33 CFR 101 Subpart F
USCG cybersecurity (33 CFR 101 Subpart F) - reporting in force, Plan due 16 Jul 2027
NRC reporting under 33 CFR 101 Subpart F is in force. CySO designation, assessment, and Cybersecurity Plan submit 16 Jul 2027. VesselMark gives you the controls, evidence workspace, and a packet you attach to your Plan. We do not generate the Plan, write it, certify it, or file it. You are responsible for the Plan. We give you the evidence trail that supports it.
Not a TPO. Not an ASP. Not a CySO. Not a filing service. Not shipboard hardware.
The calendar
What is due when
| Date | Milestone |
|---|---|
| 17 Jan 2025 | Final rule published (90 FR 6298) |
| 16 Jul 2025 | NRC reporting in force |
| 12 Jan 2026 | Initial training date (has passed) |
| 16 Jul 2027 | CySO in writing, assessment, submit Plan (vessels to MSC, facilities to COTP/OCMI) |
| - | Plan valid 5 years. Penetration test at renewal, not first filing. |
Inspectors in 2026 check training and roster, not an approved Plan. Plans go via DoD SAFE (MCP-WI-003) if you need the submission path. Homeport is dead. Do not send people to Homeport.
Applicability trap
Who owes a Cybersecurity Plan?
Subpart F is MTSA-scoped (33 CFR 101.605). If you already owe a 104, 105, or 106 plan, you now owe a Cybersecurity Plan. If you do not, you do not. Towing trigger is 33 CFR 104.105(a)(11): greater than 8 meters towing a Part 104 tank or CDC barge, with fleeting, lock, and assist exceptions. Dry inland on Sub M plus AWO RCP is usually out. Coastal and harbor are usually in.
Usually out
- • Dry inland on Sub M + AWO RCP
- • Most barges not carrying CDC or tank cargo
Usually in
- • Coastal and harbor towing with tank/CDC barges
- • Part 104 vessels
- • Facilities under Part 105
- • OCS facilities under Part 106
Read 33 CFR 101.605 and 33 CFR 104.105(a)(11) for the full applicability test. If unsure, ask your MSC or COTP/OCMI.
What this is not
We do not generate, write, certify, or file a 33 CFR 101.630 Cybersecurity Plan.
VesselMark is compliance management software. We are not a TPO. Not a class society. Not an Alternative Security Program. Not a CySO. Not a filing service. Not a SOC. Not shipboard hardware. You are responsible for the Cybersecurity Plan. We give you the controls, the evidence workspace, and a packet you attach to your Plan. The Plan itself is yours to write and file.
How it works
You do the work. We keep the evidence defensible.
VesselMark breaks down Subpart F obligations into plain-English controls. You see what is outstanding, close the gap, and attach evidence. Documents are content-hashed and held in write-once storage. When it is time to submit your Plan, export a one-click packet: your posture and evidence index, defensible and point-in-time. You attach that packet to your Plan.
Plain-English controls
See what is outstanding without a cybersecurity degree. Every control has a plain-language title and guidance.
Write-once evidence
Documents are content-hashed and held in write-once storage. Your evidence trail is tamper-evident.
One-click inspection packet
Export your posture and evidence index. A defensible point-in-time snapshot you attach to your Plan.
Renewal reminders
Drills, log refreshes, annual reviews. We schedule them, track what is due, and email before anything slips.
Unlimited users
No per-user tax. Add every captain, port engineer, and office admin who touches the system.
Sits beside existing ops
Not a replacement for Helm CONNECT, TBS, Mobile Ops, or ABS NS. Compliance-first, operations-adjacent.
References
Read the rule yourself
Final rule (90 FR 6298): https://www.federalregister.gov/documents/2025/01/17/2025-00708/cybersecurity-in-the-marine-transportation-system
eCFR 33 CFR 101 Subpart F: https://www.ecfr.gov/current/title-33/chapter-I/subchapter-H/part-101/subpart-F
Cornell 33 CFR 101.605 (applicability): https://www.law.cornell.edu/cfr/text/33/101.605
Cornell 33 CFR 104.105 (towing trigger): https://www.law.cornell.edu/cfr/text/33/104.105
Related modules
Pick and choose what you need
Subchapter M TSMS software
Run your TSMS here. Plain-English controls, hashed write-once evidence, one-click inspection packet. Not a TPO. Not a class society. $500/vessel/mo, one module.
Learn about Sub M TSMS →Inland towing compliance software
Two jobs, one workspace. Subchapter M TSMS first. USCG cybersecurity only if Subpart F actually applies. Each module $500/vessel/mo.
Learn about towing compliance →Pricing
$500 per vessel per month, one module.
No per-user tax. 14-day free trial, no card required. Annual billing saves 10%.
USCG Cyber (33 CFR 101 Subpart F)
$500/vessel/mo
or $5,400/vessel/yr - save 10%
- ✓ Plain-English controls
- ✓ Write-once evidence + append-only audit trail
- ✓ One-click inspection packet you attach to your Plan
- ✓ Renewal reminders before anything lapses
- ✓ Unlimited users
- ✓ Cancel anytime
Each framework module is priced separately. Pick and choose what you need. USCG cyber without Sub M is fine. Add Subchapter M TSMS if both apply.