U.S. Coast Guard Final Rule on Cybersecurity in the Marine Transportation System (2025)

The U.S. Coast Guard (USCG) released its long-awaited Final Rule on Cybersecurity in the Marine Transportation System (MTS), which officially went into effect on July 16, 2025. This regulatory milestone addresses the growing cybersecurity risks faced by the maritime sector, including hacking, ransomware, GPS spoofing, and potential cyber-piracy incidents. With this rule, the USCG aims to align the United States with international maritime security standards, such as SOLAS and the ISPS Code, while also strengthening domestic resilience under the Maritime Transportation Security Act (MTSA).

πŸ“Œ Key Deadlines and Requirements

The final rule outlines a phased approach with three critical compliance dates:

  1. July 16, 2025 – Immediate Incident Reporting
    • All reportable cyber incidents must be immediately submitted to the National Response Center (NRC).
    • This ensures timely situational awareness and coordinated responses across government agencies and private operators.
  2. January 12, 2026 – Mandatory Cybersecurity Training
    • All personnel working in the Marine Transportation System must complete cybersecurity awareness and response training under 33 CFR 101.650.
    • Training programs are designed to standardize cyber risk understanding among seafarers, port workers, and facility staff.
  3. July 16, 2027 – Cybersecurity Officer, Assessment, and Plan
    • Each operator must designate a Cybersecurity Officer (CySO) responsible for compliance.
    • Operators must conduct a Cybersecurity Assessment of their systems, identifying vulnerabilities and resilience gaps.
    • A comprehensive Cybersecurity Plan must be submitted to the USCG for review and approval.

⚠️ Enforcement and Consequences

The Coast Guard has made it clear that non-compliance will carry serious penalties. Facilities and vessels that fail to comply may face:

  • Deficiency notices
  • Detention of vessels
  • Denial of port entry
  • Captain of the Port (COTP) enforcement actions

These measures underscore the seriousness with which the USCG treats maritime cyber threats. In the post-NotPetya era, where ransomware crippled global shipping operations, regulators now demand proactive defenses to safeguard critical infrastructure.

🌍 Global Alignment and Strategic Value

This final rule does more than just tighten U.S. domestic security. It harmonizes cybersecurity governance with international frameworks, building trust with global partners and ensuring consistency across supply chains. For international operators, compliance with the U.S. standard will also mean readiness for future global regulations under IMO’s Maritime Autonomous Surface Ships (MASS) and cyber risk management guidelines.


λ―Έκ΅­ ν•΄μ•ˆκ²½λΉ„λŒ€μ˜ ν•΄μ–‘μš΄μ†‘μ‹œμŠ€ν…œ μ‚¬μ΄λ²„λ³΄μ•ˆ μ΅œμ’… κ·œμ • (2025)

λ―Έκ΅­ ν•΄μ•ˆκ²½λΉ„λŒ€(USCG)λŠ” ν•΄μ–‘μš΄μ†‘μ‹œμŠ€ν…œ(MTS) λ‚΄ μ‚¬μ΄λ²„λ³΄μ•ˆ μ΅œμ’… κ·œμ •μ„ 2025λ…„ 7μ›” 16μΌλΆ€λ‘œ μ‹œν–‰ν–ˆμŠ΅λ‹ˆλ‹€. 이번 μ‘°μΉ˜λŠ” 해상 μš΄μ†‘ λΆ„μ•Όμ˜ ν•΄ν‚Ή, λžœμ„¬μ›¨μ–΄, GPS μŠ€ν‘Έν•‘, 사이버 해적 ν–‰μœ„ λ“± μƒˆλ‘œμš΄ μœ„ν˜‘μ„ μ²΄κ³„μ μœΌλ‘œ κ΄€λ¦¬ν•˜κΈ° μœ„ν•œ 법적 μž₯μΉ˜μž…λ‹ˆλ‹€. λ˜ν•œ κ΅­λ‚΄ ν•΄μ–‘μš΄μ†‘λ³΄μ•ˆλ²•(MTSA) κΈ°λ°˜μ„ κ°•ν™”ν•˜λ©΄μ„œ κ΅­μ œμ μœΌλ‘œλŠ” SOLAS ν˜‘μ•½ 및 ISPS μ½”λ“œμ™€μ˜ 정합성을 확보해 κΈ€λ‘œλ²Œ 기쀀에 λ°œλ§žμΆ”λŠ” 의미λ₯Ό κ°–μŠ΅λ‹ˆλ‹€.

πŸ“Œ μ£Όμš” 이행 일정

μ΅œμ’… κ·œμ •μ€ 3단계 일정에 따라 μ μš©λ©λ‹ˆλ‹€.

  1. 2025λ…„ 7μ›” 16일 – 사이버 사고 μ¦‰μ‹œ 보고
    • λͺ¨λ“  보고 λŒ€μƒ 사이버 사건은 **κ΅­κ°€λŒ€μ‘μ„Όν„°(NRC)**에 μ¦‰μ‹œ 보고해야 ν•©λ‹ˆλ‹€.
    • 이λ₯Ό 톡해 정뢀와 λ―Όκ°„ 뢀문이 μ‹ μ†νžˆ 상황을 κ³΅μœ ν•˜κ³  λŒ€μ‘ν•  수 μžˆμŠ΅λ‹ˆλ‹€.
  2. 2026λ…„ 1μ›” 12일 – μ‚¬μ΄λ²„λ³΄μ•ˆ 의무 ꡐ윑
    • λͺ¨λ“  κ΄€λ ¨ 인λ ₯이 33 CFR 101.650에 따라 μ‚¬μ΄λ²„λ³΄μ•ˆ κ΅μœ‘μ„ ν•„μˆ˜μ μœΌλ‘œ μ΄μˆ˜ν•΄μ•Ό ν•©λ‹ˆλ‹€.
    • ν•΄μ–‘ μ’…μ‚¬μž, ν•­λ§Œ 근둜자, μ‹œμ„€ 인λ ₯의 λ³΄μ•ˆ 인식 μˆ˜μ€€μ„ ν‘œμ€€ν™”ν•˜λŠ” λͺ©μ μž…λ‹ˆλ‹€.
  3. 2027λ…„ 7μ›” 16일 – λ³΄μ•ˆ μ±…μž„μž, 평가 및 κ³„νš 수립
    • 각 μš΄μ˜μžλŠ” **μ‚¬μ΄λ²„λ³΄μ•ˆ μ±…μž„μž(CySO)**λ₯Ό μ§€μ •ν•΄μ•Ό ν•©λ‹ˆλ‹€.
    • μ‹œμ„€ 및 μ„ λ°• μ‹œμŠ€ν…œμ˜ μ‚¬μ΄λ²„λ³΄μ•ˆ 평가λ₯Ό μ‹€μ‹œν•΄ 취약점을 뢄석해야 ν•©λ‹ˆλ‹€.
    • μ‚¬μ΄λ²„λ³΄μ•ˆ κ³„νšμ„ μž‘μ„±ν•˜μ—¬ ν•΄μ•ˆκ²½λΉ„λŒ€ μŠΉμΈμ„ λ°›μ•„μ•Ό ν•©λ‹ˆλ‹€.

⚠️ λ―Έμ€€μˆ˜ μ‹œ 제재 쑰치

κ·œμ • λΆˆμ΄ν–‰ μ‹œμ—λŠ” μ‹¬κ°ν•œ μ œμž¬κ°€ λ”°λ¦…λ‹ˆλ‹€.

  • 결함 톡보
  • μ„ λ°• μ–΅λ₯˜
  • μž…ν•­ κ±°λΆ€
  • ν•­λ§Œμž₯(COTP)의 μ§‘ν–‰ 쑰치

μ΄λŠ” κ³Όκ±° κΈ€λ‘œλ²Œ ν•΄μš΄μ‚¬λ“€μ΄ NotPetya λžœμ„¬μ›¨μ–΄ 곡격으둜 μˆ˜μ–΅ λ‹¬λŸ¬ ν”Όν•΄λ₯Ό μž…μ—ˆλ˜ 사둀λ₯Ό κ΅ν›ˆ μ‚Όμ•„, 사전적 λŒ€λΉ„λ₯Ό μ œλ„ν™”ν•œ μ‘°μΉ˜μž…λ‹ˆλ‹€.

🌍 ꡭ제적 ν•¨μ˜

이번 κ·œμ •μ€ λ‹¨μˆœνžˆ λ―Έκ΅­ λ‚΄ λ³΄μ•ˆ 강화에 κ·ΈμΉ˜μ§€ μ•Šκ³ , ꡭ제적 ν‘œμ€€κ³Ό μ‘°ν™”λ₯Ό μ΄λ£¨λŠ” μ „λž΅μ  κ°€μΉ˜λ₯Ό κ°€μ§‘λ‹ˆλ‹€. μ•žμœΌλ‘œ IMO μ°¨μ›μ˜ μžμœ¨μš΄ν•­μ„ λ°•(MASS) 및 사이버 리슀크 관리 μ§€μΉ¨κ³Ό 연계될 것이며, 이λ₯Ό 톡해 λ―Έκ΅­κ³Ό ν˜‘λ ₯ν•˜λŠ” κΈ€λ‘œλ²Œ ν•΄μš΄μ‚¬ 및 ν•­λ§Œ μš΄μ˜μžλ“€λ„ λŒ€λΉ„ν•  수 μžˆμŠ΅λ‹ˆλ‹€.

Posted in , , , ,

Leave a comment