- Learn
- Align
- Perform
- Review
Learn14 min read
Comprehensive Regulatory Reference: CFATS, MTSA, and NERC-CIP Physical Security
By J Damien Scott, Trusted Advisor
A detailed, postgraduate-level analysis of three critical regulatory frameworks governing the physical security of U.S. critical infrastructure: the Chemical Facility Anti-Terrorism Standards, the Maritime Transportation Security Act, and the North American Electric Reliability Corporation Critical Infrastructure Protection standards.
Chemical Facility Anti-Terrorism Standards (CFATS)
CFATS was the first comprehensive federal security regulation specifically focused on high-risk chemical facilities. Administered by CISA within the Department of Homeland Security, CFATS required facilities possessing chemicals of interest above defined screening threshold quantities to submit information through the Chemical Security Assessment Tool. CISA then assessed whether the facility presented a high level of security risk and required development of Site Security Plans meeting 18 Risk-Based Performance Standards.
The most important legal point is that CFATS has lapsed. Because Congress allowed the statutory authority to expire, CISA cannot enforce compliance with CFATS regulations at this time. However, many facilities remain subject to other federal, state, local, industry, environmental, transportation, safety, insurance, contractual, or corporate governance requirements. CFATS-style security remains a sound benchmark for prudent risk management.
“This document provides a detailed, postgraduate-level analysis of three critical regulatory frameworks governing the physical security of U.S. critical infrastructure.”
Maritime Transportation Security Act (MTSA)
MTSA was enacted in 2002 in response to the September 11 attacks and establishes a comprehensive security framework for the U.S. maritime domain. The Coast Guard administers the program, requiring facilities and vessels to conduct security assessments, develop security plans, and implement measures across three Maritime Security levels. MTSA applies to facilities that receive vessels subject to SOLAS, handle certain dangerous cargoes, or transfer oil or hazardous materials in bulk.
Unlike CFATS, MTSA remains fully active and enforceable. The Coast Guard conducts regular compliance inspections and can impose civil penalties for violations. Facility Security Plans must address access control, restricted areas, cargo handling, monitoring and surveillance, security incident procedures, and training requirements appropriate to the declared MARSEC level.
NERC Critical Infrastructure Protection (CIP) Standards
NERC CIP standards establish mandatory cybersecurity and physical security requirements for the bulk electric system in North America. These standards are developed through an ANSI-accredited process and enforced by NERC and regional entities with FERC oversight. The physical security standards specifically address the protection of transmission stations, substations, and primary control centers identified as critical through a risk-based assessment methodology.
CIP-014 requires transmission owners to perform initial risk assessments to identify critical facilities, conduct third-party vulnerability assessments, and develop security plans addressing identified threats and vulnerabilities. The standard emphasizes a risk-based approach rather than prescriptive physical measures, allowing owners to tailor protections to site-specific conditions while meeting defined security objectives.
Originally published on LinkedIn. Read it there
Field Notes · by email
One email when a new article publishes. Nothing else.
Field notes on converged security from J Damien Scott, Trusted Advisor: the article, its summary, and the phase it belongs to. No digests, no offers, no third party reading over your shoulder.
Email delivery is being set up. The feed carries every article the day it publishes. About Field Notes
Related reading
More from Learn
Learn · 31 July 2026
The Books Being Destroyed Are Not Rare. They Are Out of Print.
A viral story claimed AI companies are destroying rare books to train their models. Most of that story is true. One word in it is not, and it happens to be the word carrying the emotional weight. The books are not rare. They are out of print. That distinction decides almost everything: what was actually destroyed, whether anything irreplaceable was lost, and whether the governance concern survives scrutiny.
8 min readLearn · 22 July 2026
TSI/EN 50600: The European Standard Quietly Reshaping How Data Centres Are Built, Secured, and Judged
EN 50600 and TÜViT's Trusted Site Infrastructure (TSI) have become the de facto benchmark for data centre quality in Europe. This article explains what they actually require, how the classification system works, and why the standard now sits at the intersection of physical security, NIS2, and the CER Directive.
14 min readLearn · 14 July 2026
AI Just Took the Front Desk: What the Tier-1 Support Takeover Actually Means
Tier-1 customer support — password resets, order status, refunds — is being absorbed by AI agents at scale. Gartner predicts 80% autonomous resolution of common service issues by 2029. But the Klarna reversal and the Air Canada chatbot liability ruling show that speed without accuracy just moves the failure point. This article examines the evidence, its limits, and what the shift means for organizations of every size.
7 min read