Coast Guard creates Office of Maritime Cybersecurity Policy

The U.S. Coast Guard has launched the Office of Maritime Cybersecurity Policy to centralize cyber policy and coordinate compliance across the Marine Transportation System.

The U.S. Coast Guard has established the Office of Maritime Cybersecurity Policy, known as CG-MCP, to centralize development and implementation of cybersecurity policy for the Marine Transportation System, including ports, vessels and other maritime infrastructure. The office will serve as the Coast Guard’s main authority and liaison on maritime cyber safety and security.

CG-MCP was created under the Director of Inspections and Compliance. Its responsibilities include developing domestic cybersecurity policy, contributing to international standards, coordinating a unified compliance and enforcement approach, and serving as the primary point of contact for industry and other government agencies. The office will also work with maritime organizations, universities and national laboratories and monitor new technologies and techniques to help the sector manage cyber risk.

The Coast Guard said, “Advanced systems and equipment, including the increased use of information and operational technology, accelerate and transform the maritime industry. While these advancements provide operational efficiencies and improvements throughout the Marine Transportation System, they also introduce increased risks to a critical infrastructure sector.”

Rear Adm. Robert C. Compher, assistant commandant for prevention policy, described the office as creating a single authority to set policy, coordinate compliance efforts and work with partners. He added the office is meant to address current threats and help prepare the maritime sector for emerging cybersecurity challenges.

The announcement follows a February 2025 Government Accountability Office report that identified weaknesses in the Coast Guard’s approach to securing the Marine Transportation System. The GAO found problems with the accuracy of cybersecurity incident information, limited access to data on cyber deficiencies, a lack of competency requirements for personnel with MTS cybersecurity responsibilities, and gaps in the agency’s cyber strategy. The watchdog also reported that the Coast Guard’s system of record did not provide ready access to complete information about cybersecurity issues found during vessel and facility inspections. The Coast Guard did not say whether CG-MCP was created in direct response to the GAO findings.

The Marine Transportation System includes roughly 360 commercial sea and river ports. The Coast Guard cited the sector’s growing use of information and operational technology as a reason for centralizing cyber policy and coordinating enforcement and outreach to help manage cyber threats.

Articles by this author