A policy describes what should happen. Evidence shows whether your organisation is actually ready.
You know the feeling when someone asks about a security routine and everyone knows it exists, but nobody remembers when it was last tested. The document is available, the responsibilities are listed, and the process looks complete. Still, an important question remains.
Would it work today?
The United States Coast Guard recently clarified parts of its cybersecurity requirements for regulated US flagged vessels, facilities, and Outer Continental Shelf facilities.
The clarification states that an existing waiver based on low physical security risk does not automatically mean that an organisation has low cybersecurity risk. A Cybersecurity Assessment must still be completed before an exemption from the cyber requirements can be considered.
For affected organisations, that assessment and any new waiver request must be completed no later than July 16, 2027.
The specific regulations apply to entities covered by the US framework, but the wider message is relevant across shipping.
Cybersecurity is moving from written intention toward operational evidence.
Additional Coast Guard guidance published in June covers the initial scope of Cybersecurity Assessments, the process for waivers and equivalencies, and how assessments and Cybersecurity Plans should be submitted.
Supporting guidance also explains that assessments should take a holistic view of the IT and OT systems that could affect maritime operations. Similar vessels may share a Cybersecurity Plan, but differences in their systems and risks must still be addressed.
It is a bit like an emergency procedure onboard. Having the procedure in a folder is important. Knowing that people understand it, equipment is available, and the response has been tested is what creates confidence.
Cybersecurity should be approached in the same way.
This does not mean producing more documents simply to prepare for an inspection. It means making sure the documentation reflects the actual environment.
A reliable cyber programme should be visible through current system inventories, controlled access, training records, tested procedures, clear responsibilities, and documented follow up.
The Coast Guard guidance also distinguishes between assessments, audits, drills, and exercises. Each provides different evidence that the Cybersecurity Plan remains relevant and can work in practice.
This is why visibility matters. When systems, responsibilities, and changes are managed continuously, evidence becomes a natural result of good operations rather than something created at the last minute.
Your cyber plan explains what should happen. Your evidence shows whether you are ready.
Join us on the voyage toward a smarter, more connected world at sea. Get the insights that keep your fleet ahead.


