1. Learn
  2. Align
  3. Perform
  4. Review

Learn14 min read

Comprehensive Regulatory Reference: CFATS, MTSA, and NERC-CIP Physical Security

By J Damien Scott, Trusted Advisor

A detailed, postgraduate-level analysis of three critical regulatory frameworks governing the physical security of U.S. critical infrastructure: the Chemical Facility Anti-Terrorism Standards, the Maritime Transportation Security Act, and the North American Electric Reliability Corporation Critical Infrastructure Protection standards.

Chemical Facility Anti-Terrorism Standards (CFATS)

CFATS was the first comprehensive federal security regulation specifically focused on high-risk chemical facilities. Administered by CISA within the Department of Homeland Security, CFATS required facilities possessing chemicals of interest above defined screening threshold quantities to submit information through the Chemical Security Assessment Tool. CISA then assessed whether the facility presented a high level of security risk and required development of Site Security Plans meeting 18 Risk-Based Performance Standards.

The most important legal point is that CFATS has lapsed. Because Congress allowed the statutory authority to expire, CISA cannot enforce compliance with CFATS regulations at this time. However, many facilities remain subject to other federal, state, local, industry, environmental, transportation, safety, insurance, contractual, or corporate governance requirements. CFATS-style security remains a sound benchmark for prudent risk management.

This document provides a detailed, postgraduate-level analysis of three critical regulatory frameworks governing the physical security of U.S. critical infrastructure.

Maritime Transportation Security Act (MTSA)

MTSA was enacted in 2002 in response to the September 11 attacks and establishes a comprehensive security framework for the U.S. maritime domain. The Coast Guard administers the program, requiring facilities and vessels to conduct security assessments, develop security plans, and implement measures across three Maritime Security levels. MTSA applies to facilities that receive vessels subject to SOLAS, handle certain dangerous cargoes, or transfer oil or hazardous materials in bulk.

Unlike CFATS, MTSA remains fully active and enforceable. The Coast Guard conducts regular compliance inspections and can impose civil penalties for violations. Facility Security Plans must address access control, restricted areas, cargo handling, monitoring and surveillance, security incident procedures, and training requirements appropriate to the declared MARSEC level.

NERC Critical Infrastructure Protection (CIP) Standards

NERC CIP standards establish mandatory cybersecurity and physical security requirements for the bulk electric system in North America. These standards are developed through an ANSI-accredited process and enforced by NERC and regional entities with FERC oversight. The physical security standards specifically address the protection of transmission stations, substations, and primary control centers identified as critical through a risk-based assessment methodology.

CIP-014 requires transmission owners to perform initial risk assessments to identify critical facilities, conduct third-party vulnerability assessments, and develop security plans addressing identified threats and vulnerabilities. The standard emphasizes a risk-based approach rather than prescriptive physical measures, allowing owners to tailor protections to site-specific conditions while meeting defined security objectives.

GRCCFATSMTSANERC-CIPRegulatory compliance

Originally published on LinkedIn. Read it there

Field Notes · by email

One email when a new article publishes. Nothing else.

Field notes on converged security from J Damien Scott, Trusted Advisor: the article, its summary, and the phase it belongs to. No digests, no offers, no third party reading over your shoulder.

Email delivery is being set up. The feed carries every article the day it publishes. About Field Notes

Related reading

All articles