Transportation
TSA, FAA, and logistics security compliance
Transportation systems face cybersecurity requirements from TSA, FAA, and other authorities governing aviation, rail, maritime, and surface transportation. Thalorin provides compliance infrastructure for transportation operators addressing security directives, safety system protection, and supply chain security.
Maritime moved first, and it moved into the Code of Federal Regulations. Subpart F of 33 CFR part 101, published at 90 FR 6447 on 17 January 2025 and effective 16 July 2025, states its cybersecurity duties as codified rules; every other mode still takes its cyber requirements from Security Directives. Training for personnel with system access was due by 12 January 2026 and repeats annually. Cybersecurity Plans for U.S.-flagged vessels, facilities and OCS facilities must reach the Coast Guard for review and approval by 16 July 2027, which is also the deadline for the first cybersecurity assessment.
TSA works the other way. Rail sits under two live directive series at once — SD 1580-21-01 and SD 1582-21-01, which imposed the Cybersecurity Coordinator, the 24-hour CISA report, an incident response plan and a vulnerability assessment, and the performance-based SD 1580/82-2022-01 series layered over them — while airport and aircraft operators take directives under 49 CFR 1542.303 and 1544.305. Any of these can be reissued with changed content and no comment period. Enhancing Surface Cyber Risk Management, the rule that would displace the surface ones, was published as a proposal on 7 November 2024 and is still one.
The requirement text is itself restricted, and that is where compliance programmes break. Security Directives and security programs are Sensitive Security Information under 49 CFR 1520.5(b), and 1520.9 obliges a covered person to store SSI in a secure container, disclose it only to covered persons with a need to know absent written authorisation from TSA, the Coast Guard or the Secretary of Transportation, mark it under 1520.13 and report unauthorised disclosure. The directive imposing a control, the plan describing it and the evidence proving it cannot share a repository with the rest of the compliance record.
Obligations in Thalorin carry the instrument that imposed them — the directive and its revision, the CFR section, the plan the Coast Guard approved — and the handling caveat travels with the evidence rather than with the document alone. SSI-derived material stays scoped to covered persons with a need to know, while the same underlying control state answers a part 101 assessment, a TSA implementation plan and a customer questionnaire without three separate collections.
Critical infrastructure is under constant threat
Plans are approved, not attested
33 CFR 101.655 requires Cybersecurity Plans to be with the Coast Guard for review and approval by 16 July 2027. Approval runs on someone else's calendar, and a plan returned for revision eats time counted as remediation.
The directive cannot go to the vendor
TSA Security Directives are Sensitive Security Information. The integrator or OT vendor implementing a requirement must qualify as a covered person with a need to know before being permitted to read the requirement itself.
One operator, three regimes
A firm running a marine terminal, a rail connection and a trucking fleet sits under 33 CFR part 101, under TSA directives, and under neither, while one OT platform and one engineering team span all three.
Patching systems that cannot stop
33 CFR 101.650 requires KEVs in critical IT and OT systems patched, or compensating controls documented, without delay, and no exploitable channels directly exposed to internet-accessible systems. Propulsion, cargo handling and signalling cannot always come out of service on that schedule.
How Thalorin helps
TSA cybersecurity directives
Track each Security Directive by series and revision alongside the Cybersecurity Implementation Plan TSA approved, with supporting evidence held under SSI handling rules rather than in the general document store.
FAA safety system security
Airworthiness security runs through project-specific special conditions and the RTCA DO-326A and DO-356A process; the FAA proposal to codify network information security protection for transport-category aircraft, published 21 August 2024, is still a proposed rule.
Maritime cybersecurity compliance
Model the 33 CFR 101.650 measures against the assets the Cybersecurity Plan covers: account lockout, replaced default passwords, multifactor authentication on password-protected IT and remotely accessible OT, approved hardware and software lists, protected logs.
Rail security requirements
Carry the rail directives' Cybersecurity Coordinator designation, the 24-hour incident report to CISA and the incident response plan as operated processes with evidence, not as documents filed once.
Fleet and logistics security
Hold CTPAT Minimum Security Criteria cybersecurity obligations and the hazardous materials security plan required by 49 CFR 172.800 against the same operational controls, so a trade programme audit and a security assessment read one state.
Transportation sector reporting
Route each incident to the destination its own rule names — the National Response Center under 33 CFR 101.620, CISA within 24 hours under the TSA directives — and keep the determination that started each clock.
Transportation: common questions
When is our Cybersecurity Plan due to the Coast Guard?
33 CFR 101.655 sets 16 July 2027 for submitting Cybersecurity Plans for review and approval, covering U.S.-flagged vessels, facilities and OCS facilities that already hold a security plan under 33 CFR parts 104, 105 and 106. Training for personnel with system access was due by 12 January 2026, and the first cybersecurity assessment is due 16 July 2027. The Coast Guard has sought comment on delaying the vessel implementation periods; those dates are what the regulation currently carries.
Does the Coast Guard cybersecurity rule apply to foreign-flagged vessels?
No. 33 CFR 101.605 applies the subpart to owners and operators of U.S.-flagged vessels, facilities and OCS facilities required to hold a security plan under parts 104, 105 and 106, and expressly excludes foreign-flagged vessels subject to part 104. Those vessels are reached through port state control and through IMO Resolution MSC.428(98), which requires cyber risk to be addressed in the safety management system. A terminal operator carries duties the foreign vessel at its berth does not.
Can we share a TSA security directive with our OT vendor?
Only if the vendor is a covered person with a need to know, or TSA authorises the disclosure in writing. 49 CFR 1520.5(b) makes Security Directives Sensitive Security Information, and 1520.9 requires covered persons to safeguard it, store it in a secure container, mark it under 1520.13 and report unauthorised disclosure. The workable pattern is to scope the statement of work so the vendor receives the control requirement rather than the directive.
Has TSA's surface cyber rule replaced the security directives?
No. Enhancing Surface Cyber Risk Management was published as a notice of proposed rulemaking on 7 November 2024, covering certain pipeline and rail owner-operators, with a narrower incident-reporting duty for over-the-road bus operators. It is a proposal; the Security Directives remain the operative instrument. That matters for planning, because a directive can be reissued with new content on TSA's own timetable while a final rule would fix the requirement in the CFR.
What does 33 CFR 101.650 require that a normal IT policy does not?
It reaches operational technology directly. Multifactor authentication is required on remotely accessible OT, not only on password-protected IT. Known exploited vulnerabilities in critical IT and OT systems must be patched, or compensating controls documented, without delay; there must be no exploitable channels directly exposed to internet-accessible systems, and no OT on the publicly accessible internet without a documented justification. Those are statements about architecture, not patch cadence. The plan rests on documentation identifying the network map and OT device configuration information, the artifact most operators find they never assembled.
Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.
Talk to us about Transportation.
See how one evidence artifact satisfies Transportation requirements alongside every other framework you carry.