Full Report
The U.S. Department of Homeland Security (DHS), through the Cybersecurity and Infrastructure Security Agency (CISA), moved forward with... The post CISA advances ChemLock information request to support security consultations, onsite assessments, risk reduction activities appeared first on Industrial Cyber.
Analysis Summary
# Regulation/Compliance: CISA ChemLock Information Collection Request (ICR)
## Overview
The ChemLock program is a voluntary security initiative led by CISA to assist facilities that handle hazardous chemicals in enhancing their security posture. This specific action involves a formal Information Collection Request (ICR) under the Paperwork Reduction Act to standardize data gathering for security consultations, onsite assessments, and risk reduction activities.
## Key Details
- **Issuing Authority:** Cybersecurity and Infrastructure Security Agency (CISA) / Department of Homeland Security (DHS)
- **Effective Date:** Currently in the notice-and-comment period; 30-day notice published June 2, 2026.
- **Jurisdiction:** United States; Chemical Sector and Critical Infrastructure.
- **Status:** Proposed (Under OMB Review).
## Requirements
### Mandatory Requirements
1. **Accuracy of Information:** While participation in ChemLock is voluntary, facilities choosing to participate must provide accurate contact information, facility descriptions, and data regarding chemicals present on-site.
2. **Handling of Sensitive Information:** Submissions must **not** include Chemical-terrorism Vulnerability Information (CVI), Sensitive Security Information (SSI), or Protected Critical Infrastructure Information (PCII) through the public docket; these must be handled via secure, approved channels.
### Recommended Practices
1. **Engagement in Services:** Facilities are encouraged to request security and technical consultations.
2. **Feedback Participation:** Organizations should complete the ChemLock Service Feedback instrument to help the agency refine performance and outcomes.
3. **Conducting Exercises:** Participation in drills and training courses offered through the program to test security readiness.
## Affected Organizations
- **Industries:** Facilities handling hazardous chemicals (Chemical Sector), including private sector and public sector partners.
- **Organization Size:** All sizes (State, local, Tribal, and territorial governments, plus private entities).
- **Geographic Scope:** United States and its territories.
## Compliance Timeline
- **December 2024:** Initial 60-day notice for public input (completed).
- **June 2, 2026:** Publication of the 30-day notice in the Federal Register.
- **July 2, 2026:** Deadline for public comments on the ICR.
- **TBD (Post-July 2026):** Final OMB approval and formal launch of consolidated information collection instruments.
## Implementation Guidance
### Assessment Phase
- **Inventory Chemicals:** Identify hazardous chemicals on-site to determine eligibility and need for ChemLock services.
- **Review Security Gaps:** Evaluate current security protocols to identify which ChemLock service (consultation, assessment, or training) is most needed.
### Implementation Phase
- **Submission of Request:** Use the "ChemLock Request for Services" instrument to provide contact and facility identification.
- **Registration/Preparation:** Complete the "Service Registration and Preparation" instrument, requiring an estimated 3.17 hours of administrative effort to prepare for onsite assessments.
### Validation Phase
- **Post-Service Feedback:** Use the "ChemLock Service Feedback" instrument to evaluate the effectiveness of the onsite assessment or consultation.
- **Risk Assessment Completion:** Utilize the tailored risk assessment provided by CISA to validate and mitigate identified vulnerabilities.
## Technical Requirements
- **Data Collection Instruments:** Use of three specific digital/standardized forms:
1. Request for Services
2. Service Registration and Preparation
3. Service Feedback
- **Facility Identification:** Requirements to provide facility description and specific chemical inventory data.
## Penalties & Enforcement
- **Fines:** None (The program is voluntary).
- **Other Consequences:** Failure to provide accurate information may result in the denial of security consultation services or inaccurate risk assessments.
- **Enforcement:** Not applicable as a voluntary program; however, the collection of data is regulated by the Paperwork Reduction Act and OMB oversight.
## Related Standards
- **Paperwork Reduction Act (PRA):** Governs how federal agencies collect information from the public.
- **Chemical Facility Anti-Terrorism Standards (CFATS) Framework:** While CFATS authority has faced legislative challenges, ChemLock aligns with the broader goal of chemical security risk reduction.
- **NIST CSF:** Can be aligned with the "Identify" and "Protect" functions during security consultations.
## Resources
- **Official Documentation:** Federal Register Notice (fedsreg[.]gov)
- **Guidance Documents:** CISA ChemLock Program Overview (cisa[.]gov/chemlock)
- **Tools:** ChemLock Security Self-Assessment Tool (where applicable).
## Practical Recommendations
- **Participate Early:** Given the voluntary nature, organizations should leverage the "onsite assessments" to receive no-cost federal security expertise.
- **Verify Disclosure Channels:** Ensure that internal legal teams review any data sharing to ensure PCII or SSI is not accidentally disclosed in public comment periods.
- **Time Allocation:** Budget approximately 3.5 to 4 hours of administrative time per facility for the full range of registration and feedback activities associated with a CISA consultation.