US Federal 2025-2026 Regular Session

US Federal Senate Bill SB4564

Introduced
 

Caption

Maritime Cybersecurity Act

Summary

SB 4564, the Maritime Cybersecurity Act, would amend federal maritime security law to require the Department of Homeland Security, through the Coast Guard and in coordination with CISA, to assess cybersecurity risks associated with certain software and hardware used at covered maritime facilities. The bill expands existing vulnerability assessments to explicitly include cybersecurity weaknesses in covered software and hardware, requires annual updates, and allows the Secretary to conduct assessments even if contracts, licensing terms, or other legal barriers would otherwise limit access. The bill also requires owners and operators of covered facilities to report annually on the software and hardware they use, including whether it was manufactured by a foreign entity or in a foreign country of concern, and to certify that such systems have been assessed against NIST or equivalent standards and that any inconsistencies have been mitigated. If an operator cannot make that certification, the bill generally prohibits use of the equipment unless the Secretary grants a waiver based on low national-security risk and a greater commercial benefit. The Secretary must also provide annual reports to Congress on findings, mitigation actions, and recommendations for strengthening maritime transportation and port security.

Impact

The bill would amend section 70102 of title 46, United States Code, adding new cybersecurity-specific duties for maritime facility vulnerability assessments and new reporting, compliance, waiver, and congressional reporting requirements. It would affect covered maritime facilities subject to Coast Guard security regulations, their owners and operators, and federal agencies responsible for maritime and cybersecurity oversight, especially the Coast Guard and CISA. The measure also creates confidentiality protections for assessment and report information while allowing interagency sharing for security and compliance purposes.

Sentiment

Based on the bill text and available context, the measure appears to be framed as a national-security and infrastructure-protection bill with no recorded opposition or committee debate in the provided materials. Its sponsors present it as a cybersecurity hardening measure for ports and maritime facilities, and the absence of votes or transcript discussion suggests no documented controversy in the available record. Overall, the bill’s tone is precautionary and security-focused, with an emphasis on risk assessment, mitigation, and federal oversight.

Contention

The main points of potential contention are the bill’s broad federal authority and compliance burden. It authorizes the Secretary to conduct assessments notwithstanding end-user license agreements and without owner or operator consent, which could raise concerns from facility operators and vendors about access, proprietary systems, and contractual rights. Another likely issue is the restriction on using software or hardware that cannot be certified to NIST or equivalent standards, especially where equipment is tied to foreign entities or foreign countries of concern; maritime operators may view this as costly or operationally disruptive. The waiver process partially addresses those concerns by allowing exceptions when national-security risk is low and commercial benefit is high.

Companion Bills

No companion bills found.

Previously Filed As

US SB3315

Health Care Cybersecurity and Resiliency Act of 2026

US HB2390

Maritime Supply Chain Security Act

US H7023

OGSR/Cybersecurity

US HB7266

Rural and Municipal Utility Cybersecurity Act

US H7013

OGSR/Cybersecurity

US S7020

OGSR/Agency Cybersecurity Information

US S0576

Local Government Cybersecurity

US SB245

Insure Cybersecurity Act of 2025

US SB1875

Streamlining Federal Cybersecurity Regulations Act of 2025

US S49

Relative to cybersecurity and artificial intelligence

Similar Bills

No similar bills found.