<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<REGINFO_RIN_DATA xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" RUN_DATE="2026-04-04-04:00" xsi:noNamespaceSchemaLocation="https://www.reginfo.gov/public/xml/REGINFO_XML_Ver10262011.xsd">
    <RIN_INFO>
        <RIN>1625-AC77</RIN>
        <PUBLICATION>
            <PUBLICATION_ID>202410</PUBLICATION_ID>
            <PUBLICATION_TITLE>The Regulatory Plan and the Unified Agenda of Federal Regulatory and Deregulatory Actions</PUBLICATION_TITLE>
        </PUBLICATION>
        <AGENCY>
            <CODE>1625</CODE>
            <NAME>U.S. Coast Guard</NAME>
            <ACRONYM>USCG</ACRONYM>
        </AGENCY>
        <PARENT_AGENCY>
            <CODE>1600</CODE>
            <NAME>Department of Homeland Security</NAME>
            <ACRONYM>DHS</ACRONYM>
        </PARENT_AGENCY>
        <RULE_TITLE>Cybersecurity in the Marine Transportation System</RULE_TITLE>
        <ABSTRACT><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>The Coast Guard has published a proposed rule to update its maritime security regulations by adding&nbsp;regulations specifically focused on establishing minimum cybersecurity requirements for U.S.-flagged vessels, Outer Continental Shelf facilities, and U.S. facilities subject to the Maritime Transportation Security Act of 2002 regulations.&nbsp; This proposed rulemaking is part of an ongoing effort to address emerging cybersecurity risks and threats to maritime security by including additional security requirements to safeguard the marine transportation system.</p>
</body>
</html>]]></ABSTRACT>
        <PRIORITY_CATEGORY>Other Significant</PRIORITY_CATEGORY>
        <RIN_STATUS>Previously Published in The Unified Agenda</RIN_STATUS>
        <RULE_STAGE>Final Rule Stage</RULE_STAGE>
        <MAJOR>Yes</MAJOR>
        <UNFUNDED_MANDATE_LIST>
            <UNFUNDED_MANDATE>No</UNFUNDED_MANDATE>
        </UNFUNDED_MANDATE_LIST>
        <CFR_LIST>
            <CFR>33 CFR 101</CFR>
        </CFR_LIST>
        <LEGAL_AUTHORITY_LIST>
            <LEGAL_AUTHORITY>46 U.S.C. 70101</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>46 U.S.C. 70102</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>46 U.S.C. 70103</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>46 U.S.C. 70104</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>46 U.S.C. 70124</LEGAL_AUTHORITY>
        </LEGAL_AUTHORITY_LIST>
        <LEGAL_DLINE_LIST/>
        <RPLAN_ENTRY>Yes</RPLAN_ENTRY>
        <RPLAN_INFO>
            <STMT_OF_NEED><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>The purpose of this rulemaking is to set minimum cybersecurity requirements for vessels and facilities to safeguard the Marine Transportation System (MTS) from cybersecurity vulnerabilities.</p>
</body>
</html>]]></STMT_OF_NEED>
            <LEGAL_BASIS><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>The Coast Guard exercises the Maritime Transportation Security Act of 2002 (MTSA) authorities of Chapter 701 of Title 46 of the U.S. Code. This includes the authority to promulgate Chapter 701 regulations under 46 U.S.C. 70124. This statute provides that the Secretary of Homeland Security may issue regulations necessary to implement Chapter 701 of Title 46.&nbsp;</p>
</body>
</html>]]></LEGAL_BASIS>
            <COSTS_AND_BENEFITS><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>The Coast Guard anticipates the costs for this final rule to come primarily from several requirements.&nbsp; These include developing a Cybersecurity Plan and performing cybersecurity drills and exercises.&nbsp; Additional costs are imposed from ensuring and implementing cybersecurity measures, such as account security measures, device security measures, data security measures, cybersecurity training for personnel, reporting cyber incidents, risk management, penetration testing, supply chain management, resilience, network segmentation, and physical security.&nbsp; The Coast Guard anticipates non-quantified benefits from reducing the risk of cyber incidents through enhanced detection and correction of vulnerabilities in Information technology (IT) and Operational technology (OT) systems; improved mitigation for impacted entities and downstream economic participants if an incident occurs; and improved protection of Marine Transportation System (MTS) firm and customer data to protect business operations, build consumer trust, and promote increased commerce in the U.S. economy.&nbsp; Additional benefits will accrue due to improving the minimum standard for cybersecurity to protect the MTS and avoid supply chain disruptions, which is vital to the U.S. economy and U.S. national security.</p>
</body>
</html>]]></COSTS_AND_BENEFITS>
        </RPLAN_INFO>
        <TIMETABLE_LIST>
            <TIMETABLE>
                <TTBL_ACTION>NPRM</TTBL_ACTION>
                <TTBL_DATE>02/22/2024</TTBL_DATE>
                <FR_CITATION>89 FR 13403</FR_CITATION>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>NPRM Comment Period Extended</TTBL_ACTION>
                <TTBL_DATE>04/09/2024</TTBL_DATE>
                <FR_CITATION>89 FR 24751</FR_CITATION>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>NPRM Comment Period End</TTBL_ACTION>
                <TTBL_DATE>04/22/2024</TTBL_DATE>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>Extended Comment Period End</TTBL_ACTION>
                <TTBL_DATE>05/22/2024</TTBL_DATE>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>Final Rule</TTBL_ACTION>
                <TTBL_DATE>12/00/2024</TTBL_DATE>
            </TIMETABLE>
        </TIMETABLE_LIST>
        <RFA_REQUIRED>YES</RFA_REQUIRED>
        <SMALL_ENTITY_LIST>
            <SMALL_ENTITY>Businesses</SMALL_ENTITY>
        </SMALL_ENTITY_LIST>
        <GOVT_LEVEL_LIST>
            <GOVT_LEVEL>Undetermined</GOVT_LEVEL>
        </GOVT_LEVEL_LIST>
        <FEDERALISM>No</FEDERALISM>
        <ENERGY_AFFECTED>No</ENERGY_AFFECTED>
        <FURTHER_INFO_URL>https://www.regulations.gov</FURTHER_INFO_URL>
        <PUBLIC_COMMENT_URL>https://www.regulations.gov</PUBLIC_COMMENT_URL>
        <PRINT_PAPER>Yes</PRINT_PAPER>
        <INTERNATIONAL_INTEREST>No</INTERNATIONAL_INTEREST>
        <AGENCY_CONTACT_LIST>
            <CONTACT>
                <FIRST_NAME>Christopher</FIRST_NAME>
                <LAST_NAME>Rabalais</LAST_NAME>
                <PREFIX>Commander</PREFIX>
                <TITLE>Chief, Systems Engineering Division (CG-ENG-3)</TITLE>
                <AGENCY>
                    <CODE>1625</CODE>
                    <NAME>U.S. Coast Guard</NAME>
                    <ACRONYM>USCG</ACRONYM>
                </AGENCY>
                <PHONE>202 372-1375</PHONE>
                <EMAIL>christopher.p.rabalais@uscg.mil</EMAIL>
                <MAILING_ADDRESS>
                    <STREET_ADDRESS>Office of Design and Engineering Standards, 2703 Martin Luther King Jr. Avenue SE, STOP 7509,</STREET_ADDRESS>
                    <CITY>Washington</CITY>
                    <STATE>DC</STATE>
                    <ZIP>20593-7509</ZIP>
                </MAILING_ADDRESS>
            </CONTACT>
        </AGENCY_CONTACT_LIST>
    </RIN_INFO>
</REGINFO_RIN_DATA>
