Back to search
GovernmentHomeland Security & Emergency Management

TSA & Transportation Security

30 min read·Updated May 14, 2026

TSA & Transportation Security

The Transportation Security Administration (TSA) was created 69 days after the September 11 attacks by the Aviation and Transportation Security Act (ATSA, signed November 19, 2001) and is responsible for screening the approximately 850 million passengers and their baggage who fly through 440+ commercial airports each year in the United States. TSA employs roughly 50,000 transportation security officers — the blue-uniformed agents who staff airport checkpoints — making it one of the largest federal workforces. For most travelers, TSA's biggest practical impact is time: standard screening lines average 15–30 minutes at major airports, while TSA PreCheck enrollees (~25 million members, $78 for 5 years) typically clear in under 5 minutes using dedicated lanes without removing shoes, laptops, or liquids. Global Entry ($100/5 years) adds expedited customs reentry. REAL ID enforcement, fully phased in by 2025, means driver's licenses from compliant states (now all states) are required for domestic air travel — non-compliant IDs will be rejected. TSA also collects a $5.60 September 11 security fee per one-way trip, embedded in every airline ticket, generating approximately $4 billion annually for aviation security operations.

Current Law (2026)

ParameterValue
AgencyTransportation Security Administration (TSA), within DHS
TSA PreCheck enrollment fee$78 for 5 years
Global Entry$100 for 5 years
Passenger screeningAll airline passengers and carry-on baggage
Federal Air Marshal ServiceOperates on domestic and international flights
Surface transportationTSA has security authority over rail, transit, trucking, pipelines
VIPR teamsVisible Intermodal Prevention and Response — deployed to any transport mode
  • 6 U.S.C. § 1101-1104 — Transportation security definitions, training consortium, immunity for good-faith suspicious activity reports
  • 6 U.S.C. § 1112 — VIPR teams (Visible Intermodal Prevention and Response — deployable security teams for any transportation mode)
  • 6 U.S.C. § 1113 — Surface transportation security inspectors (training, hiring, compliance oversight)
  • 6 U.S.C. § 1114 — Security technology information sharing (sharing performance data on security technologies)
  • 6 U.S.C. § 1116 — National explosives detection canine team training program (expanding K-9 teams)
  • 6 U.S.C. § 1117 — Roles of DHS and DOT (Secretary of Homeland Security is the primary federal official for transportation security)
  • 6 U.S.C. § 1118 — Biometrics expansion (TSA and CBP biometric assessment report)
  • 6 U.S.C. § 1119 — Voluntary use of credentialing (TWIC card satisfies multiple security credential requirements)
  • 6 U.S.C. § 1115 — TSA personnel limitations (statutory workforce caps do not apply to employees performing duties required by the Implementing Recommendations of the 9/11 Commission Act)
  • 6 U.S.C. § 1131-1143 — Public transportation security (risk assessments, grant programs, training, exercises for transit systems)
  • 6 U.S.C. § 1142 — Public transportation employee protections (whistleblower protections for transit workers who report safety or security problems; retaliation prohibited)
  • 6 U.S.C. § 1161-1172 — Railroad security (national risk assessment and strategy; mandatory vulnerability assessments and security plans for high-risk railroads; Amtrak systemwide security upgrades; fire/life safety improvements; security training programs; background checks; international railroad security; model state legislation)
  • 6 U.S.C. § 1181-1186 — Over-the-road bus security (mandatory security assessments and plans for high-risk bus operators; grant program; security exercises and training; research and development)
  • 6 U.S.C. § 1201-1208 — Hazardous materials transportation security (railroad routing and tracking of security-sensitive materials; highway hazmat routing; motor carrier hazmat tracking; hazmat security inspections; transportation security card for hazmat licensing; pipeline security inspections and enforcement; pipeline security and incident recovery plans)

How It Works

TSA screens approximately 2.5 million passengers daily at 440+ airports — its most visible function — using document verification, physical screening (walk-through metal detectors or advanced imaging technology), and baggage inspection (X-ray and CT scanners). The Federal Air Marshal Service places armed officers on selected domestic and international flights. TSA PreCheck ($78 for 5 years) lets pre-vetted U.S. citizens and lawful permanent residents skip the shoe-removal, laptop-out routine; Global Entry ($100 for 5 years, managed by CBP) adds expedited customs processing on international returns; NEXUS and SENTRI serve cross-border travelers at Canadian and Mexican borders. Since May 2025, TSA has enforced full REAL ID requirements at checkpoints — a REAL ID-compliant state driver's license (look for the star), U.S. passport, or military ID is required to clear security; non-compliant travelers face additional screening or denial.

Beyond aviation, TSA's surface division covers passenger rail (Amtrak, commuter rail), mass transit, freight rail, over-the-road buses, trucking, and pipelines — but without universal passenger screening. Surface security instead relies on legally binding security directives for high-risk operators, vulnerability assessments, inspections, and Visible Intermodal Prevention and Response (VIPR) teams — mobile forces of TSA inspectors, Federal Air Marshals, behavior detection officers, and explosives detection canine units that deploy to train stations, bus terminals, ports, and special events. The 9/11 Commission Act (2007) established mandatory vulnerability assessments and security plans for high-risk railroads (§§ 1161-1172) and long-distance bus operators (§§ 1181-1186), including background checks for workers in security-sensitive positions and dedicated Amtrak security funding. Workers needing unescorted access to secure maritime port areas must hold a Transportation Worker Identification Credential (TWIC) — a $125.25 card requiring a security threat assessment — while hazmat truck drivers and pipeline workers require the Hazardous Materials Endorsement threat assessment (§§ 1201-1208). TSA conducts pipeline security inspections under § 1207 and requires operators to maintain security and incident recovery plans under § 1208 — authority that became critical after the Colonial Pipeline ransomware attack in 2021.

How It Affects You

<!-- pria:personalize type="impact" -->

If you fly commercially: The most immediately useful thing to know is that TSA PreCheck ($78 for 5 years, renewable online) will consistently save you 15–30 minutes at security in most airports. PreCheck lanes don't require removing shoes, laptops, belts, or light jackets — and they're almost always shorter than standard lanes. Global Entry ($100 for 5 years, through CBP) includes PreCheck plus expedited customs on international returns. Many travel credit cards reimburse the enrollment fee as a cardholder benefit. Since May 7, 2025, TSA enforces full REAL ID requirements at checkpoints — your state driver's license must be REAL ID-compliant (look for the star symbol in the upper corner) or you need an alternative: U.S. passport, military ID, or enhanced driver's license from certain states. Non-compliant travelers face additional screening or checkpoint denial. If your ID is non-compliant, apply for your state's REAL ID-compliant card (typically requires a birth certificate, Social Security card, and two proofs of address) or renew your passport. Also note: TSA's Credential Authentication Technology (CAT-2) facial recognition units are now deployed at approximately 400 airports. Participation is technically optional — you can request manual ID verification — but you need to ask proactively; the opt-out is not prominently offered. File complaints or feedback at tsa.gov/contact-center.

If you're a transportation worker who needs security credentials: TSA administers Security Threat Assessments (STAs) for several transportation worker credentials. The TWIC (Transportation Worker Identification Credential) — required for unescorted access to secure maritime port areas and certain vessels — costs $125.25, takes 7–9 weeks to process, and requires fingerprinting at an enrollment center (find one at tsa.gov/for-industry/twic). A criminal history check will screen for permanent disqualifying offenses (certain drug trafficking convictions, terrorism, murder) and temporary disqualifying offenses. If you're in trucking and carry hazardous materials, TSA administers the Hazardous Materials Endorsement threat assessment for CDL holders. Airport workers needing SIDA (Security Identification Display Area) badges go through airport-specific background check programs administered locally but subject to TSA standards (49 CFR Part 1542). If you're denied a credential, you have a right to appeal — the process is described in your denial notice. TSA's OmniConnect credentialing system tracks all worker credentials. For TWIC-specific issues, contact TSA's helpdesk at 1-866-DHS-2-TSA (1-866-347-2872).

If you operate a transit agency or rail system: TSA's surface transportation authority means you have mandatory obligations — not just optional resources. TSA security directives for passenger rail and transit are legally binding; failure to comply can result in civil penalties. TSA offers free Baseline Assessment for Security Enhancement (BASE) reviews — an onsite assessment of your system's security posture against TSA standards and best practices. Request a BASE review through your TSA regional transportation security inspector (find contacts at tsa.gov/for-industry/surface). Beyond BASE reviews, TSA's Intermodal Security Training and Exercise Program (I-STEP) provides free training and exercise support. Transit security grant funding flows through DHS's Homeland Security Grant Program (see Homeland Security Grants) — specifically the Transit Security Grant Program (TSGP), with applications through FEMA. Workers who report safety or security problems are protected from employer retaliation under 49 U.S.C. § 20109 (rail) and § 60130 (pipeline).

If you operate a pipeline or critical energy infrastructure: After the Colonial Pipeline ransomware attack in May 2021, TSA issued a series of security directives that transformed pipeline security from voluntary guidelines to mandatory compliance requirements. Current TSA pipeline security directives require: designation of a Cybersecurity Coordinator available 24/7; reporting of cybersecurity incidents to CISA within 24 hours; specific cybersecurity mitigation measures including network segmentation, access controls, and detection capabilities; and a Cybersecurity Incident Response Plan. TSA conducts pipeline security inspections under 49 U.S.C. § 1207 and can issue civil penalties for non-compliance. Pipeline operators must also maintain security and recovery plans under § 1208. Coordinate cybersecurity compliance with CISA, which receives the incident reports and provides threat intelligence. TSA's pipeline security guidance and directive updates are published at tsa.gov/for-industry/pipeline.

<!-- /pria:personalize -->

State Variations

TSA is a federal agency with nationwide authority — no state can override TSA security requirements. However, states interact with TSA in several ways:

<!-- pria:personalize type="state-specific" -->
  • Airport law enforcement: Local police provide law enforcement at airports; TSA provides screening
  • Transit security: State and local transit agencies implement TSA security directives
  • State opt-out: Airports may apply to use private screening companies instead of federal TSA screeners under the Screening Partnership Program (about 20 airports currently do this)
<!-- /pria:personalize -->

Implementing Regulations

  • 49 CFR Part 1544 — Aircraft Operator Security: Air Carriers and Commercial Operators (36 sections — the TSA's binding security requirements for every U.S.-certificated airline and commercial charter operator). Key provisions:

    • § 1544.101 — Adoption requirement: each scheduled passenger airline, public charter, and twelve-five operator (operators of aircraft with 12,500+ lb max certificated takeoff weight) must adopt and implement a security program meeting Part 1544's requirements; the Full Program (for scheduled carriers) is the most stringent, covering all of subparts C, D, and E
    • § 1544.103 — Security program content: each program must provide for the safety of persons and property on flights against criminal violence and air piracy; must include procedures for screening, access control, security coordinator designation, law enforcement support, and crew notification; programs are treated as Sensitive Security Information (SSI) — they are not public documents and may not be disclosed even to employees who don't have a need to know
    • § 1544.105 — TSA approval: each airline's security program must be submitted to and approved by TSA; TSA may require amendments; airlines must implement TSA-directed amendments within the timeframe TSA specifies — which may be immediate if TSA determines a threat requires urgent response
    • § 1544.201 — Passenger and carry-on screening: each aircraft operator must use measures in its security program to prevent the carriage of weapons, explosives, incendiaries, and other prohibited items; screening must be conducted before passengers board — the airline, not TSA, is the party directly responsible for compliance with Part 1544's screening requirements (TSA enforces those requirements against the airline)
    • § 1544.203 — Checked baggage screening: airlines must use explosives detection procedures for checked baggage before it is loaded; may not accept baggage that has not been screened per the security program
    • § 1544.205 — Cargo screening: airlines operating under the Full Program must ensure cargo is screened or accepted only from known shipper programs before loading; third-party screening under TSA-certified programs is permitted
    • § 1544.215 — Security coordinators: each airline must designate an Aircraft Operator Security Coordinator (AOSC) at the corporate level available 24 hours/day, 7 days/week; the AOSC is the airline's primary contact with TSA for security issues and coordinates with TSA, law enforcement, and airport security on security incidents
    • § 1544.219 — Carriage of accessible weapons by law enforcement: law enforcement officers with accessible weapons may travel on commercial flights under protocols in the security program; they must notify the pilot in command before boarding; Part 1544 is the federal authorization for armed law enforcement air travel
    • § 1544.221 — Prisoner transport: transport of prisoners under armed escort is permitted under specific conditions — the number of armed escorts, seating requirements, and prior airline notification requirements must be in the security program
    • § 1544.223 — Federal Air Marshals: airlines must transport Federal Air Marshals on duty status; the Air Marshal may carry an accessible weapon; airlines may not disclose the presence of an Air Marshal on a flight to anyone not with a need to know
    • § 1544.225 — Aircraft and facility security: airlines must use procedures in their security programs to control access to aircraft and related facilities (gates, jet bridges, ramp areas) — access must be limited to authorized persons; challenge procedures for unknown individuals in secure areas are required

    Part 1544 is the foundational post-9/11 aviation security mandate for airlines. The security programs required under Part 1544 are TSA's primary tool for ensuring that all scheduled carriers implement equivalent security baselines — eliminating the pre-9/11 variation in carrier security practices. Because the security programs themselves are SSI, travelers cannot review them, but their effects are visible at every departure gate: boarding pass checks, ID verification, aircraft access control, and crew notification protocols all flow from Part 1544 requirements. Airlines that fail to comply face civil penalties under 49 CFR Part 1503 (up to $15,000+ per violation per day) and, for systematic failures, security directives requiring immediate corrective action.

  • 49 CFR Part 1546 — Foreign air carrier security (security programs for foreign carriers operating in U.S.)

  • 49 CFR Part 1540 — Civil aviation security general rules (applicability, terms, inspection authority)

  • 49 CFR Part 1542 — Airport Security: the TSA's binding requirements for every commercial airport operator in the United States, requiring each airport to adopt and implement an Airport Security Program (ASP) approved by TSA. Key provisions:

    • § 1542.101 — General requirements: no person may operate an airport subject to § 1542.103 unless it adopts and carries out a TSA-approved security program; the ASP must provide for the safety of persons and property on aircraft and in airport areas against criminal violence and air piracy; this is the foundational requirement — without an approved ASP, an airport cannot legally host commercial air carrier operations
    • § 1542.103 — ASP content requirements: an airport's full security program must address all areas of airport security: (1) access control systems for the secured area and Air Operations Area; (2) security identification display area (SIDA) access and badge programs; (3) security awareness training for all airport workers with unescorted access to the AOA or SIDA; (4) law enforcement response planning; (5) incident reporting protocols; (6) challenge procedures for unknown individuals in secure areas; the ASP is treated as Sensitive Security Information (SSI) — it may not be shared publicly
    • § 1542.105 — TSA approval and amendments: the ASP must be submitted to and approved by TSA before the airport begins operations subject to the program; TSA may require amendments, including on short notice for newly identified threats; airports must implement TSA-directed amendments within TSA's specified timeframe
    • § 1542.107 — Changed conditions notification: after a program is approved, the airport must notify TSA when changes occur — including new terminal construction, modified access control systems, changes to secured area boundaries, or staffing changes — within specified timeframes; TSA uses these notifications to determine whether the existing ASP still adequately covers the airport's security posture
    • § 1542.111 — Exclusive area agreements: TSA may approve an amendment under which an aircraft operator or foreign air carrier assumes responsibility for specified security functions in its exclusive-use gate areas; this allows airlines to manage SIDA access and security personnel in their own terminal areas, reducing the airport operator's direct responsibility for those zones; exclusive area agreements must be in writing and approved by TSA
    • § 1542.113 — Airport tenant security programs: non-airline tenants (cargo handlers, food service operators, aircraft maintenance companies, rental car facilities with airside access) may be required to have their own tenant security programs approved by TSA and coordinated with the airport's ASP; tenant programs extend the ASP's access controls to every entity with airside access
    • § 1542.201 — Secured area / SIDA requirements: each airport must establish a secured area — the tarmac, taxiways, gates, and terminal zones requiring the highest access control; only personnel with appropriate SIDA badges may access without escort; the SIDA badge program requires 10-year criminal history record checks for all badge applicants; airports must implement perimeter access controls, challenge procedures for unknown persons, and security incident response protocols within the secured area
    • § 1542.203 — Air Operations Area (AOA) security: the AOA — the movement area and adjacent areas where aircraft operate — must be controlled to prevent unauthorized access; the AOA is typically less restricted than the secured area (certain ground vehicles and service personnel may access the AOA with more limited credentialing), but access must still be authorized and monitored

    Part 1542 and Part 1544 (airline security programs) are interdependent: the airport's ASP governs access to the airport's shared infrastructure (terminals, tarmac, perimeter), while each airline's security program governs its own gate operations and screening. TSA enforces both against the respective regulated entities. The 10-year criminal background check requirement for SIDA badge holders (§ 1542.209) is the standard that applies to the approximately 900,000 airport workers in the U.S. who hold SIDA access badges — the workforce backbone of commercial aviation security.

  • 49 CFR Part 1570–1572 — General rules and security threat assessments (credentialing and background checks for transportation workers). Part 1572 specifically governs the two major worker credentialing programs:

    • § 1572.103 — Disqualifying criminal offenses for both the Hazardous Materials Endorsement (HME) and Transportation Worker Identification Credential (TWIC): permanent disqualifying offenses include espionage, sedition, treason, terrorism, murder, federal or state explosives violations, and certain other violent crimes — these can never be waived; temporary disqualifying offenses include drug trafficking, extortion, arson, kidnapping, and certain firearms violations committed within the past 7 years — these disqualify an applicant for 7 years after conviction or release, whichever is later; a prior "not guilty by reason of insanity" finding also disqualifies
    • § 1572.105 — Immigration eligibility: applicants must be U.S. nationals, lawful permanent residents, refugees, asylees, or other specified non-immigrant categories; undocumented individuals and those whose status is uncertain do not qualify for either the HME or TWIC
    • § 1572.15 — HME Security Threat Assessment (STA) procedures: every CDL holder who wants to transport hazardous materials requiring placarding must submit to TSA's fingerprint-based criminal history records check (CHRC), intelligence check, and immigration check; states must require the STA before issuing or renewing the hazmat endorsement; disqualified applicants lose their HME and must surrender it to the state; TSA charges a fee (see Subpart E) currently approximately $86.50 per STA, paid to TSA or to the state if it collects fingerprints
    • § 1572.17/1572.21 — TWIC STA procedures: applicants for a TWIC (required for unescorted access to secure maritime port areas, outer continental shelf facilities, and certain vessels) must submit biographical data, fingerprints, and consent to all three background checks; TSA's OmniConnect system manages TWIC enrollment; approved applicants receive a smart card credential with biometric (fingerprint) data embedded; TWICs are valid for 5 years (§ 1572.23) and must be renewed before expiration; TSA charges a separate TWIC fee (Subpart F) currently approximately $125.25
    • § 1572.107 — Other screening analyses: TSA may deny credentials based on searches of Interpol databases, terrorist watchlists and related databases, state and local law enforcement records, and foreign government records — threat analysis is not limited to formal criminal convictions; TSA may also obtain waiver-ineligible threat information from intelligence community sources
    • § 1572.109 — Mental capacity: an applicant who has been adjudicated as lacking mental capacity or involuntarily committed to a mental health facility is disqualified; the disqualification can be waived upon evidence of restoration of rights or mental capacity

    The HME program applies to approximately 1.7 million CDL holders who carry hazardous materials placards. The TWIC program covers approximately 2.6 million workers at U.S. seaports, liquefied natural gas facilities, and related maritime locations. Both programs are administered through TSA's Identity Verification Service, which connects to the FBI's CHRC system and DHS's watchlist databases. A worker denied a credential has the right to correct erroneous records (through CHRC review or FBI fingerprint amendment) and may seek a waiver for temporary disqualifying offenses if the threat the offense poses is outweighed by the applicant's need for the credential. TWIC reader regulations (49 CFR Part 1585, finalized 2016) require high-risk vessels and maritime facilities to actively verify TWICs using card readers rather than visual inspection alone.

  • 49 CFR Part 1503 — Investigative and enforcement procedures: TSA's civil penalty process for violations of its security regulations. Key provisions:

    • § 1503.201 — Reports of violations: any person who knows of a TSA security requirement violation should report it to TSA field personnel; TSA may also initiate investigations on its own initiative
    • § 1503.203 — Investigations: the TSA Administrator (or a designated official) may conduct investigations, hold hearings, issue subpoenas, and require testimony under oath; TSA inspectors have authority to enter and inspect regulated facilities during reasonable hours
    • § 1503.301 — Warning notices and letters of correction: when a violation does not warrant a civil penalty (first-time, minor, or technical violation), TSA may issue a warning notice; letters of correction are used when the person corrects the deficiency before TSA initiates formal penalty action
    • § 1503.401 — Maximum civil penalty amounts: civil penalties for violating TSA requirements can reach $10,000–$15,000 per violation per day for individuals and substantially more for operators; the exact cap depends on the category of violation (aviation security vs. surface transportation vs. hazmat) and is adjusted for inflation under the Federal Civil Penalties Inflation Adjustment Act
    • § 1503.413 — Notice of Proposed Civil Penalty (NOCP): TSA commences formal civil penalty proceedings by serving a Notice of Proposed Civil Penalty specifying the alleged violation, the facts underlying it, and the amount proposed; the respondent has 30 days to respond by requesting an informal conference, paying the proposed penalty, or requesting a formal hearing
    • § 1503.421 — Streamlined civil penalty procedures: for certain categories of minor security violations (prohibited items at checkpoints, specific access control violations), TSA may use a streamlined Notice of Violation process — a faster, lower-cost process capped at $10,000 per violation with limited formal hearing rights; TSA uses these for the most common checkpoint infractions
    • Subpart G — Rules of Practice in TSA Civil Penalty Actions: formal civil penalty cases (above the streamlined threshold) are heard by an ALJ under APA § 554; parties may present evidence, call witnesses, and cross-examine; the ALJ issues a decision subject to appeal to the full Department of Transportation and then to federal circuit court

    Civil penalties are TSA's primary enforcement lever against regulated entities — airlines, airports, hazmat carriers, pipeline operators, and transit systems. For individual travelers, penalty amounts are much smaller (typically $250–$2,000 for prohibited items), and TSA routinely resolves checkpoint violations through warning notices rather than formal proceedings. For operators with systematic non-compliance, the formal NOCP-to-ALJ pipeline can take 12–18 months but can result in orders requiring systemic remediation as well as financial penalties.

  • 49 CFR Part 1560 — Secure Flight Program: TSA's pre-departure passenger watchlist screening program — the system through which every airline passenger on domestic and international flights is screened against the Terrorist Screening Dataset (TSD) before boarding. Secure Flight replaced the pre-2009 system under which airlines themselves performed their own watchlist screening with inconsistent results:

    • § 1560.101 — Passenger information collection: covered aircraft operators (all U.S. domestic carriers and international carriers serving U.S. airports) must collect full legal name (as it appears on government ID), date of birth, sex, and the passenger's Redress Number (if any) and transmit this Secure Flight Passenger Data (SFPD) to TSA via secure electronic connection before departure; operators must collect this information at the time of reservation, during check-in, or as soon as practicable; passengers who decline to provide the required information may be denied boarding; the collection and transmission occurs invisibly to most passengers — the information flows automatically from the airline's reservation system to TSA's matching system
    • § 1560.105 — Watch list matching results and actions: TSA compares each passenger's data against the TSD (which contains the No Fly List, Selectee List, and broader terrorism and law enforcement watchlist records); TSA provides the airline one of three results: (1) Cleared — the passenger may proceed to check-in and board; (2) Designated for Enhanced Screening (SSSS) — the passenger must receive additional physical screening at the checkpoint but may board; (3) Inhibited — TSA instructs the airline to deny the passenger a boarding pass; the criteria for each result are classified; airlines must follow TSA's result and may not override it
    • § 1560.107 — Restricted use of results: airlines must use Secure Flight matching results only for purposes authorized by TSA (allowing or denying boarding and providing enhanced screening) and may not use them for any commercial purpose, share them with unauthorized parties, or retain them beyond the period TSA specifies; the results are government intelligence information shared on a restricted basis
    • § 1560.205 — Redress process: a passenger who believes they were improperly denied boarding, designated for enhanced screening, or otherwise affected by Secure Flight may submit a redress request to DHS through the Traveler Redress Inquiry Program (DHS TRIP) at trip.dhs.gov; DHS TRIP reviews whether the person was correctly matched against a watchlist entry or was incorrectly matched (a "false positive" — a common traveler with a name similar to a listed individual); DHS TRIP can issue a Redress Number that travels with the passenger's reservation to prevent recurring false positive matches; the redress process is confidential — TSA will neither confirm nor deny whether a specific individual is on the No Fly List

    Secure Flight is one of the highest-volume government watchlist screening programs in the world — TSA processes approximately 900 million passenger records per year against the TSD. False positive matches (innocent travelers with names similar to listed persons) are the program's primary civil liberties concern; the Redress Number system was created specifically to address this. The No Fly List (subset of TSD) is estimated to contain under 10,000 individuals; the full TSD contains far more. Travelers who cannot resolve a Secure Flight issue through DHS TRIP may challenge their placement through the courts — litigation about watchlist inclusion procedures continues. Recent changes: TSA updated the SFPD transmission requirements in 2018 to require earlier transmission (at time of reservation for many booking channels) to maximize lead time for watchlist checks.

  • 49 CFR Part 1510 — Passenger Civil Aviation Security Service Fees: establishes the September 11th Security Fee — the $5.60 per one-way trip fee that appears on every domestic airline ticket to fund TSA's aviation security operations:

    • § 1510.5 — Imposition of fee: every direct air carrier and foreign air carrier must collect a $5.60 per one-way trip security service fee from each passenger on flights originating at an airport in the United States; the fee applies to each one-way segment separately — a round trip generates two $5.60 charges; a multi-stop itinerary generates one fee regardless of the number of connections, as long as the routing is one "one-way trip" (no overnight stop)
    • § 1510.7 — Advertising requirement: airlines must identify this fee as the "September 11th Security Fee" in all advertisements and solicitations for air transportation; the specific label is mandated — airlines cannot substitute generic "security fee" language; this naming requirement ensures passengers understand what the fee funds
    • § 1510.9 — Who must collect: direct air carriers and foreign air carriers operating scheduled or public charter operations with aircraft having 61 or more passenger seats must collect the fee; codeshare arrangements, commuter flights, and charter operations below the seat threshold are exempt
    • § 1510.11 — Safekeeping: airlines are responsible for safeguarding collected fees from the moment of collection; the fee is held in trust for TSA — it is federal money, not airline revenue, from the moment it is collected; airlines that commingle security fees with operating funds or use them for other purposes violate the rule
    • § 1510.13 — Remittance: airlines must remit all security fees collected in each calendar month to TSA by the last calendar day of the following month; fees are remitted as directed by TSA (electronic transfer); late remittance triggers interest and may constitute a violation subject to enforcement under 49 U.S.C. § 41712 (unfair and deceptive practices)
    • § 1510.15 / 1510.17 — Accounting and reporting: airlines must maintain separate accounting records for security fees collected, refunded, and remitted; quarterly reports to TSA provide a full reconciliation; TSA auditors may inspect records at any time

    The September 11th Security Fee was created after the 9/11 attacks to partially offset the massive expansion of federal aviation security (the creation of TSA, hardened cockpit doors, explosive detection equipment). At $5.60 per one-way segment, the fee generates approximately $4–5 billion annually — covering roughly 30-40% of TSA's annual budget, with the remainder coming from general appropriations. Congress set the fee level through statute (49 U.S.C. § 44940); the current rate was last adjusted by the Consolidated Appropriations Act of 2014. The HR 7941 (Pay TSA Act of 2026) would dedicate the fee revenue to a DHS trust fund specifically for TSA during government shutdowns, preventing TSA from having to operate without pay during funding lapses.

  • 49 CFR Part 1549 — Certified Cargo Screening Program (CCSP): the TSA program that allows third-party facilities to screen air cargo destined for passenger aircraft, part of the 100% cargo screening mandate for U.S. passenger flights:

    • § 1549.5 — Security program requirement: no person may screen cargo for passenger aircraft under the CCSP without an approved security program from TSA; facilities apply for TSA certification by submitting a security program describing their screening procedures, equipment, personnel security measures, and training; TSA reviews the program and issues a certification allowing the facility to screen cargo as a Certified Cargo Screening Facility (CCSF) — a CCSF certification allows a shipper, manufacturer, freight forwarder, or third-party logistics provider to screen cargo at their own facility before handing it to the airline
    • § 1549.7 — Certification process: the initial application must describe the facility layout, screening equipment types, personnel rosters with security roles, and the specific screening methods (X-ray, ETD, physical examination, etc.); TSA may inspect the facility before approving the program; certifications must be renewed; material changes to facilities or procedures require TSA approval of an amendment; the full certification must be renewed on a regular cycle
    • § 1549.101 — Screening requirements: each certified facility must screen cargo using the methods specified in its security program to prevent or deter explosive or incendiary devices from being carried aboard passenger aircraft; cargo that has been screened must be maintained in a "chain of custody" — physically secured from screening through tender to the aircraft operator to prevent tampering; if the chain of custody is broken (e.g., screened cargo is left unsecured), the cargo must be re-screened
    • § 1549.103 — Personnel qualifications: individuals authorized to perform cargo screening at a CCSF must pass a Security Threat Assessment (STA) — a background check administered by TSA; individuals with disqualifying criminal histories or terrorism connections may not perform cargo screening; the STA requirement creates a vetted workforce of cargo screeners throughout the supply chain, not just at the airport
    • § 1549.111 — Security threat assessments: the facility must maintain records of STAs for all personnel authorized to screen cargo, and must immediately remove individuals whose STA is revoked or who become disqualified

    The CCSP was created as part of the Implementing Recommendations of the 9/11 Commission Act of 2007, which required TSA to achieve 100% screening of cargo transported on passenger aircraft. Without the CCSP, airlines would be required to screen all incoming cargo at the airport — operationally impossible given cargo volumes. The CCSP allows cargo to be screened further upstream in the supply chain, reducing airport congestion while maintaining security. As of 2026, thousands of facilities are certified under the CCSP, creating a distributed cargo screening network. Recent rulemakings: 74 FR 47706 (September 2009) — original CCSP rule; 76 FR 51868 (August 2011) — amended requirements.

  • 49 CFR Part 1552 — Flight Training Security Program (FTSP): TSA's post-9/11 framework requiring background checks for all individuals seeking flight training in the United States — citizen and non-citizen alike. The hijackers who executed the September 11 attacks received flight training in U.S. flight schools, prompting Congress to mandate comprehensive vetting of anyone seeking to learn to fly:

    • § 1552.7 — Training prohibition: no flight training provider may provide any flight training — ground school, simulator time, or aircraft instruction — until the candidate's eligibility has been established; a provider that begins training before completing the eligibility check is in violation regardless of whether the candidate ultimately passes the background check
    • § 1552.9 — Security Coordinator: each flight training provider must designate a Security Coordinator at the corporate level responsible for managing FTSP compliance, maintaining communication with TSA, and ensuring that all employees with direct student contact receive security awareness training (§ 1552.13)
    • § 1552.17 — FTSP Portal: all interactions between candidates, providers, and TSA occur through the FTSP Portal — a TSA-managed web system; candidates initiate background check requests through the portal; providers notify TSA of all proposed and completed training events (§ 1552.51); fees are paid through the portal (§ 1552.39)
    • § 1552.31 — Security Threat Assessment (STA): every candidate — whether a U.S. citizen, lawful permanent resident, or foreign national — must complete an STA and receive a TSA Determination of Eligibility before beginning flight training; STAs screen for terrorism connections, criminal history, and immigration status; U.S. citizens and nationals receive streamlined review; non-citizen candidates face more extensive checks; TSA may accept equivalent background checks conducted by other U.S. government agencies (§ 1552.37)
    • § 1552.35 — Presence in the United States: non-citizen candidates must be lawfully present in the United States and within their period of authorized stay at the time of training; training a candidate who has overstayed a visa or whose immigration status is lapsed is a violation

    The FTSP applies to all flight training providers — from large commercial academies training thousands of students per year to single-aircraft operators offering private pilot instruction. A "candidate" under Part 1552 includes any individual seeking flight training, whether a U.S. citizen or foreign national — the background check requirement is universal, though the depth of review differs. Providers must maintain recordkeeping sufficient to demonstrate TSA compliance (§ 1552.15) and must notify TSA of every training event, not just initial enrollments. Recent rulemakings: 89 FR 35626 (2024) — restructured FTSP regulations; 91 FR 7161 (2026) — most recent amendment updating portal and notification requirements.

  • 49 CFR Part 1515 — Appeal and Waiver Procedures for Security Threat Assessments (6 sections — TSA's administrative due process framework for individuals who have received an Initial Determination of Threat Assessment in connection with transportation worker credentials, implementing 49 U.S.C. § 114 and 46 U.S.C. § 70105):

    A Security Threat Assessment (STA) is TSA's determination about whether an individual poses a security risk based on criminal history, immigration status, or other factors. STAs are required for a wide range of transportation credentials: hazardous materials (hazmat) endorsements for commercial truck drivers, Transportation Worker Identification Credentials (TWIC) for port workers, flight crew credentials, and others. When TSA issues an Initial Determination of Threat Assessment (finding that the person poses a security risk), the person loses or is denied the credential. Part 1515 is the appeal pathway.

    • § 1515.5 — Appeal of Initial Determination based on criminal conviction, immigration status, or mental capacity: an applicant who receives an Initial Determination may appeal by providing TSA with materials establishing that the factual basis for the determination is erroneous (e.g., the criminal conviction was expunged, the immigration status has changed, or the mental health commitment has been lifted); TSA reviews the submission and either confirms or withdraws the determination; this is the first-level administrative review
    • § 1515.7 — Waiver procedures: an applicant who cannot contest the factual basis for an Initial Determination (because the conviction, immigration status, or other disqualifier is accurately stated) may instead apply for a waiver — a discretionary TSA determination that the security risk posed by the individual is sufficiently mitigated by other factors; waiver applications must provide personal statement, criminal history documentation, evidence of rehabilitation, character references, and information about the specific transportation credential sought; TSA weighs the nature and recency of the disqualifying factor against evidence of rehabilitation and the specific security risks of the credential position
    • § 1515.9 — Review by administrative law judge: an applicant who is denied a waiver under § 1515.7 may request review by a TSA Administrative Law Judge (ALJ); the ALJ proceeding is in addition to the discretionary waiver review and provides a formal hearing track; the ALJ reviews TSA's denial under an abuse of discretion standard; the ALJ proceeding is the second-level of appeal within TSA's administrative process
    • § 1515.11 — ALJ decision and TSA Final Decision Maker: the ALJ issues an initial decision; either party may appeal to the TSA Final Decision Maker (typically a senior TSA official); the Final Decision Maker's decision is the final agency action subject to judicial review; an applicant who loses at the Final Decision Maker level may seek review in federal court under the APA

    Part 1515 matters enormously to the transportation worker community. A truck driver who loses a hazmat endorsement because of a decades-old drug conviction cannot haul hazardous materials — a significant portion of freight work. A port worker denied a TWIC card cannot access secure areas of ports — effectively ending their career. The waiver process is the main avenue for workers with old or minor disqualifying records to restore their credentials, and Part 1515 is the procedural framework that governs whether they get a fair hearing.

  • 49 CFR Part 1554 — Aircraft Repair Station Security (6 sections — TSA's security program requirements for FAA-certificated aircraft repair stations under 49 CFR Part 145, covering the maintenance facilities where commercial aircraft are serviced and where security vulnerabilities could allow unauthorized modifications or access to aircraft):

    • § 1554.1 — Scope: applies to all FAA Part 145-certificated repair stations except those on U.S. or foreign government military installations; covers both U.S.-located stations and foreign stations that perform maintenance on U.S.-registered aircraft or on aircraft serving U.S. carriers
    • § 1554.101 — Security measures: stations located on an airport's air operations area (AOA) or security identification display area (SIDA) must implement security measures consistent with the airport security program under Part 1542; stations on security restricted areas of foreign airports serving U.S. carriers must implement comparable measures; the key requirements include access control procedures, personnel identification, and reporting of security incidents to TSA; stations located off-airport premises face fewer mandatory security measures but must still implement basic access controls and worker vetting consistent with TSA's standards
    • § 1554.103 — Security directives: when TSA determines that additional security measures are necessary in response to a threat assessment or specific threat against civil aviation, TSA issues Security Directives to repair stations; stations must comply with each Security Directive and may not disclose its contents (Security Directives are SSI); this authority allows TSA to impose immediate security requirements without going through notice-and-comment rulemaking — a flexibility critical in fast-moving threat environments
    • § 1554.201 — Suspension of FAA certificate for security deficiencies: TSA's most powerful enforcement tool for repair stations is not a TSA-issued penalty but a recommendation to the FAA — if TSA identifies security deficiencies that a station fails to correct after notification, TSA notifies both the station and the FAA; the FAA may suspend the repair station's Part 145 certificate; loss of FAA certification ends the station's ability to perform authorized maintenance on U.S.-registered aircraft — a far more severe consequence than any civil monetary penalty TSA could impose directly
    • § 1554.203 — Immediate revocation for immediate risk: if TSA determines a repair station poses an immediate risk to security (a higher threshold than mere deficiency), TSA notifies both the station and the FAA of the determination; the FAA may immediately revoke the repair station's certificate; the immediate revocation pathway bypasses the opportunity-to-correct step — reflecting the heightened urgency of an imminent threat at an aviation maintenance facility

    Part 1554 closes a significant vulnerability: an aircraft undergoing maintenance is at its most accessible — disassembled, on jacks, with technicians carrying out work in areas not normally reachable. Unauthorized access to a repair station could allow tampering with aircraft systems, installation of prohibited devices, or sabotage. The TSA/FAA joint enforcement structure — where TSA identifies the security deficiency and FAA pulls the certificate — creates accountability while respecting the FAA's primary jurisdiction over aircraft maintenance certification.

Pending Legislation

  • HR 7941Pay TSA Act of 2026: locks 9/11 Security Fee into DHS trust fund for TSA, funding available during lapses. Status: Introduced.

Recent Developments

TSA has been deploying Credential Authentication Technology (CAT) units that use facial recognition to verify traveler identity at checkpoints — reducing reliance on manual document checking. CT scanners are replacing legacy X-ray machines for carry-on baggage, allowing passengers to leave electronics in bags. TSA PreCheck enrollment has expanded to include online renewal and more enrollment locations.

The Trump FY2027 budget proposed cutting TSA funding and requiring privatization of security operations at small airports, reigniting debate over the federal role in aviation security screening.

  • REAL ID full enforcement at TSA checkpoints (May 2025): TSA implemented full REAL ID enforcement at airport security checkpoints on May 7, 2025. Travelers without a REAL ID-compliant state ID, enhanced driver's license, or acceptable alternative (passport, military ID) face additional screening procedures or denial of checkpoint access. The first weeks of enforcement produced significant disruption at major airports, with long lines and travelers learning their state IDs were non-compliant. TSA estimated 25-30% of travelers attempted to use non-compliant IDs in the first month; most had passports or other acceptable alternatives, but a meaningful fraction required enhanced screening resolution.
  • Facial recognition expansion and privacy concerns: TSA's Credential Authentication Technology (CAT) units with facial recognition capabilities have been deployed at approximately 400 airports as of 2026. The CAT-2 units use live facial capture matched against photo IDs and CBP traveler databases. TSA maintains that facial recognition use is optional — travelers may request manual ID verification. However, opt-out rates are very low in practice, and civil liberties organizations (ACLU, EFF) have documented that "optional" facial recognition becomes effectively mandatory given social and time pressure at security checkpoints. Congress has considered legislation requiring affirmative consent for biometric capture at TSA checkpoints; no bill has passed.
  • Air Marshal program and staffing review: DOGE reviewed the Federal Air Marshal Service (FAMS) as a high-cost, potentially redundant program. FAMS employs approximately 2,500 air marshals at significant cost (approximately $500,000 per marshal annually including training, travel, and benefits); DHS has studied whether diverting those resources to hardened cockpit door requirements and armed pilot programs would achieve equivalent security outcomes. The Trump administration proposed reducing FAMS staffing while expanding armed pilot training; airlines and pilot unions have mixed views on armed flight deck officers. No final decision on FAMS restructuring has been announced.
  • TSA PreCheck and Global Entry expansion: TSA PreCheck enrollment reached approximately 25 million members as of 2026; CBP's Global Entry (which includes PreCheck) has 15 million members. The OBBBA included a provision allowing TSA PreCheck enrollment fees to be paid through HSA and FSA accounts (as qualifying security-related travel expenses), reducing the after-tax cost of enrollment. TSA has partnered with airlines and credit card companies for complimentary PreCheck enrollment offers, accelerating program growth. TSA's automated PreCheck screening (removing shoes/belts only for standard screening, not for PreCheck lanes) has significantly improved throughput at major hub airports.

At My Address

See how TSA & Transportation Security plays out in your area

Pull up the federal-data report for any U.S. ZIP, federal spending, environmental risk, hospitals, schools, your reps, all on one page.

Enter your address