Checklist
TSA Pipeline Cybersecurity Evidence Checklist
TSA wants evidence that each obligation is actually being met, not only a Cybersecurity Coordinator designated or a plan written: dated documents, exercise records, and a tracked schedule. This checklist lists what to have on file for every obligation across both directive series.
For the full explanation of what each obligation requires and why, see the TSA Pipeline Cybersecurity Requirements guide. This page is the shorter, working reference: what to pull together and keep current, organized the same way the directives are.
SD Pipeline-2021-01G: Enhancing Pipeline Cybersecurity
- Coordinator designation — a written designation naming a primary and alternate Cybersecurity Coordinator, with current contact details matching what's on file with TSA.
- Incident-reporting procedure — a documented process for reporting cybersecurity incidents to CISA, naming who decides an incident is reportable, who files the report, and the timeframe for doing so.
- Cybersecurity Vulnerability Assessment — the completed assessment itself, on TSA's form, covering both IT and OT, with identified gaps and a remediation plan. A summary of the assessment isn't the same as the assessment.
SD Pipeline-2021-02G: Pipeline Cybersecurity Mitigation Actions, Contingency Planning, and Testing
- Cybersecurity Implementation Plan — the TSA-approved plan, plus a change log showing it's been updated after network or system changes rather than left as it was at approval.
- Incident Response Plan — the documented plan itself, naming roles, escalation, containment, and recovery steps.
- Incident Response Plan exercise record — a report from a tabletop or live exercise run within the last 12 months, including what the exercise found.
- Cybersecurity Assessment Plan — the plan TSA has approved within the last 12 months, describing how the Implementation Plan itself gets validated.
- Assessment rotation schedule — a documented schedule showing at least one-third of the Implementation Plan assessed every year, reaching 100 percent over any three-year period, with which third was covered in which year tracked in advance.
- Architecture design review — a completed cybersecurity architecture design review, including verification of network traffic and system log review, dated within the last two years.
Why the evidence matters more than the plan
A plan that hasn't been exercised, updated, or scheduled doesn't hold up under review, even though the document itself is on file. The pattern across both directives is the same: TSA's own language asks for completed, dated, current artifacts, not a description of what the program intends to do. Assembling this evidence once, and keeping it current as part of routine operations, is faster and more defensible than reconstructing it under deadline before an audit meeting.
Frequently asked questions
Is this checklist itself something TSA reviews?
No. This is an independent reference, not a TSA form or an official compliance checklist. It's organized to match the underlying directive obligations so nothing gets missed, not to replace the Cybersecurity Assessment Plan or Vulnerability Assessment TSA actually requires.
Does having all this evidence mean a program is compliant?
Having the evidence on file is necessary but not sufficient. The evidence has to reflect an accurate, current state, not just exist. TSA is the only party that can determine compliance.
Where do I start if I'm missing most of this?
The OT Security Readiness Check scores which obligations are open in about five minutes and orders the gaps by priority, which is usually a faster starting point than working through this list top to bottom.
Regulatory content on this page reflects the signed SD Pipeline-2021-01G and SD Pipeline-2021-02G directives. Last verified 2026-09-23.
Need help building or running this program?