Amending Regulations Relating to the Safeguarding of Vessels, Harbors, Ports, and Waterfront Facilities of the United States
The order directly amends federal maritime security regulations to extend existing Coast Guard authority over vessels, ports, and waterfront facilities to cover digital infrastructure — networks, data, programs, and systems — alongside traditional physical assets.
It responds to what the order calls persistent and increasingly sophisticated malicious cyber campaigns against the United States, formally weaving cybersecurity into the legal framework that has governed U.S. port and harbor security since 1950.
What this order does
What it orders
The order amends Part 6 of Title 33 of the Code of Federal Regulations — the longstanding maritime security rules — by inserting references to digital infrastructure throughout. It adds new defined terms for "damage" (as used in the federal computer-fraud statute) and "cyber incident" (as used in federal information-security law). It authorizes the Coast Guard Captain of the Port to inspect, search, and remove data, networks, programs, and other digital infrastructure from vessels and waterfront facilities, and to prevent digital infrastructure from being placed on vessels or in port facilities without permission. It also extends the Commandant's safety-measure authority to cover prevention, detection, assessment, and remediation of actual or threatened cyber incidents, and it requires that evidence of actual or threatened cyber incidents be reported immediately to the FBI, the Cybersecurity and Infrastructure Security Agency, and the Captain of the Port.
The order directs the Commandant to coordinate with the Department of Justice and other relevant agencies in enforcing the amended regulations. It includes standard provisions preserving existing agency authorities, limiting implementation to available appropriations, and clarifying that the order creates no individually enforceable rights.
Who it affects
Masters, owners, operators, and agents of vessels and waterfront facilities subject to Coast Guard jurisdiction, who now bear explicit security responsibility for digital infrastructure on their vessels and facilities. Coast Guard Captains of the Port gain new enumerated authority over that digital infrastructure.
Why it matters
Vessel and port operators must now treat their onboard and facility-based digital systems as security assets subject to Coast Guard oversight — including inspection, search, and removal orders. Any actual or threatened cyber incident at a port or on a vessel must be immediately reported to the FBI and CISA, adding a new mandatory notification obligation.
What must happen and when
How the order is supposed to work
The order works by directly rewriting the CFR text, so the new cyber-inclusive rules take effect immediately without further rulemaking. The Captain of the Port's existing enforcement powers — inspecting, searching, excluding persons or articles, taking vessel control — now expressly reach digital infrastructure. The Commandant's safety-measure authority is likewise extended to cyber incident response. Coordination with DOJ is required but no reporting timeline or joint-action trigger is specified. No sunset clause is included.
Actions and deadlines
- Coordinate with the Department of Justice and relevant agencies in enforcing the amended port security regulations