Coast Guard regulated facilities
Your Cybersecurity Plan is due to the Coast Guard on July 16, 2027.
The Coast Guard's cybersecurity rule took effect in July 2025. If your facility runs under a Facility Security Plan, you need a named Cybersecurity Officer, a cybersecurity assessment, and a Cybersecurity Plan approved by your COTP. The training deadline has already passed.
Already in force
July 16, 2025
Rule in force. Reportable cyber incidents go to the National Response Center without delay.
Already in force
January 12, 2026
Cybersecurity training for everyone with access to IT or OT systems.
Next deadline
July 16, 2027
Cybersecurity Officer named, Cybersecurity Assessment done, and the Cybersecurity Plan submitted to your COTP.
The assessment and the plan take about six months. To file by July 16, 2027, start by January 2027. The guide lays out the work month by month.
What you end up holding
The file the Coast Guard can inspect.
Every requirement in the rule, mapped to a piece of work and a document, with who owns it written on each one.
| Cybersecurity Officer letter | Named person, title and 24-hour contact. You name them; we coach the form. |
| Training records | Catch-up for the January 2026 date that has already passed, plus new-hire and new-system timing. |
| Incident reporting playbook | National Response Center reporting, and for waterfront facilities FBI, CISA and COTP notice. |
| Cybersecurity Assessment | Every path into the plant, including the ones that come through headquarters, the cloud, and vendors. |
| Cybersecurity Plan and response plan | All fourteen required sections, marked Sensitive Security Information, with a section per facility. |
| Network maps and a device list | Every control system device, and how it connects, built from your own traffic captures. The rule asks for this. |
| Drill and exercise schedule | Twice-yearly drills and an annual exercise, with the first tabletop run for you. |
| Submission coaching | How to file with your COTP. You file it. We get it ready. |
How the work is done
Remote by default. Your staff pull traffic captures from the SPAN ports you already have and run our collection tool on the systems we point to. Our engineers do the analysis and write it up. No flights and no hotels unless you want people on site.
Plant-safe throughout. We do not run active scans against live control-room systems, and nothing we do touches a running process.
What we won't do
Be your Cybersecurity Officer, file the plan for you, or lead with a penetration test. The rule puts those on the facility owner, and the test comes at the five-year renewal.
Is your facility covered?
Coverage follows your Facility Security Plan under 33 CFR part 105, not your shoreline. A dock handling bulk oil or hazardous cargo usually is. A waterfront location alone is not enough. We confirm it with you before anything else.
What it costs
Priced per facility. One call to price yours.
| Standard facility | Assessment, plan, response plan, training coordination, and all the paperwork. | From $60,000 |
| Facility with a marine transfer dock | The same, plus the dock's own control systems and transfer paths. | From $75,000 |
| Each additional facility | Same owner. The plan framework is shared; each facility gets its own section. | From $12,000 |
Workforce training is delivered through CambiOS Academy and priced by headcount. On-site work is available and quoted separately.
Who you get
Twenty-five years inside plants, at a set price.
A method run on more than 500 live plants, written down so it comes out the same every time, whoever runs it. A senior control-system engineer signs off on your report before it leaves the building.
25+ yrs
inside live plant control systems
500+
plant-safe assessments and penetration tests worldwide
4,500+
people trained on plant cybersecurity
A founding contributor and editor of ISA/IEC 62443 and the early NERC CIP standards.