Reference Guide

TSA Pipeline Cybersecurity Requirements

Two Security Directives govern cybersecurity for TSA-designated pipeline, hazardous liquid, and LNG operators: one covering coordination and incident reporting, the other covering implementation, incident response, and ongoing assessment. This guide explains what each requires, how they fit together, and what TSA has proposed to change.

Who this applies to

TSA designates a pipeline system or facility as critical based on factors like whether it serves national-defense installations, key infrastructure such as power plants or major airports, or similar impact criteria in the Pipeline Security Guidelines ยง5. Typical critical facilities include compressor stations, pump stations, metering or regulating stations, operational control facilities, main line valves, and tank farms or terminals. TSA notifies operators directly when a system or facility is designated critical. If you haven't received that notification, you're most likely not currently designated, though TSA can designate a facility at any time as circumstances change.

Not sure where you stand? The OT Security Readiness Check sorts this out in the first question.

SD Pipeline-2021-01G: coordination and incident reporting

SD Pipeline-2021-01G (Enhancing Pipeline Cybersecurity) is the shorter of the two directives, and the one most operators satisfy first. It requires three things: a named Cybersecurity Coordinator and an alternate, with current contact details on file with TSA; a documented process for reporting cybersecurity incidents to CISA; and a completed Cybersecurity Vulnerability Assessment, on TSA's form, covering both IT and OT.

The Vulnerability Assessment is the piece most often underestimated. It has to cover the operational environment as well as the corporate network, and TSA's form asks for specifics: what was assessed, what gaps were found, and what the remediation plan is. A vulnerability assessment scoped to IT alone doesn't satisfy this requirement.

SD Pipeline-2021-02G: implementation, response, and assessment

SD Pipeline-2021-02G (Pipeline Cybersecurity Mitigation Actions, Contingency Planning, and Testing) is the larger and more durable of the two. It requires a TSA-approved Cybersecurity Implementation Plan, a documented Incident Response Plan exercised at least annually, and a Cybersecurity Assessment Plan that validates the Implementation Plan is actually working. Three separate documents, each with its own maintenance obligation:

The three-year assessment rotation

SD Pipeline-2021-02G requires a documented schedule showing at least one-third of the Implementation Plan assessed every year, reaching 100 percent over any three-year period, plus a cybersecurity architecture design review, including verification of network traffic and system log review, at least once every two years.

The schedule matters as much as the assessment itself. TSA wants to see which third of the environment was assessed in which year, tracked in advance, not reconstructed after the fact. An operator that can't answer "which third was assessed this year" doesn't have a defensible schedule, even if the underlying assessment work was done.

What's changing: the pending TSA cyber risk management rule

TSA has proposed a rulemaking, Enhancing Surface Cyber Risk Management, that would eventually replace the current directive-based regime with a formal federal regulation covering pipeline and rail cybersecurity. The proposed rule, published in the Federal Register on November 7, 2024, would require covered operators to maintain a Cybersecurity Operational Implementation Plan identifying who governs the program, apply specific measures to protect and monitor critical cyber systems, maintain continuity plans for those systems, and run a Cybersecurity Assessment Plan that identifies unaddressed vulnerabilities and reports annual assessment results. The shape of that structure will be familiar to anyone already working under SD Pipeline-2021-01G and SD Pipeline-2021-02G: this is a codification of the existing directive approach into a rule, not a replacement with something unrelated.

The public comment period closed February 5, 2025. As of the most recent confirmation available (a Congressional Research Service update dated June 2026), TSA had not yet issued a final rule. Until one is issued, the current Security Directives remain the binding requirement, and nothing here changes what's owed today. Operators building a program now have a real advantage in not designing purely to the letter of the current directives: a program built around the underlying obligations, documented coordination, a living implementation plan, an exercised response plan, a tracked assessment schedule, holds up whether the final form is a directive renewal or a codified rule.

Evidence to have ready

Across both directives, the pattern is consistent: TSA wants evidence a plan reflects reality, not only the plan itself. That means dated documentation for the Coordinator designation, a written incident-reporting procedure with names attached to each step, the Vulnerability Assessment report itself (not a summary of it), change logs showing the Implementation Plan was updated after network changes, an exercise report for the Incident Response Plan, and the assessment schedule showing which third was covered in which year. An assessment or audit meeting goes faster when this evidence already exists in one place rather than being assembled under deadline. The full evidence checklist lists exactly what to have on file for each obligation.

Frequently asked questions

Do both directives apply to natural gas pipelines, hazardous liquid pipelines, and LNG facilities?

Yes. Both series cover the same population, an owner/operator TSA has notified that their pipeline system or facility is critical, regardless of commodity. They split by subject matter (coordination and incident reporting versus implementation and assessment), not by what the pipeline carries.

What happens if TSA's proposed rule is finalized?

Until a final rule is issued, the current Security Directives remain in effect. A final rule would likely include a compliance transition period, as federal rulemakings generally do, rather than an immediate cutover. The proposed structure closely mirrors the existing directives, so a program built to the substance of SD Pipeline-2021-01G and SD Pipeline-2021-02G today is well positioned for that transition rather than starting over.

Is a self-assessment against this guide the same as a TSA-required assessment?

No. This guide and the OT Security Readiness Check are independent, informational resources. They're not a substitute for the Cybersecurity Vulnerability Assessment or Cybersecurity Assessment Plan the directives require, and they carry no official TSA standing.

What if my facility isn't TSA-designated?

See the OT/ICS Security Assessment page instead: the same underlying methodology, structured against NIST CSF and IEC 62443 rather than the TSA directives specifically.

Regulatory content on this page reflects the signed SD Pipeline-2021-01G and SD Pipeline-2021-02G directives, TSA's Pipeline Security Guidelines, and the Enhancing Surface Cyber Risk Management proposed rule (Federal Register, November 7, 2024). Last verified 2026-09-23.

Need help building or running this program?