Cybersecurity Implementation Plan: what operators must maintain

  • TSA Pipeline Security Directives
  • Cybersecurity Implementation Plan

A TSA-approved Cybersecurity Implementation Plan is often treated as a milestone: submit it, get it approved, move on. SD Pipeline-2021-02G §III.B.2 says otherwise. Once approved, the Owner/Operator must implement and maintain every measure in the plan and meet any schedule it stipulates. Approval is the starting point of an ongoing obligation, not the end of one.

What “maintain” means in practice

The Implementation Plan documents the specific cybersecurity measures a program has in place, network segmentation, access control, continuous monitoring, patch management, and how it meets each requirement in §III.A through §III.E. An environment that changes without the plan changing with it stops describing reality. That gap is exactly what shows up as a finding during a Cybersecurity Assessment Plan review, and exactly what an auditor asks about first: does this document still describe what’s actually running.

The amendment process most programs don’t know exists

SD Pipeline-2021-02G §VI sets out a formal amendment process, and it’s more specific than most operators expect. A request to amend the Implementation Plan is required whenever there’s a change to ownership or control of operations, or a permanent change, defined as one intended to stay in effect for 45 or more calendar days, to the policies, procedures, or measures TSA already approved. That covers two situations by name: a specific policy or measure turning out to be ineffective based on Cybersecurity Assessment Plan results, and the operator identifying or obtaining new capabilities that haven’t been approved yet.

The deadline is concrete: the amendment request has to be filed with TSA no later than 50 calendar days after the permanent change takes effect, unless TSA allows more time. TSA can approve the amendment, ask for more information first, or deny it, and a denial can be petitioned for reconsideration within 30 days under 49 CFR 1570.119.

In practice, this means a change that looks purely operational, a new segmentation control, a revised patch management timeline, a capability added after an assessment found a gap, can carry a real regulatory clock most programs aren’t tracking. The trigger is the nature and duration of the change, not whether anyone thought to ask TSA about it.

Where this connects to the rest of the program

The Implementation Plan, the Incident Response Plan, and the Cybersecurity Assessment Plan aren’t three independent documents. Assessment results are one of the two named reasons an Implementation Plan amendment is required, which means the assessment schedule and the plan’s maintenance obligation run on the same clock, whether or not that connection is being tracked as one.

For the full breakdown of both directive series, see the TSA Pipeline Cybersecurity Requirements guide. For what to have on file to show the plan reflects the current environment, see the evidence checklist.

Regulatory content in this post reflects the signed SD Pipeline-2021-02G directive. Last verified 2026-09-23.

All posts