Back to search
Defense & SecurityHomeland Security

Maritime Port Security

21 min read·Updated May 17, 2026

The Maritime Transportation Security Act (MTSA) of 2002 established the framework for securing America's ports, waterways, and maritime transportation system against terrorism and other threats. Administered by the Coast Guard under the Department of Homeland Security, the program requires vulnerability assessments, security plans at the national, regional, and facility level, and a biometric identification credential (TWIC) for workers accessing secure port areas.

Current Law (2026)

ParameterValue
Lead agencyU.S. Coast Guard (DHS)
Security plansNational, Area, facility, and vessel levels
TWIC credentialRequired for access to secure areas of MTSA-regulated facilities and vessels
Port security grantsRisk-based allocation to port authorities, facility operators, state/local agencies
Foreign port assessmentsCoast Guard evaluates antiterrorism measures at foreign ports serving U.S. trade
Deployable forcesSpecialized maritime security teams established by statute
  • 46 U.S.C. § 70101 — Definitions (defines key terms including "transportation security incident," "Area Maritime Transportation Security Plan," and "cybersecurity risk")
  • 46 U.S.C. § 70102 — United States facility and vessel vulnerability assessments (directs the Secretary to assess vessel types and facilities to identify high-risk targets for transportation security incidents)
  • 46 U.S.C. § 70103 — Maritime transportation security plans (requires a National Maritime Transportation Security Plan and subordinate Area Maritime Transportation Security Plans for each Coast Guard Captain of the Port zone)
  • 46 U.S.C. § 70104 — Transportation security incident response (establishes response plans for vessels and facilities involved in security incidents; integrates with FEMA response frameworks)
  • 46 U.S.C. § 70105 — Transportation Worker Identification Credential (TWIC) (prescribes biometric identification requirements for individuals accessing secure areas of vessels and facilities)
  • 46 U.S.C. § 70106 — Deployable, specialized forces (establishes maritime security teams to safeguard vessels, harbors, ports, facilities, and cargo)
  • 46 U.S.C. § 70107 — Grants (creates a risk-based grant program for implementing Area Maritime Transportation Security Plans and facility security plans)
  • 46 U.S.C. § 70108 — Foreign port assessment (requires Coast Guard assessment of antiterrorism effectiveness at foreign ports serving U.S.-documented vessels)
  • 46 U.S.C. § 70109 — Notifying foreign authorities (directs notification to foreign governments when their ports are found to lack effective antiterrorism measures)
  • 46 U.S.C. § 70110 — Actions for foreign ports and U.S. territories (authorizes conditions on entry to U.S. waters for vessels arriving from ports with inadequate security, up to and including denial of entry)
  • 14 U.S.C. § 311 — Captains of the port (Commandant may appoint officers as port captains with broad authority over vessel movements, port operations, and safety/security in U.S. waters — the Coast Guard's primary port-level authority)
  • 14 U.S.C. § 522 — Coast Guard law enforcement (boarding and inspection authority: Coast Guard may board and inspect any vessel on the high seas or in U.S. waters to prevent, detect, and stop violations of U.S. law without a warrant)
  • 14 U.S.C. § 527 — Safety of vessels of the Armed Forces (Secretary may control vessel anchoring and movement in navigable waters to protect armed forces vessels; if Secretary has not acted, the senior Coast Guard officer present may take immediate action)

How It Works

Maritime port security operates through a layered system of assessments, plans, credentials, and enforcement. At the top level, the Coast Guard maintains a National Maritime Transportation Security Plan that sets standards and coordinates federal, state, local, and private-sector efforts. Below that, Area Maritime Transportation Security Plans cover each Captain of the Port zone — roughly corresponding to major port regions — tailoring security measures to local geography, traffic patterns, and threats.

Individual facilities (terminals, refineries, chemical plants adjacent to navigable waters) and vessels must develop and implement their own security plans, approved by the Coast Guard. These plans address access control, restricted areas, cargo handling security, surveillance, communications, and incident response procedures.

The broader legal framework for maritime commerce, including vessel documentation and maritime liens, operates alongside port security requirements. The Transportation Worker Identification Credential (TWIC) is the program's most visible feature for workers. Anyone needing unescorted access to secure areas of MTSA-regulated facilities or vessels must hold a valid TWIC — a biometric (fingerprint-based) credential issued by TSA after a security threat assessment including criminal history, immigration status, and terrorism database checks. The credential requirement affects hundreds of thousands of port workers, truck drivers, merchant mariners, and longshoremen.

The Coast Guard also conducts vulnerability assessments of U.S. facilities and vessel types to identify high-risk targets. These assessments inform both security plan requirements and the allocation of port security grants, which flow to port authorities, facility operators, and state and local agencies on a risk-based formula.

Port security also intersects with Customs and Border Protection screening of cargo and admiralty law governing vessel operations. Internationally, the Coast Guard assesses antiterrorism measures at foreign ports that serve vessels trading with the United States. When a foreign port is found deficient, the U.S. notifies the foreign government and recommends improvements. If deficiencies persist, the Secretary can impose conditions on vessels arriving from that port — including denying entry to U.S. waters entirely.

The statute also establishes deployable specialized forces — maritime security teams that can be surged to ports facing elevated threats. These forces supplement the Coast Guard's standing presence with additional capabilities for high-risk situations.

How It Affects You

If you work at a port, terminal, marine facility, or need unescorted access to a secure waterfront area, you need a Transportation Worker Identification Credential (TWIC) — the biometric ID card that proves TSA has conducted a security threat assessment on you. The TWIC application process: apply at a TSA enrollment center (tsa.gov/for-industry/twic), submit fingerprints, pay the $124.00 enrollment fee (reduced to $91.75 if you already hold a comparable Security Threat Assessment such as a HazMat endorsement), and wait approximately 7–9 weeks for processing. TSA conducts a criminal history, immigration status, and terrorism database check. Permanent disqualifying offenses — including espionage, treason, and certain violent crimes — result in automatic denial. Interim disqualifying offenses (felony drug convictions within 7 years, certain felonies within 7 years) can also result in denial but may be waived. The TWIC card is valid for 5 years and must be renewed before expiration; you cannot continue working in secure areas with an expired TWIC. If you're denied a TWIC, you have the right to appeal and to seek a waiver for certain offenses — the TSA appeals process is described at tsa.gov/for-industry/twic-waiver-process. If you work at a facility that uses electronic TWIC readers, your card is verified biometrically; some facilities still conduct visual inspections, which provide less security assurance.

If you're a vessel operator, shipping company, or maritime carrier operating at U.S. ports, your MTSA compliance obligations fall into two tracks: the vessel and its crew. Every MTSA-regulated vessel must have a Vessel Security Plan (VSP) approved by the Coast Guard — a living document covering access control, restricted areas, cargo security, surveillance, communications, drills, and incident response. Your designated Vessel Security Officer (VSO) is responsible for implementing and maintaining the plan. The Coast Guard assesses MARSEC (Maritime Security Condition) levels — MARSEC 1 (baseline), MARSEC 2 (heightened), MARSEC 3 (imminent threat) — and facilities and vessels must escalate their security measures accordingly. Drills are required at minimum intervals: crew security drills at least every 3 months, full-scale exercises annually. Coast Guard Port State Control (PSC) officers board foreign-flagged vessels calling at U.S. ports and inspect for MTSA compliance — deficiencies can result in a vessel being detained until corrected. The cybersecurity requirements in Vessel Security Plans are actively expanding following the Coast Guard's 2024-2026 rulemaking; cyber incident reporting and network segmentation requirements are moving toward mandatory standards for commercial vessels.

If you manage or operate a waterfront facility — a marine terminal, bulk liquid terminal, cruise ship pier, ferry terminal, or other MTSA-regulated facility — your Facility Security Plan (FSP) is your central compliance document. The FSP must address access control (identifying who may enter secure areas and how), restricted zones, cargo handling security, personnel identification, surveillance systems, communications, drills, and recordkeeping. The Coast Guard's Captain of the Port (COTP) approves your FSP and verifies compliance through periodic inspections. MARSEC level escalations require you to implement pre-planned additional security measures on short notice — your FSP should include specific measures for each MARSEC level. Civil penalties for MTSA violations can reach $25,000 per day per violation. The Port Security Grant Program (fema.gov/port-security-grant-program) provides risk-based federal funding to help facilities implement security improvements — port authorities and facility operators in high-risk areas should check their eligibility annually. The Chinese crane cybersecurity issue identified in 2024 is increasingly relevant for terminal operators with ZPMC-manufactured ship-to-shore cranes — coordinate with your IT security team and the Coast Guard's cyber team on risk mitigation.

If you're an importer, cargo owner, or trade logistics professional, MTSA's foreign port assessment authority directly affects your supply chain. When the Coast Guard finds that a foreign port lacks adequate antiterrorism measures, vessels arriving from that port face additional inspections, delays, or — in extreme cases — denial of entry to U.S. ports. Importers can reduce these risks and accelerate cargo processing by joining C-TPAT (Customs-Trade Partnership Against Terrorism, administered by CBP at cbp.gov/trade/trusted-trader-programs/ctpat) — a voluntary program where importers commit to specific supply chain security standards in exchange for expedited processing, reduced exam rates, and front-of-line positioning. C-TPAT Tier 3 certified importers receive the highest level of trusted trader benefits. Even with C-TPAT certification, only a fraction of inbound containers receive physical examination — the screening system relies heavily on CBP's National Targeting Center pre-arrival risk scoring, which assesses manifests, carrier history, and shipper profiles. If a container is flagged for examination, you can expect 3–5 day delays at minimum; a full physical exam (devanning) can take longer and creates re-stuffing costs.

State Variations

Maritime port security is exclusively federal law administered by the Coast Guard. However, state and local agencies play significant roles:

  • State and local law enforcement often participate in Area Maritime Security Committees
  • Port authorities (state or local entities) implement facility security plans and receive federal grant funding
  • Some states have additional port security requirements beyond the federal baseline
  • State and local first responders integrate with federal incident response plans

Implementing Regulations

  • 33 CFR Part 101 — Maritime Security: General — the master regulatory framework implementing the Maritime Transportation Security Act of 2002. Part 101 establishes the nationwide threat-level system, credentialing requirements, and cybersecurity obligations that bind all MTSA-regulated vessels, facilities, and Outer Continental Shelf installations. Key provisions:

    • § 101.200MARSEC Levels: three graduated threat conditions that the Coast Guard Commandant or Captain of the Port (COTP) can set for specific ports or nationally — Level 1 (normal baseline security, all standard measures in effect), Level 2 (heightened risk; additional measures required from vessels and facilities within the affected zone), Level 3 (specific or imminent threat; most restrictive operations, potential port closure or vessel diversions). The COTP communicates MARSEC Level changes via Broadcast Notice to Mariners and electronic notification. Unlike DHS's broader NTAS threat levels, MARSEC levels trigger specific, enumerated operational requirements in each facility's and vessel's approved security plan
    • §§ 101.514–101.555TWIC (Transportation Worker Identification Credential): all persons requiring unescorted access to secure areas of MTSA-regulated vessels, facilities, and OCS facilities must hold a valid TWIC — a biometric identification card issued by TSA following a security threat assessment. Risk Group A vessels and facilities (those with the highest-consequence access profiles, such as liquefied natural gas carriers and chemical facilities) must conduct electronic TWIC inspection using an approved PACS (Physical Access Control System) that reads the card's biometric chip and checks against TSA's cancelled-TWIC list (updated at least every 7 days at MARSEC 1). Risk Group B facilities may use visual inspection alone. The 30-day recurring access provision (§ 101.555) allows pre-vetted TWIC holders who regularly visit the same facility to be added to an approved list, streamlining entry without eliminating the biometric check
    • §§ 101.600–101.640Cybersecurity (Subpart F): added in 2024, this subpart establishes minimum cybersecurity requirements for all U.S.-flagged vessels and MTSA-regulated facilities with an approved security plan. Each covered owner or operator must designate a Cybersecurity Officer (CySO) — who may also hold other roles — responsible for developing, implementing, and verifying a written Cybersecurity Plan. The Plan must address: asset inventory (hardware, software, network architecture), access control (role-based permissions, multi-factor authentication for critical systems), network segmentation (operational technology networks separated from business IT), incident response procedures, and supply chain risk. Annual cybersecurity drills and exercises are required. The CySO must maintain records of all cybersecurity incidents for at least two years. Subpart F has preemptive effect over state and local cybersecurity requirements within the same field for covered facilities
    • § 101.405MARSEC Directives: when the Coast Guard determines that additional security measures are necessary in response to a specific threat assessment, it may issue a MARSEC Directive containing sensitive security information (SSI) — classified or restricted operational instructions not disclosed publicly. Vessel and facility operators in the directive's scope must implement the required measures within the specified timeframe. Violation of a MARSEC Directive carries the same civil and criminal penalty exposure as any other MTSA violation (§ 101.415)
    • § 101.505Declaration of Security (DoS): a written coordination agreement between a vessel master and a facility security officer that specifies security responsibilities for each party during the vessel-facility interface (cargo transfer, passenger embarkation, crew change). The DoS requirement derives from the ISPS Code (International Ship and Port Facility Security Code) and applies at MARSEC 2 and above, or when either party assesses that enhanced coordination is warranted at MARSEC 1
    • § 101.112Preemption: Part 101 and the 33 CFR Parts 103, 104, and 106 regulations have full preemptive effect over state or local regulation in the same field — port security planning and vessel/facility security plans cannot be supplemented by inconsistent state requirements

    The MTSA security framework is a three-layer system: national standards set in Part 101, area-level coordination through Area Maritime Security Committees (Part 103), and individual vessel/facility security plans (Parts 104 and 105). Part 101 is the constitutional spine — it defines the threat-level vocabulary and enforcement authority that makes the rest of the subchapter operate. For port operators, terminal managers, shipping companies, and offshore energy facilities, compliance turns on three ongoing obligations: maintaining a Coast Guard-approved security plan, holding valid TWIC credentials for all security-relevant personnel, and — since 2024 — maintaining a functioning Cybersecurity Plan with a designated CySO.

    Recent rulemakings: 68 FR 39278 (2003) — original MTSA implementing regulations. 81 FR 57709 (2016) — TWIC reader rule establishing Risk Group A electronic inspection requirements. 89 FR (2024) — Subpart F cybersecurity requirements, effective 2025 for most covered vessels and facilities.

  • 33 CFR Part 103 — Area Maritime Security (FMSC designation, AMS Committee composition/responsibilities, AMS Assessment elements)

  • 49 CFR Part 1520 — Protection of Sensitive Security Information (SSI): TSA's regulations governing a category of transportation security information that is protected from public disclosure — including FOIA — because its release would be detrimental to transportation security:

    • § 1520.5 — What constitutes SSI: SSI includes a broad range of transportation security information: security programs and security directives issued by DHS; security screening procedures; information regarding threats to transportation (when combined with protective measures); details of transportation security activities by covered persons; the identities of TSA-certified or approved individuals, programs, and facilities (such as the TWIC database and known shipper lists); airport and seaport vulnerability assessments; and records in the possession of Coast Guard or TSA relating to maritime and aviation security assessments; the SSI designation is not equivalent to classified information — SSI is a separate, lower-sensitivity category that nonetheless warrants protection
    • § 1520.7 — Covered persons: SSI requirements apply to airport operators, aircraft operators, air carriers, indirect air carriers, maritime vessel operators, port facility operators, rail carriers, mass transit systems, and any person who has received SSI from TSA or the Coast Guard; covered persons must actively protect SSI in their possession
    • § 1520.9 — Duties to safeguard SSI: covered persons must (1) take reasonable steps to safeguard SSI from unauthorized disclosure; (2) store SSI in a secure manner when not in their physical possession; (3) disclose SSI only to those with a need to know (§ 1520.11); and (4) promptly report unauthorized disclosure to TSA; the duty to protect SSI is ongoing and continues after the covered person's involvement with a transportation security program ends
    • § 1520.11 — Need to know: a person has a need to know SSI when they require access to carry out transportation security activities approved by DHS or DOT, when they are a party to a proceeding before a federal court involving security matters and the court has authorized access, or when TSA specifically determines disclosure is necessary; the need-to-know standard prevents general distribution of SSI within organizations — only those directly involved in security activities may access it
    • § 1520.13 — Marking requirements: paper records containing SSI must bear the marking "SENSITIVE SECURITY INFORMATION" at the top and the distribution limitation statement at the bottom; electronic records (presentations, spreadsheets, emails) must be similarly marked; the marking requirement ensures that SSI is clearly identifiable and that recipients understand its protected status
    • § 1520.15 — FOIA exemption: SSI is not available for public inspection or copying under FOIA, the Privacy Act, or other laws requiring public disclosure; when SSI appears in federal court proceedings, courts must use protective orders to prevent public access; journalists and researchers who file FOIA requests for TSA security programs, threat assessments, or security directives will receive a response withholding SSI under this provision
    • § 1520.17 — Consequences of unauthorized disclosure: unauthorized disclosure of SSI is grounds for civil penalties and enforcement action; in federal court, it is a crime under 49 U.S.C. § 46507; the combination of civil and criminal exposure for SSI leaks reflects the seriousness of the security information involved

    Part 1520 is one of the most litigated areas of transportation security law because SSI protection frequently conflicts with public access, judicial transparency, and the rights of parties in security-related litigation. Courts have repeatedly wrestled with how to handle cases where SSI is material evidence — allowing sufficient access for defendants and their counsel while maintaining protection from public disclosure. Journalists and civil liberties groups have challenged the breadth of the SSI designation, arguing that TSA has used it to shield programs from legitimate public accountability. The Coast Guard's 2024 cybersecurity rule for maritime facilities relied heavily on SSI to protect the specific security measures required, which limits public knowledge of exactly what maritime operators must do to comply. Recent rulemakings: 69 FR 28082 (May 2004) — original Part 1520 rule; 85 FR 16499 (March 2020) — updated provisions.

  • 33 CFR Part 6 — Protection and Security of Vessels, Harbors, and Waterfront Facilities (USCG, 26 sections): the foundational pre-MTSA port security regulation implementing the Espionage Act of 1917 and the Magnuson Act (now codified at 46 U.S.C. § 70051), which gave the Coast Guard broad authority over vessels and waterfront facilities long before the post-9/11 security framework existed. While the MTSA's 33 CFR Parts 101–106 are now the primary operative port security framework, Part 6 remains in force as the underlying statutory authority for COTP enforcement powers and is referenced throughout the MTSA regulations. Key provisions:

    • § 6.04-5 — Access control: the Captain of the Port (COTP) may prevent any person, article, or thing — including digital data, networks, programs, or systems — from boarding or entering any vessel or waterfront facility within the jurisdiction; this provision was updated in 2024 to expressly cover cyber infrastructure, extending the physical access-control authority to cyber vectors
    • § 6.04-6 — Security zones: the COTP may establish security zones — areas of land, water, or both — in which no person or vessel may enter without COTP permission; no person may board or place any article in a security zone without authorization; security zones are typically established by temporary rule published in the Federal Register and through Broadcast Notice to Mariners for vessel operators (this authority predates the Part 165 security zone framework; both authorities remain operative)
    • § 6.04-7 — Search authority: as consistent with law, the COTP may inspect and search at any time any vessel, waterfront facility, or security zone, or any person, article, or thing thereon; the search authority extends to cyber infrastructure — data, networks, programs, or systems on regulated vessels and facilities; the COTP may also remove or destroy any article posing a security risk
    • § 6.04-8 — Vessel seizure: the COTP may take full or partial possession or control of any vessel or part thereof within the territorial waters under the COTP's jurisdiction when necessary to prevent damage to other vessels or waterfront facilities, or to secure compliance with any regulation or order; this is the legal basis for the Coast Guard's authority to board and redirect vessels that have lost propulsion control (as in the Dali/Francis Scott Key Bridge incident)
    • § 6.10-1 — Merchant mariner vetting: no person shall be issued a document required for employment on a U.S. merchant vessel unless the Commandant is satisfied that the person's character and habits make them suitable for employment; this is the foundational statutory basis for the merchant mariner credentialing background check system that TWIC complemented after 9/11
    • § 6.10-5 — Identification credentials: any person aboard a vessel or seeking access to a waterfront facility may be required to carry identification credentials issued by or satisfactory to the Commandant; the Commandant may designate areas where credentials are required for access
    • § 6.12-1 — Hazardous cargo oversight: the COTP may supervise and control the transportation, handling, loading, discharging, and storage of hazardous materials on board vessels, referencing the DOT (49 CFR Parts 170–189) and Coast Guard (46 CFR) hazmat regulations; this COTP coordination authority is the legal hook for COTP enforcement actions against vessels or facilities that mishandle dangerous cargo
    • § 6.14-1 — Safety conditions on waterfront facilities: the Commandant may prescribe conditions relating to waterfront facility safety — fire prevention, structural integrity, hazardous materials storage — as necessary to prevent damage to vessels in port; the COTP may prohibit a vessel from mooring at a facility that poses danger (§ 6.14-2)
    • § 6.16-1 — Sabotage and cyber incident reporting: masters, owners, and operators of vessels and waterfront facilities must immediately report any evidence of sabotage, subversive activity, or any actual or threatened cyber incident involving the vessel, harbor, port, or waterfront facility — including cyber attacks on vessel control systems, navigation systems, or cargo management systems; the cyber incident reporting requirement was codified in this section in 2024
    • § 6.18-1 — Violations: failure to comply with any regulation or order under Part 6, or obstruction of enforcement, is a criminal violation under 46 U.S.C. § 70052; civil enforcement also applies through the COTP and DOJ

    Part 6 is the legal foundation that the MTSA built on. Where the MTSA (Parts 101–106) creates a comprehensive compliance framework — security plans, threat levels, credentialing programs, and area security committees — Part 6 provides the COTP's core enforcement powers: the authority to exclude people, search vessels, establish security zones, and seize vessels as necessary. Together they form a layered structure: Part 6 emergency powers + MTSA systematic compliance requirements. The 2025 updates adding explicit cyber incident reporting authority to § 6.16-1 reflect the Coast Guard's integration of maritime cybersecurity into its traditional physical security mission. No major structural changes to Part 6 since its original promulgation — the core authorities predate the postwar era; the 2024/2025 updates added cyber-specific language to the existing physical security provisions.

  • 49 CFR Part 1572 — Credentialing and Security Threat Assessments (TSA, 24 sections): the regulatory standard that governs who qualifies for a TWIC or Hazardous Materials Endorsement (HME) and how TSA conducts the background check to make that determination. Where Parts 33 CFR 104–106 and 46 CFR 10 establish the requirement to hold a TWIC, Part 1572 specifies the eligibility criteria that determine whether TSA will issue one — and the same standards apply to the HME (the CDL endorsement that truck drivers need to haul hazardous materials):

    • § 1572.3 — Scope: covers two distinct populations: (1) CDL drivers applying for an HME (hazardous materials endorsement allowing transport of hazardous materials by commercial vehicle, including explosives, flammable liquids, radioactive materials, and toxic substances); (2) maritime/port workers applying for a TWIC (required for unescorted access to secure areas of MTSA-regulated vessels and facilities); both programs use the same security threat assessment standards but have separate fee schedules
    • § 1572.5 — Standards for denial: TSA may deny an HME or TWIC if the applicant (1) has a disqualifying criminal offense under § 1572.103; (2) does not meet immigration status requirements under § 1572.105; (3) is found in terrorist watchlist or threat database checks under § 1572.107; or (4) has been adjudicated as lacking mental capacity or committed to a mental health facility under § 1572.109; all four are independent grounds for denial
    • § 1572.103 — Permanent disqualifying criminal offenses: convictions that result in automatic denial with no waiver possible include espionage, sedition, or treason; terrorism offenses or material support for terrorism; murder; transportation of explosives with intent to harm (18 U.S.C. § 842); and use of a weapon of mass destruction; conviction in any civilian or military court applies, and "found not guilty by reason of insanity" also counts as a disqualifying finding; the permanent list reflects Congress's judgment that certain crimes are categorically incompatible with access to critical transportation infrastructure
    • § 1572.103(b) — Interim disqualifying offenses (7-year lookback): felony convictions within the past 7 years (or release from incarceration within 5 years) for unlawful possession or use of a firearm, a federal crime of terrorism or material support, dishonesty-related fraud convictions, bribery, smuggling, immigration fraud, or transport of illegal aliens are grounds for denial — but these are waivable through TSA's appeals and waiver process
    • § 1572.105 — Immigration status requirements: applicants must be U.S. nationals, lawful permanent residents, refugees, or asylees; limited exceptions for M-1 visa students enrolled in U.S. Merchant Marine Academy programs; all other nonimmigrant visa categories (work visas, student visas, tourist visas) are ineligible — undocumented individuals cannot hold a TWIC or HME regardless of employment authorization documents
    • § 1572.107 — Database checks: TSA searches Interpol and other international law enforcement databases, terrorist watchlists (TSC/TSDB), and any other databases TSA determines are relevant; a hit on the terrorist watchlist triggers a more intensive review and possible threat determination
    • Subparts E and F — Fees: HME security threat assessment fee: $86.50 (updated periodically; lower because HME doesn't require biometric enrollment separate from the CDL system); TWIC enrollment and STA fee: $124.00 (includes fingerprinting and biometric credential production; reduced to $91.75 for HME holders who already have a comparable STA on file with TSA)

    Part 1572 matters most to transportation workers when applications are denied or when an employer discovers an employee's credentials are at risk. TSA's denial process triggers rights: an Initial Determination of Threat Assessment must be served on the applicant, who then has 60 days to request a Final Determination review and, in some cases, an opportunity to appeal or apply for a waiver. The waiver process covers most interim disqualifying offenses and gives applicants the chance to demonstrate they no longer pose a security threat. Without a waiver, a CDL driver with a disqualifying offense loses the HME and cannot haul hazmat; a port worker loses access to secure areas and their employment. Recent rulemakings: 72 FR 3595 (January 2007) — original Part 1572 rule implementing the TWIC and HME programs; 78 FR 24359 (April 2013) — minor amendments.

Pending Legislation

  • HR 6507 — Standardize DHS grant deadlines, 30-day application windows, 54-month spending periods for port security grants. Status: In committee.
  • S 1541 (Sen. Kelly, D-AZ) — Boost U.S. shipbuilding with $20B Maritime Security Trust Fund, workforce upgrades, cargo-preference rules. Status: Introduced.
  • HR 2510 (Rep. Garbarino, R-NY) — Create U.S.-Israel-Greece-Cyprus counterterrorism and maritime security training program. Status: Introduced.

Recent Developments

  • Chinese-manufactured port cranes designated a national security threat: The Biden administration identified ship-to-shore cranes manufactured by ZPMC (Zhenhua Port Machinery Company, a subsidiary of Chinese state-owned COSCO Shipping) as a potential espionage and sabotage risk. Approximately 80% of large ship-to-shore cranes at major U.S. ports are ZPMC-manufactured; Coast Guard and CISA investigations found that crane control systems contained communications equipment capable of transmitting operational data. Executive Order 13873 (May 15, 2019) and subsequent directives required federal agencies to review and mitigate risks from Chinese-manufactured port infrastructure. The Port Infrastructure Development Program now prioritizes domestic or allied-nation crane sourcing for new acquisitions. ZPMC cranes already installed present a longer-term remediation challenge — replacing them involves multi-billion-dollar capital costs.
  • Coast Guard maritime cybersecurity authority expanded and exercised: The Maritime Transportation Security Act, as amended, now explicitly includes cybersecurity requirements in Facility Security Plans and Vessel Security Plans. The Coast Guard issued a cybersecurity marine safety information bulletin (MSIB) series and began incorporating cyber assessments into facility security inspections. A Coast Guard rulemaking to formalize cybersecurity requirements for Outer Continental Shelf facilities, vessels, and MTSA-regulated facilities is in progress as of 2026 — proposing standardized incident reporting, network segmentation requirements, and crew cybersecurity training for commercial vessels.
  • Francis Scott Key Bridge collapse (March 2024) tested port security and continuity protocols: The collapse of Baltimore's Francis Scott Key Bridge after a container ship allision closed the Port of Baltimore for weeks and blocked the Patapsco River channel. The incident tested the inter-agency coordination structure under MTSA — Coast Guard, MARAD, Army Corps of Engineers, FEMA, and state emergency management all engaged simultaneously. The port closure demonstrated the economic cascading effects when a major port is taken offline: approximately $100 million/day in cargo throughput disruption at peak. The incident renewed attention to bridge vulnerability assessments for bridges over navigable waterways, which the Coast Guard and Army Corps assess but cannot directly protect.
  • Container cargo inspection rates remain low despite screening advances: CBP's National Targeting Center pre-screens all manifest data for inbound containers, but physical examination rates for sea containers remain under 5% nationally. The Container Security Initiative inspects cargo at foreign ports before loading at origin; the Customs-Trade Partnership Against Terrorism (C-TPAT) certifies trusted importers for expedited processing. Despite technology advances in non-intrusive inspection (NII) equipment, the volume of container traffic (approximately 50 million TEUs per year) means that comprehensive physical inspection is operationally impossible. A radiological or chemical weapon concealed in a container remains one of the highest-consequence, lower-probability threat scenarios MTSA security frameworks are designed to detect.

At My Address

See how Maritime Port Security plays out in your area

Pull up the federal-data report for any U.S. ZIP, federal spending, environmental risk, hospitals, schools, your reps, all on one page.

Enter your address