The Cybersecurity Officer Problem
Subpart F’s Hardest Requirement for Small Maritime Operators
The requirement that cannot be bought
The compliance conversation around 33 CFR Part 101, Subpart F is organized around documents. The Cybersecurity Plan is due to the Coast Guard by July 16, 2027. The Cybersecurity Assessment must precede it. Training came due in January 2026 and recurs annually. Each of these obligations has a deadline, a deliverable, and a market of providers ready to help produce it.
One requirement does not fit the pattern. Each covered owner or operator must designate a Cybersecurity Officer, in writing, by name and title, accessible to the Coast Guard 24 hours a day, 7 days a week. The duties assigned to that person under § 101.625 amount to the standing management of the entire cybersecurity program: the annual assessment, the annual audit, the training cycle, drills twice each year, the annual exercise, incident recording and reporting, and the prompt correction of everything the exercises, audits, and inspections find. The CySO also makes the single most consequential judgment in the rule, the determination of which systems are Critical IT and OT, and must be able to defend it on review.
The Coast Guard estimated the covered population at 3,447 owners and operators, and determined that roughly 91 percent of them are small entities. For that majority, every requirement in the rule can be purchased except this one. The CySO is a person, not a deliverable, and in most covered organizations that person does not currently exist.
What the paper covers
The paper reviews the requirement as written and converts the duties into calendar terms, showing why the role is smaller than a full-time position in most small operations and much larger than a collateral duty performed in spare hours. It then examines why the burden falls disproportionately on the small majority of the covered population, where no employee spans cybersecurity, maritime operations, and regulatory administration, and where the available internal candidates each involve a compromise the Coast Guard’s review is structured to find.
The heart of the paper is an even-handed evaluation of the three staffing structures available to an owner or operator: internal designation with external support, one CySO shared across multiple vessels or facilities as the rule expressly permits, and an outside designee under contract. Each structure is examined with its price stated plainly, including the real drawbacks of outsourcing the role, and the paper closes with the questions a management team should be able to answer before putting anyone’s name in the plan.
The Cybersecurity Officer Problem, 8 pages, with references to the controlling regulatory text.
The designation decision has a longer horizon than the submission deadline. The plan will be reviewed once. The name in it will answer for the program every year afterward, through every audit, drill, inspection, and renewal the rule schedules. Operators who treat the designation as a staffing decision made deliberately among the three available structures will carry the program. Operators who treat it as a blank on a form will discover the difference at their first inspection.