The rule has a relief valve. It only opens after the assessment.
Subpart F was written for a covered population that ranges from single-vessel operators to major terminal companies, and it acknowledges that some requirements will not fit every environment. The relief runs through 33 CFR 101.665: a waiver where a requirement is unnecessary for the specific operation, or an equivalence determination where a different measure achieves the same or higher level of protection. Both paths are open now, both require a completed Cybersecurity Assessment first, and both travel to the Coast Guard through a specific submission process. This page covers all three.
Minimum requirements for 3,000 different operations produce misfits. The rule plans for them.
During the rulemaking, the Coast Guard declined to exclude small operators or operators with limited systems from coverage, and instead built flexibility into the requirements themselves. The mechanism is § 101.665, which allows an owner or operator, after completing the required Cybersecurity Assessment, to seek a waiver or an equivalence determination for requirements of the subpart, consistent with the waiver and equivalence provisions that already exist in the MTSA security plan regulations at 33 CFR parts 104, 105, and 106.
The assessment prerequisite is the design of the provision, not an obstacle in it. In revising the section, the Coast Guard explained that a Cybersecurity Assessment is necessary so that an owner or operator can identify which requirements are unnecessary. The logic runs one direction: the assessment establishes what the operation is, and only then can the operator credibly argue what parts of the rule the operation does not need. A request written before the assessment is an opinion. A request written after it is a finding.
Relief under Subpart F is not an exemption from the rule. Coverage, the assessment, and the plan obligation remain. What relief changes is the content of compliance for the specific requirements the assessment shows do not fit, which is a narrower and far more achievable request.
The June 2026 guidance made the pathway concrete. CG-MCP-WI-002 harmonizes the preparation and submission of waiver and equivalency requests across U.S.-flagged vessels, facilities, and OCS facilities, so that all maritime entities, regardless of size or digital maturity, follow the same guidelines, with determinations informed by the cybersecurity assessment. And notably, while the Coast Guard has asked operators to hold full Cybersecurity Plan submissions until its review process is finalized, it is receiving and processing waiver and equivalency requests now. For operators whose environments genuinely do not fit parts of the rule, the relief pathway is the one submission lane currently open.
Waiver, equivalence, and temporary deviation are different requests.
The three mechanisms are frequently discussed as one, and they are not. Each answers a different situation, carries a different argument, and leaves the operator in a different position afterward.
The requirement is unnecessary here.
A waiver request argues that a specific requirement of the subpart serves no purpose in the specific operation, with the completed assessment as the evidence. The argument is about absence: the systems, connections, or exposures the requirement protects against do not exist in this environment, and the assessment record shows it.
A different measure protects as well or better.
An equivalence request accepts the requirement's purpose and proposes a different way of meeting it, one that achieves the same or a higher level of protection. The argument is comparative, and it has to be made in security terms: what the required measure protects, what the proposed measure protects, and why the proposed measure is at least its equal in this environment.
The operation must deviate for a period.
Separately from waivers and equivalencies, the rule addresses temporary deviation: an owner or operator must notify the Coast Guard when the operation must temporarily deviate from the requirements. This is a notification obligation for a bounded circumstance rather than a request for standing relief, and treating it as an informal grace period misreads it.
The choice between waiver and equivalence is made by the assessment finding, not by preference. A finding that the protected exposure does not exist supports a waiver. A finding that the exposure exists but is addressed differently supports an equivalence. Requesting a waiver where the exposure exists invites denial, and requesting an equivalence where nothing needs protecting concedes an obligation the operator did not have. Matching the instrument to the finding is most of the craft in this corner of the rule.
A request is an argument with an evidence record behind it.
The harmonized guidance in WI-002 gives every covered entity the same preparation path. In practice, a defensible request is assembled in three stages, and each stage depends on the quality of the work before it.
The assessment finding
The completed Cybersecurity Assessment, properly scoped, either shows the requirement's protected exposure absent from the environment or shows it addressed by other means. The finding has to be specific: which requirement, which systems, what the assessment examined, and what it found. A general statement that the operation is small or simple is not a finding.
The argument
The request connects the finding to the relief sought, in the form the guidance contemplates: a waiver argument built on absence, or an equivalence argument built on comparison to the same or a higher level of protection. The argument should anticipate the reviewer's question, which is always some version of what happens to the risk if this request is granted.
The submission
The request travels through the Coast Guard's secure transmission process. CG-MCP-WI-003 provides the instructions for submitting Cybersecurity Assessments, Cybersecurity Plans, and waiver and equivalency requests through the DoD SAFE portal. The mechanics are not difficult, but they are specific, and a request prepared well deserves to arrive the way the Coast Guard has asked to receive it.
Four ways operators misuse the relief provisions.
The relief pathway rewards operators who use it precisely and works against those who reach for it as a general escape. The recurring failures are predictable.
Requesting relief before the assessment
The provision is sequenced deliberately: relief follows the completed assessment because the assessment is what identifies unnecessary requirements. A request submitted ahead of that work asks the Coast Guard to accept a conclusion without its basis, and the sequence in the rule gives the reviewer every reason to decline.
Treating a waiver as an exit from coverage
Waivers and equivalencies operate requirement by requirement within a covered operation. An operator who believes the rule should not apply to it at all is raising an applicability question under the MTSA security plan framework, which is a different analysis made at a different point, before compliance money is spent.
Proposing an equivalence that protects less
The standard is the same or a higher level of protection, and the comparison is judged in security terms rather than cost terms. A proposed measure that is cheaper, easier, or already owned but demonstrably weaker is not an equivalence, and submitting it as one spends credibility the operator may want for a stronger request later.
Letting the deadline logic invert
Some operators are deferring the assessment because plan submissions are paused, then deferring relief because the assessment is not done. The dependency runs the other way: the assessment enables the relief request, the relief determination shapes the plan, and the July 16, 2027 deadline for all of it has not moved. The open relief lane is a reason to complete the assessment sooner, not later.
Support for the relief analysis and the request.
Relief Analysis
A structured pass through the assessment findings against the requirements of the subpart, identifying where the operation has a genuine waiver case, where an equivalence is the right instrument, and where the requirement fits and should simply be implemented. The output is an honest map of the relief the operation can credibly seek, including where the answer is none.
Request Preparation
Development of the waiver or equivalence request itself, following the harmonized guidance: the assessment finding stated specifically, the argument connected to it, and the supporting record assembled with the sensitive security information handling the material requires. The request is the operator's, built on defensible groundwork.
Submission Preparation
Preparation of the complete package for transmission through the DoD SAFE process the Coast Guard has specified, so that the assessment, the request, and eventually the plan arrive in the form and through the channel the Coast Guard has asked for, with the operator's records showing what was submitted and when.
The relief pathway is the last stop on a road that starts with scope.
Everything on this page depends on an assessment worth citing. The assessment scoping page covers how that assessment is scoped under the Coast Guard's June 2026 guidance, and the Critical IT and OT designation page covers the determination that decides where the strictest requirements, and therefore the most consequential relief questions, apply. The program lifecycle page covers the recurring obligations that continue whether or not relief is granted.
The full practice, including the applicability question that precedes all of this, is covered on the maritime cybersecurity practice page.
Sources
The waiver and equivalence provision is 33 CFR 101.665, available from the Electronic Code of Federal Regulations, and the Coast Guard's discussion of the assessment prerequisite and the temporary deviation notification appears in the final rule published January 17, 2025. CG-MCP-WI-002 (waiver and equivalency guidance) and CG-MCP-WI-003 (DoD SAFE submission instructions) were announced on Maritime Commons on June 4, 2026 and are available from the Coast Guard Maritime Industry Cybersecurity Resource Center.
The descriptions on this page are a practitioner summary. For compliance decisions, rely on the current regulatory text and Coast Guard guidance directly, together with legal counsel where appropriate; relief requests in particular sit close to legal questions where counsel involvement is often warranted. David Koran & Associates Inc. is an independent advisory practice and is not affiliated with, endorsed by, or acting on behalf of the United States Coast Guard.
Discuss a Waiver or Equivalence Question
A first conversation on relief usually covers where the operation stands in the assessment, which requirements appear not to fit the environment and why, whether the case points toward waiver or equivalence, and how the request fits the timeline to July 2027. Call, email, or send a note. I respond personally to every inquiry, usually within one business day.
Discuss a Request
Whether you are testing whether a requirement genuinely fits your environment, weighing waiver against equivalence, or preparing a request for submission, the first conversation carries no commitment and no pitch.
Discuss a Request →