- Learn
- Align
- Perform
- Review
Learn12 min read
CFATS After the Sunset: Why Chemical Security Still Matters
By J Damien Scott, Trusted Advisor
The Chemical Facility Anti-Terrorism Standards program has legally lapsed after Congress allowed its statutory authority to expire. This article examines why CFATS-style security remains essential for antiterrorism, what organizations should do during the regulatory gap, and how to maintain chemical security discipline without enforceable federal mandates.
What CFATS was designed to do
CFATS was the first comprehensive federal security regulation specifically focused on high-risk chemical facilities. It required facilities possessing chemicals of interest above screening threshold quantities to submit information through the Chemical Security Assessment Tool. If determined to be high risk, facilities developed Site Security Plans satisfying 18 Risk-Based Performance Standards covering prevention, protection, response, and management.
Several CFATS concepts remain especially important: Chemicals of Interest defined which facilities needed screening. The Top-Screen was the initial facility submission helping CISA determine risk level. The Security Vulnerability Assessment examined how a facility could be attacked or exploited. The Site Security Plan documented how the facility would meet required security outcomes. These concepts translate directly into sound security practice regardless of regulatory status.
“These are not abstract compliance questions. They are antiterrorism questions.”
Why CFATS still applies to antiterrorism
Chemical security is antiterrorism work because chemicals can become attack enablers. A terrorist or violent extremist does not always need sophisticated weapons if they can exploit industrial materials, access control weaknesses, insider knowledge, poor inventory practices, cyber-connected process systems, or gaps in emergency coordination. CFATS approached this problem through layers of prevention and resilience.
A facility should be able to answer several hard questions before an incident occurs. Can we detect suspicious activity early? Can we delay an adversary long enough for an effective response? Do we know who has access to sensitive chemicals, control rooms, loading areas, and cyber systems? Are our inventory records accurate enough to detect diversion? Are contractors, vendors, and temporary personnel managed with the same seriousness as employees? Can our site respond differently when threat conditions rise?
What to do during the regulatory gap
The practical conclusion is simple: CFATS is not enforceable today, but CFATS-style security remains a sound benchmark for prudent risk management. For senior leaders, that distinction matters. Compliance is about meeting a legal requirement. Security is about reducing the chance and consequence of a foreseeable attack. An elevated threat time frame is not the moment to discover that badge access is poorly administered, a camera system has blind spots, or a response plan has not been exercised in years.
Organizations should maintain their security posture using CFATS performance standards as voluntary benchmarks, continue personnel surety programs, sustain relationships with local law enforcement and emergency management, exercise response plans regularly, and document security decisions with the same rigor as when the regulation was enforceable. The threat did not expire when the statute did.
Originally published on LinkedIn. Read it there
Field Notes · by email
One email when a new article publishes. Nothing else.
Field notes on converged security from J Damien Scott, Trusted Advisor: the article, its summary, and the phase it belongs to. No digests, no offers, no third party reading over your shoulder.
Email delivery is being set up. The feed carries every article the day it publishes. About Field Notes
Related reading
More from Learn
Learn · 31 July 2026
The Books Being Destroyed Are Not Rare. They Are Out of Print.
A viral story claimed AI companies are destroying rare books to train their models. Most of that story is true. One word in it is not, and it happens to be the word carrying the emotional weight. The books are not rare. They are out of print. That distinction decides almost everything: what was actually destroyed, whether anything irreplaceable was lost, and whether the governance concern survives scrutiny.
8 min readLearn · 22 July 2026
TSI/EN 50600: The European Standard Quietly Reshaping How Data Centres Are Built, Secured, and Judged
EN 50600 and TÜViT's Trusted Site Infrastructure (TSI) have become the de facto benchmark for data centre quality in Europe. This article explains what they actually require, how the classification system works, and why the standard now sits at the intersection of physical security, NIS2, and the CER Directive.
14 min readLearn · 14 July 2026
AI Just Took the Front Desk: What the Tier-1 Support Takeover Actually Means
Tier-1 customer support — password resets, order status, refunds — is being absorbed by AI agents at scale. Gartner predicts 80% autonomous resolution of common service issues by 2029. But the Klarna reversal and the Air Canada chatbot liability ruling show that speed without accuracy just moves the failure point. This article examines the evidence, its limits, and what the shift means for organizations of every size.
7 min read