Chemical Facility Anti-Terrorism Standards
CFATS set security requirements for high-risk chemical facilities. Congress allowed the statutory authority to expire on 28 July 2023, and CISA cannot currently enforce the regulations.
- Status
- lapsed
- Authority
- CISA, under 6 CFR Part 27
- Applies to
- High-risk chemical facilities holding chemicals of interest above screening thresholds, including refineries, petrochemical plants, fertiliser and chemical storage.
Key points
- Congress allowed the statutory authority for CFATS to expire on 28 July 2023, and CISA has stated that it cannot enforce compliance with the regulations while the lapse continues.
- During the lapse CISA cannot require facilities to report chemicals of interest, cannot conduct inspections, and cannot require implementation of a site security plan or an alternative security programme.
- CISA has continued to encourage facilities to maintain the security measures they had in place, so the absence of enforcement does not indicate a reduction in risk.
- The programme required high-risk facilities to assess security risk and implement a site security plan addressing defined risk-based performance standards, several of which concern perimeter security and detection.
- Reauthorisation has been proposed on several occasions, so facilities should check the current position rather than rely on a summary.
What the programme did
CFATS applied to facilities holding chemicals of interest above screening thresholds. Those identified as high-risk were tiered, required to assess their security risk, and required to implement a site security plan meeting risk-based performance standards. Several of those standards concerned perimeter security, restricting access and detecting intrusion, which is where aerial exposure would sit.
CISA administered it, including inspections and approval of site security plans.
The current position
Congress allowed the statutory authority to expire on 28 July 2023. CISA has stated that it cannot enforce the regulations during the lapse. In practical terms it cannot require chemical of interest reporting, cannot inspect, and cannot require a facility to implement its site security plan or an alternative security programme.
CISA has asked facilities to maintain the measures they had in place.
Reauthorisation has been proposed on more than one occasion without being enacted, so anyone relying on the status of the programme should confirm it directly.
What this changes for a facility
Three things follow, and none of them concern the physical risk.
The first is that internal justification replaces external requirement. Security work at a chemical site was previously supported by a compliance driver; at present the case has to stand on its own.
The second is that the review cycle has stopped. Site security plans that were approved under the programme remain as documents, without the inspection and revision process that kept them current.
The third is a practical caution about proposals. Any vendor or adviser citing CFATS as a current mandate for a purchase is describing a programme that cannot presently require anything.
A reasonable approach in the meantime
Most facilities have kept their plans and their measures in place, which is what CISA has asked for.
Where aerial exposure has not previously been considered, it can be assessed and added to the existing plan as a normal security matter. Doing the work that way has the advantage of remaining useful if the programme is reauthorised, since it slots into the structure the regulations already used.
FAQ
▸Do we still have to comply with CFATS?
The regulations cannot currently be enforced, so there is no active compliance obligation while the authority remains expired. CISA has asked facilities to maintain their existing measures voluntarily. Because reauthorisation has been proposed more than once, the current status is worth confirming directly with CISA rather than assuming the position has not changed.
▸Does the lapse mean drone security is no longer relevant to a chemical site?
No. The lapse removed a regulatory mechanism, not the underlying risk. What changes in practice is that security spending has to be justified internally on its merits rather than by reference to a requirement, which affects how the business case is written.
▸A vendor cited CFATS as a reason we need drone detection. Is that right?
It would be out of date. CFATS never named drone detection as a required technology, and the programme has been unenforceable since July 2023. A proposal resting on CFATS as a live mandate should be questioned.
▸What should a chemical facility do instead?
Most facilities have kept their existing site security plans in place. Where aerial exposure has not previously been assessed, it can be added to the existing plan as an ordinary security matter. That keeps the analysis useful if and when the programme is reauthorised.