executive-ordertrade-pressNewsThe Broadside2 min read

Coast Guard readies foreign-vessel cyber rule for November 2026

The proposal extends the maritime cyber mandate while testing whether inspectors have enough technical depth to enforce it.


TL;DR

The Coast Guard plans a November 2026 proposed rule setting minimum cybersecurity requirements for foreign-flagged vessels operating in U.S. waters, Inside Cybersecurity reports, citing the 2026 unified regulatory agenda. Operators could face requirements resembling the January 2025 U.S.-flagged vessel rule: incident reporting to the FBI and CISA, cybersecurity officers, cyber plans and security posture measures. The open question is whether foreign vessels get the same rulebook or a harder one, backed by port denial and detention authorities.

Coast Guard readies foreign-vessel cyber rule for November 2026
Editorial illustration · drawn by The Broadside

The Coast Guard’s next maritime cyber rulemaking moves foreign-flagged vessels into the same mandatory-security conversation that already reached U.S.-flagged vessels in January 2025. Inside Cybersecurity reports that the 2026 unified regulatory agenda lists a November 2026 notice of proposed rulemaking to establish minimum cybersecurity requirements for foreign vessels operating in U.S. territorial waters.

That matters because foreign-flagged vessels already sit under a sharper Coast Guard enforcement posture than U.S.-flagged vessels. The article notes the Coast Guard can bar foreign systems from U.S. ports if they have operated in “substandard conditions.” If cyber controls become part of that inspection and security baseline, a failed control set is no longer just a remediation memo for the operator. It can become a port-access problem.

The January 2025 rule for U.S.-flagged vessels is the obvious template. It required covered maritime transportation systems to report incidents to the FBI and the Cybersecurity and Infrastructure Security Agency, develop and maintain a cybersecurity plan, designate a cybersecurity officer and take steps to strengthen security posture. It also tied the maritime rules to CISA’s coming Cyber Incident Reporting for Critical Infrastructure Act requirements, with the unified agenda placing that separate CIRCIA final rulemaking in September.

The unresolved part is whether the Coast Guard copies that structure for foreign operators or uses the foreign-vessel context to impose stricter terms. GAO’s 2025 review gives the agency an uncomfortable backdrop: oversight concerns over inspection-result review and the workforce’s technical knowledge for mitigation work. A mandate is only as useful as the inspection muscle behind it. For maritime operators, primes and contractors in the port and vessel security chain, the practical work now is not waiting for November 2026. It is mapping existing cyber plans, incident escalation paths and officer responsibilities against the U.S.-flagged rule, because that is the clearest preview of where the foreign-vessel proposal is headed.


Published ·Deep Fathom