EO 14116Executive OrderBiden · D Quiet signal

Executive Order 14116

Amending Regulations Relating to the Safeguarding of Vessels, Harbors, Ports, and Waterfront Facilities of the United States

This executive order amends Coast Guard maritime security regulations (33 CFR Part 6) to explicitly include cybersecurity protections for ports, vessels, and waterfront facilities. It grants Captains of the Port authority to control access to digital infrastructure, establish cyber-focused security zones, inspect and remove unauthorized data or systems, and requires reporting of cyber incidents to CISA and the FBI. The order modernizes 1917-era authorities to address malicious cyber campaigns against U.S. maritime infrastructure.

Impact dates

  1. EO effective; regulatory amendments take effect

Key directives

  • Amend 33 CFR Part 6 to incorporate cyber incident and damage definitions
  • Authorize Captains of the Port to prevent access of data, networks, programs, systems, or digital infrastructure to vessels and waterfront facilities
  • Authorize establishment of security zones restricting digital infrastructure access
  • Authorize inspection, search, and removal of unauthorized digital infrastructure from vessels, facilities, and security zones
  • Grant possession and control of vessels to prevent cyber damage
  • Require Commandant to consult Secretary of Labor on Port Security Card issuance
  • Authorize Commandant to prescribe cybersecurity measures for prevention, detection, assessment, and remediation of cyber incidents
  • Require immediate reporting of actual or threatened cyber incidents to FBI and CISA
  • Mandate owners/operators take precautions to protect digital infrastructure from sabotage
  • Commandant to coordinate enforcement with DOJ and other relevant agencies

Who is ordered

Timeline

Immediate

  • EO takes effect upon signing; regulatory amendments are self-executing
  • Coast Guard Captains of the Port gain expanded authority over digital infrastructure
  • Cyber incident reporting obligations to FBI and CISA become active

Near term (90d)

  • Coast Guard to develop implementation guidance for new cyber authorities
  • Industry adjustment to expanded inspection and access-control regimes
  • Coordination protocols between Coast Guard, DOJ, and other agencies to be established

Long term

  • Potential for sustained increase in maritime cybersecurity enforcement
  • Possible expansion of security zone designations to cover cyber assets
  • Evolution of Coast Guard Port Security Card vetting to include cyber risk factors
  • Long-term industry compliance costs for cybersecurity safeguards at waterfront facilities

Risks & tensions

  • Vague scope: 'data, information, network, program, system, or other digital infrastructure' is broadly defined and could enable overreach
  • No explicit limits on duration of security zones or digital access restrictions—'as the Captain of the Port deems necessary'
  • Potential tension between cybersecurity authority and Fourth Amendment protections for searches of digital systems
  • Industry compliance costs unclear; no regulatory impact analysis provided
  • Coordination with DOJ and other agencies (Sec. 2) lacks specificity on mechanisms or timelines
  • Cyber incident reporting to both FBI and CISA may create duplicate or conflicting demands
  • Unclear how 1917-era statute authorizes modern cybersecurity regulation of private networks
Executive Order 14116: Amending Regulations Relating to the Safeguarding of Vessels, Harbors, Ports, and Waterfront Facilities of the United States · Executive Orders