Cybersecurity Assessment Plan: preparing for the annual cycle
The Cybersecurity Implementation Plan describes what a program is supposed to do. The Cybersecurity Assessment Plan is how TSA finds out whether it’s actually doing it. SD Pipeline-2021-02G §III.G requires both a plan for how that verification happens and, every year, a report on what it found.
What the Assessment Plan has to cover
Four things, per §III.G.2:
- Assess the effectiveness of the TSA-approved Implementation Plan itself, not a generic security checklist. The assessment has to map back to what the Implementation Plan actually committed to.
- A cybersecurity architecture design review at least once every two years, including verification and validation of network traffic and system log review, aimed at surfacing vulnerabilities in network design, configuration, and interconnectivity to internal and external systems.
- Other assessment capabilities, which the directive names specifically: penetration testing of IT systems, and “red” or “purple” team adversarial-perspective testing.
- A schedule that assesses at least one-third of the Implementation Plan’s policies, procedures, measures, and capabilities every year, reaching 100 percent over any three-year period.
That schedule requirement is the one that turns into a year-end scramble if it isn’t tracked from the start. TSA isn’t asking whether the assessment work eventually got done. It’s asking which third was assessed in which year, on a schedule set in advance.
What the annual report has to say
Separately from the Plan itself, §III.G.2.e requires an annual report submitted to TSA covering the previous 12 months: which assessment method or methods were used to determine whether the Implementation Plan’s policies, procedures, and capabilities are actually effective, and the results of the individual assessments conducted in that period. A report that says work happened without saying what method was used or what it found doesn’t meet the requirement.
The Plan and the report run on related but distinct clocks. The Assessment Plan itself has to be resubmitted to TSA no later than 12 months from the date TSA approved the previous one. The annual report has to be submitted no later than 12 months from the date TSA approved the most recent Assessment Plan. Missing either date means missing the cycle, not just the paperwork around it.
Why passive methodology matters here specifically
Nothing in §III.G restricts how the architecture review or the one-third rotation gets executed, which means the choice of assessment method is the operator’s to make, and it’s worth making deliberately. A vulnerability scan that trips an RTU or a fuel controller mid-cycle risks turning the assessment meant to prove the program works into the incident that proves it doesn’t. Architecture review, configuration audit, and passive protocol capture can satisfy the same requirement without sending traffic to a device that was never built to receive it.
For the full breakdown of both directive series, see the TSA Pipeline Cybersecurity Requirements guide. For what to have on file to prove the schedule is real, see the evidence checklist.
Regulatory content in this post reflects the signed SD Pipeline-2021-02G directive. Last verified 2026-09-23.