Checked baggage Commandant Company Company Security Officer (CSO) Contracting Government Cruise ship Cruise ship terminal Cruise ship voyage Dangerous goods and/or hazardous substances, Dangerous substances or devices Declaration of Security (DoS) Designated Recurring Access Area (DRAA) Disembark District Commander Drill Electronic TWIC inspection Embark Escorting Exercise Explosives detection system Facility Facility Security Assessment (FSA) Facility Security Officer (FSO) Facility Security Plan (FSP) Ferry Foreign vessel General shipyard facility (1) For operations on land, any structure or appurtenance thereto designed for the construction, repair, rehabilitation, refurbishment, or rebuilding of any vessel, including graving docks, building ways, ship lifts, wharves, and pier cranes; the land necessary for any structures or appurtenances; and the equipment necessary for the performance of any function referred to in this definition; and (2) For operations other than on land, any vessel, floating drydock, or barge used for, or a type that is usually used for, activities referred to in paragraph (1) of this definition. Gross register tons (GRT) Gross tonnage, ITC (GT ITC) Hazardous materials High seas Identity verification Infrastructure International voyage ISPS Code Maritime Security (MARSEC) Directive Maritime Security (MARSEC) Level MARSEC Level 1 MARSEC Level 2 MARSEC Level 3 Master Merchant mariner credential or MMC Mobile Offshore Drilling Unit (MODU) Non-TWIC visual identity verification OCS Facility Offshore Supply Vessel (OSV) Operator, Uninspected Towing Vessel Owner or operator Passenger vessel (1) On an international voyage, a vessel carrying more than 12 passengers, including at least one passenger-for-hire; and (2) On other than an international voyage: (i) A vessel of at least 100 gross register tons carrying more than 12 passengers, including at least one passenger-for-hire; (ii) A vessel of less than 100 gross register tons carrying more than 6 passengers, including at least one passenger-for-hire; (iii) A vessel that is chartered and carrying more than 12 passengers; (iv) A submersible vessel that is carrying at least one passenger-for-hire; or (v) A wing-in-ground craft, regardless of tonnage, that is carrying at least one passenger-for-hire. Passenger-for-hire Personal Identification Number Physical Access Control System (PACS) Port of call Public access facility (1) That is used by the public primarily for purposes such as recreation, entertainment, retail, or tourism, and not for receiving vessels subject to part 104; (2) That has minimal infrastructure for servicing vessels subject to part 104 of this chapter; and (3) That receives only: (i) Vessels not subject to part 104 of this chapter, or (ii) Passenger vessels, except: (A) Ferries certificated to carry vehicles; (B) Cruise ships; or (C) Passenger vessels subject to SOLAS Chapter XI-1 or SOLAS Chapter XI-2. Qualified Reader Recurring unescorted access Registered length Restricted areas Review and approval Risk Group Screener Screening Secure area Security sweep Security system Sensitive security information (SSI) SOLAS Survey Terminal screening program or TSP Transparent Reader Transportation security incident (TSI) TWIC TWIC Program TWIC reader Unaccompanied baggage Unescorted access Vessel-to-facility interface Vessel-to-port interface Vessel Security Assessment (VSA) Vessel Security Plan (VSP) Vessel Security Officer (VSO) Vessel stores (1) Materials that are on board a vessel for the upkeep, maintenance, safety, operation or navigation of the vessel; and (2) Materials for the safety or comfort of the vessel's passengers or crew, including any provisions for the vessel's passengers or crew. Vessel-to-vessel activity Visual TWIC inspection Waters subject to the jurisdiction of the U.S., [USCG-2003-14792, 68 FR 39278, July 1, 2003] Editorial Note: For Federal Register www.govinfo.gov. § 101.110 Applicability. Unless otherwise specified, this subchapter applies to vessels, structures, and facilities of any kind, located under, in, on, or adjacent to waters subject to the jurisdiction of the U.S. § 101.112 Federalism. (a) The regulations in 33 CFR parts 101, 103, 104, and 106 have preemptive effect over State or local regulation within the same field. (b) The regulations in 33 CFR part 105 have preemptive effect over State or local regulations insofar as a State or local law or regulation applicable to the facilities covered by part 105 would conflict with the regulations in part 105, either by actually conflicting or by frustrating an overriding Federal need for uniformity. [USCG-2007-28915, 81 FR 57708, Aug. 23, 2016] § 101.115 Incorporation by reference. (a) Certain material is incorporated by reference into this subchapter with the approval of the Director of the Federal Register under 5 U.S.C. 552(a) and 1 CFR part 51. To enforce any edition other than that specified in paragraph (b) of this section, the Coast Guard must publish notice of change in the Federal Register http://www.archives.gov/federal_register/code_of_federal_regulations/ibr_locations.html. (b) The materials approved for incorporation by reference in this subchapter are as follows: International Maritime Organization (IMO) Publication Section, 4 Albert Embankment, London SE1 7SR, United Kingdom. Conference resolution 1, Adoption of amendments to the Annex to the International Convention for the Safety of Life at Sea, 1974, and amendments to Chapter XI of SOLAS 1974, adopted December 12, 2002, (SOLAS Chapter XI-1 or SOLAS Chapter XI-2) 101.120; 101.310; 101.410; 101.505; 104.105; 104.115; 104.120; 104.297; 104.400. Conference resolution 2, Adoption of the International Code for the Security of Ships and of Port Facilities, parts A and B, adopted on December 12, 2002 (ISPS Code) 101.410; 101.505; 104.105; 104.115; 104.120; 104.297; 104.400. [USCG-2003-14792, 68 FR 39278, July 1, 2003, as amended at 69 FR 18803, Apr. 9, 2004; USCG-2010-0351, 75 FR 36282, June 25, 2010; USCG-2013-0397, 78 FR 39173, July 1, 2013] § 101.120 Alternatives. (a) Alternative Security Agreements. (2) As further provided in SOLAS Chapter XI-2, Regulation 11, a vessel covered by such an agreement shall not conduct any vessel-to-vessel activity with any vessel not covered by the agreement. (b) Alternative Security Programs. (2) Owners or operators must implement an approved Alternative Security Program in its entirety to be deemed in compliance with either part 104, 105, or 106. (3) Owners or operators who have implemented an Alternative Security Program must send a letter to the appropriate plan approval authority under part 104, 105, or 106 of this subchapter identifying which Alternative Security Program they have implemented, identifying those vessels or facilities that will implement the Alternative Security Program, and attesting that they are in full compliance therewith. A copy of this letter shall be retained on board the vessel or kept at the facility to which it pertains along with a copy of the Alternative Security Program and a vessel, facility, or Outer Continental Shelf facility specific security assessment report generated under the Alternative Security Program. (4) Owners or operators shall make available to the Coast Guard, upon request, any information related to implementation of an approved Alternative Security Program. (c) Approval of Alternative Security Programs. (1) A list of the vessel and facility type that the Alternative Security Program is intended to apply; (2) A security assessment for the vessel or facility type; (3) Explanation of how the Alternative Security Program addresses the requirements of parts 104, 105, or 106, as applicable; and (4) Explanation of how owners and operators must implement the Alternative Security Program in its entirety, including performing an operational and vessel or facility specific assessment and verification of implementation. (d) Amendment of Approved Alternative Security Programs. (i) The submitter of an Alternative Security Program under paragraph (c) of this section; or (ii) The Coast Guard upon a determination that an amendment is needed to maintain the security of a vessel or facility. The Coast Guard will give the submitter of an Alternative Security Program written notice and request that the submitter propose amendments addressing any matters specified in the notice. The submitter will have at least 60 days to submit its proposed amendments. (2) Proposed amendments must be sent to the Commandant (CG-5P). If initiated by the submitter, the proposed amendment must be submitted at least 30 days before the amendment is to take effect unless the Commandant (CG-5P) allows a shorter period. The Commandant (CG-5P) will approve or disapprove the proposed amendment in accordance with paragraph (f) of this section. (e) Validity of Alternative Security Program. (f) The Commandant (CG-5P) will examine each submission for compliance with this part, and either: (1) Approve it and specify any conditions of approval, returning to the submitter a letter stating its acceptance and any conditions; (2) Return it for revision, returning a copy to the submitter with brief descriptions of the required revisions; or (3) Disapprove it, returning a copy to the submitter with a brief statement of the reasons for disapproval. [USCG-2003-14792, 68 FR 39278, July 1, 2003, as amended at 68 FR 60471, Oct. 22, 2003; USCG-2013-0397, 78 FR 39173, July 1, 2013] § 101.125 [Reserved] § 101.130 Equivalent security measures. (a) For any measure required by part 104, 105, or 106 of this subchapter, the owner or operator may substitute an equivalent security measure that has been approved by the Commandant (CG-5P) as meeting or exceeding the effectiveness of the required measure. The Commandant (CG-5P) may require that the owner or operator provide data for use in assessing the effectiveness of the proposed equivalent security measure. (b) Requests for approval of equivalent security measures should be made to the appropriate plan approval authority under parts 104, 105 or 106 of this subchapter. [USCG-2003-14792, 68 FR 39278, July 1, 2003, as amended by USCG-2013-0397, 78 FR 39173, July 1, 2013] Subpart B—Maritime Security (MARSEC) Levels § 101.200 MARSEC Levels. (a) MARSEC Levels advise the maritime community and the public of the level of risk to the maritime elements of the national transportation system. Ports, under direction of the local COTP, will respond to changes in the MARSEC Level by implementing the measures specified in the AMS Plan. Similarly, vessels and facilities required to have security plans under part 104, 105, or 106 of this subchapter shall implement the measures specified in their security plans for the applicable MARSEC Level. (b) Unless otherwise directed, each port, vessel, and facility shall operate at MARSEC Level 1. (c) The Commandant will set (raise or lower) the MARSEC Level commensurate with risk, and in consideration of any maritime nexus to any active National Terrorism Advisory System (NTAS) alerts. Notwithstanding the NTAS, the Commandant retains discretion to adjust the MARSEC Level when necessary to address any particular security concerns or circumstances related to the maritime elements of the national transportation system. (d) The COTP may raise the MARSEC Level for the port, a specific marine operation within the port, or a specific industry within the port, when necessary to address an exigent circumstance immediately affecting the security of the maritime elements of the transportation in his/her area of responsibility. Application of this delegated authority will be pursuant to policies and procedures specified by the Commandant. [USCG-2003-14792, 68 FR 39278, July 1, 2003, as amended by USCG-2013-0397, 78 FR 39173, July 1, 2013] § 101.205 [Reserved] Subpart C—Communication (Port—Facility—Vessel) § 101.300 Preparedness communications. (a) Notification of MARSEC Level change. (b) Communication of threats. (1) Geographic area potentially impacted by the probable threat; (2) Any appropriate information identifying potential targets; (3) Onset and expected duration of probable threat; (4) Type of probable threat; and (5) Required actions to minimize risk. (c) Attainment. (2) Each owner or operator of a facility required to have a security plan under part 106 of this subchapter affected by a change in the MARSEC Level must ensure confirmation to their cognizant District Commander the attainment of measures or actions described in their security plan and any other requirements imposed by the District Commander or COTP that correspond with the MARSEC Level being imposed by the change. [USCG-2003-14792, 68 FR 39278, July 1, 2003, as amended at 68 FR 60472, Oct. 22, 2003] § 101.305 Reporting. (a) Notification of suspicious activities. (b) Notification of breaches of security. (c) Notification of transportation security incident (TSI). (2) Any owner or operator required to have a security plan under part 106 of this subchapter shall, without delay, report a TSI to their cognizant District Commander and immediately thereafter begin following the procedures set out in their security plan, which may include contacting the National Response Center via one of the means listed in paragraph (a) of this section. (d) Callers to the National Response Center should be prepared to provide as much of the following information as possible: (1) Their own name and contact information; (2) The name and contact information of the suspicious or responsible party; (3) The location of the incident, as specifically as possible; and (4) The description of the incident or activity involved. [USCG-2003-14792, 68 FR 39278, July 1, 2003, as amended by USCG-2004-18057, 69 FR 34925, June 23, 2004; USCG-2005-21531, 70 FR 36349, June 23, 2005; USCG-2006-25150, 71 FR 39208, July 12, 2006; USCG-2008-0179, 73 FR 35009, June 19, 2008] § 101.310 Additional communication devices. (a) Alert Systems. (b) Automated Identification Systems (AIS). Subpart D—Control Measures for Security § 101.400 Enforcement. (a) The rules and regulations in this subchapter are enforced by the COTP under the supervision and general direction of the District Commander, Area Commander, and the Commandant. All authority and power vested in the COTP by the rules and regulations in this subchapter is also vested in, and may be exercised by, the District Commander, Area Commander, and the Commandant. (b) The COTP, District Commander, Area Commander, or Commandant may assign the enforcement authority described in paragraph (a) of this section to any other officer or petty officer of the Coast Guard or other designees authorized by the Commandant. (c) The provisions in this subchapter do not limit the powers conferred upon Coast Guard commissioned, warrant, or petty officers by any other law or regulation, including but not limited to 33 CFR parts 6, 160, and 165. § 101.405 Maritime Security (MARSEC) Directives. (a)(1) When the Coast Guard determines that additional security measures are necessary to respond to a threat assessment or to a specific threat against the maritime elements of the national transportation system, the Coast Guard may issue a MARSEC Directive setting forth mandatory measures. Only the Commandant or his/her delegee may issue MARSEC Directives under this section. Prior to issuing a MARSEC Directive, the Commandant or his/her delegee will consult with those Federal agencies having an interest in the subject matter of that MARSEC Directive. All MARSEC Directives issued under this section shall be marked as sensitive security information (SSI) in accordance with 49 CFR part 1520. (2) When a MARSEC Directive is issued, the Coast Guard will immediately publish a notice in the Federal Register, (b) Each owner or operator of a vessel or facility to whom a MARSEC Directive applies is required to comply with the relevant instructions contained in a MARSEC Directive issued under this section within the time prescribed by that MARSEC Directive. (c) Each owner or operator of a vessel or facility required to have a security plan under parts 104, 105 or 106 of this subchapter that receives a MARSEC Directive must: (1) Within the time prescribed in the MARSEC Directive, acknowledge receipt of the MARSEC Directive to their local COTP or, if a facility regulated under part 106 of this subchapter, to their cognizant District Commander; and (2) Within the time prescribed in the MARSEC Directive, specify the method by which the measures in the MARSEC Directive have been implemented (or will be implemented, if the MARSEC Directive is not yet effective). (d) In the event that the owner or operator of a vessel or facility required to have a security plan under part 104, 105, or 106 of this subchapter is unable to implement the measures in the MARSEC Directive, the owner or operator must submit proposed equivalent security measures and the basis for submitting the equivalent security measures to the COTP or, if a facility regulated under part 106 of this subchapter, to their cognizant District Commander, for approval. (e) The owner or operator must submit the proposed equivalent security measures within the time prescribed in the MARSEC Directive. The owner or operator must implement any equivalent security measures approved by the COTP, or, if a facility regulated under part 106 of this subchapter, by their cognizant District Commander. [USCG-2003-14792, 68 FR 39278, July 1, 2003, as amended at 68 FR 60472, Oct. 22, 2003] § 101.410 Control and Compliance Measures. (a) The COTP may exercise authority pursuant to 33 CFR parts 6, 160 and 165, as appropriate, to rectify non-compliance with this subchapter. COTPs or their designees are the officers duly authorized to exercise control and compliance measures under SOLAS Chapter XI-2, Regulation 9, and the ISPS Code (Incorporated by reference, see § 101.115). (b) Control and compliance measures for vessels not in compliance with this subchapter may include, but are not limited to, one or more of the following: (1) Inspection of the vessel; (2) Delay of the vessel; (3) Detention of the vessel; (4) Restriction of vessel operations; (5) Denial of port entry; (6) Expulsion from port; (7) Lesser administrative and corrective measures; or (8) Suspension or revocation of a security plan approved by the U.S., thereby making that vessel ineligible to operate in, on, or under waters subject to the jurisdiction of the U.S. in accordance with 46 U.S.C. 70103(c)(5). (c) Control and compliance measures for facilities not in compliance with this subchapter may include, but are not limited to, one or more of the following: (1) Restrictions on facility access; (2) Conditions on facility operations; (3) Suspension of facility operations; (4) Lesser administrative and corrective measures; or (5) Suspension or revocation of security plan approval, thereby making that facility ineligible to operate in, on, under or adjacent to waters subject to the jurisdiction of the U.S. in accordance with 46 U.S.C. 70103(c)(5). (d) Control and compliance measures under this section may be imposed on a vessel when it has called on a facility or at a port that does not maintain adequate security measures to ensure that the level of security to be achieved by this subchapter has not been compromised. [USCG-2003-14792, 68 FR 39278, July 1, 2003, as amended at 68 FR 60472, Oct. 22, 2003] § 101.415 Penalties. (a) Civil and criminal penalty. (b) Civil penalty. [USCG-2003-14792, 68 FR 39278, July 1, 2003, as amended by USCG-2008-0179, 73 FR 35009, June 19, 2008; USCG-2020-0304, 85 FR 58277, Sept. 18, 2020] § 101.420 Right to appeal. (a) Any person directly affected by a decision or action taken by a COTP under this subchapter, may appeal that action or decision to the cognizant District Commander according to the procedures in 46 CFR 1.03-15. (b) Any person directly affected by a decision or action taken by a District Commander, whether made under this subchapter generally or pursuant to paragraph (a) of this section, with the exception of those decisions made under § 101.410 of this subpart, may appeal that decision or action to the Commandant (CG-5P), according to the procedures in 46 CFR 1.03-15. Appeals of District Commander decisions or actions made under § 101.410 of this subpart should be made to the Commandant (CG-CVC), according to the procedures in 46 CFR 1.03-15. (c) Any person directly affected by a decision or action taken by the Commanding Officer, Marine Safety Center, under this subchapter, may appeal that action or decision to the Commandant (CG-5P) according to the procedures in 46 CFR 1.03-15. (d) Decisions made by Commandant (CG-5P), whether made under this subchapter generally or pursuant to the appeal provisions of this section, are considered final agency action. [USCG-2003-14792, 68 FR 39278, July 1, 2003, as amended at 68 FR 60472, Oct. 22, 2003; 68 FR 62502, Nov. 4, 2003; USCG-2008-0179, 73 FR 35009, June 19, 2008; USCG-2013-0397, 78 FR 39173, July 1, 2013] Subpart E—Other Provisions § 101.500 Procedures for authorizing a Recognized Security Organization (RSO). [Reserved] § 101.505 Declaration of Security (DoS). (a) The purpose of a DoS, as described in SOLAS Chapter XI-2, Regulation 10, and the ISPS Code (Incorporated by reference, see § 101.115), is to state the agreement reached between a vessel and a facility, or between vessels in the case of a vessel-to-vessel activity, as to the respective security measures each must undertake during a specific vessel-to-facility interface, during a series of interfaces between the vessel and the facility, or during a vessel-to-vessel activity. (b) Details as to who must complete a DoS, when a DoS must be completed, and how long a DoS must be retained are included in parts 104 through 106 of this subchapter. A DoS must, at a minimum, include the information found in the ISPS Code, part B, appendix 1 (Incorporated by reference, see § 101.115). (c) All vessels and facilities required to comply with parts 104, 105, and 106 of this subchapter must, at a minimum, comply with the DoS requirements of the MARSEC Level set for the port. (d) The COTP may also require a DoS be completed for vessels and facilities during periods of critical port operations, special marine events, or when vessels give notification of a higher MARSEC Level than that set in the COTP's Area of Responsibility (AOR). [USCG-2003-14792, 68 FR 39278, July 1, 2003, as amended at 68 FR 60472, Oct. 22, 2003] § 101.510 Assessment tools. Ports, vessels, and facilities required to conduct security assessments by part 103, 104, 105, or 106 of this subchapter may use any assessment tool that meets the standards set out in part 103, 104, 105, or 106, as applicable. These tools may include USCG assessment tools, which are available from the cognizant COTP or at https://www.dco.uscg.mil/Our-Organization/NVIC/ (a) Navigation and Vessel Inspection Circular titled, “Guidelines for Port Security Committees, and Port Security Plans Required for U.S. Ports” (NVIC 9-02 series); (b) Navigation and Vessel Inspection Circular titled, “Security Guidelines for Vessels”, (NVIC 10-02 change 1); and (c) Navigation and Vessel Inspection Circular titled, “Security Guidelines for Facilities”, (NVIC 11-02 change 1). [USCG-2012-0306, 77 FR 37313, June 21, 2012, as amended by USCG-2013-0397, 78 FR 39173, July 1, 2013; USCG-2022-0323, 88 FR 10028, Feb. 16, 2023] § 101.514 TWIC Requirement. (a) All persons requiring unescorted access to secure areas of vessels, facilities, and OCS facilities regulated by parts 104, 105 or 106 of this subchapter must possess a TWIC before such access is granted, except as otherwise noted in this section. A TWIC must be obtained via the procedures established by TSA in 49 CFR part 1572. (b) Federal officials are not required to obtain or possess a TWIC. Except in cases of emergencies or other exigent circumstances, in order to gain unescorted access to a secure area of a vessel, facility, or OCS facility regulated by parts 104, 105 or 106 of this subchapter, a Federal official must present his/her agency issued, HSPD 12 compliant credential. Until each agency issues its HSPD 12 compliant cards, Federal officials may gain unescorted access by using their agency's official credential. The COTP will advise facilities and vessels within his or her area of responsibility as agencies come into compliance with HSPD 12. (c) Law enforcement officials at the State or local level are not required to obtain or possess a TWIC to gain unescorted access to secure areas. They may, however, voluntarily obtain a TWIC where their offices fall within or where they require frequent unescorted access to a secure area of a vessel, facility or OCS facility. (d) Emergency responders at the State or local level are not required to obtain or possess a TWIC to gain unescorted access to secure areas during an emergency situation. They may, however, voluntarily obtain a TWIC where their offices fall within or where they desire frequent unescorted access to a secure area of a vessel, facility or OCS facility in non-emergency situations. [USCG-2006-24196, 72 FR 3578, Jan. 25, 2007, as amended at 73 FR 25565, May 7, 2008; USCG-2015-0433, 80 FR 44281, July 27, 2015; USCG-2007-28915, 81 FR 57708, Aug. 23, 2016] § 101.515 TWIC/Personal Identification. (a) Persons not described in § 101.514 must present personal identification in order to gain entry to a vessel, facility, and OCS facility regulated by parts 104, 105 or 106 of this subchapter. These individuals must be under escort, as that term is defined in § 101.105 of this part, while inside a secure area. This personal identification must, at a minimum, meet the following requirements: (1) Be laminated or otherwise secure against tampering; (2) Contain the individual's full name (full first and last names, middle initial is acceptable); (3) Contain a photo that accurately depicts that individual's current facial appearance; and (4) Bear the name of the issuing authority. (b) The issuing authority in paragraph (a)(4) of this section must be: (1) A government authority, or an organization authorized to act on behalf of a government authority; or (2) The individual's employer, union, or trade association. (c) Vessel, facility, and OCS facility owners and operators must permit law enforcement officials, in the performance of their official duties, who present proper identification in accordance with this section and § 101.514 to enter or board that vessel, facility, or OCS facility at any time, without delay or obstruction. Law enforcement officials, upon entering or boarding a vessel, facility, or OCS facility, will, as soon as practicable, explain their mission to the Master, owner, or operator, or their designated agent. (d) Inspection of credential. (2) Each person who has been issued or possesses a TWIC must pass an electronic TWIC inspection, and must submit his or her reference biometric, such as a fingerprint, and any other required information, such as a Personal Identification Number, upon a request from TSA, the Coast Guard, any other authorized DHS representative, or a Federal, State, or local law enforcement officer. [USCG-2006-24196, 72 FR 3578, Jan. 25, 2007, as amended by USCG-2007-28915, 81 FR 57708, Aug. 23, 2016] § 101.520 Electronic TWIC inspection. To conduct electronic TWIC inspection, the owner or operator of a vessel or facility must ensure the following actions are performed. (a) Card authentication. (b) Card validity check. (c) Identity verification. (2) If an individual is unable to provide a valid live sample biometric, the TWIC-holder must enter a Personal Identification Number (PIN) and pass a visual TWIC inspection. [USCG-2007-28915, 81 FR 57708, Aug. 23, 2016] § 101.525 TSA list of cancelled TWICs. (a) At Maritime Security (MARSEC) Level 1, the card validity check must be conducted using information from the TSA that is no more than 7 days old. (b) At MARSEC Level 2, the card validity check must be conducted using information from the TSA that is no more than 1 day old. (c) At MARSEC Level 3, the card validity check must be conducted using information from the TSA that is no more than 1 day old. (d) The list of cancelled TWICs used to conduct the card validity check must be updated within 12 hours of any increase in MARSEC level, no matter when the information was last updated. (e) Only the most recently obtained list of cancelled TWICs must be used to conduct card validity checks. [USCG-2007-28915, 81 FR 57709, Aug. 23, 2016] § 101.530 PACS requirements for Risk Group A. This section lays out requirements for a Physical Access Control System (PACS) that may be used to meet electronic TWIC inspection requirements. (a) A PACS may use a TWIC directly to perform electronic TWIC inspection; (b) Each PACS card issued to an individual must be linked to that individual's TWIC, and the PACS must contain the following information from each linked TWIC: (1) The name of the TWIC-holder holder as represented in the Printed Information container of the TWIC. (2) The TWIC-signed CHUID (with digital signature and expiration date). (3) The TWIC resident biometric template. (4) The TWIC digital facial image. (5) The PACS Personal Identification Number (PIN). (c) When first linked, a one-time electronic TWIC inspection must be performed, and the TWIC must be verified as authentic, valid, and biometrically matched to the individual presenting the TWIC. (d) Each time the PACS card is used to gain access to a secure area, the PACS must— (1) Conduct identity verification by: (i) Conducting a biometric scan, and match the result with the biometric template stored in the PACS that is linked to the TWIC, or (ii) Having the individual enter a stored PACS PIN and conducting a Non-TWIC visual identity verification as defined in § 101.105. (2) Conduct a card validity check; and (3) Maintain records in accordance with § 104.235(g) or § 105.225(g) of this subchapter, as appropriate. [USCG-2007-28915, 81 FR 57709, Aug. 23, 2016] § 101.535 Electronic TWIC inspection requirements for Risk Group A. Owners or operators of vessels or facilities subject to part 104 or 105 of this subchapter, that are assigned to Risk Group A in § 104.263 or § 105.253 of this subchapter, must ensure that a Transportation Worker Identification Credential (TWIC) Program is implemented as follows: (a) Requirements for Risk Group A vessels. (b) Requirements for Risk Group A facilities. (c) A Physical Access Control System that meets the requirements of § 101.530 may be used to meet the requirements of this section. (d) The requirements of this section do not apply under certain situations described in § 101.550 or § 101.555. (e) Emergency access to secure areas, including access by law enforcement and emergency responders, does not require electronic TWIC inspection. [USCG-2007-28915, 81 FR 57709, Aug. 23, 2016] § 101.540 Electronic TWIC inspection requirements for vessels, facilities, and OCS facilities not in Risk Group A. A vessel or facility not in Risk Group A may use the electronic TWIC inspection requirements of § 101.535 in lieu of visual TWIC inspection. If electronic TWIC inspection is used, the recordkeeping requirements of § 104.235(b)(9) and (c) of this subchapter, or § 105.225(b)(9) and (c) of this subchapter, as appropriate, apply. [USCG-2007-28915, 81 FR 57709, Aug. 23, 2016] § 101.545 [Reserved] § 101.550 TWIC inspection requirements in special circumstances. Owners or operators of any vessel, facility, or Outer Continental Shelf (OCS) facility subject to part 104, 105, or 106 of this subchapter must ensure that a Transportation Worker Identification Credential (TWIC) Program is implemented as follows: (a) Lost, damaged, stolen, or expired TWIC. (1) The individual provides proof that he or she has reported the TWIC as lost, damaged, or stolen to the Transportation Security Administration (TSA) as required in 49 CFR 1572.19(f), or the individual provides proof that he or she has applied for the renewal of an expired TWIC; (2) The individual can present another identification credential that meets the requirements of § 101.515; and (3) There are no other suspicious circumstances associated with the individual's claim that the TWIC was lost, damaged, or stolen. (b) TWIC on the Canceled Card List. (c) Special requirements for Risk Group A vessels and facilities. (1) The owner or operator must conduct a visual TWIC inspection and require the individual to correctly submit his or her TWIC Personal Identification Number. (2) [Reserved] (d) If an individual cannot present a TWIC for any reason other than those outlined in paragraphs (a) or (b) of this section, the vessel or facility operator may not grant the individual unescorted access to secure areas. The individual must be under escort at all times while in the secure area. (e) With the exception of individuals granted access according to paragraphs (a) or (b) of this section, all individuals granted unescorted access to secure areas of a vessel, facility, or OCS facility must be able to produce their TWICs upon request from the TSA, the Coast Guard, another authorized Department of Homeland Security representative, or a Federal, State, or local law enforcement officer. (f) There must be disciplinary measures in place to prevent fraud and abuse. (g) Owners or operators must establish the frequency of the application of any security measures for access control in their approved security plans, particularly if these security measures are applied on a random or occasional basis. (h) The vessel, facility, or OCS facility operator should coordinate the TWIC Program, when practical, with identification and TWIC access control measures of other entities that interface with the vessel, facility, or OCS facility. [USCG-2007-28915, 81 FR 57709, Aug. 23, 2016] § 101.555 Recurring Unescorted Access for Risk Group A vessels and facilities. This section describes how designated TWIC-holders may access certain secure areas on Risk Group A vessels and facilities on a continual and repeated basis without undergoing repeated electronic TWIC inspections. (a) An individual may enter a secure area on a vessel or facility without undergoing an electronic TWIC inspection under the following conditions: (1) Access is through a Designated Recurring Access Area (DRAA), designated under an approved Vessel, Facility, or Joint Vessel-Facility Security Plan. (2) The entire DRAA is continuously monitored by security personnel at the access points to secure areas used by personnel seeking Recurring Unescorted Access. (3) The individual possesses a valid TWIC. (4) The individual has passed an electronic TWIC inspection within each shift and in the presence of the on-scene security personnel. (5) The individual passes an additional electronic TWIC inspection prior to being granted unescorted access to a secure area if he or she enters an unsecured area outside the DRAA and then returns. (b) The following requirements apply to a DRAA: (1) It must consist of an unsecured area where personnel will be moving into an adjacent secure area repeatedly. (2) The entire DRAA must be visible to security personnel. (3) During operation as a DRAA, there must be security personnel present at all times. (c) An area may operate as a DRAA at certain times, and during other times, access to secure areas may be obtained through the procedures in § 101.535. (d) Personnel may enter the secure areas adjacent to a DRAA at any time using the procedures in § 101.535. [USCG-2007-28915, 81 FR 57710, Aug. 23, 2016] Subpart F—Cybersecurity Source: 90 FR 6447, Jan. 17, 2025, unless otherwise noted. § 101.600 Purpose. The purpose of this subpart is to set minimum cybersecurity requirements for U.S.-flagged vessels, facilities, and Outer Continental Shelf (OCS) facilities to safeguard and ensure the security and resilience of the Marine Transportation System (MTS). § 101.605 Applicability. (a) This subpart applies to the owners and operators of U.S.-flagged vessels, facilities, and OCS facilities required to have a security plan under 33 CFR parts 104, 105, and 106. (b) This subpart does not apply to any foreign-flagged vessels subject to 33 CFR part 104. § 101.610 Federalism. Consistent with § 101.112(b), with respect to a facility regulated under 33 CFR part 105 to which this subpart applies, the regulations in this subpart have preemptive effect over a State or local law or regulation insofar as the State or local law or regulation applicable to the facility conflicts with these regulations, either by actually conflicting or by frustrating an overriding Federal need for uniformity. § 101.615 Definitions. Unless otherwise specified, as used in this subpart: Approved list Backup Credentials Critical Information Technology (IT) or Operational Technology (OT) systems Cyber incident Cyber Incident Response Plan Cyber threat Cybersecurity Assessment Cybersecurity Officer, Cybersecurity Plan Cybersecurity risk Cybersecurity vulnerability Encryption Executable code Exploitable channel Firmware Hardware Human-Machine Interface, Information system Information Technology, Known Exploited Vulnerability, or KEV, Log Multifactor authentication Network Network map Network segmentation Operational Technology, Patching Penetration test Principle of least privilege Privileged user Reportable cyber incident Risk Software Supply chain Threat Vulnerability Vulnerability scan § 101.620 Owner or operator. (a) Each owner or operator of a U.S.-flagged vessel, facility, or OCS facility is responsible for compliance with the requirements of this subpart. (b) For each U.S.-flagged vessel, facility, or OCS facility, the owner or operator must— (1) Ensure a Cybersecurity Plan is developed, approved, and maintained; (2) Define in Section 1 of the Cybersecurity Plan the cybersecurity organizational structure and identify each person exercising cybersecurity duties and responsibilities within that structure, with the support needed to fulfill those obligations; (3) Designate, in writing, by name and by title, a Cybersecurity Officer (CySO) who is accessible to the Coast Guard 24 hours a day, 7 days a week, and identify how the CySO can be contacted at any time; (4) Ensure that cybersecurity exercises, audits, and inspections, as well as the Cybersecurity Assessment, are conducted as required by this part and in accordance with the Cybersecurity Plan (see § 101.625(d)(1), (3), (6) and (7)); (5) Ensure that the U.S.-flagged vessel, facility, or OCS facility operates in compliance with the approved Cybersecurity Plan; (6) Ensure the development, approval, and execution of the Cyber Incident Response Plan; and (7) For entities that have not reported to the Coast Guard pursuant to, or are not subject to, 33 CFR 6.16-1, ensure all reportable cyber incidents are reported to the National Response Center (NRC). § 101.625 Cybersecurity Officer. (a) Other duties. (b) Serving as CySO for Multiple Vessels, Facilities, or OCS Facilities. (c) Assigning Duties Permitted. (d) Responsibilities. (1) Ensure that the Cybersecurity Assessment is conducted as required by this part; (2) Ensure the cybersecurity measures in the Cybersecurity Plan are developed, implemented, and operating as intended; (3) Ensure that an annual audit of the Cybersecurity Plan and its implementation is conducted and, if necessary, ensure that the Cybersecurity Plan is updated; (4) Ensure the Cyber Incident Response Plan is executed and exercised; (5) Ensure the Cybersecurity Plan is exercised in accordance with § 101.635(c); (6) Arrange for cybersecurity inspections, which may be conducted as their own inspections, or in conjunction with any scheduled Coast Guard inspection of a U.S.-flagged vessel, facility, or OCS facility; (7) Ensure the prompt correction of problems identified by exercises, audits, or inspections; (8) Enhance the cybersecurity awareness and vigilance of personnel; (9) Ensure adequate cybersecurity training of personnel; (10) Ensure all reportable cyber incidents are recorded and reported to the owner or operator; (11) Ensure that records required by this part are maintained in accordance with § 101.640; (12) Ensure any reports as required by this part have been prepared and submitted; (13) Ensure that the Cybersecurity Plan, as well as proposed amendments to cybersecurity measures included in the Plan, are submitted for approval to the cognizant COTP or the Officer in Charge, Marine Inspections (OCMI) for facilities or OCS facilities, or to the Marine Safety Center (MSC) for U.S.-flagged vessels, prior to amending the Cybersecurity Plan, in accordance with § 101.630; (14) Ensure relevant security and management personnel are briefed regarding changes in cybersecurity conditions on board the U.S.-flagged vessel, facility, or OCS facility; and (15) Ensure identification and mitigation of all KEVs in critical IT or OT systems, without delay. (e) Qualifications. (1) General vessel, facility, or OCS facility operations and conditions; (2) General cybersecurity guidance and best practices; (3) The vessel, facility, or OCS facility's Cyber Incident Response Plan; (4) The vessel, facility, or OCS facility's Cybersecurity Plan; (5) Cybersecurity equipment and systems; (6) Methods of conducting cybersecurity audits, inspections, control, and monitoring techniques; (7) Relevant laws and regulations pertaining to cybersecurity; (8) Instruction techniques for cybersecurity training and education; (9) Handling of Sensitive Security Information and security related communications; (10) Current cybersecurity threat patterns and KEVs; (11) Recognizing characteristics and behavioral patterns of persons who are likely to threaten security; and (12) Conducting and assessing cybersecurity drills and exercises. § 101.630 Cybersecurity Plan. (a) General. (b) Protecting sensitive security information. (c) Format. (1) Cybersecurity organization and identity of the CySO; (2) Personnel training; (3) Drills and exercises; (4) Records and documentation; (5) Communications; (6) Cybersecurity systems and equipment, with associated maintenance; (7) Cybersecurity measures for access control, including the computer, IT, and OT access areas; (8) Physical security controls for IT and OT systems; (9) Cybersecurity measures for monitoring; (10) Audits and amendments to the Cybersecurity Plan; (11) Reports of all cybersecurity audits and inspections, to include documentation of resolution or mitigation of all identified vulnerabilities; (12) Documentation of all identified, unresolved vulnerabilities, to include those that are intentionally unresolved due to owner or operator risk acceptance; (13) Cyber incident reporting procedures in accordance with part 101 of this subchapter; and (14) Cybersecurity Assessment. (d) Submission and approval. (1) The COTP, OCMI, or MSC will evaluate each submission for compliance with this part, and either— (i) Approve the Cybersecurity Plan and return a letter to the owner or operator indicating approval and any conditional approval; (ii) Require additional information or revisions to the Cybersecurity Plan and return a copy to the owner or operator with a brief description of the required revisions or additional information; or (iii) Disapprove the Cybersecurity Plan and return a copy to the owner or operator with a brief statement of the reasons for disapproval. (iv) If the cognizant COTP, OCMI, or MSC requires additional time to review the Plan, they may return a written acknowledgement to the owner or operator stating that the Coast Guard will review the Cybersecurity Plan submitted for approval, and that the U.S.-flagged vessel, facility, or OCS facility may continue to operate as long as it remains in compliance with the submitted Cybersecurity Plan. (2) Owners or operators submitting one Cybersecurity Plan to cover two or more U.S.-flagged vessels, facilities, or OCS facilities of similar operations must ensure the Plan addresses the specific cybersecurity risks for each U.S.-flagged vessel, facility, or OCS facility. (3) A Plan that is approved by the COTP, OCMI, or MSC is valid for 5 years from the date of its approval. (e) Amendments to the Cybersecurity Plan. (i) The owner or operator or the CySO; or (ii) When the COTP, OCMI, or MSC finds that the Cybersecurity Plan no longer meets the requirements in this part, the Plan will be returned to the owner or operator with a letter explaining why the Plan no longer meets the requirements and requires amendment. The owner or operator will have at least 60 days to submit its proposed amendments. Until the amendments are approved, the owner or operator must ensure temporary cybersecurity measures are implemented to the satisfaction of the Coast Guard. (2) Proposed amendments to the Cybersecurity Plan must be sent to the Coast Guard at least 30 days before the proposed amendment's effective date. The Coast Guard will approve or disapprove the proposed amendment in accordance with this part. (i) Nothing in this section should be construed as limiting the owner or operator of the U.S.-flagged vessel, facility, or OCS facility from the timely implementation of such additional security measures not enumerated in the approved VSP, FSP, or OCS FSP as necessary to address exigent security situations. (ii) In such cases, the owner or operator must notify the cognizant COTP for a facility or OCS facility, or the MSC for U.S.-flagged vessels, by the most rapid means practicable as to the nature of the additional measures, the circumstances that prompted these additional measures, and the period of time these additional measures are expected to be in place. (3) If the owner or operator has changed, the CySO must amend the Cybersecurity Plan as soon as reasonably practicable in light of the individual circumstances, but, in any case, not longer than 96 hours, to include the name and contact information of the new owner or operator and submit the affected portion of the Plan for review and approval in accordance with this part. (4) If the CySO has changed, the Coast Guard must be notified as soon as reasonably practicable in light of the individual circumstances, but, in any case, not longer than 96 hours, and the affected portion of the Cybersecurity Plan must be amended and submitted to the Coast Guard for review and approval in accordance with this part as soon as reasonably practicable in light of the individual circumstances, but, in any case, not longer than 96 hours. (f) Audits. (2) In addition to the annual audit, the CySO must ensure that an audit of the Cybersecurity Plan occurs if there is a change in the owner or operator of the U.S.-flagged vessel, facility, or OCS facility, or if there have been modifications to the cybersecurity measures, including, but not limited to, physical access, incident response procedures, security measures, or operations. (3) Additional audits of the Cybersecurity Plan as a result of modifications to the U.S.-flagged vessel, facility, or OCS facility, or because of changes to the cybersecurity measures in accordance with paragraph (f)(2) of this section, may be limited to those sections of the Plan affected by the modifications. (4) Personnel conducting internal audits of the cybersecurity measures specified in the Plan or evaluating its implementation must— (i) Have knowledge of methods of conducting audits and inspections, as well as access control and monitoring techniques; (ii) Not have regularly assigned cybersecurity duties for the U.S.-flagged vessel, facility, or OCS facility being audited; and (iii) Be independent of any cybersecurity measures being audited. (5) If the results of an audit require amending the Cybersecurity Plan, the CySO must submit, in accordance with this part, the amendments to the Coast Guard for review and approval no later than 30 days after completion of the audit. § 101.635 Drills and exercises. (a) General. (2) The drill or exercise requirements specified in this section may be satisfied with the implementation of cybersecurity measures required by the VSP, FSP, OCS FSP, and Cybersecurity Plan as the result of a cyber incident, as long as the U.S.-flagged vessel, facility, or OCS facility achieves and documents attainment of drill and exercise goals for the cognizant COTP. (b) Drills. (2) Drills must test individual elements of the Cybersecurity Plan, including responses to cybersecurity threats and incidents. Cybersecurity drills must take into account the types of operations of the U.S.-flagged vessel, facility, or OCS facility; changes to the U.S.-flagged vessel, facility, or OCS facility personnel; the type of vessel a facility is serving; and other relevant circumstances. (3) If a vessel is moored at a facility on a date a facility has planned to conduct any drills, the facility cannot require the vessel or vessel personnel to be a part of or participate in the facility's scheduled drill. (c) Exercises. (2) Exercises may be— (i) Full-scale or live; (ii) Tabletop simulation; (iii) Combined with other appropriate exercises as required by 33 CFR 104.230, 105.220, or 106.225; or (iv) A combination of the elements in paragraphs (c)(2)(i) through (iii) of this section. (3) Exercises may be vessel-, facility-, or OCS facility-specific, or part of a cooperative exercise program to exercise applicable vessel, facility, and OCS facility Cybersecurity Plans or comprehensive port exercises. (4) Each exercise must test communication and notification procedures and elements of coordination, resource availability, and response. (5) Exercises are a full test of the cybersecurity program and must include the substantial and active participation of the CySO(s). (6) If any corrective action identified during an exercise is needed, it must be addressed and documented as soon as possible. § 101.640 Records and documentation. All records, reports, and other documents mentioned in this subpart must be created and maintained in accordance with 33 CFR 104.235 for U.S.-flagged vessels, 105.225 for facilities, and 106.230 for OCS facilities. At a minimum, the records must be created for the following activities: training, drills, exercises, cybersecurity threats, reportable cyber incidents, and audits of the Cybersecurity Plan. § 101.645 Communications. (a) The CySO must have a means to effectively notify owners or operators and personnel of a U.S.-flagged vessel, facility, or OCS facility of changes in cybersecurity conditions at the U.S.-flagged vessel, facility, and OCS facility and document these means in Section 5 of the Cybersecurity Plan. (b) Communication systems and procedures must allow effective and continuous communications between U.S.-flagged vessel, facility, and OCS facility security personnel, vessels interfacing with a facility or an OCS facility, the cognizant COTP, and national and local authorities with security responsibilities. § 101.650 Cybersecurity measures. (a) Account security measures. (1) Automatic account lockout after repeated failed login attempts must be enabled on all password-protected IT systems; (2) Default passwords must be changed before using any IT or OT systems. When changing default passwords is not feasible, appropriate compensating security controls must be implemented and documented; (3) A minimum password strength must be maintained on all IT and OT systems that are technically capable of password protection; (4) Multifactor authentication must be implemented on password-protected IT and remotely accessible OT systems. When multifactor authentication is not feasible, appropriate compensating security controls must be implemented and documented; (5) The principle of least privilege must be applied to administrator or otherwise privileged accounts on both IT and OT systems; (6) The owner or operator must ensure that users maintain separate credentials on critical IT and OT systems; and (7) The owner or operator must ensure that user credentials are removed or revoked when a user leaves the organization. (b) Device security measures. (1) Develop and maintain a list of approved hardware, firmware, and software that may be installed on IT or OT systems. Any hardware, firmware, and software installed on IT and OT systems must be on the owner- or operator-approved list; (2) Ensure applications running executable code are disabled by default on critical IT and OT systems; (3) Maintain an accurate inventory of network-connected systems, including designation of critical IT and OT systems; and (4) Develop and maintain accurate documentation identifying the network map and OT device configuration information. (c) Data security measures. (1) Logs must be securely captured, stored, and protected so that they are accessible only by privileged users; and (2) Effective encryption must be deployed to maintain confidentiality of sensitive data and integrity of IT and OT traffic, when technically feasible. (d) Cybersecurity training for personnel. (1) All personnel with access to the IT or OT systems, including contractors, whether part-time, full-time, temporary, or permanent, must have cybersecurity training in the following topics: (i) Relevant provisions of the Cybersecurity Plan; (ii) Recognition and detection of cybersecurity threats and all types of cyber incidents; (iii) Techniques used to circumvent cybersecurity measures; (iv) Procedures for reporting a cyber incident to the CySO; and (v) OT-specific cybersecurity training for all personnel whose duties include using OT. (2) Key personnel with access to the IT or remotely accessible OT systems, including contractors, whether part-time, full-time, temporary, or permanent, must also have cybersecurity training in the following additional topics: (i) Understanding their roles and responsibilities during a cyber incident and response procedure; and (ii) Maintaining current knowledge of changing cybersecurity threats and countermeasures. (3) When personnel must access IT or OT systems but are unable to receive cybersecurity training as specified in paragraphs (d)(1) and (2) of this section, they must be accompanied or monitored by a person who has completed the training specified in paragraphs (d)(1) and (2) of this section. (4) All personnel must complete the training specified in paragraphs (d)(1)(ii) through (v) of this section by January 12, 2026, and annually thereafter. Key personnel must complete the training specified in paragraph (d)(2) of this section by January 12, 2026, and annually thereafter, or more frequently as needed. Training for new personnel not in place at the time of the effective date of this rule must be completed within 5 days of gaining system access, but no later than within 30 days of hiring, and annually thereafter. Training for personnel on new IT or OT systems not in place at the time of the effective date of this rule must be completed within 5 days of system access, and annually thereafter. All personnel must complete the training specified in paragraph (d)(1)(i) within 60 days of receiving approval of the Cybersecurity Plan. The training must be documented and maintained in the owner's or operator's records in accordance with 33 CFR 104.235 for U.S.-flagged vessels, 105.225 for facilities, and 106.230 for OCS facilities. (e) Risk management. (1) Cybersecurity Assessment. (i) Analyze all networks to identify vulnerabilities to critical IT and OT systems and the risk posed by each digital asset; (ii) Validate the Cybersecurity Plan; (iii) Document recommendations and resolutions in the Vessel Security Assessment (VSA), Facility Security Assessment (FSA), or OCS FSA, in accordance with 33 CFR 104.305, 105.305, and 106.305; (iv) Document and ensure patching or implementing of documented compensating controls for all KEVs in critical IT or OT systems, without delay; and (v) Incorporate recommendations and resolutions from paragraph (e)(1)(iii) of this section into the Cybersecurity Plan through an amendment, in accordance with § 101.630(e). (2) Penetration testing. (3) Routine system maintenance. (i) Ensure patching or implementation of documented compensating controls for all KEVs in critical IT or OT systems, without delay; (ii) Maintain a method to receive and act on publicly submitted vulnerabilities; (iii) Maintain a method to share threat and vulnerability information with external stakeholders; (iv) Ensure there are no exploitable channels directly exposed to internet-accessible systems; (v) Ensure no OT is connected to the publicly accessible internet unless explicitly required for operation, and verify that, for any remotely accessible OT system, there is a documented justification; and (vi) Conduct vulnerability scans as specified in the Cybersecurity Plan. (f) Supply chain. (1) Consider cybersecurity capability as criteria for evaluation to procure IT and OT systems or services; (2) Establish a process through which all IT and OT vendors or service providers notify the owner or operator or designated CySO of any cybersecurity vulnerabilities or reportable cyber incidents, without delay; and (3) Monitor and document all third-party remote connections to detect cyber incidents. (g) Resilience. (1) For entities that have not reported to the Coast Guard pursuant to, or not subject to, 33 CFR 6.16-1, report reportable cyber incidents to the NRC without delay; (2) In addition to other plans mentioned in this subpart, develop, implement, maintain, and exercise the Cyber Incident Response Plan; (3) Periodically validate the effectiveness of the Cybersecurity Plan through annual exercises, annual reviews of incident response cases, or post-cyber incident review, as determined by the owner or operator; and (4) Perform backup of critical IT and OT systems, with those backups being sufficiently protected and tested frequently. (h) Network segmentation. (1) Implement segmentation between IT and OT networks; and (2) Verify that all connections between IT and OT systems are logged and monitored for suspicious activity, breaches of security, TSIs, unauthorized access, and cyber incidents. (i) Physical security. (1) In addition to any other requirements in this part, limit physical access to OT and related IT equipment to only authorized personnel, and confirm that all HMIs and other hardware are secured, monitored, and logged for personnel access; and (2) Ensure unauthorized media and hardware are not connected to IT and OT infrastructure, including blocking, disabling, or removing unused physical access ports, and establishing procedures for granting access on a by-exception basis. § 101.655 Cybersecurity compliance dates. All Cybersecurity Plans mentioned in this subpart must be submitted to the Coast Guard for review and approval no later than July 16, 2027, according to 33 CFR 104.410 for U.S.-flagged vessels, 33 CFR 105.410 for facilities, or 33 CFR 106.410 for OCS facilities. § 101.660 Cybersecurity compliance documentation. Each owner or operator must ensure that the cybersecurity portion of their Plan and penetration test results are available to the Coast Guard upon request. The Alternative Security Program provisions apply to cybersecurity compliance documentation and are addressed in 33 CFR 104.140 for vessels, 33 CFR 105.140 for facilities, and 33 CFR 106.135 for OCS facilities. § 101.665 Noncompliance, waivers, and equivalents. An owner or operator, after completion of the required Cybersecurity Assessment, may seek a waiver or an equivalence determination for the requirements in subpart F using the standards and submission procedures applicable to a U.S.-flagged vessel, facility, or OCS facility as outlined in 33 CFR 101.130, 104.130, 104.135, 105.130, 105.135, 106.125, or 106.130. If an owner or operator must temporarily deviate from the requirements in this part, they must notify the cognizant COTP for facilities or OCS facilities, or the MSC for U.S.-flagged vessels, and may request temporary permission to continue to operate under the provisions as outlined in 33 CFR 104.125, 105.125, or 106.120. § 101.670 Severability. Any provision of this subpart held to be invalid or unenforceable as applied to any person or circumstance shall be construed so as to continue to give the maximum effect to the provision permitted by law, including as applied to persons not similarly situated or to dissimilar circumstances, unless such holding is that the provision of this subpart is invalid and unenforceable in all circumstances, in which event the provision shall be severable from the remainder of this subpart and shall not affect the remainder thereof.