Insight

Deadline to Comment on TSA Proposed Rule on Enhancing Cyber Risk Management for Surface Transportation Sectors

Client Alerts

On November 7, 2024, the Transportation Security Administration (the “TSA”) published a Notice of Proposed Rulemaking (the “Proposed Rule”) that would mandate cyber risk management (“CRM”) and reporting requirements for certain surface transportation owners and operators, including certain pipeline, freight railroad, passenger railroad, rail transit, and over-the-road bus owners and operators. Comments to the Proposed Rule are due by February 5, 2025.

The TSA aims to strengthen cybersecurity and resiliency for the surface transportation sector following the 2021 ransomware attack on the Colonial Pipeline by mandating the reporting of cybersecurity incidents to the TSA and Cybersecurity and Infrastructure Security Agency (“CISA”), as well as the development of a robust CRM program.

The Proposed Rule is based on the TSA’s previously issued requirements and recommendations, the cybersecurity framework developed by the National Institute of Standards and Technology, and the cross-sector cybersecurity performance goals developed by CISA.

The Proposed Rule would require, in addition to other requirements, covered owners and operators to:

  • Have a TSA-approved CRM program;
  • Conduct annual enterprise-wide cybersecurity evaluations;
  • Develop a Cybersecurity Operational Implementation Plan which identifies who is responsible for the governance of the CRM program, have detailed measures to protect and monitor critical cyber systems, and have continuity plans for these critical systems; and
  • Establish a Cybersecurity Assessment Plan that includes the identification of unaddressed vulnerabilities and the reporting of annual assessment results.

Both physical security incidents and cybersecurity incidents would need to be reported. The Proposed Rule builds on previously issued security directives, which are emergency regulations that the TSA may issue without providing notice or soliciting public comment. Security directives are only effective up to 90 days unless ratified by the Transportation Security Oversight Board. The TSA estimates the Proposed Rule would impact approximately 300 surface transportation owners and operators, including 115 pipeline facilities.

Given the potential compliance burden and rapidly approaching end of the comment period, industry stakeholders should evaluate how the proposed new CRM requirements align with their existing security.

The Vinson & Elkins Technology Transactions team assists clients in identifying, managing, and mitigating cybersecurity risks and managing incident response and resulting investigations and litigation. If you have questions, please contact your V&E attorney.


This information is provided by Vinson & Elkins LLP for educational and informational purposes only and is not intended, nor should it be construed, as legal advice.

Discover our latest:

Insights

CLE Events

Texas Reincorporation 101: Recent Developments and Key Considerations for Boards

Join Vinson & Elkins and FTI Consulting for a webinar on the growing trend of companies reincorporating to Texas.

October 1, 2026

October 1, 2026 • 1-minute read

CLE Events

Financing and Bankability of Data Center Projects

This program will examine the key legal and commercial considerations for financing data center projects, with a focus on what makes these projects bankable for lenders and investors.

September 29, 2026

September 29, 2026 • 1-minute read

Events

Paige Anderson to Speak on BARBRI Webinar

Partner Paige Anderson will speak on BARBRI’s live video CLE program, “Mastering Public and Private REITs: Key Tax, Structuring, Financing, …

September 22, 2026

September 22, 2026 • 1-minute read

Events

Paige Anderson and Vinay Prabhakar to Present on REIT Tax and Data Centers in Upcoming myLawCLE Webinar

Partners Paige Anderson and Vinay Prabhakar will present on myLawCLE’s live CLE program, “REIT Tax in the Data Center Era: …

September 18, 2026

September 18, 2026 • 1-minute read

Articles

Four Antitrust Pathways to AI Lab Coordination

The debate over AI lab coordination has collapsed into a false binary. There are at least four paths forward. In …

September 17, 2026

September 17, 2026 • 8-minute read

News & Achievements
V&E

Get in Touch

Thoughts or questions? Send us a note, and we’ll connect you with the right person.

The ESG GC: How Your Role as Chief Legal Officer is Integral To Your Company’s ESG Efforts Background Image