LAUNCHING JULY 6, 2026

Compliance.
Automated.

The purpose-built platform for 33 CFR Part 101 Subpart F maritime cybersecurity assessments. From SIW upload to submission-ready report in minutes.

Early access for maritime operators & facilities
ccSentinel compliance dashboard showing 94% Subpart F compliance score, network topology, and control status
94% Compliant • 12 systems • 3 facilities

LIVE DASHBOARD PREVIEW — ILLUSTRATIVE

USCG MTSA / 33 CFR 101 Subpart F
CISA KEV Catalog Integration
MITRE ATT&CK for ICS
OT/ICS Vendor Detection (35+)
THE MARITIME COMPLIANCE BURDEN

Manual assessments are slow, risky, and hard to defend.

USCG audits, MTSA requirements, and Subpart F demand rigorous documentation. Most teams spend weeks compiling evidence across spreadsheets, emails, and disparate tools — only to face gaps during inspection.

Weeks of manual effort

Per facility or vessel assessment. Repeating the same analysis across dozens of systems.

High audit risk

Missed KEV matches, inconsistent control mapping, and incomplete drill/exercise records lead to findings.

Defensibility gaps

Hard to prove compensating controls or show continuous monitoring when regulators ask for evidence.

THE ccSENTINEL PLATFORM

Purpose-built for maritime cybersecurity compliance.

Server-based, multi-user SaaS. No client software required. Accessible from any browser. Designed by maritime cyber practitioners.

15
Subpart F control areas fully mapped
30+
SIW-based detection rules
25+
Companion script rules
35
OT/ICS vendors recognized

Intelligent Data Ingestion

Drag-and-drop SIW XML exports, ccSentinel Companion JSON, Yokogawa CENTUM VP RevInf CSVs, and Phosphorus OT/IoT scans. Systems auto-assigned to Facility or Vessel.

Instant analysis triggered

Multi-Layer Vulnerability Detection

CISA KEV catalog matching (refreshed every 6 hrs) + 30+ SIW rules + 25+ Companion rules + 10 MITRE ATT&CK for ICS techniques. OT systems get stricter thresholds.

Automated Subpart F Mapping

Every finding is automatically mapped to the relevant control areas. AI chat provides context-aware guidance per control. Assessor questions auto-suggested from drill & training records.

Live Scanner & Training Integrations

Action1, Nessus, Rapid7 for continuous asset/vuln sync. KnowBe4, Proofpoint, ESET for training completion. Overdue drills trigger alerts and email notifications.

Defensible Regulatory Reports

Print-optimized PDF reports with executive summary, KEV matches, rule findings, per-system detail, and full 15-area Subpart F compliance assessment. Ready for USCG submission.

Network Topology Visualization

Auto-generated interactive SVG maps showing all scanned systems grouped by subnet. Circular and hierarchical layouts. Embedded directly in reports and Security Binder.

5-STEP WORKFLOW

From scan to compliant in record time.

1
Upload or Sync

Drag SIW + Companion files or pull live data from Action1/Nessus. Assign to Facility/Vessel at upload.

2
Review Findings

Filter by severity, source (KEV/Rule/Scanner), OT flag. Accept risk, override, or document mitigation with notes.

3
Complete Controls

Review auto-mapped findings per control area. Answer assessor questions (AI-suggested from drills/training). Use built-in AI chat for guidance.

4
Log Drills & Training

Record §101.535 drills/exercises. Pull training records from integrated LMS. Overdue items flagged automatically.

5
Generate Report

One-click PDF with executive summary, detailed findings, control status, and full compliance narrative. Submission-ready.

FULL SUBPART F COVERAGE

Every finding mapped.
Every control scored.

The compliance engine evaluates automated findings, your answers to assessor questions, and uploaded policy documents against all 15 areas of 33 CFR § 101.650. Status is calculated automatically: Compliant, Needs Review, or Non-Compliant.

Compliant
Needs Review
Non-Compliant
§ 101.650(a) — Cybersecurity Plan COMPLIANT
§ 101.650(b) — Risk Assessment COMPLIANT
§ 101.650(c) — Personnel Training NEEDS REVIEW
§ 101.650(d) — Drills & Exercises COMPLIANT
§ 101.650(e) — Incident Response COMPLIANT
§ 101.650(f) — Access Control COMPLIANT
§ 101.650(g) — Physical Security COMPLIANT
§ 101.650(h) — Network Segmentation COMPLIANT
+ 7 additional control areas fully supported (Audit, Maintenance, Supply Chain, etc.)
OT / ICS AWARE

Built for the realities of maritime operational technology.

Systems running Yokogawa, Siemens, Rockwell, Honeywell, Kongsberg, Wärtsilä, and 29 other OT/ICS platforms are automatically flagged. Wireless adapters, remote access tools, and cloud sync become Critical findings on OT systems — not just High.

Yokogawa CENTUM
Siemens
Rockwell Automation
Honeywell
Kongsberg
+ 30 more
STRICTER OT THRESHOLDS
  • Wireless on OT = Critical
  • Remote access tools = Supply chain risk
  • Legacy protocols flagged automatically
  • Companion script detects open ICS ports
SEAMLESS CONNECTIONS

Works with the tools you already use.

Action1
Live asset & vuln sync
Nessus / Rapid7
Scanner integrations
KnowBe4 & Proofpoint
Training record sync
ESET Protect
Security awareness
Yokogawa & Phosphorus
OT/IoT scan support
SAML SSO Ready
Entra ID, Okta & more

Built for every role on your team.

Administrators
  • • Manage users, SSO, scanner integrations
  • • Configure facilities/vessels & scan schedules
  • • Oversee alerts, training compliance, drill status
  • • No access to raw assessment data (separation of duties)
Analysts
  • • Upload scans & review findings
  • • Complete compliance assessments with AI assistance
  • • Document mitigations and accepted risks
  • • Generate regulatory submission reports
Read-Only Viewers
  • • Dashboard, inventory, findings & compliance views
  • • Access to PDF reports and network maps
  • • Perfect for executives, auditors, or third parties
  • • Zero ability to modify data
EARLY ACCESS OPEN

Be among the first to experience automated Subpart F compliance.

Limited pilot spots available before the July 6 public launch. Join the waitlist for priority access, onboarding support, and special founding pricing.

We respect your inbox. Unsubscribe anytime. No spam.

Or email info@cc-sentinel.com for enterprise pilots

See ccSentinel in action.

Schedule a personalized 30-minute walkthrough with our maritime cybersecurity team. We'll show you how the platform maps directly to your specific facilities or fleet.

Available for qualified maritime operators and compliance teams.