Port security in the United States is the federal system of laws, personnel requirements, credentialing, screening technology, and cybersecurity rules that protects the country’s more than 360 maritime ports. Two statutes anchor it: the Maritime Transportation Security Act of 2002 and the Security and Accountability for Every Port Act of 2006. Together they require regulated facilities to maintain approved security plans, vet workers biometrically, screen inbound cargo before it lands, and, since 2025, defend their networks against cyberattack. The Coast Guard enforces the rules, and civil penalties currently reach $43,527 per day after inflation adjustments.1eCFR. 33 CFR 27.3 – Penalty Adjustment Table
The Two Federal Laws Behind Port Security
The Maritime Transportation Security Act of 2002, codified at 46 U.S.C. Chapter 701, directed the Coast Guard and the Department of Homeland Security to set national standards for identifying and reducing risks at ports, aboard vessels, and along waterways.2Office of the Law Revision Counsel. 46 USC Chapter 701 – Port Security It also aligned U.S. requirements with the International Ship and Port Facility Security Code, so domestic facilities and foreign-flagged vessels operate under compatible rules.
The SAFE Port Act of 2006 expanded that foundation. It grew grant programs, created training and exercise programs, and required area-level security plans that coordinate federal, state, local, and private partners across an entire port region rather than facility by facility.3Congress.gov. Public Law 109-347 – Security and Accountability For Every Port Act of 2006
Under 46 U.S.C. § 70103, each port area maintains an Area Maritime Transportation Security Plan built by a Federal Maritime Security Coordinator with input from an Area Security Advisory Committee. These plans map the critical infrastructure, population centers, and environmental resources in the area, then set coordinated response and recovery protocols. Every area plan must also include a salvage component to reopen waterways after a disruption, and a cybersecurity component.4Office of the Law Revision Counsel. 46 USC 70103 – National Maritime Transportation Security Plan
MARSEC Threat Levels
Operations run against a three-tier threat scale called the Maritime Security, or MARSEC, level. The Coast Guard sets the current level, and every facility and vessel security plan spells out what additional measures kick in at each one. The Commandant can raise MARSEC nationally; a Captain of the Port can raise it for a specific zone.5eCFR. 33 CFR 101.105 – Definitions
- Level 1 is the baseline for normal operations, with routine access control, ID checks, and monitoring of restricted areas.
- Level 2 activates when there is a heightened risk. Facilities add measures for as long as the elevated threat persists, such as increased screening of vehicles and personnel, tighter waterside access, and expanded patrols.
- Level 3 activates when an incident is probable or imminent, even if the target is unknown. Facilities apply their most intensive posture for a limited period, which can include halting certain operations and coordinating directly with law enforcement.
Because each plan already prescribes the response for every level, a change in MARSEC triggers a concrete, immediate shift on the ground rather than a vague alert.
Facility Security Plans and Officers
Any facility on or adjacent to waters under U.S. jurisdiction that receives certain vessel categories must comply with 33 CFR Part 105. That covers facilities receiving passenger vessels certified for more than 150 people, foreign cargo vessels over 100 gross register tons, comparable U.S. cargo vessels, and barges carrying more than 10 tons of certain dangerous cargo.6eCFR. 33 CFR Part 105 – Maritime Security: Facilities
The core requirement is a written Facility Security Plan built on a Facility Security Assessment that identifies vulnerabilities. The plan specifies access control procedures, restricted-area designations, surveillance, lighting, physical barriers, and communication protocols for each MARSEC level. It must be submitted for approval to the local Coast Guard Captain of the Port.
Every regulated facility designates a Facility Security Officer to own daily execution. The FSO ensures the assessment gets done, the plan stays current, and personnel are trained, and serves as the primary Coast Guard contact.7eCFR. 33 CFR 105.205 – Facility Security Officer The FSO must also run a security drill at least every three months and a full-scale exercise at least once per calendar year, with no more than 18 months between exercises. A real-world response to a MARSEC increase counts if reported.8eCFR. 33 CFR 105.220 – Drill and Exercise Requirements
Who Can Enter Secure Areas: TWIC
Anyone needing unescorted access to the secure areas of a regulated maritime facility or vessel must carry a Transportation Worker Identification Credential, or TWIC. That covers longshoremen, truck drivers entering terminal gates, facility employees, and vessel crew. The program is established under 46 U.S.C. § 70105 and administered by TSA.9Office of the Law Revision Counsel. 46 USC 70105 – Transportation Worker Identification Credentials
Applicants enroll in person, submit fingerprints and biographical information, and pay a non-refundable fee. As of 2026, a new TWIC costs $124, with a reduced rate of $93 for applicants who already hold a valid hazardous materials endorsement or a FAST card. Online renewals are $116 and replacements are $60. The card is valid for five years and contains a biometric chip that verifies the holder at access points.10Transportation Security Administration. TWIC
TSA runs a security threat assessment checking criminal history, immigration status, and ties to organizations that pose a national security risk. Certain felony convictions permanently bar an applicant with no time limit: espionage, treason, sedition, federal terrorism offenses, murder, crimes involving a transportation security incident, improper transportation of hazardous materials, explosives offenses, and false threats about explosive devices. Conspiracy or attempt to commit any of these also results in permanent disqualification.11eCFR. 49 CFR 1572.103 – Disqualifying Criminal Offenses
A second category of offenses disqualifies applicants for seven years from the date of conviction, or five years from release from incarceration, whichever is later. It covers robbery, arson, kidnapping, voluntary manslaughter, assault with intent to kill, smuggling, bribery, extortion, immigration violations, firearms offenses, drug distribution, racketeering, and fraudulent entry into a seaport under 18 U.S.C. § 1036.12Transportation Security Administration. Disqualifying Offenses and Other Factors An applicant with a preliminary determination of ineligibility can request an appeal, a waiver, or both, and has 60 days from receipt of the denial letter to respond.13Transportation Security Administration. What If I Receive a Preliminary Determination of Ineligibility Letter
How Inbound Cargo Is Screened
Screening starts before cargo reaches U.S. waters. Under the Importer Security Filing rule (known as “10+2”), importers or their agents submit eight data elements to Customs and Border Protection no later than 24 hours before cargo is loaded onto a U.S.-bound vessel; carriers provide two more.14U.S. Customs and Border Protection. Import Security Filing (ISF) – When to Submit to CBP CBP uses that advance data to flag high-risk shipments for examination before arrival.
At the port, non-intrusive inspection technology lets officers see inside sealed containers without opening them. Large-scale X-ray and gamma-ray imaging systems reveal hidden compartments and prohibited items. Roughly 1,300 Radiation Portal Monitors are deployed at ports of entry, screening containers for radioactive materials as vehicles pass terminal gates at normal speed.
Late, inaccurate, or incomplete security filings carry liquidated damages of $5,000 per violation. For a first offense, CBP may cancel the claim on payment of $1,000 to $2,000 if law enforcement goals were not compromised. Subsequent violations can be mitigated to no less than $2,500.
The Customs-Trade Partnership Against Terrorism, or C-TPAT, is a voluntary program in which CBP partners with importers, carriers, brokers, and manufacturers to strengthen supply chain security. Members commit to specific security measures across their supply chains and submit security profiles to CBP. In return they are classified as low-risk, with fewer physical examinations and front-of-line processing.15U.S. Customs and Border Protection. Customs Trade Partnership Against Terrorism
Cybersecurity Rules Effective July 2025
Port facilities depend on networked systems for container tracking, crane operations, access control, and surveillance. A final rule effective July 16, 2025, added mandatory cybersecurity protections at 33 CFR Part 101 Subpart F, structured to mirror the physical security framework.16eCFR. 33 CFR Part 101 Subpart F – Cybersecurity
Each owner or operator must develop and obtain approval for a Cybersecurity Plan and designate a Cybersecurity Officer, or CySO, accessible to the Coast Guard 24 hours a day, 7 days a week. The CySO conducts assessments, ensures the plan is implemented and exercised, arranges inspections, performs annual audits, and corrects problems identified along the way.
Every regulated entity must also develop a Cyber Incident Response Plan. Reportable cyber incidents must be reported to the National Response Center without delay. For entities already reporting under 33 CFR 6.16-1, which was amended by Executive Order 14116 to require reporting to the FBI, CISA, and the local Captain of the Port, that existing report satisfies the obligation.17United States Coast Guard. Coast Guard Maritime Industry Cybersecurity Resource Website The Coast Guard strongly encourages facilities to isolate operational and industrial control systems from business networks; a cyberattack that reaches crane or physical security controls can be dangerous, not merely disruptive.
Penalties and Enforcement
Under 46 U.S.C. § 70119, a person who violates Chapter 701 or its regulations faces a civil penalty of up to $25,000 per day, with a statutory cap of $50,000 for continuing violations.18Office of the Law Revision Counsel. 46 USC 70119 – Civil Penalty After inflation adjustments the current maximum is $43,527 per day and $78,210 for continuing violations.1eCFR. 33 CFR 27.3 – Penalty Adjustment Table
Beyond fines, the Coast Guard can restrict vessel movements, deny entry to a port, or shut down a facility that fails to meet its obligations. The Captain of the Port for each zone has authority to take immediate enforcement action when a threat or violation warrants it. For an operator, the revenue lost from a terminal shutdown will usually exceed the fine itself, which is the point of the design.