Ports must purge foreign tech—but rules stay secret from public
S. 4564 — Maritime Cybersecurity Act · Filed by Rick Scott (R-FL) · 1 cosponsor · Introduced May 19, 2026 · Referred to committee
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill requires U.S. maritime facilities (ports, terminals, etc.) to identify and assess all software and hardware they use—especially equipment made by or controlled by foreign entities deemed a security concern—and certify that it meets cybersecurity standards set by the National Institute of Standards and Technology. Facility operators must report annually to the Department of Homeland Security on what foreign-origin equipment they use and any cybersecurity incidents; they cannot use non-compliant equipment unless the Secretary grants a waiver. The bill benefits port security and national defense by reducing exposure to compromised foreign technology; it imposes compliance costs on maritime operators.
Why we flagged it
The bill's core function is to mandate cybersecurity assessments and compliance standards for software and hardware at U.S. maritime facilities, with a focus on identifying and restricting foreign-origin equipment deemed a national security risk.
What the text implies
- The bill grants the Secretary broad authority to conduct assessments 'notwithstanding any provision of an end user licensing agreement or other contract'—effectively overriding vendor licensing terms and potentially creating legal friction with software vendors.
- The definition of 'covered software or hardware' is expansive ('any software or hardware that connects to the internet or otherwise poses a cybersecurity risk') and includes systems 'determined by Sec. to be a high cybersecurity risk'—giving the Secretary discretionary power to expand scope without further legislation.
The full analysis lists 5 implications of this text.
Who stands to gain
U.S. cybersecurity software and hardware vendors (especially those competing with foreign manufactur; Domestic IT consulting and compliance firms (assessment and remediation services); U.S. industrial equipment manufacturers (cranes, port machinery) competing with foreign suppliers