Full Report
The Government Accountability Office says the Transportation Security Administration (TSA) has taken some steps to communicate Transportation Worker Identification Credential (TWIC®) program information with stakeholders. However, TSA relies on an ad hoc communication approach rather than a documented communication plan to determine how to share information with stakeholders. This has contributed to some stakeholders reporting…
Analysis Summary
# Regulation/Compliance: Transportation Worker Identification Credential (TWIC®) Program Oversight
## Overview
The TWIC® program is a statutory security requirement designed to ensure that only individuals who do not pose a security threat are allowed unescorted access to secure areas of maritime facilities and vessels. This recent GAO audit (GAO-26-107521) highlights critical gaps in the Transportation Security Administration’s (TSA) communication strategy and the U.S. Coast Guard’s data analysis practices regarding compliance enforcement.
## Key Details
- **Issuing Authority:** Transportation Security Administration (TSA) & U.S. Coast Guard (USCG)
- **Effective Date:** Ongoing; GAO Report issued July 30, 2026
- **Jurisdiction:** United States Maritime Sector
- **Status:** In Effect (with GAO-recommended modifications pending)
## Requirements
### Mandatory Requirements
1. **Unescorted Access Control:** Only personnel with a valid TWIC® card may enter secure areas of maritime facilities without an escort.
2. **Personnel Qualification:** Facility operators must ensure all personnel with security duties are fully qualified and credentialed a per maritime security regulations.
3. **Inspection Compliance:** Facilities must submit to U.S. Coast Guard inspections to verify credentialing and access control protocols.
### Recommended Practices
1. **Documented Communication Plan:** TSA should transition from ad hoc stakeholder engagement to a formal, documented communication plan.
2. **Data-Driven Oversight:** The Coast Guard should analyze comprehensive inspection data, including "deficiencies," to identify systemic security risks.
3. **Escort Procedures:** Facilities should maintain rigorous logs and physical oversight for any non-credentialed individuals entering secure zones.
## Affected Organizations
- **Industries:** Maritime transportation, port authorities, shipping, and coastal critical infrastructure.
- **Organization Size:** All entities operating MTSA (Maritime Transportation Security Act) regulated facilities or vessels.
- **Geographic Scope:** All U.S. ports, territorial waters, and regulated maritime facilities.
## Compliance Timeline
- **FY 2019–2024:** Audit period showing 888 deficiencies and 83 major violations.
- **Current Status:** Immediate requirement for facilities to address "deficiencies" before they escalate to "violations."
- **Future Milestone:** Pending implementation of a formal TSA communication plan to improve update timelines for stakeholders.
## Implementation Guidance
### Assessment Phase
- **Audit Access Points:** Review all entry points to secure areas to ensure TWIC® readers or manual checks are functional.
- **Review Training Records:** Verify that security personnel have documented proof of qualification for their specific roles.
### Implementation Phase
- **Formalize Stakeholder Liaison:** Designate a point of contact to monitor TSA program updates to mitigate "ad hoc" communication delays.
- **Address Deficiencies:** Treat "minor deficiencies" found in inspections as leading indicators of security breaches.
### Validation Phase
- **Internal Mock Inspections:** Conduct self-audits using the same criteria as the Coast Guard to identify unauthorized unescorted access.
## Technical Requirements
- **Credential Verification:** Requirements for biometric or visual verification of TWIC® cards.
- **Physical Security:** Infrastructure must support the restriction of unescorted individuals to designated "secure areas" only.
## Penalties & Enforcement
- **Fines:** Civil penalties are assessed for "Violations" (the more severe category of noncompliance).
- **Other Consequences:** Notices of Violation (NOV), operational shutdowns, or revocation of facility security plans.
- **Enforcement:** Enforced by the U.S. Coast Guard via periodic and unannounced facility/vessel inspections.
## Related Standards
- **MTSA 2002:** The Maritime Transportation Security Act, which provides the legal framework for TWIC®.
- **33 CFR Part 105:** Federal regulations governing maritime facility security.
## Resources
- **Official Documentation:** [gao.gov/products/gao-26-107521](https://www.gao.gov/products/gao-26-107521)
- **TSA Program Support:** [tsa.gov/for-industry/twic](https://www.tsa.gov/for-industry/twic)
## Practical Recommendations
- **Improve Response Times:** Organizations should not wait for TSA outreach; proactively check for program updates due to the reported "ad hoc" nature of current TSA communications.
- **Focus on Personnel Duty Qualifications:** Given that "personnel not qualified for roles" was a primary deficiency in the GAO report, organizations should perform an immediate audit of security staff certifications.