Essex Junction, VT802-335-2662dkoran@davidkoran.com
DK
David Koran& Associates
Maritime Cybersecurity · The Program Lifecycle

July 16, 2027 is not the finish line. It is the day the recurring obligations begin counting.

Most covered operators are treating Subpart F as a project: complete the assessment, submit the plan, return to normal operations. The rule is not structured that way. After the plan is approved, the regulation runs on a permanent operating rhythm of annual assessments, annual audits, annual training, annual exercises, twice-yearly drills, continuous incident reporting, and a five-year plan renewal that carries a penetration test. This page lays out that rhythm, obligation by obligation, so the program can be planned as what it actually is.

2× / Year
Cybersecurity Drills
Annual
Assessment, Audit, Training, Exercise
5 Years
Plan Cycle From Approval
At Renewal
Penetration Test
Project or Program

The rule describes a program. Budgets are being written for a project.

The visible deadline in Subpart F is July 16, 2027, when covered operators must have designated a Cybersecurity Officer, completed the Cybersecurity Assessment, and submitted the Cybersecurity Plan. Because that milestone dominates the conversation, most compliance planning treats it as the destination, and most budgets fund the work leading up to it and nothing after.

Reading the rule as a whole gives a different picture. Nearly every major obligation in Subpart F recurs. The assessment is annual. The audit of the plan and its implementation is annual. Training is annual for all personnel with access to covered systems, with new personnel trained within days of gaining access. Exercises are annual and drills are twice yearly. Incident reporting to the National Response Center never stops. The plan itself runs on a five-year cycle from its initial approval date, and its renewal carries a penetration test. An operator who funds the road to submission and not the years after it has budgeted for half the regulation.

The question for management is not what compliance costs by July 2027. It is what the operating rhythm costs per year, every year, and who inside or outside the organization carries it. That number, not the project number, is the real cost of the rule.

The sections below organize the recurring obligations by cadence rather than by regulatory section, because cadence is how an operating calendar is actually built. The section citations are included so each item can be traced to the controlling text.

The Operating Rhythm

Every recurring obligation, organized by how often it comes due.

This is the calendar the rule imposes once the program is running. The descriptions are a practitioner summary; each carries its citation so the controlling text is one lookup away.

ContinuousNo cycle. Always on.
§ 101.615, § 101.620

Reportable cyber incident reporting

Reportable cyber incidents must be reported to the National Response Center. The obligation has run since the rule took effect and does not pause between drills, audits, or renewals. The Cyber Incident Response Plan that supports it must be maintained, executed when needed, and exercised.

§ 101.650

KEV response on critical systems

Known exploited vulnerabilities in Critical IT and OT systems must be patched, or documented compensating controls implemented, without delay. This is an obligation that arrives whenever the vulnerability does, which makes it a standing operational duty rather than a scheduled one.

§ 101.630(d)

Training for new personnel and new systems

New personnel must complete cybersecurity training within 5 days of gaining system access and no later than 30 days after hiring. Personnel on new IT or OT systems must be trained within 5 days of system access. In an operation with seasonal crews and turnover, this clock runs constantly.

§ 101.625

CySO accessibility and prompt correction

The Cybersecurity Officer must be accessible to the Coast Guard 24 hours a day, 7 days a week, and must ensure the prompt correction of problems identified by exercises, audits, or inspections. Both duties are continuous by definition.

Twice Each Year§ 101.635(b)
§ 101.635(b)(1)

Cybersecurity drills

The CySO must ensure cybersecurity drills are conducted at least twice each calendar year. Drills test individual elements of the Cybersecurity Plan, including responses to threats and incidents, and may be held in conjunction with other required security drills where appropriate.

§ 101.635(b)(2)

Drill variation

Successive drills should test different parts of the plan, accounting for the operation's type, personnel changes, the vessels a facility serves, and other relevant circumstances. Running the same tabletop twice a year does not satisfy the intent, and the drill record should show the variation.

Every YearThe heaviest band of the calendar
§ 101.650(e)(1)

Cybersecurity Assessment

The assessment recurs annually, and must be conducted sooner if ownership of the vessel, facility, or OCS facility changes. Each cycle includes analyzing networks for vulnerabilities to Critical IT and OT systems, documenting recommendations and resolutions in the underlying security assessment, and incorporating them into the plan through amendment.

§ 101.625(d)

Audit of the plan and its implementation

The CySO must ensure an annual audit of the Cybersecurity Plan and its implementation, updating the plan where the audit shows it no longer matches the operation. The audit is the mechanism that keeps the approved document honest between renewals.

§ 101.630(d)(4)

Training for all personnel

All personnel with access to covered systems repeat cybersecurity training annually, with key personnel trained annually or more frequently as needed. The training record must show topics covered and alignment with the regulation, and training compliance is already being verified during routine Coast Guard inspections.

§ 101.635(c)

Cybersecurity exercise

Where drills test individual elements, the exercise is a full test of the cybersecurity program, conducted annually. Real-world events and responses can serve the purpose when they genuinely test the plan, and the record should demonstrate what was tested and what the exercise found.

Every Five YearsCycle runs from initial plan approval
§ 101.630

Cybersecurity Plan renewal

The plan runs on a five-year schedule set by its initial approval date. Renewal is not a rubber stamp of the existing document: five years of annual assessments, audits, amendments, and operational change accumulate into the version the Coast Guard reviews next.

§ 101.650(e)(2)

Penetration test and certification letter

In conjunction with plan renewal, the owner, operator, or designated CySO must ensure a penetration test has been completed. A letter certifying the test was conducted, together with all identified vulnerabilities, must be included in the renewal. This is the one obligation in the cycle that most operators cannot perform internally and should be procured well ahead of the renewal date.

Stack the bands and the shape of the program appears: a light continuous duty cycle, a drill every six months, a heavy annual band where the assessment, audit, training, and exercise cluster, and a five-year summit with the penetration test. An operator who plots these on a single calendar, anchored to the plan approval date, has converted a regulation into an operating schedule.
Who Carries It

The rhythm has a name attached to it: the Cybersecurity Officer.

Every recurring obligation above routes through the CySO, whose duties under § 101.625 read as the job description for the whole program. In most covered operations the role lands on someone who already has a full position, which is where programs quietly fail.

The duties are ongoing, not annual

The CySO ensures the assessment is conducted, the measures in the plan are developed, implemented, and operating as intended, the annual audit happens, the incident response plan is executed and exercised, drills and exercises run, personnel stay trained and vigilant, reportable incidents are recorded and reported, and problems found by exercises, audits, or inspections are promptly corrected. That is a standing management function, not a compliance season.

The role meets the Coast Guard directly

The CySO arranges cybersecurity inspections, which may run on their own or alongside scheduled Coast Guard inspections of the vessel or facility, and must be accessible to the Coast Guard around the clock. When the program is examined, the CySO is the person answering, with the records the rhythm produced.

One person may cover multiple operations

The rule permits one CySO to serve multiple vessels or facilities where the arrangement works. For fleet operators and multi-facility companies, that consolidation is often the only practical structure, and it concentrates the recurring workload accordingly.

The records are the program

Training rosters, drill and exercise records, audit findings, assessment documentation, incident reports, and correction records are what the recurring obligations leave behind, and they are what an inspection examines. A program that runs but does not record has, for regulatory purposes, not run. The plan itself is sensitive security information, protected under 49 CFR part 1520, which adds a handling discipline to the recordkeeping.

Whether the CySO role is held inside the organization or supported from outside, the workload is the same. What changes is whether the person carrying it has the time, the maritime context, and the cybersecurity depth to carry it well, year after year, alongside everything else they do.
The Five Year Summit

Renewal is where five years of program quality comes due.

The renewal submission is built from everything the rhythm produced: five annual assessments, five audits, ten or more drills, five exercises, the amendments they generated, and the penetration test with its certification letter listing all identified vulnerabilities. An operator whose annual cycles ran honestly assembles the renewal from records that already exist. An operator whose cycles were performed on paper faces a reconstruction project with a penetration test at the end of it, and the test does not grade on effort.

The penetration test deserves early planning for a practical reason: it is specialized work in an environment that includes OT, vessels, and operational constraints most testing firms do not know. Scoping the test against the Critical IT and OT designation, scheduling it around operations, and leaving time to address findings before the renewal is submitted all argue for starting the procurement a year or more ahead of the renewal date rather than in its final months.

A planning note on the approval date

The five-year cycle runs from the plan's initial approval date, which means the renewal date is set the day the Coast Guard approves the first plan. Operators submitting in 2027 are simultaneously setting their renewal dates in 2032, and the annual rhythm between those two dates is what determines whether the second submission is an assembly job or a rescue job.

Services

Support for the program, on its own calendar.

01

Program Calendar and Design

Conversion of the rule's recurring obligations into a single operating calendar for the specific operation, anchored to the plan approval date and fitted to sailing schedules, seasons, and crew cycles, with ownership assigned for each obligation and the records each cycle must produce defined in advance.

02

Annual Cycle Support

Support for the heavy annual band: conducting or facilitating the annual assessment, supporting the audit of the plan and its implementation, aligning training to the operation and its record requirements, and designing drills and exercises that test the plan honestly and vary over time as the rule intends.

03

CySO Advisory Support

Continuing advisory support for the designated Cybersecurity Officer, who in most operations carries the role alongside other duties. The work covers the responsibilities the rule assigns, the records the role must maintain, preparation for inspections, and the judgment calls the position involves between them.

The Lifecycle in Context

The program begins where the assessment ends.

Everything on this page presumes the foundational work is done well: an assessment scoped to the actual operation and a Critical IT and OT determination the operator can defend, because the annual cycles inherit their size from both. The assessment scoping page covers the Coast Guard's June 2026 scoping guidance, and the Critical IT and OT designation page covers the determination that decides where the strictest recurring obligations apply.

The full practice, including applicability, the core obligations, and how an engagement proceeds, is covered on the maritime cybersecurity practice page. For operators asking whether the program will survive crew changes, vendor turnover, and budget cycles, a C2M2 maturity assessment answers the sustainability question directly.

Sources

The recurring obligations summarized on this page appear in 33 CFR Part 101, Subpart F, principally § 101.620 (reporting), § 101.625 (Cybersecurity Officer), § 101.630 (Cybersecurity Plan and training), § 101.635 (drills and exercises), and § 101.650 (cybersecurity measures, including the annual assessment and the penetration test at renewal), available from the Electronic Code of Federal Regulations. The final rule was published in the Federal Register on January 17, 2025, and the Coast Guard has addressed the five-year plan schedule and the distinction between drills and exercises in its published implementation guidance and FAQ materials.

The descriptions on this page are a practitioner summary. For compliance decisions, rely on the current regulatory text and Coast Guard guidance directly, together with legal counsel where appropriate. David Koran & Associates Inc. is an independent advisory practice and is not affiliated with, endorsed by, or acting on behalf of the United States Coast Guard.

Get In Touch

Discuss the Program

A first conversation about the program lifecycle usually covers where the operation stands against the 2027 deadline, who will carry the Cybersecurity Officer role, what the annual cycle will look like for the specific vessels and facilities involved, and how the recurring work will be resourced. Call, email, or send a note. I respond personally to every inquiry, usually within one business day.

Travel
I travel to client sites nationally.

Discuss the Program

Whether you are planning the recurring program before the first submission, resourcing the Cybersecurity Officer role, or building the operating calendar for the years after approval, the first conversation carries no commitment and no pitch.

Discuss the Program →