SecurıdigmMaritime A new paradigm in cybersecurity
Securidigm Maritime · Compliance Assessment Tool

Every 33 CFR 101 Subpart F requirement.
Vessels, facilities, OCS facilities.
One file. Zero install. Zero network connections.

A complete compliance assessment programme for MTSA-regulated operators — U.S.-flagged vessels, waterfront facilities and OCS facilities. Every individual requirement of 33 CFR 101 Subpart F, scoped to your subchapter, guided question by question, with the evidence trail an inspector actually asks for. It runs from a double-click and never sends your data anywhere.

150individually tracked requirements — all of them in your file, one regulation
3populations — vessel (104), facility (105), OCS facility (106)
0network connections — verifiable
1file. No install, no account, no cloud
4document generators — Cybersecurity Plan, Assessment record, pen-test certification letter, CIRP
file:///C:/compliance/securidigm-maritime.html
Compliance dashboard with completion by directive and by sectionClick to enlarge
Why this exists

The directives weren't written for a four-person IT team.

Subpart F runs to roughly 150 distinct duties across eleven sections, with clocks anchored to Plan approval, to the calendar year, and to events as they happen — and citations, filing authority and the assessment it lands in all change depending on whether you are a vessel, a facility or an OCS facility. Missing any of it is a finding.

01One regulation, three populations

The duties are common but the paperwork is not: your Plan files into the VSA, the FSA or the OCS FSA depending on subchapter, and the approving authority is the Marine Safety Center or your cognizant COTP or OCMI. A generic checklist cites all three and is wrong twice.

02Clocks everywhere

72-hour incident reports. 24-hour supplements. 7-day coordinator updates. 60-day notices. Annual plans, exercises, and reports anchored to approval dates nobody wrote down.

03The Coast Guard inspects your Plan, not the regulation

Once your Cybersecurity Plan is approved under §101.630(d), the audit surface is that Plan. Drift from your own commitments and you can be non-compliant while every generic checklist shows green.

04"Prove it" is the real test

An inspector can request your asset inventory, firewall rules, diagrams, logs — even a 24-hour packet capture. The question is never whether you did the work; it's whether you can show it in five seconds.

Watch it work

From blank file to defensible program.

Real screenshots, real sample data, no mockups — this is the actual tool, which you can hold in your hands five minutes from now.

Setup wizard Questionnaire, unanswered requirement Questionnaire, answered with evidence Dashboard Gap register Incident report builder with the 72-hour clock Maritime edition — 33 CFR 101 Subpart F assessment grid
01
Built around how the work actually happens

Everything the directives demand, nothing you don't need to see.

Six areas below, numbered in the order you use them: scoping, assessment, deadlines, evidence, readiness, assessor layer.

01 — Scoping

Scoped to your operation before you answer anything

A four-step setup interview asks the question that decides everything downstream — which subchapter you fall under: 104 vessel, 105 facility or 106 OCS facility — plus a handful of scoping facts (do you report through a 33 CFR 6.16-1 channel? multiple CySOs? an Alternative Security Program?).

  • Rows scoped out by your answers stay visible, grouped and reasoned — so an inspector asking "why is this not applicable?" gets a five-second answer
  • Conditional requirements scope out automatically, with the reason recorded — so the inspector's "why isn't this here?" always has an answer
  • Fully reversible: a change of subchapter or COTP zone is a field, not a re-assessment
Setup — 1. Identity & applicability
Setup wizardClick to enlarge
02 — Assessment

A guided questionnaire that speaks operator, not regulation

One requirement per screen: plain English first, the section cite as a footnote. Every screen tells you how to implement it in your environment — naming actual tools and configurations — and what evidence would satisfy it, down to "an attendance roster by position, because a sign-in sheet without positions is the classic audit failure."

  • Work any section in any order; "unanswered only" mode auto-advances as you go
  • Guidance adapts to your OT tooling and your IT stack — Microsoft shop or not
  • Marking a requirement non-compliant automatically opens a gap entry
Questionnaire — requirement detail
Guided questionnaireClick to enlarge
03 — Deadlines

A calendar that already knows your deadlines

Enter your anchor dates once — plan approval, last exercise, last assessment — and every derived obligation appears with its clock: annual plan updates, exercise anniversaries, biennial architecture reviews, amendment windows, the next renewal.

  • Overdue and due-within-60-days flagged automatically
  • One-click .ics export drops every deadline into Outlook, where deadlines actually survive
  • Standing duties — the 72-hour report, the 7-day coordinator update — listed so nobody has to remember them
Obligations calendar
Obligations calendar with due-within-60-days flagsClick to enlarge
04 — Evidence

Evidence by fingerprint — your documents never enter the tool

Drop a file on the register: it's hashed (SHA-256) in your browser's memory and the bytes are immediately discarded. What's recorded is the name, date, fingerprint, and where the artifact actually lives. Your firewall rules and network diagrams stay in your controlled repository — the tool holds proof they exist and haven't changed, never the documents themselves.

  • One artifact links across many requirements — the way real evidence works
  • Tagged against the §101.660 production list and the §101.640 records requirements
Evidence register — SHA-256 fingerprints
Evidence register with hashes and pointersClick to enlarge
05 — Readiness

Inspection readiness, answered before the Coast Guard asks

§101.660 requires records to be produced to the Coast Guard on request, and §101.640 sets out what must be kept. The readiness view cross-references that against your evidence register: green where you can produce it, red where you can't. Including the ones that catch everyone: can you evidence the drills and exercises for this calendar year, and the training completed within 60 days of Plan approval?

Inspection readiness
Inspection readiness viewClick to enlarge
06 — Assessor layer

For the assessor: the layer the Coast Guard actually inspects

An assessor view adds what a consultant needs and an operator doesn't: requirement IDs, candid commonly-failed commentary, advisory framework mappings (NIST CSF 2.0, SP 800-82), and the Implementation Plan commitment layer — what your approved plan promised, next to what you actually do, with a drift flag that watches the amendment clock.

Assessor view — Plan commitment fields
Assessor view with Plan commitment fieldsClick to enlarge
Boardroom-ready in one click

A print-to-PDF executive briefing: completion, overdue items, filings due in 90 days, top risks. What you hand a GM who will never open the grid.

A real Excel workbook, generated on demand

Read Me, live-formula dashboard, full assessment, gap register — frozen headers, dropdowns, autofilter. Stands entirely alone; no app needed to read it. Zero lock-in.

Built for amendment, not a fixed cycle

Subpart F changes by rulemaking, on no schedule — so we watch the Federal Register and the eCFR, including the docket on delaying vessel compliance dates. When it changes, your file migrates: statuses carry forward, changed requirements are flagged for re-review, and the what-changed report is stored as a permanent audit trail.

Not a Microsoft shop? Covered.

Guidance defaults to Microsoft 365/Azure tooling; flip one setting and every affected requirement shows the capability actually required plus common equivalents — CrowdStrike, Splunk, Okta, Tenable, Veeam and more.

Gap register with the column that matters

Every gap carries description, dated remediation plan, interim compensating control, and the Coast-Guard-facing risk written the way an inspector would see it.

Honest status math

Scoped-out requirements leave the denominator entirely. "Not Applicable" requires a reason. The statuses that carry a notification duty say so, loudly.

The filings the Coast Guard actually inspects

From assessment to the documents your regulator asks for — generated, not retyped.

Maritime operators get the §101.630(c) Cybersecurity Plan skeleton — all fourteen prescribed sections — plus the Assessment record, the penetration-test certification letter, the Cyber Incident Response Plan starter, and NRC incident records on the correct without-delay regime.

The mitigation-series directives require three approved artifacts — an Implementation Plan, an Assessment Plan, and an annual Assessment Report — plus timed incident reports and the written policies the directives demand by name. Securidigm Maritime builds each one from the assessment you already did, and refuses to produce anything that would certify a breach.

07 — Incidents

Incident Report Builder with the 72-hour clock

Log an incident with the moment it was identified — backdated to the real time, because that is when the directive's clock starts, not when you opened the tool. A live countdown runs against the absolute deadline; every "new information" entry starts its own 24-hour supplement clock.

  • Report fields are drawn from the regulation itself, and the reportable-cyber-incident threshold of §101.615 is stated where you are asked to judge it — not merely referenced
  • Paste-ready record text for the National Response Center call, a one-click Outlook reminder with a 12-hour alarm, print-to-PDF
  • "Record as reported" judges within-72-hours or late and files the report into your evidence register automatically
  • It never submits anything — reporting stays a deliberate human act
Incident report builder — 72-hour clock
Incident Report BuilderClick to enlarge
08 — The Plan

A fourteen-section Cybersecurity Plan skeleton, in the order §101.630(c) prescribes

§101.630(c) prescribes the Plan's sections and their order, and requires an index if you depart from it. The generator emits all fourteen in order, routing every requirement to the section the regulation itself says it is documented in — then fills each from what your assessment already records: statuses, linked evidence, programme dates, open items. ⟦AUTO⟧ marks what it drew from your file; ⟦INPUT⟧ marks what only you can write. It is a starter draft and says so on every page.

  • Filing citations resolve to your population — VSA per 104.305, FSA per 105.305, OCS FSA per 106.305 — never a three-way list
  • The Assessment record, the §101.650(e)(2) penetration-test certification letter and the CIRP starter come from the same state
  • Every generated document is marked for SSI handling; the Plan is SSI expressly under §101.630(b)
Coast Guard filings view
Maritime filings view
09 — Policies

The policies you're required to have in writing — and the ones you're missing

Subpart F names the written policies and procedures you must hold, and the checklist derives that list from the regulation text rather than from a generic template. It tracks three states — on record, missing, and the one that causes findings: requirement marked compliant, no written policy on record. The samples ship with one policy deliberately revealed as missing, so you can see the red state at work.

  • Starter drafts for any missing policy: the regulatory basis with each governing requirement's current status and on-file evidence from your assessment, a checklist of what the directive requires the document to contain, roles and known artifacts pre-filled — and "skeleton" stated in the title, the first line and the footer
  • A starter draft never counts as evidence; only the approved policy you register does
Required policies checklist
Required policies checklistClick to enlarge
11 — Maritime

The fourteen-section Cybersecurity Plan — and the Coast Guard's clocks

The Maritime edition generates the §101.630(c) Plan skeleton in the regulation's own prescribed section order, each section carrying the requirements that must document there — with each requirement's assessed status and on-file evidence, your program dates, the open-gap register and your incident history pre-filled from the assessment, everything the file knows marked for your review. The calendar runs the deadlines the way the regulation actually works: the 2027 Plan and Assessment dates, the drill count per calendar year, the exercise rule's two independent constraints — and the January 2026 training baseline shown honestly as overdue if your records can't prove it.

  • Assessment record, penetration-test certification letter (the prescribed artifact, as a provider deliverable format) and CIRP starter — all marked STARTER DRAFT on their face
  • Incident records on the National Response Center's without-delay regime — elapsed time is displayed and no hour-count is invented, because Subpart F states none. Operators reporting through a 33 CFR 6.16-1 channel see that instead
  • The §101.660 readiness list: what the Coast Guard can ask for on request, matched against your evidence register
Maritime obligations calendar
Maritime obligations calendarClick to enlarge
Records index (§101.640 / §101.660)

Your evidence register re-sorted into regulation sequence — the index the regulative requires when you rely on existing documents. Printable, and embedded in the Plan skeleton.

The right authority, by purpose

Your Plan goes to the Marine Safety Center or to the cognizant COTP or OCMI depending on your subchapter, and reportable cyber incidents go to the National Response Center. The Contacts view names the right one for each, with your CySO and the designation details beside them.

Change history on every requirement

Every change, when it was made, and the before-and-after values — the trail an inspector asks for when a status looks too convenient.

Compliance trend

A snapshot on every save; the executive briefing shows "61% → 84% since March" instead of a number with no direction.

Word documents with no Word library

The Plan skeleton, Assessment record, certification letter and CIRP starter are written directly in the .docx format by the tool itself — the same zero-dependency, zero-network discipline as everything else.

Deterministic, inspectable, no AI

Every generated document is templates, rules and arithmetic over your own data. The same input always produces the same output, and there is no model to leak your SSI into.

The security case

Built for operators who don't trust software — correctly.

Your completed assessment describes your vulnerabilities. It should never live in someone else's cloud. So this tool isn't a portal, a platform, or a service — it's a single readable file, and every claim below is verifiable on your own machine in five minutes.

Zero network connections

No analytics, telemetry, update checks, external fonts, or cloud calls. Nothing you type is transmitted to the Coast Guard, a vendor, or anyone. Enforced by an automated test on every release of the file.

Your data lives in exactly two places

The client file you save where you choose, and a crash-recovery copy in your browser you can wipe with one button. Nowhere else. Ever.

Your documents never enter it

Evidence files are fingerprinted in memory and discarded. A stolen copy of your assessment file contains pointers and hashes — not your firewall rules.

Zero third-party code

No libraries, frameworks, or package dependencies. There is no supply chain to compromise and no upstream project that can be abandoned.

Not a Coast Guard channel

The tool submits nothing to the Coast Guard. Every submission remains the deliberate, human, prescribed act the regulation requires. SSI-aware handling guidance is built in — the Plan is SSI expressly, under §101.630(b).

No vendor to outlive

If the tool disappeared tomorrow, your record survives: an open-format data file plus a standalone Excel workbook with live formulas.

Don't take our word for any of it — the app tells you how to check
  1. Airplane-mode test — disconnect entirely; every feature still works, including Excel export.
  2. Network-tab test — open your browser's developer tools and watch: the request list stays empty.
  3. Read the source — it's one readable file. Have your IT person inspect it before anyone types a word.
And the limits, stated plainly, because trust pages that hide them are sales copy: the data file is readable text — protect it with your normal file controls (disk encryption, restricted folders); there is no login — anyone with the file can open it; one person edits at a time, with a merge tool to reconcile copies; and the requirement paraphrases are advisory — validate against the official text of 33 CFR 101 Subpart F before any submission. All of this is printed inside the app itself, on a dedicated About & Security page.
The demo is the product

No demo video. No sales call. Request the file, open it, and click.

One demo build, carrying all three population samples — a waterfront facility, a U.S.-flagged vessel and an OCS facility. Each has every applicable requirement answered to the standard we expect, deliberately not fully compliant, because the worked gap entries, the open findings and the evidence trails are the demonstration. Every view, every feature, freely explorable; nothing persists. Running a live assessment of your operation — with saving, your data file, and annual regulatory updates — is what the licensed build adds.

Waterfront facility (105)

The Plan files into the FSA per 33 CFR 105.305 and the authority is your cognizant COTP or OCMI. Shows the Coast Guard clocks live — Plan approval anchoring the audit and the 5-year validity, the 60-day post-approval training clock — the drill and exercise date-list rules, a closed NRC-reported incident with its case reference, an open finding against an unregistered vendor connection, and the worked auditor-independence gap that is the small-operator trap.

U.S.-flagged vessel (104)

Same 150 requirements, but the Plan files into the VSA per 33 CFR 104.305 and approval runs through the Marine Safety Center. Modelled with multiple CySOs and a multi-vessel Plan, because that population exists.

OCS facility

Subchapter 106: the same 150 requirements, but the Plan files into the OCS FSA per 33 CFR 106.305 and the authority line reads for the cognizant COTP or OCMI. Modelled with an operator reporting through its own 33 CFR 6.16-1 channel rather than the NRC, because that population exists.

Start screen (consultant working build shown) — sample operators for facility, vessel and OCS
Start screen of the consultant working build with sample facility, vessel and OCS operators; the demo build opens the same wayClick to enlarge
Pricing

Priced against one avoided finding, not against software.

Coast Guard civil penalties run to five figures per violation per day. Every tier below costs less than the finding it prevents — and every tier keeps your data on your machines. Deliverables are the artifacts Subpart F actually names: the fourteen-section Cybersecurity Plan, the Assessment record, the §101.650(e)(2) penetration-test certification letter, the CIRP, the drill and exercise cadences, and incident records on the National Response Center regime.

Licensed Tool

For operators with the staff to run their own program
$6,500 one-time, per operator
+ $2,500/year catalog updates (33 CFR Subpart F amendments) & migration support
Annual maintenance also keeps editing active — if it lapses, the tool stops writing edits back to your working file; viewing, printing and exporting always work, permanently, and Save still hands you a complete downloaded copy of your current record, so a lapse can never trap work you have already done.
  • The full tool, licensed to your operation
  • Every requirement of your edition's regime — the directives, or 33 CFR 101 Subpart F — scoped and guided
  • Evidence register, calendar, Excel & briefing exports
  • The Cybersecurity Plan skeleton, Assessment record, §101.650(e)(2) pen-test certification letter and CIRP starter — plus incident records, all generated from your assessment
  • Updates when your regime's text changes — statuses carry forward, changes flagged for re-review
  • Onboarding session for your team
Ask about licensing
Most engagements start here

Guided Assessment

We assess, you operate
from $18,000 per engagement
One flat engagement, whichever directives apply to you
  • Everything in Licensed Tool
  • Full gap assessment conducted with you, requirement by requirement
  • Approved-plan commitments — Implementation Plan or Cybersecurity Plan — mapped against actual practice, drift flagged
  • Gap register written to inspection standard — remediation plans, compensating controls, regulator-facing risk
  • Evidence register built and readiness check completed
  • Executive briefing delivered to your leadership
Scope an assessment
Fully managed

Managed Program

Your compliance program, run for you — by the consultant who built it
$3,500 per month retainer
Annual commitment · includes the Guided Assessment in year one
  • Everything in Guided Assessment, kept continuously current
  • Obligations calendar managed — plan updates, reports, and filings prepared on their clocks
  • Incident-response exercises designed, facilitated, and documented to your regime's standard
  • Assessment cadence tracked — the drill count per calendar year, and the exercise rule's two constraints (once a year, and never more than 18 months apart)
  • Renewals and amendments migrated and re-reviewed for you, every cycle
  • Pre-inspection readiness runs, and support assembling records when your regulator asks
  • Guidance on reportable incidents — keeping the 72-hour clock, or the NRC's without-delay rule, met
Discuss a managed program
Every tierLicensed per operator · your data never leaves your machines · SSI-aware handling built in · no cloud dependency, ever · cancel and keep your records — the data file and Excel workbook are yours, viewable and exportable forever (writing edits back to the working file needs current maintenance; Save still downloads a copy)

One flat price per operator — no per-site, per-vessel or per-population math. An operator also regulated under the TSA surface Security Directives licenses that separate product — Securidigm Surface — alongside this one.

Questions operators actually ask

Frequently asked.

Not covered here? Ask directly — michael@securidigm.com

Does this send our data to the Coast Guard?

No. Nothing is sent anywhere, to anyone, ever. Coast Guard submissions remain the deliberate acts the directives prescribe — this tool prepares you for them and tracks them; it never performs them.

Where does our assessment data live?

In one file, saved wherever you choose — your own server, SharePoint, an encrypted folder. Plus a local crash-recovery copy in your browser that you can clear with one button. There is no cloud component to breach.

What does it need to run?

A browser. Nothing else — no install, no admin rights, no account, no network. Double-click the file on the most locked-down machine you own and it runs. Chrome or Edge give the best experience (Save writes straight back to your data file); Firefox and Safari also work — there, each Save downloads a fresh copy of the data file and you keep the newest.

Can more than one person work in it?

One person edits at a time — deliberately: a compliance record needs one accountable pen. The file lives wherever your team shares files, an assessor view adds a second layer of eyes (everything it adds is visibly marked as assessor-layer), every change to a requirement is logged in its history with a timestamp and the before-and-after values, and if two copies do diverge, a built-in merge tool reconciles them difference by difference instead of silently overwriting.

What happens when the Coast Guard amends the regulation?

You receive an updated tool file. Open your existing data with it: statuses carry forward requirement-by-requirement, anything that changed is flagged for re-review, and the migration report is stored in your file as an audit trail. Subpart F changes by rulemaking on no fixed schedule, so we watch the Federal Register and the eCFR — including the docket on delaying vessel compliance dates.

We don't run Microsoft 365. Is the guidance useless to us?

No — flip one profile setting and every Microsoft-flavored recommendation appends the capability the requirement actually needs plus common equivalents. The directives are capability-based; no requirement anywhere names a product.

Is this a legal compliance determination?

No, and it says so prominently. It's a working self-assessment built from careful paraphrases of the directive text — the tool itself instructs you to validate requirement wording against the official regulation before any submission or inspection.

Does it write our Cybersecurity Plan for us?

It generates a structured skeleton from your assessment — all fourteen sections in the order §101.630(c) prescribes, each filled from what your file already records, with ⟦AUTO⟧ marking what it drew from your data and ⟦INPUT⟧ marking what only you can write. The Assessment record, the pen-test certification letter and the CIRP starter come the same way. Every one states plainly that it is a starter draft, and none of them is evidence.

Is the free demo the full product?

It's the full interface with three fully worked sample operators — a vessel, a facility and an OCS facility — explore everything, verify every security claim. What it doesn't do is run an assessment of your own operation: creating client assessments, saving, and file import are licensed-build features, and licensed builds include the catalog updates when the Coast Guard amends Subpart F. The demo exists so your decision is informed, not so the decision is unnecessary. Verify the file you received is authentic — check with shasum -a 256 (macOS/Linux) or certutil -hashfile <file> SHA256 (Windows) against the published hash:
99001079595d7fdc39a1e294d3a6ee1f9424331130447418f155387f1e3afbde

We're a facility, not a vessel operator. Is this for us?

Yes — this product covers 33 CFR 101 Subpart F end to end: all 150 individually enumerated requirements for U.S.-flagged vessels, facilities and OCS facilities, the Coast Guard clocks (the 2027 Plan and Assessment deadlines, the already-passed 2026 training baseline shown honestly as overdue, the twice-a-year drill and 18-month exercise rules), the fourteen-section Cybersecurity Plan skeleton, and incident records on the National Response Center's without-delay regime — with elapsed time shown and no hour-count invented, because Subpart F states none.

We operate multiple sites — or both a facility and vessels. How does licensing work?

A license is flat per operator — no per-site, per-vessel or per-population math. Within the tool, an assessment file tracks one regulated population (facility, U.S.-flagged vessel, or OCS facility — the choice sets the review authority, COTP/OCMI or the MSC, in every relevant row), and the rule allowing one CySO to serve several assets is modeled where the regulation provides for it; an operator spanning populations simply runs a file per population under the same license. An operator also subject to the TSA surface Security Directives licenses that separate product (Securidigm Surface) alongside this one and keeps a separate assessment file for it

Why should we trust a file over a "real" platform?

Inspect it. A single readable file with no network access and no dependencies has far less that can go wrong than any portal — and unlike a platform, every security claim it makes can be tested by your own IT person in minutes.

One file, by email

Get your sector's demo — the full interface, a fully worked sample operator.

Open it, explore the samples, run the airplane-mode test. If it isn't obviously useful in fifteen minutes, delete it — it uninstalls by being deleted.

Request Demo
Click anywhere to close