The bill strengthens federal oversight, coordination, and clarity to reduce maritime cyber risk and protect trade, but does so at the cost of added compliance burdens for industry, potential new taxpayer spending, and some loss of local flexibility.
Maritime operators and the broader U.S. economy face lower risk of major trade disruption because the bill directs attention and resources to maritime transportation system (MTS) cyber risks that could affect roughly $2.1 trillion in trade activity.
GAO review and required reporting will identify Coast Guard staffing/funding gaps and increase Congressional oversight, enabling targeted remediation or policy fixes for maritime cybersecurity readiness.
Recognizing DHS and DOT as co‑SRMAs and tying the SRMA definition to existing statute clarifies federal responsibility and should improve interagency coordination (Coast Guard, TSA, DOT, CISA) for maritime cyber defenses.
Regulated maritime businesses (ports, terminals, utilities) will likely face higher compliance costs and administrative burden from expanded Coast Guard oversight, incident reporting requirements, and potential new statutory duties (e.g., reporting to CISA).
If the GAO finds Coast Guard underfunding, addressing gaps could require increased federal spending or reallocations that raise taxpayer costs or force tradeoffs in other appropriations.
Emphasis on federal SRMA roles and narrow statutory definitions may shift regulatory pressure onto state and local port operators, create coordination challenges, and limit local flexibility when novel maritime assets or services fall outside the listed categories.
Based on analysis of 4 sections of legislative text.
Requires GAO to assess the Coast Guard's funding, staffing, guidance, and capability to carry out maritime cybersecurity SRMA duties and report recommendations within 270 days.
Official title: To direct the Comptroller General of the United States to conduct a review of the budget, resources, and capabilities of the Coast Guard as the co-Sector Risk Management Agency for the marine transportation system.
Introduced February 20, 2026 by Addison P. McDowell · Last progress February 20, 2026
Directs the Government Accountability Office to complete a review, within 270 days of enactment, assessing the U.S. Coast Guard’s funding, staffing, guidance, and capabilities to carry out Sector Risk Management Agency (SRMA) responsibilities for marine transportation system cybersecurity. The review must evaluate whether resources, personnel, training, enforcement capacity, and regulatory guidance are sufficient, and deliver findings and recommendations to specified congressional committees. The law defines the marine transportation system and ties the SRMA definition to existing statutory law, and it documents congressional findings about the economic importance of maritime trade, growing cyber threats to ports and vessels, recent Coast Guard rulemakings, and infrastructure funding gaps without cybersecurity-specific allocations.