As of July 28, 2023, Congress has allowed the statutory authority for the Chemical Facility Anti-Terrorism Standards (CFATS) program (6 CFR Part 27) to expire. Therefore, CISA cannot enforce compliance with the CFATS regulations at this time.
Due to this lapse in statutory authority, CISA cannot enforce compliance with the CFATS regulations.
Access to the Chemical Security Assessment Tool (CSAT) 2.0 has been removed, and users cannot log in to the portal.
Unless CFATS is reauthorized, CISA can no longer:
- require facilities to report their chemicals of interest,
- submit any information in CSAT,
- perform inspections, or
- provide CFATS compliance assistance
Additionally, CISA can no longer require facilities to implement their CFATS Site Security Plan or Alternative Security Program.
CISA also cannot accept new names for vetting pursuant to the CFATS Personnel Surety Program.
Notwithstanding the expiration of CFATS, CISA encourages facilities to maintain security measures.
CISA’s voluntary ChemLock resources are available at cisa.gov/ChemLock.
If CFATS is reauthorized, CISA will follow up with your facility in the future. CISA is hosting two webinars for the stakeholder community to discuss the expiration of the CFATS program. The contents of the webinars will be the same.
Webinar 1: Thursday August 3rd, 1PM ET.
Webinar 2: Tuesday, August 8th, 10AM ET.
Registration for these webinars
If CFATS is reauthorized, CISA will follow up with facilities in the future. To reach us, please contact [email protected]
FAQs on CFATS Lapse in Authorization
Q1: When can I access the Chemical Security Assessment Tool (CSAT)?
A1: Access to CSAT has been shut down. If you require access to information stored in the CSAT system, please contact
[email protected] for assistance.
Q2: I have an inspection scheduled. Will that inspection be cancelled?
A2: CISA is contacting facilities to cancel scheduled inspections on a rolling basis. Most facilities will be contacted approximately one to two weeks in advance of the scheduled date. If CFATS is reauthorized before your inspection is cancelled, CISA may move forward with your scheduled inspection date. If you have any questions or concerns, please email
[email protected].
Q3: Will my facility still be subject to regular inspections in the future?
A3: Since the statutory authority for CFATS has expired, CISA cannot perform Authorization or Compliance Inspections at this time. If CFATS is reauthorized by Congress, CISA will follow up with your facility in the future.
Q4: I received a notice to review a [letter/survey] in CSAT. Do I still need to review it?
A4: No, not at this time. Access to CSAT has been shut down since the statutory authority for CFATS expired. If CFATS is reauthorized, CISA will follow up with your facility in the future.
Q5: Will my facility’s information still be protected as Chemical-terrorism Vulnerability Information (CVI)?
A5: CISA does not have the authority to enforce the CFATS regulations, which include the provisions for protecting CVI from public disclosure. At this time, no newly developed information can be designated (and protected) as CVI. With regard to pre-existing information, CISA is continuing to handle and safeguard all information in CISA’s possession that was designated as CVI prior to the lapse of the CFATS statutory authority consistent with CISA’s previously established CVI protection regime until further notice. The agency encourages its chemical security stakeholders to continue to appropriately safeguard information that can be exploited by an adversary in furtherance of an act utilizing or against dangerous chemicals. If you receive a request to obtain or divulge any of your information that was previously designated as CVI, or if you have specific questions, you are welcome to email
[email protected].
Q6: I need to submit [a Top-Screen/SVA/SSP/ASP/EAP/PSP info]. How do I submit if the CSAT Portal is shut down?
A6: Since the statutory authority for CFATS has expired, CISA cannot require facilities to report their chemicals of interest or submit any information in CSAT. CISA can no longer require facilities to submit or implement their CFATS Site Security Plan or Alternative Security Program.
Q7: I have planned measures in my security plan. Do I still need to implement those security measures?
A7: Since the statutory authority for CFATS has expired, CISA can no longer require facilities to implement their CFATS Site Security Plan or Alternative Security Program. CISA encourages facilities to maintain security measures. Information about CISA’s voluntary ChemLock resources is available at
cisa.gov/ChemLock.
Q8: Is CISA still holding the 2023 Chemical Security Summit?
A8: Yes, the Summit will be hosted August 29-31st in Arlington, VA. You may register at cisa.gov/chemical-security-summit.