TSA Compliance
TSA Pipeline Cybersecurity Consulting
Independent, vendor-neutral support for pipeline and LNG operators subject to the TSA Pipeline Security Directives: assessment planning, annual reporting, and readiness.
SD Pipeline-2021-01G and SD Pipeline-2021-02G apply to any hazardous liquid pipeline, natural gas pipeline, or LNG facility TSA has notified as critical. Together they require a named Cybersecurity Coordinator, incident reporting to CISA, a completed Cybersecurity Vulnerability Assessment, an approved Cybersecurity Implementation Plan, and a Cybersecurity Assessment Plan covering one-third of the program every year and 100 percent over any three-year period. Windlass Consulting builds and runs that assessment program for operators who need it done right the first time, from an executive who ran one inside a regulated pipeline operator before advising on them.
What the directives require
SD Pipeline-2021-01G (Enhancing Pipeline Cybersecurity) requires a named Cybersecurity Coordinator and an alternate, a documented process for reporting cybersecurity incidents to CISA, and a completed Cybersecurity Vulnerability Assessment covering both IT and OT.
SD Pipeline-2021-02G (Pipeline Cybersecurity Mitigation Actions, Contingency Planning, and Testing) requires an approved Cybersecurity Implementation Plan, a documented Incident Response Plan exercised at least annually, and a Cybersecurity Assessment Plan that validates the Implementation Plan is actually working.
Both series cover the same population and split by subject matter, not commodity. There's no gas-only or liquid-only directive. For the full breakdown, including how the three-year assessment rotation works and what TSA's pending cyber risk management rule would change, see the TSA Pipeline Cybersecurity Requirements guide.
Who this applies to
TSA designates a pipeline system or facility as critical based on factors like whether it serves national-defense installations, key infrastructure such as power plants or major airports, or similar impact criteria in the Pipeline Security Guidelines ยง5. Typical critical facilities include compressor stations, pump stations, metering or regulating stations, operational control facilities, main line valves, and tank farms or terminals. TSA notifies operators directly when a system or facility is designated critical. If you haven't received that notification, you're most likely not currently designated, though TSA can designate a facility at any time as circumstances change.
Not sure where you stand? The OT Security Readiness Check sorts this out in the first question.
Where programs most often fall short
The directives are specific about deliverables and less specific about upkeep. In practice, the gap isn't usually the first Cybersecurity Coordinator designation or the initial Implementation Plan submission. Those get done because TSA asks for them directly. The gap shows up afterward: a plan that hasn't been updated since the network changes it was written to describe, an Incident Response Plan that exists on paper but hasn't been exercised in the last 12 months, and an assessment schedule that isn't tracked against the one-third-per-year requirement until the year is almost over.
How Windlass approaches it
An engagement is built around the same deliverables TSA is going to ask for: the Cybersecurity Assessment Plan and the annual report that backs it up. Architecture review, configuration audit, and protocol capture build the underlying picture, kept passive by design so the work never sends OT traffic it wasn't built to handle. Findings map against the Implementation Plan's own controls instead of a generic checklist, so the output is the document TSA reads, not a translation layer between the two.
The three-year rotation in practice
SD Pipeline-2021-02G requires one-third of the Implementation Plan assessed every year, with 100 percent covered over any three-year period, plus a cybersecurity architecture design review every two years. Run as a standing program instead of an annual scramble, that schedule sets which third of the environment gets assessed each year well in advance, so the review date never forces a rushed scope.
Why an independent assessor
Assessments are vendor-neutral: no reseller arrangement or product line decides what gets recommended, and there's nothing else being sold alongside the finding.
What an engagement looks like
Engagements start with a scoping call to confirm what's already in place, an existing Implementation Plan, a prior assessment, an internal review, and where you sit in the three-year cycle. From there, the assessment runs against your actual environment. The output is the Cybersecurity Assessment Plan and annual report TSA expects to see, plus a prioritized list of what to fix before the next cycle starts. Windlass is based in Houston, on-site for Gulf Coast operators and remote-capable everywhere else.
Frequently asked questions
Does Windlass file anything with TSA directly?
No. The Cybersecurity Assessment Plan and annual report are prepared for your team to submit under your own name, and the filing relationship stays between your organization and TSA. Engagement support can include direct involvement in the audit meetings themselves.
Is this an official TSA determination?
No. This is independent advisory work, not a TSA determination or certification of compliance. TSA is the only party that can approve a Cybersecurity Implementation Plan or determine compliance.
What if I'm not sure whether I'm TSA-designated?
Start with the OT Security Readiness Check. The first question sorts that out, and TSA notifies operators directly when a facility is designated critical.
Do you work with natural gas pipelines, hazardous liquid pipelines, and LNG facilities?
Yes. Both directive series cover all three. They split by subject matter (coordinator and incident reporting versus implementation and assessment), not by commodity.
What if my facility isn't TSA-designated?
See the OT/ICS Security Assessment page instead: the same passive-by-design methodology, structured against NIST CSF and IEC 62443 rather than the TSA directives specifically.
Regulatory content on this page reflects the signed SD Pipeline-2021-01G and SD Pipeline-2021-02G directives and TSA's Pipeline Security Guidelines. Last verified 2026-09-23.
Discuss your program