TSA Pipeline Cybersecurity Directives

US FederalCritical Infrastructure2021
ByDecipherU Editorial

TSA issued emergency cybersecurity directives for pipeline operators following the Colonial Pipeline ransomware attack in May 2021. Security Directive Pipeline-2021-01 (May 2021) required incident reporting and cybersecurity assessment. Pipeline-2021-02 (July 2021, reissued 2022 and 2023) mandated specific cybersecurity measures including network segmentation, access controls, and continuous monitoring. These directives apply to owners and operators of TSA-designated critical pipelines.

Quick Reference

EnactedSD Pipeline-2021-01 (May 2021); SD Pipeline-2021-02 (July 2021, reissued July 2022 and July 2023)
Enforcement BodyTransportation Security Administration (TSA)
PenaltiesCivil penalties up to $86,000+ per violation per day under 49 U.S.C. 114; operational shutdowns for severe non-compliance
Applicable ToOwners and operators of TSA-designated critical pipeline systems (hazardous liquids and natural gas pipelines)

Key Requirements

SD Pipeline-2021-01

Pipeline operators must report cybersecurity incidents to CISA within 12 hours, designate a cybersecurity coordinator available 24/7, and complete a vulnerability assessment within 30 days

SD Pipeline-2021-02C (Network Segmentation)

Operators must implement network segmentation policies to separate IT and OT systems, ensuring that compromise of one network does not lead to disruption of the other

SD Pipeline-2021-02C (Access Control)

Operators must implement zero-trust architecture principles for access to OT systems, including multi-factor authentication for all remote access and a pipeline-specific cybersecurity implementation plan

How Does TSA Pipeline Directives Affect Cybersecurity Careers?

The TSA pipeline directives created urgent demand for OT security professionals in the oil and gas sector. Incident responders with pipeline security experience are in high demand. GRC analysts at pipeline operators must manage compliance with evolving TSA requirements. The directives established a precedent for TSA cybersecurity regulation that is expanding to other transportation sectors (rail, aviation).

How Does TSA Pipeline Directives Affect Cybersecurity Sales?

Pipeline cybersecurity spending increased dramatically after the Colonial Pipeline attack and subsequent TSA directives. OT security monitoring, network segmentation, identity management, and incident response solutions all address specific directive requirements. Sales teams should reference specific TSA requirements when selling to pipeline operators.

Cybersecurity Roles That Work With TSA Pipeline Directives

Related Cybersecurity Certifications

Related Cybersecurity Laws

Read the full text of TSA Pipeline Directives at the official source: https://www.tsa.gov/for-industry/surface-transportation-cybersecurity-toolkit

Frequently Asked Questions

TSA issued emergency cybersecurity directives for pipeline operators following the Colonial Pipeline ransomware attack in May 2021. Security Directive Pipeline-2021-01 (May 2021) required incident reporting and cybersecurity assessment. Pipeline-2021-02 (July 2021, reissued 2022 and 2023) mandated specific cybersecurity measures including network segmentation, access controls, and continuous monitoring. These directives apply to owners and operators of TSA-designated critical pipelines.

The TSA pipeline directives created urgent demand for OT security professionals in the oil and gas sector. Incident responders with pipeline security experience are in high demand. GRC analysts at pipeline operators must manage compliance with evolving TSA requirements. The directives established a precedent for TSA cybersecurity regulation that is expanding to other transportation sectors (rail, aviation).

Civil penalties up to $86,000+ per violation per day under 49 U.S.C. 114; operational shutdowns for severe non-compliance

Last verified: April 2026?Report an inaccuracy

Explore Related Cybersecurity Resources

Was this page helpful?