<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-BON26146-HKW-22-V7G"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>119 S4564 IS: Maritime Cybersecurity Act</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2026-05-19</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>119th CONGRESS</congress><session>2d Session</session><legis-num>S. 4564</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20260519">May 19, 2026</action-date><action-desc><sponsor name-id="S404">Mr. Scott of Florida</sponsor> (for himself and <cosponsor name-id="S426">Mr. Kim</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSCM00">Committee on Commerce, Science, and Transportation</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To amend title 46, United States Code, to require the Secretary of the department in which the Coast Guard is operating to assess cybersecurity risks of certain software and hardware used in certain maritime facilities, and for other purposes.</official-title></form><legis-body><section id="S1" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Maritime Cybersecurity Act</short-title></quote>.</text></section><section id="ida17730adfe914348a3ca70d4d28a1e67"><enum>2.</enum><header>Cybersecurity vulnerability assessments of certain maritime facility software and hardware</header><text display-inline="no-display-inline">Section 70102 of title 46, United States Code, is amended—</text><paragraph commented="no" display-inline="no-display-inline" id="idabf1b1d9f1ae47d99acac681b08fcaae"><enum>(1)</enum><text display-inline="yes-display-inline">in subsection (b)—</text><subparagraph commented="no" display-inline="no-display-inline" id="id21c9392dbfbf48568ed14a9cda272c1f"><enum>(A)</enum><text>in paragraph (1)(C), by inserting <quote>(including, with respect to covered facilities, cybersecurity risks of covered software or hardware as provided under subsection (d)(1))</quote> after <quote>cybersecurity risks</quote>;</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ideca1d5b74d914fbd98703bb072c4834d"><enum>(B)</enum><text display-inline="yes-display-inline">in paragraph (3), by inserting before the period <quote>, except that, for covered facilities, the Secretary shall annually update each such vulnerability assessment with respect to the identification of weaknesses in security and cybersecurity risks of covered software or hardware in accordance with subsection (d)(1)</quote>; and</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id8bdc9a5125d442c89b3876aa0e0dff4e"><enum>(C)</enum><text>in paragraph (4)—</text><clause commented="no" display-inline="no-display-inline" id="idd1a2cf192cf94ad1bd9f05ac19843881"><enum>(i)</enum><text display-inline="yes-display-inline">by striking <quote>In lieu</quote> and inserting <quote>(A) Except as provided in subparagraph (B), in lieu</quote>; and</text></clause><clause commented="no" display-inline="no-display-inline" id="idff68c0ab15004c538f132eb6dfc0adaa"><enum>(ii)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id64B7B6A035744180B49ED89F4397D50B"><subparagraph commented="no" display-inline="no-display-inline" id="idb29b5e5fbe904ed68f5e825428d05878" indent="up1"><enum>(B)</enum><text>In the event that the Secretary accepts an alternative assessment described in subparagraph (A) for a covered facility, the Secretary shall still conduct an assessment under paragraph (1) of weaknesses in security and cybersecurity risks of covered software or hardware used at the facility in accordance with subsection (d)(1).</text></subparagraph><after-quoted-block>; and</after-quoted-block></quoted-block></clause></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idc3d98e2f886042188639af74a0050ecf"><enum>(2)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id9EBEC833DB2949DA85B6C628C6313E97"><subsection commented="no" display-inline="no-display-inline" id="idc12e364b16724e798e21ffdce0979ff9"><enum>(d)</enum><header>Assessing cybersecurity risks of covered software or hardware</header><paragraph id="id31c6c92f56384415839054959bd96078"><enum>(1)</enum><header>Assessments</header><subparagraph commented="no" display-inline="no-display-inline" id="idce806526b4334e20bfd5ac6cf03bfcc5"><enum>(A)</enum><header display-inline="yes-display-inline">In general</header><text>Not later than 1 year after the date of enactment of this subsection, and annually thereafter, the Secretary, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, shall conduct an assessment under subsection (b)(1) with respect to weaknesses in security and cybersecurity risks of covered software or hardware. </text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ida94178f049aa49f180c73b5b36f73c47"><enum>(B)</enum><header>Reducing barriers</header><text display-inline="yes-display-inline">The Secretary may conduct an assessment under this paragraph—</text><clause commented="no" display-inline="no-display-inline" id="id460f5299121b47de93da7804df58bead"><enum>(i)</enum><text display-inline="yes-display-inline">notwithstanding any provision of an end user licensing agreement or other contract that would otherwise hinder such assessment; and</text></clause><clause commented="no" display-inline="no-display-inline" id="id291d4bc42ffd492196fb70baec65ef51"><enum>(ii)</enum><text display-inline="yes-display-inline">without obtaining the consent of any owner or operator of a covered facility, or any other person, notwithstanding any other provision of law.</text></clause></subparagraph></paragraph><paragraph id="id592c74afddad43e88d1ceca1e6405e6a"><enum>(2)</enum><header>Covered facility reports and compliance</header><subparagraph commented="no" display-inline="no-display-inline" id="ided258383655045b6a5af3a093766d6d9"><enum>(A)</enum><header display-inline="yes-display-inline">In general</header><text>Not later than 180 days after the date of enactment of this subsection, and annually thereafter, the owner or operator of a covered facility shall submit a report to the Secretary that—</text><clause commented="no" display-inline="no-display-inline" id="id4be978ba00d94c679318dbdc60d34d99"><enum>(i)</enum><text display-inline="yes-display-inline">identifies—</text><subclause id="id6de5a3b805014c6f8971b7c5838fcb47"><enum>(I)</enum><text>any covered software or hardware that—</text><item commented="no" display-inline="no-display-inline" id="id3deb7d6e69b5418faa27edb8b739fd67"><enum>(aa)</enum><text display-inline="yes-display-inline">the owner or operator is using, plans to use, or during the previous year used at the facility; and</text></item><item commented="no" display-inline="no-display-inline" id="id574fee0411264e649906a614536544f5"><enum>(bb)</enum><text display-inline="yes-display-inline">was manufactured—</text><subitem commented="no" display-inline="no-display-inline" id="ide7ebc33d8007475688ab91270f457c8b"><enum>(AA)</enum><text display-inline="yes-display-inline">by a foreign entity of concern or a foreign country of concern; </text></subitem><subitem commented="no" display-inline="no-display-inline" id="id9eadf51eda7b4517bce6055c722ae2c6"><enum>(BB)</enum><text display-inline="yes-display-inline">by a company controlled or operated by a foreign entity of concern or a foreign country of concern; or</text></subitem><subitem commented="no" display-inline="no-display-inline" id="id6564c4624b764567a5ad51de64f0bcc9"><enum>(CC)</enum><text>in a foreign country of concern;</text></subitem></item></subclause><subclause id="id88012b814c114b558edce09e4715b5cc"><enum>(II)</enum><text>any instance with respect to the facility of a cybersecurity risk resulting in a transportation security incident involving the marine transportation system or any port security system; and</text></subclause><subclause id="id386e570c82954f94b7fcce94c75d5f45"><enum>(III)</enum><text>any other cybersecurity risk with respect to the facility, without regard to whether the risk resulted in a transportation security incident; and</text></subclause></clause><clause commented="no" display-inline="no-display-inline" id="idd630c45d0f8541ad9319042a74b3745a"><enum>(ii)</enum><text>except as provided under subparagraph (B)(ii), certifies that any covered software or hardware that the owner or operator is using, plans to use, or during the previous year used has been assessed for consistency with standards of the National Institute of Standards and Technology or equivalent standards within the previous year and the owner or operator has mitigated against any inconsistencies with such standards. </text></clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id8a20a58d00214e309a939b86be660664"><enum>(B)</enum><header>Compliance</header><clause commented="no" display-inline="no-display-inline" id="idde844d3f7df84ff58a5928503b310a02"><enum>(i)</enum><header display-inline="yes-display-inline">In general</header><text>Except as provided in clause (ii), the owner or operator of a covered facility may not use any covered software or hardware described in subparagraph (A)(ii) for which it cannot certify consistency with standards of the National Institute of Standards and Technology or equivalent standards. </text></clause><clause commented="no" display-inline="no-display-inline" id="id5f10ef99b6aa43f1a854f7b0c491aff1"><enum>(ii)</enum><header>Waiver process</header><text>The Secretary may issue a waiver to allow an owner or operator of a covered facility to use covered software or hardware for which it cannot certify consistency with standards of the National Institute of Standards and Technology or equivalent standards if the Secretary determines that there is low risk to national security which is outweighed by the benefit to commerce.</text></clause></subparagraph></paragraph><paragraph id="id55bb84046d004fab8288e5b68bd92a29"><enum>(3)</enum><header>Annual reports to Congress</header><text display-inline="yes-display-inline">Not later than 1 year after the date of enactment of this subsection, and annually thereafter, the Secretary, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, shall provide a report, to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives, on—</text><subparagraph commented="no" display-inline="no-display-inline" id="id403997fd282b465f99081c3bf9f43d8b"><enum>(A)</enum><text>the findings of the most recent assessment under paragraph (1);</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idfb82d9d16dee4b3da2b2643ba145b616"><enum>(B)</enum><text display-inline="yes-display-inline">the findings of the most recent reports under paragraph (2);</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id999df1c535ba4cd3b7be8d5d0a33e9a3"><enum>(C)</enum><text display-inline="yes-display-inline">any actions taken by the Secretary, or the Director of the Cybersecurity and Infrastructure Security Agency, to mitigate cybersecurity risks with respect to covered software or hardware; and</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id206f833cb28245fabd7613a2cc7e2534"><enum>(D)</enum><text display-inline="yes-display-inline">any recommendations to Congress on strengthening maritime transportation and port security with respect to cybersecurity risks of covered software or hardware. </text></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idcfc042d93cfd42989e15c5007ce961e5"><enum>(4)</enum><header>Nondisclosure</header><text display-inline="yes-display-inline">Subject to paragraph (5), information in any assessment or report under this subsection shall not be disclosed to the public, pursuant to section 552(b)(3) of the United States Code. </text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id3dbfd06ba5e84e109c2248c91b9d5b0b"><enum>(5)</enum><header>Coordination</header><text>The Secretary shall coordinate, as appropriate, with Federal entities, and any other entities that have an agreement in effect with the Secretary for the sharing of information, to make information compiled by the Secretary under this subsection available to such entities for the purposes of maritime transportation security, cybersecurity risk mitigation, or compliance assistance related to covered facilities or covered software or hardware.</text></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ide608d9c298d24c5e9f1499cbbe6978ef"><enum>(e)</enum><header>Definitions</header><text display-inline="yes-display-inline">In this section:</text><paragraph commented="no" display-inline="no-display-inline" id="idf5593b68cf76436c88060f75f8934f30"><enum>(1)</enum><header display-inline="yes-display-inline">Covered facility</header><text>The term <term>covered facility</term> means a facility—</text><subparagraph commented="no" display-inline="no-display-inline" id="ide3c3a99f5c93485eae2fc2f8ab9e4ae7"><enum>(A)</enum><text display-inline="yes-display-inline">that is described in subsection (b)(1); and</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id206d1a197a714a1da099f02bd2be87c7"><enum>(B)</enum><text>to which part 105 or 106 of title 33, Code of Federal Regulations (or successor regulations), applies.</text></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id504b72f9cc024b438a3b88366a814ffd"><enum>(2)</enum><header display-inline="yes-display-inline">Covered software or hardware</header><text>The term <term>covered software or hardware</term> means any software or hardware that—</text><subparagraph commented="no" display-inline="no-display-inline" id="ida2c84eef9db1454bbc8a173437414ab8"><enum>(A)</enum><text display-inline="yes-display-inline">connects to the internet or otherwise poses a cybersecurity risk; </text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idc0856130664c46b8a6e434b4c7ccaae1"><enum>(B)</enum><text display-inline="yes-display-inline">is used at a covered facility; and</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id26f955f8c9ec4470aa6462466fc6ca35"><enum>(C)</enum><text display-inline="yes-display-inline">is used in—</text><clause commented="no" display-inline="no-display-inline" id="id36fae5a2c978428a928d3325a8f52aef"><enum>(i)</enum><text display-inline="yes-display-inline">the marine transportation system, including in a crane manufactured—</text><subclause commented="no" display-inline="no-display-inline" id="id46ffa017cbfd4093916282a4b281069d"><enum>(I)</enum><text display-inline="yes-display-inline">by a foreign entity of concern or a foreign country of concern; </text></subclause><subclause commented="no" display-inline="no-display-inline" id="id308692bf85de400bbeb45c6709fd3d37"><enum>(II)</enum><text display-inline="yes-display-inline">by a company controlled or operated by a foreign entity of concern or a foreign country of concern; or</text></subclause><subclause commented="no" display-inline="no-display-inline" id="ida925a64180e7407895a09a8292abc499"><enum>(III)</enum><text>in a foreign country of concern; or</text></subclause></clause><clause id="id7b07b36fb427442ab5917ab43fe6de6e"><enum>(ii)</enum><text>a business system that, if compromised or exploited, could result in a transportation security incident;</text></clause><clause id="id320aa9c9f4fd4cf9a31b16a3d31c14ef"><enum>(iii)</enum><text>a system whose ownership, operation, maintenance, or control is delegated wholly or in part to any other party; or </text></clause><clause id="idc9fc6a35bda849c6b00fd10e06d59aa4" commented="no" display-inline="no-display-inline"> <enum>(iv)</enum> <text display-inline="yes-display-inline">any other maritime infrastructure determined by the Secretary to be a high cybersecurity risk to the security of any covered facility or to maritime transportation security.</text>
 </clause></subparagraph></paragraph><paragraph id="ida71c1198de7c43e39a60835ff562b66f"><enum>(3)</enum><header>Cybersecurity vulnerability</header><text>The term <term>cybersecurity vulnerability</term> means a characteristic or specific weakness that renders software or hardware or affiliated systems open to exploitation by a given threat or susceptible to a given hazard.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id5dd7e855f92e434185a6b015d923f343"><enum>(4)</enum><header display-inline="yes-display-inline">Foreign country of concern; foreign entity of concern</header><text>The terms <term>foreign country of concern</term> and <term>foreign entity of concern</term> have the meanings given such terms in section 10612(a) of the Research and Development, Competition, and Innovation Act (<external-xref legal-doc="usc" parsable-cite="usc/42/19221">42 U.S.C. 19221(a)</external-xref>).</text></paragraph></subsection><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></section></legis-body></bill>

