The US will require all ships that call on ports in the country to ensure cyber risk management is appropriately addressed in their safety management system (SMS) from January.

BIMCO said that the United States Coast Guard (USCG) expects that all companies with US flagged ships and foreign flagged ships address cyber risk management in their SMS by the company's first annual verification of the document of compliance after 1 January 2021.
USCG will include cyber risk assessment in their Port State Control (PSC) inspection post 1 January 2021. Failure to meet this requirement may result in detention of a ship at port.
If objective evidence is found that the ship failed to implement its SMS with respect to cyber risk management, the Port State Control Officers (PSCO) may issue a deficiency with action code 30 - Ship Detained, with the requirement of an external audit within three months or prior to returning to a US port after sailing in foreign waters.
When objective evidence indicates that the ship failed to implement its SMS with respect to cyber risk management, a deficiency for both the operational deficiency and an ISM deficiency may be issued with an action code 17 - Rectify Prior to Departure and require the vessel to conduct an internal audit, focused on the vessel’s cyber risk management, within three months or, prior to returning to a US port after sailing in foreign waters.
When objective evidence indicates there is a serious failure to implement the SMS with respect to cyber risk management that directly resulted in a cybersecurity incident impacting ship operations, the PSCO may issue a deficiency for both the operational deficiency and an ISM deficiency with action code 30 – Ship Detained with the requirement of an external audit within three months or prior to returning to a US port after sailing in foreign waters.