One definition in the rule decides which systems carry the heaviest obligations. The operator makes that call, and has to defend it.
Subpart F does not hand covered operators a list of critical systems. It hands them a definition, a consequence test, and the responsibility for applying both. The Critical IT and OT determination is made by the operator, documented in the Cybersecurity Plan, and reviewed by the Coast Guard, and it controls where the strictest measures in the rule apply: executable code restrictions, protected and tested backups, vulnerability analysis, and patching of known exploited vulnerabilities without delay. This page covers how the determination works and where it goes wrong.
What the rule actually says, and the three parts that matter.
The definition of Critical IT and OT systems sits in the definitions section of Subpart F, and every word of it carries weight in practice. Paraphrased from the regulatory text, it has three operative parts.
The consequence test. A Critical IT or OT system is any IT or OT system used by the vessel, facility, or OCS facility that, if compromised or exploited, could result in a transportation security incident, as determined by the Cybersecurity Officer in the Cybersecurity Plan.
The business support extension. Critical systems include business support services whose compromise or exploitation could result in a transportation security incident, which reaches beyond navigation and industrial control into ordinary business systems the operation depends on.
The delegation extension. The term includes systems whose ownership, operation, maintenance, or control is delegated wholly or in part to any other party. Outsourcing a system does not remove it from the determination.
The consequence standard, the transportation security incident, is itself defined in the maritime security regulations as a security incident resulting in a significant loss of life, environmental damage, transportation system disruption, or economic disruption in a particular area. That is the yardstick against which every system in the operation is measured. The question is never whether a system is important to the business. The question is whether its compromise could produce one of those four consequences.
Notice who makes the call. The determination belongs to the Cybersecurity Officer and is documented in the Cybersecurity Plan, which means it is an operator judgment submitted for Coast Guard review rather than a designation the Coast Guard issues. That structure gives the operator real discretion and real accountability at the same time. The discretion is why two similar operations can reach different, equally defensible determinations. The accountability is why the determination needs a documented analysis behind it.
Three questions, asked of every system in the inventory.
In practice, the determination is a disciplined pass through the system inventory built during assessment scoping, asking the same questions of each system and recording the answers.
What does this system actually control or enable?
Not what it is named or where it sits on the network, but what happens in the physical operation when it functions and when it fails. A scheduling system that sequences vessel movements has operational reach its label does not suggest. An engineering workstation with standing access to OT has reach far beyond its own function.
What could compromise of this system plausibly cause?
The chain from compromise to consequence has to be traced honestly: through the interfaces, dependencies, and delegated services the system touches, to the point where the chain either reaches a transportation security incident or credibly stops. Both endings are legitimate findings when the analysis supports them.
Does the consequence meet the TSI standard?
Significant loss of life, environmental damage, transportation system disruption, or economic disruption in a particular area. Consequences that are severe for the company but contained within it, a payroll outage, a lost sales database, generally do not meet the standard. Consequences that reach the waterway, the cargo, or the public generally do.
Business support services trip up operators who scope by system type. A determination that designates the vessel control systems and stops has not applied the definition, because the definition explicitly reaches business support services whose compromise could produce a transportation security incident. Terminal operating systems, access control, and communications platforms all have to be run through the test rather than excluded by category. Delegated systems trip up operators who scope by ownership. The vendor-managed monitoring platform, the integrator-maintained control system, and the cloud service the operation depends on remain candidates for designation even though someone else runs them. The rule says so directly, and the assessment has to reach them.
Designation is not a label. It is a set of obligations.
The reason the determination deserves care is that specific requirements in the cybersecurity measures section attach to critical systems by name. Each system designated as Critical IT or OT inherits the obligations below, and each system left off the list does not. That is the practical consequence of where the line is drawn, in both directions.
Executable code disabled by default
Applications running executable code must be disabled by default on critical IT and OT systems. On a general business workstation this is a policy decision. On a designated critical system it is a regulatory requirement the operator must implement and be able to demonstrate.
Protected, tested backups
The operator must perform backups of critical IT and OT systems, with those backups sufficiently protected and tested frequently. Backup coverage, protection, and testing cadence all follow the designation list.
Network vulnerability analysis
The operator must analyze networks to identify vulnerabilities to critical IT and OT systems and the risk posed by each digital asset. The analysis obligation is framed around the critical systems, so the designation defines what the analysis must protect.
KEV patching without delay
Known exploited vulnerabilities in critical IT or OT systems must be patched, or documented compensating controls implemented, without delay. For a designated system there is no discretionary patching window; the obligation is immediate and continuous.
Four recurring errors, two in each direction.
Determinations fail in predictable ways. Two errors designate too little and surface during Coast Guard review or after an incident. Two designate too much and surface in the budget, year after year.
Scoping by system category
Designating navigation and industrial control systems while excluding business systems as a class. The definition reaches business support services explicitly, and a determination that never tested them against the consequence standard is incomplete on its face.
Scoping by ownership
Excluding vendor-managed, integrator-maintained, and cloud-hosted systems because another party runs them. The definition includes systems whose operation or control is delegated wholly or in part, and the delegated systems are frequently the ones with the broadest remote access.
Designating by importance instead of consequence
Marking systems critical because the business would suffer without them. Business criticality and TSI potential are different standards, and applying the wrong one inflates the designation list and the recurring obligations that follow it.
Copying another operation's determination
Adopting a designation list from a template, a sister facility, or a vendor's reference architecture. The same system can be critical in one operation and peripheral in another, because the consequence chain runs through the specific vessels, cargo, waterway, and dependencies involved. A borrowed determination carries no analysis, and the analysis is what the operator will be asked to show.
Support for the determination.
Consequence Analysis
A system by system pass through the inventory, tracing compromise to consequence against the transportation security incident standard, including the business support services and delegated systems the definition reaches. Conducted onsite, with the people who operate the systems, because the consequence chain lives in the operation rather than in the documentation.
Determination Documentation
A written determination record that captures the reasoning for each designation and each exclusion, in a form that supports the Cybersecurity Plan and stands up to review. The determination remains the operator's and the Cybersecurity Officer's; the work product is the analysis that makes it defensible.
Determination Review
An independent review of a determination already made, whether internally or by another provider, before the plan is finalized. The review tests the designation list in both directions: systems the definition reaches that the list missed, and designations the consequence analysis does not support.
The determination sits inside the scoping process, and the scoping process sits inside the rule.
The Critical IT and OT determination is the final stage of the assessment scoping methodology the Coast Guard described in Policy Letter 01-26, which begins with a broad inventory of systems and dependencies and narrows through risk filtering to the formal designation. The assessment scoping page covers that full process, including the June 2026 guidance documents and the two points operators most often misread.
The full Subpart F program, applicability, the six core obligations, the compliance timeline, and how an engagement proceeds, is covered on the maritime cybersecurity practice page.
Sources
The definition of Critical IT and OT systems and the cybersecurity measures that reference critical systems appear in 33 CFR Part 101, Subpart F, available from the Electronic Code of Federal Regulations. The definition of transportation security incident appears at 33 CFR 101.105. The final rule was published in the Federal Register on January 17, 2025, and the Coast Guard's assessment scoping guidance, including the risk analysis process for designating Critical IT and OT, was announced on Maritime Commons on June 4, 2026.
The descriptions on this page are a practitioner summary and paraphrase of the regulatory text. For compliance decisions, rely on the current regulatory text and Coast Guard guidance directly, together with legal counsel where appropriate. David Koran & Associates Inc. is an independent advisory practice and is not affiliated with, endorsed by, or acting on behalf of the United States Coast Guard.
Discuss the Determination
A first conversation on the Critical IT and OT determination usually covers the systems in the operation, what inventory and scoping work exists so far, who will serve as Cybersecurity Officer, and whether a determination has already been drafted. Call, email, or send a note. I respond personally to every inquiry, usually within one business day.
Discuss the Determination
Whether you are making the determination for the first time, documenting one already made, or checking a designation list someone else produced before it goes into the plan, the first conversation carries no commitment and no pitch.
Discuss the Determination →