Checklist

TSA Pipeline Cybersecurity Evidence Checklist

TSA wants evidence that each obligation is actually being met, not only a Cybersecurity Coordinator designated or a plan written: dated documents, exercise records, and a tracked schedule. This checklist lists what to have on file for every obligation across both directive series.

For the full explanation of what each obligation requires and why, see the TSA Pipeline Cybersecurity Requirements guide. This page is the shorter, working reference: what to pull together and keep current, organized the same way the directives are.

SD Pipeline-2021-01G: Enhancing Pipeline Cybersecurity

SD Pipeline-2021-02G: Pipeline Cybersecurity Mitigation Actions, Contingency Planning, and Testing

Why the evidence matters more than the plan

A plan that hasn't been exercised, updated, or scheduled doesn't hold up under review, even though the document itself is on file. The pattern across both directives is the same: TSA's own language asks for completed, dated, current artifacts, not a description of what the program intends to do. Assembling this evidence once, and keeping it current as part of routine operations, is faster and more defensible than reconstructing it under deadline before an audit meeting.

Frequently asked questions

Is this checklist itself something TSA reviews?

No. This is an independent reference, not a TSA form or an official compliance checklist. It's organized to match the underlying directive obligations so nothing gets missed, not to replace the Cybersecurity Assessment Plan or Vulnerability Assessment TSA actually requires.

Does having all this evidence mean a program is compliant?

Having the evidence on file is necessary but not sufficient. The evidence has to reflect an accurate, current state, not just exist. TSA is the only party that can determine compliance.

Where do I start if I'm missing most of this?

The OT Security Readiness Check scores which obligations are open in about five minutes and orders the gaps by priority, which is usually a faster starting point than working through this list top to bottom.

Regulatory content on this page reflects the signed SD Pipeline-2021-01G and SD Pipeline-2021-02G directives. Last verified 2026-09-23.

Need help building or running this program?