A waiver issued under the physical security regime does not travel with you into the cybersecurity regime. That is the substance of a clarification the Coast Guard's Office of Maritime Cybersecurity Policy published on July 22, 2026, and it matters most to the operators least likely to be watching for it: smaller terminals, vessels, and facilities that received a waiver years ago and have reasonably treated the matter as settled ever since.
The clarification concerns the new maritime cybersecurity regulations in 33 CFR Part 101, Subpart F, which became effective on July 16, 2025. If your organization holds a waiver from the Maritime Transportation Security Act security plan requirements and has assumed that waiver covers the cybersecurity rule as well, the Coast Guard has now said directly that it does not.
What Happened
Some background is useful. The Maritime Transportation Security Act, or MTSA, is the framework under which U.S.-flagged vessels, waterfront facilities, and Outer Continental Shelf facilities maintain security plans, under 33 CFR Parts 104, 105, and 106 respectively. Over the years, the Coast Guard granted waivers or exemptions to certain regulated entities based on risk assessments tied to the security threats prevalent at the time. Those waivers typically relieved an entity of certain Part 104, 105, or 106 requirements because it presented a low physical security risk of a Transportation Security Incident, or TSI, the regulatory term for an incident causing significant loss of life, environmental damage, or transportation system disruption.
On July 22, 2026, the Coast Guard clarified how those legacy waivers interact with the cybersecurity requirements in Subpart F. Entities that were granted a waiver in the past from the requirement to have a security plan under Part 104, 105, or 106 are not automatically exempt from the cybersecurity regulations. The Coast Guard's reasoning is straightforward: the threat landscape has changed significantly since the original MTSA waivers were issued, and it is premature to assume that a low physical security risk equates to a low cybersecurity risk before that question has actually been evaluated.
The required evaluation is the Cybersecurity Assessment, or CSA, under 33 CFR 101.650(e)(1). After completing the CSA, and pursuant to 33 CFR 101.665, an entity may request a waiver from all or individual Subpart F requirements. The deadline for that sequence is July 16, 2027. The Coast Guard also stated that it will send a notice letter outlining this information to affected entities, and it pointed to its waiver guidance in CG-MCP Work Instruction MCP-WI-002, available through the Coast Guard's maritime cybersecurity resource site.
Who Is Affected
This clarification is aimed at a specific population: U.S.-flagged vessels, facilities, and OCS facilities that hold an existing waiver from the security plan requirements of Part 104, 105, or 106. In practice, that tends to mean smaller operations whose physical risk profile justified relief years ago, which is exactly the population most likely to have modest cybersecurity resources and no one tracking Subpart F developments. If your organization holds such a waiver, or is not certain whether it does, this brief is for you.
Why It Matters
The operational significance is the sequence. An organization cannot go straight to a cybersecurity waiver request. The regulation requires the Cybersecurity Assessment first, because the assessment is what establishes whether the organization's cybersecurity risk is in fact low, and which Subpart F requirements a waiver request can credibly cover. An entity that waits until 2027 to begin will be compressing the assessment, the waiver preparation, and the Coast Guard's review into the same window, and a waiver that is denied or granted only in part leaves the remaining Subpart F obligations, including the Cybersecurity Plan, still due.
There is also a quieter administrative point. The Coast Guard is sending notice letters to affected entities, which means it knows who holds these waivers. An operator who assumed the matter was settled should also assume the Coast Guard has not.
A Waiver Request Still Requires the Assessment
The clarification does not close the door on relief. Subpart F expressly allows an owner or operator to seek a waiver from all or individual requirements. What it does not allow is skipping the Cybersecurity Assessment that must precede the request. The assessment is the evidence base for the waiver: it is how an organization demonstrates, rather than assumes, that its cybersecurity risk justifies relief. A well-documented CSA serves the organization either way, as the foundation for a waiver request if the risk is genuinely low, or as the starting point for a right-sized Cybersecurity Plan if it is not.
What Waiver Holders Should Do Now
- Locate the original waiver and confirm in writing exactly what it covers, which regulatory provisions it cites, and any conditions attached to it.
- Obtain and read CG-MCP Work Instruction MCP-WI-002, the Coast Guard's waiver and equivalency guidance for Subpart F, from the Coast Guard maritime cybersecurity resource site.
- Schedule and scope the Cybersecurity Assessment now rather than in 2027. The assessment covers the organization's IT and OT environment, and scoping it properly takes longer than most first-time entities expect.
- Decide the waiver strategy after the assessment, not before it. The CSA results determine whether a full waiver, a partial waiver covering selected requirements, or full Subpart F implementation is the defensible path.
- Calendar July 16, 2027 as the deadline for the completed sequence, and work backward from it with time reserved for Coast Guard review.
- Identify who in the organization receives Coast Guard correspondence, and make sure that person will recognize the notice letter and route it to whoever owns this obligation.
- Preserve the assessment documentation regardless of the outcome. It supports the waiver request, any future Cybersecurity Plan, and the organization's record either way.
Questions Management Should Ask Today
- Do we hold an MTSA waiver, and can we produce the document and state exactly what it covers?
- Who in our organization owns Subpart F compliance, and do they know this clarification exists?
- Has a Cybersecurity Assessment been scheduled, and who will perform it?
- If we intend to request a cybersecurity waiver, what evidence will support it, and does that evidence exist yet?
- What is our plan and timeline if the waiver is denied or granted only in part?
- Who receives correspondence from the Coast Guard, and will the notice letter reach the right person?
The Bottom Line
This clarification is about an assumption, and the assumption is understandable. A waiver felt like a closed file. The Coast Guard's position is that the file addressed physical risk in a threat environment that no longer exists, and that the cybersecurity question remains open until a Cybersecurity Assessment answers it. The deadline of July 16, 2027 sounds distant, but the required sequence, an assessment, a documented waiver request, and Coast Guard review, is not a last-quarter exercise. The organizations that locate their waiver, read the guidance, and schedule the assessment this year will make the waiver decision from evidence and on their own schedule. This site's maritime pages on assessment scoping and waiver and equivalency submissions cover the underlying process in more depth.