1. Learn
  2. Align
  3. Perform
  4. Review

Learn12 min read

CFATS After the Sunset: Why Chemical Security Still Matters

By J Damien Scott, Trusted Advisor

The Chemical Facility Anti-Terrorism Standards program has legally lapsed after Congress allowed its statutory authority to expire. This article examines why CFATS-style security remains essential for antiterrorism, what organizations should do during the regulatory gap, and how to maintain chemical security discipline without enforceable federal mandates.

What CFATS was designed to do

CFATS was the first comprehensive federal security regulation specifically focused on high-risk chemical facilities. It required facilities possessing chemicals of interest above screening threshold quantities to submit information through the Chemical Security Assessment Tool. If determined to be high risk, facilities developed Site Security Plans satisfying 18 Risk-Based Performance Standards covering prevention, protection, response, and management.

Several CFATS concepts remain especially important: Chemicals of Interest defined which facilities needed screening. The Top-Screen was the initial facility submission helping CISA determine risk level. The Security Vulnerability Assessment examined how a facility could be attacked or exploited. The Site Security Plan documented how the facility would meet required security outcomes. These concepts translate directly into sound security practice regardless of regulatory status.

These are not abstract compliance questions. They are antiterrorism questions.

Why CFATS still applies to antiterrorism

Chemical security is antiterrorism work because chemicals can become attack enablers. A terrorist or violent extremist does not always need sophisticated weapons if they can exploit industrial materials, access control weaknesses, insider knowledge, poor inventory practices, cyber-connected process systems, or gaps in emergency coordination. CFATS approached this problem through layers of prevention and resilience.

A facility should be able to answer several hard questions before an incident occurs. Can we detect suspicious activity early? Can we delay an adversary long enough for an effective response? Do we know who has access to sensitive chemicals, control rooms, loading areas, and cyber systems? Are our inventory records accurate enough to detect diversion? Are contractors, vendors, and temporary personnel managed with the same seriousness as employees? Can our site respond differently when threat conditions rise?

What to do during the regulatory gap

The practical conclusion is simple: CFATS is not enforceable today, but CFATS-style security remains a sound benchmark for prudent risk management. For senior leaders, that distinction matters. Compliance is about meeting a legal requirement. Security is about reducing the chance and consequence of a foreseeable attack. An elevated threat time frame is not the moment to discover that badge access is poorly administered, a camera system has blind spots, or a response plan has not been exercised in years.

Organizations should maintain their security posture using CFATS performance standards as voluntary benchmarks, continue personnel surety programs, sustain relationships with local law enforcement and emergency management, exercise response plans regularly, and document security decisions with the same rigor as when the regulation was enforceable. The threat did not expire when the statute did.

GRCCFATSChemical securityAntiterrorismRegulatory gap

Originally published on LinkedIn. Read it there

Field Notes · by email

One email when a new article publishes. Nothing else.

Field notes on converged security from J Damien Scott, Trusted Advisor: the article, its summary, and the phase it belongs to. No digests, no offers, no third party reading over your shoulder.

Email delivery is being set up. The feed carries every article the day it publishes. About Field Notes

Related reading

All articles