Two recent rule changes are worth tracking even where they do not apply directly to every private yacht. The first is the US Coast Guard's 2025 cybersecurity final rule for the Marine Transportation System. The second is the IMO's 2026 STCW update on preventing and responding to violence, harassment, bullying, sexual harassment, and sexual assault at sea.
The USCG rule became effective on July 16, 2025 and introduces minimum cybersecurity requirements, including a cybersecurity plan and a designated cybersecurity officer for covered entities. The IMO STCW changes entered into force on January 1, 2026 and add new competence requirements to the Personal Safety and Social Responsibilities part of basic training.
The pattern matters. Regulators are paying attention to digital risk and crew culture, not only traditional navigation and machinery safety. Yacht managers should expect flag, insurance, charter, marina, and family-office questions to move in the same direction over time.
A pragmatic response is to keep a live compliance tracker: cyber plan status, incident contacts, crew training matrix, harassment reporting procedure, flag-state interpretation, and evidence location. That makes future inspections, insurance renewals, and management reviews much easier.