EU and US Cybersecurity Regulations Impact Port and Terminal Operations
New cybersecurity regulations in the European Union and the United States are reshaping the operational landscape for ports and terminals. These frameworks introduce new requirements for product manufacturers and operators.

New cybersecurity regulations from the European Union and the United States are significantly impacting the global port and terminal sector. The EU's Cyber Resilience Act (CRA) and the US Coast Guard's Cybersecurity in the Marine Transportation System (MTS) final rule establish comprehensive new requirements for cybersecurity.
The EU's CRA, which entered into force in December 2024 with primary obligations effective from December 2027, mandates manufacturers and retailers of products containing digital elements to ensure cybersecurity throughout the product lifecycle. This includes requirements for planning, design, development, and maintenance, addressing historical issues of insecure products with fundamental vulnerabilities.
In the US, the Coast Guard's MTS final rule, effective July 2025, applies to US-flagged vessels and many ports and marine terminals. Requirements include developing and maintaining a cybersecurity plan and designating a cybersecurity officer. All reportable cybersecurity incidents must now be reported to the Coast Guard's National Response Center.
Additionally, the US National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) serves as a widely adopted voluntary guideline. It provides a framework for risk management and best practices, although it is not a certification standard like ISO 27001. The CSF shares similarities with ISO 27001 in areas of governance, risk management, and control structures.
These regulations and guidelines compel companies to take greater responsibility for the cybersecurity of their products and systems throughout their entire lifecycle, a critical consideration for equipment with long operational lives, such as Kalmar's solutions.