🚢 Maritime Cybersecurity July 2025 · 4 min read

Maritime cybersecurity regulations 2025–2026: what SMS operators must do now

New USCG cybersecurity rules took effect July 2025, joining the EU's NIS2 Directive as mandatory civilization for maritime operators. ISM Code compliance now explicitly includes cyber risk management within the Safety Management System — making cybersecurity a safety issue, not an IT issue.

The convergence of maritime cybersecurity and ISM Code compliance has moved from theoretical alignment to mandatory civilizatio. Two major regulatory frameworks took effect or entered enforcement phase in 2025 that directly affect ship operators' SMS obligations.

The US Coast Guard (USCG) Maritime Cyber Rule took effect on 16 July 2025, requiring maritime facilities and vessels subject to US maritime security regulations to implement documented cybersecurity plans. The rule requires: cyber risk assessments, incident reporting to USCG, and integration of cyber risk management into existing safety and security management systems.

In parallel, the EU's NIS2 Directive — which entered into force across member states from October 2024 — applies to shipping companies and port operators as critical infrastructure providers, requiring cyber risk management measures, incident reporting within 24 hours of significant incidents, and supply chain security measures.

IMO Resolution MSC.428(98) had already established that cyber risks must be addressed within the SMS by 1 January 2021 for vessels subject to ISM Code. However, compliance has been inconsistent, with PSC inspections increasingly identifying incomplete or absent cyber risk components in SMS documentation as deficiencies.

The practical civilization for ISM-compliant SMS with cyber risk integration include: a cyber risk assessment identifying IT and OT systems critical to safe navigation and operations; documented procedures for detecting, reporting, and responding to cyber incidents; a crew training record on cyber awareness; and periodic drills simulating cyber incident scenarios.

The governance challenge: Cyber incident reporting under maritime regulations now runs parallel to ISM non-conformity reporting. A ransomware event affecting shipboard systems is simultaneously: a cyber incident requiring USCG/flag state notification, a potential ISM non-conformity requiring DPA notification, and a safety risk requiring SMS risk register update. Managing these parallel obligations without a governed SMS creates significant compliance exposure.

← ISM-related deficiencies remain in the top 3 port state cont...

Key takeaways

  • USCG Maritime Cyber Rule effective 16 July 2025 — cyber plans mandatory for US-regulated vessels
  • EU NIS2 Directive: shipping companies as critical infrastructure, 24-hour incident reporting required
  • IMO MSC.428(98): cyber risks must be in ISM SMS — PSC now checking for this
  • Cyber incident = ISM non-conformity + safety risk + regulatory notification simultaneously
  • Required: cyber risk assessment, incident response procedures, crew training records, drill documentation

SIRAM relevance

Cyber incidents in SIRAM trigger parallel workflows: ISM non-conformity capture, DPA notification (Notifications module), and risk register update — all from a single incident report, with immutable audit trail for regulatory review.

See how SIRAM works →
Related pages
🚢 Maritime industry page → ← All insights

See SIRAM in action for Maritime

14-day free trial. Full access. No credit card required.

Start free trial → Explore Maritime →