MTS CYBER Act of 2026
Summary
What This Bill Does
The MTS CYBER Act of 2026 directs the Comptroller General to review the Coast Guard's budget and capabilities as a sector risk management agency for the marine transportation system. The review must be completed within 270 days after enactment.
GAO must assess whether Coast Guard funding is sufficient for cybersecurity personnel, training, and enforcement under existing statutory and presidential-policy responsibilities. It must evaluate whether Coast Guard personnel can assess regulated entities' compliance with cybersecurity requirements. It must also assess whether industry receives sufficient implementation and compliance guidance, using applicable law, federal regulatory benchmarks, and recognized maritime-cybersecurity practices.
GAO must submit findings and recommendations to the listed Senate commerce, appropriations, and homeland-security committees and House transportation, appropriations, and homeland-security committees.
The findings describe maritime trade's economic importance, increasing cyber threats, DHS and Transportation co-leadership, Coast Guard and TSA responsibilities, expanded Coast Guard authority, mandatory incident reporting, prior port-infrastructure investment, and claimed Coast Guard staffing and funding shortfalls. The operative section requires only the GAO review and report; it does not appropriate money, change cybersecurity standards, or itself add regulated-entity duties.
Who Benefits and How
Congress receives an independent funding and capability assessment before deciding whether to increase Coast Guard resources. Coast Guard cybersecurity programs gain a documented account of personnel, training, and enforcement needs. Ports, vessel operators, and other regulated maritime entities may benefit from recommendations for clearer guidance and better-resourced oversight. Maritime workers and supply-chain users may benefit indirectly from stronger cyber resilience.
Who Bears the Burden and How
GAO cybersecurity evaluators must complete the review and recommendations within 270 days. Coast Guard budget, workforce, enforcement, and compliance staff must provide records and operational evidence. Regulated maritime entities and industry stakeholders may be asked to describe compliance experience and guidance gaps. Congressional committee staff must review the resulting report. The bill itself does not impose a new private compliance standard or provide funding to carry out any recommendation.
Key Provisions
- Requires a GAO review within 270 days.
- Evaluates Coast Guard cybersecurity funding and resource needs.
- Assesses personnel, training, and enforcement capacity.
- Reviews the ability to evaluate regulated-entity compliance.
- Compares industry guidance with legal and technical benchmarks.
- Requires findings and recommendations for six congressional committees.
- Creates no direct appropriation or new maritime cybersecurity rule.
Evidence Chain:
This summary is generated from the full bill text using AI analysis. Expand "Detailed Analysis" below for identified beneficiaries/burden bearers with clause-level evidence links.
At a Glance
What This Bill Does
Requires GAO within 270 days to review whether the Coast Guard has sufficient funding, personnel, training, enforcement capacity, compliance-assessment ability, and industry guidance to perform its marine transportation system cybersecurity sector-risk duties.
Key Policy Areas
Maritime Cybersecurity, Coast Guard Resources, Marine Transportation System, Critical Infrastructure, Congressional Oversight
Primary Purpose
Requires GAO within 270 days to review whether the Coast Guard has sufficient funding, personnel, training, enforcement capacity, compliance-assessment ability, and industry guidance to perform its marine transportation system cybersecurity sector-risk duties.
Policy Domains
Section 3 Coast Guard budget and capability review
Identified Gains
- Coast Guard maritime cybersecurity programs
- Congressional homeland-security committees
- Congressional appropriations committees
- Port operators seeking cybersecurity guidance
- Vessel operators seeking cybersecurity guidance
- Maritime supply-chain users
Identified Costs
- GAO maritime-cybersecurity evaluators
- Coast Guard budget staff
- Coast Guard cybersecurity personnel
- Coast Guard compliance-assessment staff
- Regulated maritime entities providing evidence
- Congressional committee review staff
Sponsors
Legislative Progress
In CommitteeReferred to the Subcommittee on Transportation and Maritime Security.
Referred to the Subcommittee on Coast Guard and Maritime Transportation.
Referred to the Committee on Transportation and Infrastructure, and in …
Introduced in House
Mr. McDowell introduced the following bill; which was referred to …
Stakeholder Effects
cui bono?How this legislation distributes effects. Mention counts reflect frequency, not effect magnitude.
Coast Guard budget staff, Coast Guard compliance-assessment staff, Coast Guard maritime cybersecurity programs
Positive-direction: Coast Guard maritime cybersecurity programs, Congressional appropriations committees, Congressional homeland-security committees
Negative-direction: Coast Guard budget staff, Coast Guard compliance-assessment staff, GAO maritime-cybersecurity evaluators
Port operators seeking cybersecurity guidance, Regulated maritime entities providing evidence, Vessel operators seeking cybersecurity guidance
Bill Structure & Actor Mappings
Who is "The Secretary" in each section?
- "subject"
- → Coast Guard marine transportation cybersecurity program
- "reviewer"
- → Comptroller General
- "recipient"
- → Listed congressional oversight committee
- "regulated_entity"
- → Maritime entity subject to Coast Guard cybersecurity requirements
Key Definitions
Terms defined in this bill
The marine transportation system for which DHS and Transportation serve as sector risk management agencies and the Coast Guard performs delegated cybersecurity functions.
An assessment of funding, cyber personnel, training, enforcement, compliance evaluation, and guidance for regulated maritime entities.
We use a combination of our own taxonomy and classification in addition to large language models to assess meaning and potential beneficiaries. High confidence means strong textual evidence. Always verify with the original bill text.
Learn more about our methodology