Compliance Timeline for MTSA Cyber Regulations
Staying ahead of these deadlines is critical to avoiding penalties and supporting operational resilience.
★ February 2024 – Regulations Issued
USCG updates cybersecurity requirements for MTSA-regulated facilities, mandating the integration of cybersecurity into Facility Security Plans (FSPs) and Vessel Security Plans (VSPs). Compliance planning begins.
★ July 16, 2025 – Final Rule Goes into Effect
The final rule published by the USCG establishes minimum cybersecurity requirements for MTSA-regulated entities. All qualifying cyber incidents must be reported to the National Response Center (NRC). See NVIC 02-24
★ January 12, 2026 – Training Must be Complete
Every employee must complete specified cybersecurity training covering threat recognition, detection, reporting procedures and measures to counter cyber attacks including specialized training for operational technology (OT).
Additionally, key personnel must receive focused training on their roles during a cyber incident, response procedures, and stay current on evolving threats. New hires and staff accessing new IT or OT systems must complete required training within 5 days (and no later than 30 days for new hires) of system access, with annual refresher training thereafter.
★ July 16, 2027 – Full Compliance Deadline
Owners and operators are required to submit a written designation of their Cybersecurity Officer (CySO). Additionally, they must conduct a Cybersecurity Assessment within 24 months of the rule’s effective date and then annually (or sooner if there is a change in ownership)-and submit their Cybersecurity Plan to the USCG for approval within that same 24-month period.