The scope of the Cybersecurity Assessment decides the cost of everything that follows. The Coast Guard has now explained how to set it.
On June 4, 2026, the Coast Guard released CG-5PC Policy Letter 01-26, Cybersecurity Assessment Initial Scoping and Process, its first detailed guidance on how a covered operator determines what the Cybersecurity Assessment required under 33 CFR 101.650 must cover. The methodology moves from a broad inventory of systems and dependencies, through an optional risk filtering process, to the formal designation of Critical IT and OT. Where that line lands determines the size of the assessment, the length of the Cybersecurity Plan, and the compliance budget for years afterward.
The assessment is the foundation. Scoping is the foundation of the assessment.
Under Subpart F, the sequence is fixed. The Cybersecurity Assessment identifies the systems, vulnerabilities, risks, and operational dependencies of the covered operation, and the Cybersecurity Plan is built on what the assessment finds. The Coast Guard's scoping guidance describes the assessment as the foundational first step in a continuous maturity process, and states plainly that because the outcomes and findings of the assessment form the foundation of the plan, the initial assessment is highly consequential and should be rigorously conducted.
That places the scoping decision at the head of the entire compliance effort. Before an operator can assess anything, it has to decide what is in the assessment: which vessels, which facility systems, which business support services, which vendor connections, and which of the systems on that list rise to the level of Critical IT or OT. Every downstream cost follows from that decision. The number of systems assessed, the measures the plan must describe, the evidence the operator must maintain, and the recurring assessment cycle all inherit their size from the initial scope.
An operator who scopes too broadly buys an assessment several times larger than the rule requires. An operator who scopes too narrowly submits a plan that will not survive Coast Guard review. The scoping decision is where those two errors are either made or avoided, and it is made before any technical work begins.
The scoping guidance also matters for a second reason: waivers and equivalencies run through it. Under § 101.665, an owner or operator may seek a waiver or an equivalence determination for requirements of the subpart after completing the required Cybersecurity Assessment, because the assessment is what identifies which requirements are unnecessary for the specific operation. An operator who believes parts of the rule do not fit its environment cannot make that argument until the assessment, properly scoped, has been done.
Three documents, released together, that define the submission path.
The Coast Guard Office of Maritime Cybersecurity Policy released the scoping guidance alongside two work instructions. Together they describe how the assessment is scoped, how waiver and equivalency requests are prepared, and how everything is transmitted to the Coast Guard. The descriptions below are a practitioner summary; the documents themselves are available from the Coast Guard Maritime Industry Cybersecurity Resource Center.
Cybersecurity Assessment Initial Scoping and Process
Guidance for determining the scope of the Cybersecurity Assessment required under 33 CFR 101.650, including an optional risk filtering process grounded in industry standards such as the NIST Cybersecurity Framework and clarification of how risk analysis determines which priority assets are formally designated as Critical IT or OT.
Waiver and Equivalency Guidance
Harmonized guidance for regulated U.S.-flagged vessels, facilities, and OCS facilities on preparing and submitting requests for a cybersecurity requirement to be waived or satisfied through an equivalent measure achieving the same or higher level of protection, with determinations informed by the completed assessment.
DoD SAFE Submission Instructions
Guidance on the Coast Guard's process for secure transmission of Cybersecurity Assessments, Cybersecurity Plans, and waiver and equivalency requests using the DoD SAFE portal, establishing the mechanical path by which the documents the operator produces actually reach the Coast Guard.
The guidance is not mandatory. The Coast Guard states that these policies support and inform compliance with the legal requirements but are not themselves legal requirements, and that owners and operators are welcome to use other frameworks or approaches suited to their own footprint and operations. An operator who treats the policy letter as binding in every particular will overscope. The pause on plan submissions does not move the deadline. The Coast Guard has asked maritime entities to refrain from submitting full Cybersecurity Plans until further notice while it finalizes its review process, and is meanwhile receiving waiver and equivalency requests. Nothing in that request suspends the July 16, 2027 deadline for the designated Cybersecurity Officer, the completed assessment, and the submitted plan. Operators reading the pause as permission to wait are spending runway they will want back.
From everything the operation touches, to the systems that matter most.
The methodology in the policy letter narrows in stages. It begins with the whole connected environment and ends with a defensible, documented determination of which assets are Critical IT and OT. Each stage below is smaller than the one before it, and each produces a record the operator will rely on when the Coast Guard reviews the plan.
Broad inventory of systems, dependencies, and interfaces
The starting universe is wide by design: vessel and facility IT and OT, business support systems, external dependencies, vendor and remote connections, and the interfaces between them. The purpose of the assessment is to identify vulnerabilities, threats, operational dependencies, and interdependencies that could result in an operational disruption or a transportation security incident, and the inventory has to be complete enough to support that purpose. Scoping errors at this stage are usually errors of omission: the vendor maintenance link, the shore-side system a vessel depends on, the service whose operation is delegated to another party.
Risk filtering
The policy letter provides an optional risk filtering process, grounded in industry standards such as the NIST Cybersecurity Framework, to work through threats, vulnerabilities, likelihood, and impact across the inventory. Filtering is where the inventory stops being a list and becomes an analysis: which compromises are plausible, which consequences are operationally significant, and which systems sit on the path between the two. Because the process is optional, an operator may use another framework, but whatever method is used has to leave a record that explains the conclusions.
Risk analysis of priority assets
The filtered set is analyzed to determine which priority assets warrant formal designation. This is the judgment stage: the analysis has to connect specific systems to the operational disruptions or transportation security incidents their compromise could produce, in the context of the actual vessel or facility rather than in the abstract. The same system can be critical in one operation and peripheral in another, which is why this determination cannot be copied from a template or from another operator's plan.
Critical IT and OT designation
The process concludes in the formal designation of Critical IT and OT. That designation defines what the assessment examines in depth, what the Cybersecurity Plan must address, and where the operator's protective measures concentrate. It is the single scoping output with the most consequence, and the one the operator most needs to be able to defend when the plan is reviewed.
Four costs that inherit their size from the scoping decision.
Scope is often treated as a preliminary detail. It is closer to the opposite: the scoping decision is the largest single cost driver in the entire compliance program, because four separate obligations take their dimensions from it.
The assessment itself
The number of systems, locations, and dependencies in scope determines the duration and cost of the assessment, and the assessment recurs on the cycle the rule establishes. A scope set carelessly at the outset is paid for again at every renewal.
The Cybersecurity Plan
The plan must describe how the required measures are implemented for the systems the assessment covers. Every system in scope is a system the plan has to address, with measures that actually exist and evidence that supports them through Coast Guard review and subsequent audits.
The waiver and equivalency posture
Requests to waive a requirement or satisfy it through an equivalent measure are informed by the completed assessment. An operator whose environment genuinely does not fit parts of the rule needs a properly scoped assessment to make that case, and cannot make it beforehand.
The recurring program
Training populations, drill and exercise design, audit coverage, and recordkeeping all follow the covered systems. Scope reaches forward into every annual obligation the operator will carry after the plan is approved.
Scoping support, delivered onsite.
Scoping Analysis and Inventory
A structured pass through the operation to build the inventory the policy letter contemplates: vessel and facility systems, business support services, external dependencies, vendor and remote connections, and the interfaces between them. Conducted onsite, because the inventory that matters is the one in the switch closet and on the vessel rather than the one on the network diagram.
Risk Filtering and Critical IT/OT Determination
Facilitation of the risk filtering and analysis stages, using the policy letter's process or another framework fitted to the operation, ending in a documented Critical IT and OT determination the operator can defend. The determination is the operator's, made with a record that explains it.
Assessment and Plan Follow-Through
Once scope is set, support for the Cybersecurity Assessment and the development of a Cybersecurity Plan that describes the actual operation, together with waiver and equivalency analysis where the assessment shows requirements that do not fit the environment, and preparation for submission through the Coast Guard's process.
Scope is the first decision. It is not the last.
The scoping determination sits at the head of the full Subpart F program: the assessment, the plan, the Cybersecurity Officer designation, and the recurring cycle of training, drills, audits, and renewals that continues after July 2027. The maritime cybersecurity practice page covers the whole of the rule, including applicability for operators still determining whether they are covered at all, which is the question that precedes even scoping.
For operators whose leadership wants to understand not just whether the program complies but whether it will last, a C2M2 maturity assessment evaluates the capabilities behind the plan across IT and OT together, which fits the maritime environment well.
Sources
The Coast Guard announced the release of CG-5PC Policy Letter 01-26 and the accompanying work instructions on Maritime Commons on June 4, 2026. The documents are available from the Coast Guard Maritime Industry Cybersecurity Resource Center. The controlling regulatory text is 33 CFR Part 101, Subpart F, available from the Electronic Code of Federal Regulations, and the final rule was published in the Federal Register on January 17, 2025.
The descriptions on this page are a practitioner summary. The Coast Guard's guidance documents are not themselves legal requirements, and for compliance decisions operators should rely on the current regulatory text and Coast Guard guidance directly, together with legal counsel where appropriate. David Koran & Associates Inc. is an independent advisory practice and is not affiliated with, endorsed by, or acting on behalf of the United States Coast Guard.
Discuss Assessment Scoping
A first conversation on scoping usually covers the vessels and facilities involved, what is currently known about the connected environment, whether any inventory or assessment work has been started, and where the operation stands against the July 2027 deadline. Call, email, or send a note. I respond personally to every inquiry, usually within one business day.
Discuss Scoping
Whether you are building the initial inventory, working through the Critical IT and OT determination, or checking a scope someone else proposed before you commit to it, the first conversation carries no commitment and no pitch.
Discuss Scoping →