Chemical Security: DHS Should Provide Options for Voluntary Vetting of Facility Personnel for Terrorist Ties
DHS/CISA’s regulatory program requiring terrorist-watchlist vetting for personnel at high‑risk chemical facilities was discontinued after authorization lapsed in July 2023, removing the federal option for watchlist‑based screening.…

Intelligence Package
Chemical Security: DHS Should Provide Options for Voluntary Vetting of Facility Personnel for Terrorist Ties
Breaking analysis of what happened and who is affected.
DHS/CISA’s regulatory program requiring terrorist-watchlist vetting for personnel at high‑risk chemical facilities was discontinued after authorization lapsed in July 2023, removing the federal option for watchlist‑based screening.…
Read full report →Segment ImpactChemical Security: DHS Should Provide Options for Voluntary Vetting of Facility Personnel for Terrorist Ties
Deep dive into how this impacts each market segment.
The GAO report finds that DHS’s CISA discontinued a regulatory program established in 2007 after its authorization lapsed in July 2023, and that loss included federal options for vetting chemical facility personnel against the U.S.…
Read full report →Action KitChemical Security: DHS Should Provide Options for Voluntary Vetting of Facility Personnel for Terrorist Ties
Actionable checklists and implementation guidance.
The GAO found that DHS’s Cybersecurity and Infrastructure Security Agency (CISA) previously ran a regulatory program that included vetting facility personnel and certain visitors against the U.S. terrorist watchlist.…
Read full report →TL;DR
DHS (Department of Homeland Security)/CISA’s long-standing regulatory program requiring terrorist-watchlist vetting for personnel at high‑risk chemical facilities was discontinued after its authorizing authority lapsed in July 2023, removing a federal option for watchlist-based personnel screening. CISA staffing devoted to chemical sector activities fell sharply between fiscal years 2024 and 2025, reducing on-site assessments and regular stakeholder engagement while some services (security training, cybersecurity guidance) continue. CISA has said (as of May 2026) it is exploring whether its SRMA authority could be used to reestablish a vetting process, but no federal replacement is in place today. The loss of a federal vetting option leaves facility owners/operators without an inherently governmental screening capability, increasing insider-threat risk and potential disruption to critical national supply chains; DHS estimates more than 89 million people lived or worked within 2 miles of facilities using high‑risk chemicals as of 2025. Immediate implications: facility owners must assume greater responsibility for personnel security, contractors should reposition service offerings to fill gaps (risk assessments, training, physical security hardening, personnel-security program design), and capture teams must prioritize opportunities tied to chemical-sector security support.
Key Points
- What happened: CISA’s regulatory program that required terrorist-watchlist vetting for high‑risk chemical facility personnel ended after authorization lapsed in July 2023; the vetting process was discontinued and facilities now self-manage personnel security.
- Who is affected: Chemical Manufacturing and related sectors identified in segmentation (NAICS 325000, 325100, 325200, 325300, 325400, 325500, 325600, 325900, 561612, 541690, 561621) and DHS/CISA; market segments include Chemical Manufacturing, Critical Infrastructure Protection, Physical Security, Personnel Security and Vetting, Risk Management, Security Assessments, Cybersecurity, and Security Training.
- Timeline: Program established in 2007; authorization lapsed July 2023; as of May 2026 CISA is exploring options; CISA active personnel for chemical sector declined from 214 (fiscal year 2024) to 52 (fiscal year 2025).
- What contractors should do NOW: Immediately inventory existing chemical-sector customers, offer rapid-risk-assessment packages and personnel‑security program design, prioritize capture for short-term task orders supporting physical security and training, update pipelines and bid/no‑bid decisions using Cabrillo Signals products, and notify BD/capture/proposals and security practice leads for coordinated outreach.
Who Is Affected
Affected segments include chemical manufacturers and service providers supporting chemical facility security, personnel vetting, and related risk-management activities. Explicitly named in the segmentation are NAICS codes 325000, 325100, 325200, 325300, 325400, 325500, 325600, 325900, 561612, 541690, and 561621, and the agencies DHS and CISA. Compliance surfaces called out include CFATS and Personnel Vetting Requirements/Terrorist Watchlist Screening. Specific contract vehicles are TBD pending source review.
Frequently Asked Questions
Q: Why did the federal terrorist-watchlist vetting stop for chemical facility personnel?
A: Authorization for the regulatory program lapsed in July 2023; when the program authorization lapsed the personnel‑vetting process was discontinued and high‑risk facilities became responsible for identifying and mitigating their own security risks.
Q: Is CISA reestablishing a federal vetting option?
A: As of May 2026, CISA said it was exploring whether its SRMA authority could be used to set up a vetting process. The status is exploratory; no operational federal vetting option is in place today. Further developments are pending source review.
Q: How have CISA personnel changes affected sector services?
A: From fiscal years 2024 to 2025 CISA active personnel dedicated to chemical sector activities declined from 214 (96 percent of authorized positions) to 52 (25 percent of authorized positions). CISA stated reductions have required reducing or eliminating services such as most on‑site facility assessments, although it continues to offer services like security training and cybersecurity guidance.
Definitions
- Sector risk management agency (SRMA): The agency assigned responsibility for implementing programs to assist a critical infrastructure sector in identifying and mitigating security risks (term as used in the Summary).
- Terrorist vetting / Terrorist-watchlist vetting: Screening personnel and certain visitors against the U.S. government terrorist watchlist to identify ties to terrorist actors; described in the Summary as an inherently governmental function.
- High‑risk chemical facility: Facilities using chemicals identified as high risk under the discontinued regulatory program; these facilities were subject to personnel vetting under that program.
Intelligence Response
- Cabrillo Signals War Room — Already detected this event and delivered this briefing. Continuously monitors regulatory changes, contract vehicles, and policy shifts.
- Cabrillo Signals Match Engine — Automatically rescores opportunity pipelines when events like this shift the competitive landscape.
- Cabrillo Signals Intelligence Hub — Tracks affected agencies, NAICS codes, and contract vehicles. Saved searches alert when follow-on solicitations appear on SAM.gov (System for Award Management).
- Proposal Studio (Proposal OS) — AI-powered proposal automation with compliance matrices, win theme library, and bid/no-bid decision engine.
- Proposal Studio Workflow Tracker — 9-gate capture management with automated compliance routing and audit-ready documentation.
Which products to leverage: Immediately activate Cabrillo Signals War Room and Intelligence Hub to track follow-on policy activity and solicitations; run the Match Engine to reprioritize opportunities; open Proposal Studio and Workflow Tracker to prepare rapid-response capture packages and compliance matrices. Notify capture leads, proposals, security practice leads, and BD teams.
Who to notify in your org:
- Capture Lead — prioritize target accounts and immediate pursuits tied to chemical‑sector security support.
- Security Practice Lead / Service Line Director — mobilize subject‑matter teams for rapid‑response service offerings (assessments, training, vetting policy design).
- Proposals Manager — initiate accelerated Proposal Studio workflows and compliance matrices.
- BD / Account Execs — begin outreach to affected facilities and primes.
First 48‑hour response playbook:
- Hour 0–4: Confirm receipt of this briefing; trigger War Room alert; notify capture, security practice lead, and proposals manager; run Intelligence Hub saved searches for chemical-sector solicitations.
- Hour 4–12: Use Match Engine to rescore and reprioritize pipeline; create short-list of priority accounts and task‑order opportunities; assemble rapid-response capture team.
- Hour 12–24: Draft rapid-risk-assessment and training Statement of Work templates in Proposal Studio; prepare compliance checklist focused on personnel-security and physical-security deliverables.
- Hour 24–48: Outreach to target clients and primes with capability briefings; enter prioritized pursuits into Proposal Studio Workflow Tracker and schedule capture milestones.
Reference materials: Winning Federal Contracts Guide (/insights/winning-federal-contracts). See related guidance on security and controlled information handling: CMMC (Cybersecurity Maturity Model Certification) Compliance Guide (/insights/cmmc-compliance-guide) and CUI (Controlled Unclassified Information)-Safe CRM Guide (/insights/cui-safe-crm-guide).