Pipeline security directives, answered with evidence instead of effort
Since 2021, pipeline operators have had to prove their OT cybersecurity to the TSA every year. SecurityGate.io turns that proof into a repeatable assessment program across every station, terminal and control room.
One IT breach changed the rules for every pipeline
In May 2021, ransomware hit the business network of Colonial Pipeline, the largest refined fuel pipeline in the United States. The attackers never touched the pipeline controls, yet the operator shut the line down for several days because it could not be sure the OT side was safe.
The lesson for regulators was blunt: separation between IT and OT had to be proven, not assumed. Security directives followed within weeks.
- May 2021
Ransomware reaches the business network
Operations are halted as a precaution. Fuel supply along the East Coast is disrupted.
- May 2021
First TSA directive
Operators must name a cybersecurity coordinator, report cybersecurity incidents to CISA, and review their current practices against guidance.
- July 2021
Second directive series begins
Mandatory mitigation measures for designated pipeline owners and operators, focused on OT.
- 2022 onward
Performance-based requirements
The directive is reissued in performance-based form and renewed each year, with an implementation plan and an annual assessment plan submitted to TSA.
- Every year
Prove it again
Assessment results, remediation status and evidence have to be current each cycle, across every in-scope site.
Your annual assessment cycle, before and after
The same directive obligations, handled two ways. The difference is not the effort of one assessment. It is whether next year starts from zero.
| Stage | Spreadsheet program | On SecurityGate.io |
|---|---|---|
| Assess each site | Consultant visits, questionnaires emailed around, answers pasted together. | Directive-aligned assessments run remotely per site, with evidence attached to each answer. |
| Find the gaps | Gaps listed in a report that is out of date by the time it is approved. | Controls are mapped to threats and impact automatically, so priorities are visible at once. |
| Fix and verify | Action items tracked in email and meeting notes. | Remediations assigned with owners and due dates, then validated before they close. |
| Report to TSA and leadership | Weeks of assembling slides and appendices. | Board-ready reporting by site, function and geography, current at any moment. |
| Next year | Start again. | Re-run the same assessment and compare against last cycle. |
Four outcomes you must be able to show
The performance-based directives describe outcomes rather than products. Each one needs to be assessed at every in-scope site and documented in a way an inspector can follow.
Segmentation
OT keeps running safely even if the IT network is compromised.
Access control
Only authorized people and systems reach critical cyber systems.
Monitoring and detection
Threats and anomalies on critical systems are detected and acted on.
Patching and hardening
The risk from unpatched systems is reduced on a defined timeline.
Operators also maintain a cybersecurity incident response plan and an assessment program that tests whether these measures work.
Built for distributed, hard-to-reach assets
Remote by design
Compressor stations, pump stations and terminals are assessed without sending a team to each one, and without disrupting operations.
Suppliers in the same loop
Integrators and service providers with access to your OT answer the same questions on the same platform through third-party risk assessments.
Open to your tools
An open API, plus integrations such as Tenable and Atlassian cloud products, keeps remediation where your teams already work.
your IT provider sets up your in-scope sites, runs the first directive assessments with your operations team, and keeps the remediation and reporting cycle moving so each annual submission builds on the last.
Make this year's directive assessment the last one you build from scratch
Directive history per TSA public announcements. Vendor figures per securitygate.io, September 2026.
Get in touch with Your Company
Questions about this solution? Reach us directly.