Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

TSA’s pipeline cybersecurity directives point toward stronger preparation: covered operators must coordinate incident response, plan for mitigation, and assess and address vulnerabilities. But the directives and rulemaking records do not show that pipeline operators as a group are improving. They document requirements, not sector-wide results. There is also a current-status caveat: TSA’s 2025 versions state that they expired on May 2, 2026, and the available records do not establish whether TSA later extended or replaced them.

What TSA’s pipeline directives cover

TSA’s requirements are not automatically applicable to every pipeline company. The 2025 directives apply to owners and operators of hazardous-liquid and natural-gas pipelines or liquefied natural gas facilities that TSA has notified are critical. The Federal Register described the directive framework as covering systems selected by TSA, rather than the entire pipeline sector.

The framework is divided into two separate directive series. The 01 series addresses incident reporting, coordination, and review of cybersecurity practices. The 02 series covers mitigation actions, contingency planning, and testing. They are complementary, not interchangeable.

Pipeline-2021-01E: reporting, coordination, and review

TSA’s 2025 memorandum for Pipeline-2021-01E lists three continuing actions: report cybersecurity incidents to CISA, designate a cybersecurity coordinator and alternates so someone is available to TSA and CISA at all times, and review current cybersecurity activity against TSA recommendations. The January 2025 Federal Register notice describes the 01 series more broadly as including a vulnerability assessment, gap identification, and remediation planning.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Pipeline-2021-02F: plans and assessment

TSA’s 2025 memorandum titles Pipeline-2021-02F “Pipeline Cybersecurity Mitigation Actions, Contingency Planning, and Testing.” The January 2025 Federal Register notice describes the 02 series’ principal elements as a TSA-approved Cybersecurity Implementation Plan (CIP), an up-to-date Cybersecurity Incident Response Plan (CIRP), and a Cybersecurity Assessment Program (CAP) with an annual plan to assess security measures, identify vulnerabilities, and resolve them.

The 02 series is performance-based: TSA sets outcomes while allowing covered operators to choose measures suited to their systems and operations. That flexibility can accommodate different operational environments, but the existence of a plan or program requirement is not evidence that a vulnerability has been fixed or that security outcomes have improved.

How the two series differ

Directive series Main obligations described in the records What the evidence does not establish
01 series, including 01E Incident reporting to CISA; a coordinator and alternates available to TSA and CISA; review of cybersecurity activity. The Federal Register also describes vulnerability assessment, gap identification, and remediation planning. Whether covered operators completed remediation or improved security outcomes sector-wide.
02 series, including 02F A TSA-approved CIP, an up-to-date CIRP, and a CAP with an annual assessment plan. The 02 series uses performance-based requirements, according to the Federal Register. Whether plans were implemented effectively or produced measurable reductions in risk.

What changed, and when

TSA issued its first pipeline cybersecurity directive in May 2021 and a second in July 2021. The Federal Register’s January 2025 account describes the 01 and 02 directives as separate renewal series and says the 02 series had shifted toward performance-based requirements. Its renewal history includes 2024 versions 01D and 02E.

TSA’s May 1, 2025 memorandum says 02F superseded 02E, took effect May 3, 2025, and retained the performance-based requirements first issued in July 2021 without substantive revisions in that renewal. Both the 2025 01E and 02F documents state an expiration date of May 2, 2026.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Are the 2025 directives still in effect?

The available records do not settle that question. The 2025 directive texts give May 2, 2026, as the expiration date, but the materials available here do not confirm a later extension, replacement, or other current status. As of October 7, 2026, it would therefore be inaccurate to describe those specific versions as definitely governing—or to assume that their expiration means no later requirements exist.

Two administrative records from 2026 do not resolve the issue. A May 2026 OIRA information-collection record remains associated with the 02 series and lists forms for the assessment plan, implementation plan, and incident response plan. A separate TSA information-collection record says a one-time burden for submitting a 01-series cybersecurity vulnerability assessment was deleted. Neither record, by itself, establishes a directive renewal or current applicability.

What the records say about broader cybersecurity rulemaking

The Spring 2025 Unified Agenda listed TSA’s “Enhancing Surface Cyber Risk Management” rulemaking (RIN 1652-AA74) as intended to codify critical cybersecurity requirements for pipeline and rail modes. That agenda snapshot listed an NPRM on November 7, 2024, and the final-rule date as “To Be Determined.” It is a dated status record, not confirmation of the rulemaking’s stage today.

Do these requirements show that pipeline operators are improving?

No—not on their own. The directive documents describe what covered operators are expected to do, and the Federal Register explains TSA’s approach. The records provide no named statistic measuring operator progress or the directives’ cybersecurity effectiveness, and paperwork totals would not be a valid substitute for security outcomes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To substantiate progress, evidence would need to show what operators actually implemented and what changed as a result. Useful operator-level indicators could include disclosed plan implementation, assessment findings, remediation milestones, incident readiness, or independently documented outcomes. The cited policy records do not provide that sector-wide comparison.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How covered operators can use the documented framework

For an operator, the useful first step is to establish which requirements currently apply, rather than relying on an expired-version date or an administrative collection record alone. Then map the applicable directive obligations to operational evidence.

  1. Confirm applicability and current status. Check whether TSA has notified the owner or operator that its pipeline system or LNG facility is critical, and verify the current directive or successor requirements with TSA. The 2025 versions’ stated expiration date does not answer what followed.
  2. Keep the directive series distinct. Track 01-series reporting, coordinator, and review obligations separately from the 02-series mitigation, contingency-planning, testing, and plan requirements.
  3. Connect plans to actions. For the 02-series elements described in the Federal Register, link the CIP, CIRP, and annual CAP plan to assigned owners, assessment findings, and remediation work. A document alone does not demonstrate effective implementation.
  4. Measure outcomes, not paperwork. Record completed remediation, incident-response readiness, and assessment results in a way that can demonstrate change over time. The available records do not prescribe a sector-wide scorecard.

In practical terms, the framework shows a direction toward structured preparation and operator-specific security measures. Whether operators are actually headed in the right direction is a separate empirical question; the directive texts do not answer it.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.