Chemical Security: DHS Should Provide Options for Voluntary Vetting of Facility Personnel for Terrorist Ties
The GAO report finds that DHS’s CISA discontinued a regulatory program established in 2007 after its authorization lapsed in July 2023, and that loss included federal options for vetting chemical facility personnel against the U.S.…
Cabrillo Club
Editorial Team · September 8, 2026 · 5 min read

Also in this intelligence package
Executive Summary
The GAO report finds that DHS (Department of Homeland Security)’s CISA discontinued a regulatory program established in 2007 after its authorization lapsed in July 2023, and that loss included federal options for vetting chemical facility personnel against the U.S. terrorist watchlist — a capability the private sector cannot perform on its own. The absence of that federal vetting option is identified by stakeholders and CISA officials as the most significant security challenge facing high‑risk chemical facilities. Compounding the gap, CISA active personnel dedicated to chemical sector activities fell from 214 in fiscal year 2024 to 52 in fiscal year 2025, which has led to reductions or eliminations of services such as most on‑site facility assessments; CISA said it continues to offer other services such as security training and cybersecurity guidance. As of May 2026, CISA was exploring whether its SRMA authority could be used to set up a vetting process.
Contractors across the tagged market segments should pay attention now because (1) a critical capability (federal terrorist vetting of personnel) is not available following the program discontinuation, (2) CISA staffing reductions have materially reduced federal support services, and (3) stakeholders report increased risk to facilities and to critical supply chains (the report notes more than 89 million people lived or worked within 2 miles of a facility using high‑risk chemicals as of 2025). This creates near‑term demand for alternative mitigations, advisory support, training, assessment capabilities, and technology solutions that help facilities manage insider risk and compensate for reduced federal engagement. Specific opportunities and procurement paths are TBD pending solicitation language.
Impact Matrix
Chemical Manufacturing
- Risk Level: High
- Opportunity: Support owners/operators with alternative insider‑risk mitigations, risk assessments, security training, and operational continuity planning. Specific NAICS codes: 325000, 325100, 325200, 325300, 325400, 325500, 325600, 325900 (from Tags). Specific opportunities TBD pending solicitation language.
- Timeline: Authorization for the regulatory program lapsed in July 2023; CISA staffing declines from FY2024 to FY2025; CISA exploring options as of May 2026.
- Action Required: Reassess personnel security controls and supply‑chain risk, prioritize mitigations that do not rely on federal watchlist vetting, and accelerate upgrades to access controls, insider‑threat programs, and contingency plans.
- Competitive Edge: Package industry‑specific operational-security services (training + assessments + technology) that map to CFATS/chemical sector risk priorities and demonstrate rapid deployment capability.
Critical Infrastructure Protection
- Risk Level: Critical
- Opportunity: Provide systemic risk‑management support, continuity planning, and sector coordination services to substitute for some functions previously provided through the federal program. Specific opportunities TBD pending solicitation language.
- Timeline: Program discontinued after July 2023 authorization lapse; CISA exploring options as of May 2026; workforce reductions in FY2024–FY2025.
- Action Required: Offer cross‑facility risk assessments, regional incident‑response planning, and scalable mitigation services to reduce potential cascading impacts on supply chains and surrounding populations.
- Competitive Edge: Build consortiums or regional programs that offer standardized assessments and mutual‑aid protocols to demonstrate scale and resilience.
Physical Security
- Risk Level: Critical
- Opportunity: Deliver physical access control modernization, identity‑proofing, visitor management, and hardened perimeter solutions to reduce insider risk in the absence of federal watchlist vetting. Specific opportunities TBD pending solicitation language.
- Timeline: Timeline elements as above (authorization lapse July 2023; staffing reductions FY2024–FY2025; CISA exploring May 2026).
- Action Required: Increase emphasis on multi‑factor identity verification, visitor escorting policies, and layered physical controls that do not depend on federal vetting capabilities.
- Competitive Edge: Integrate physical security products with training and policy services to present turnkey solutions that facilities can implement quickly.
Personnel Security and Vetting
- Risk Level: Critical
- Opportunity: Advise on lawful commercial background checks, identity‑proofing, insider‑threat program design, and staffing practices that fill gaps left by the discontinued federal vetting process. Specific opportunities TBD pending solicitation language.
- Timeline: Federal vetting process discontinued when program authorization lapsed in July 2023; CISA exploring options as of May 2026.
- Action Required: Help facilities review and strengthen personnel policies, deploy alternative vetting workflows consistent with law, and document compensating controls for stakeholders and insurers.
- Competitive Edge: Demonstrate expertise in designing personnel security programs that combine legal compliance, operational practicality, and traceable audit trails.
Risk Management
- Risk Level: High
- Opportunity: Offer enterprise risk assessments, supply‑chain risk modeling, and prioritization frameworks to help facilities identify and mitigate remaining critical vulnerabilities. Specific opportunities TBD pending solicitation language.
- Timeline: Ongoing; note reduced federal support after FY2024–FY2025 staffing changes and July 2023 program lapse; CISA exploring options as of May 2026.
- Action Required: Reassess risk registers to reflect loss of federal vetting, quantify residual risk, and prioritize investments and insurance/recovery planning accordingly.
- Competitive Edge: Provide tools and reporting that translate risk mitigation into measurable KPIs and compliance‑oriented documentation for board/executive decision‑makers.
Security Assessments
- Risk Level: High
- Opportunity: Fill gaps in on‑site assessment capability that CISA reduced or eliminated; offer virtual and on‑site assessment services, validation testing, and remediation roadmaps. Specific opportunities TBD pending solicitation language.
- Timeline: CISA reduced or eliminated most on‑site facility assessments following personnel reductions between FY2024 and FY2025.
- Action Required: Scale assessment teams, develop remote/augmented assessment offerings, and align deliverables with facility risk priorities.
- Competitive Edge: Combine assessment services with prioritized remediation contracting to shorten the time from findings to mitigation.
Cybersecurity
- Risk Level: High
- Opportunity: Provide cybersecurity guidance, managed services, incident response, and OT/IT convergence solutions; CISA continues to offer cybersecurity guidance but staffing reductions may increase demand for private providers. Specific opportunities TBD pending solicitation language.
- Timeline: CISA continues to offer cybersecurity guidance even as personnel dedicated to the chemical sector declined in FY2024–FY2025.
- Action Required: Emphasize integrated cyber‑physical security assessments, patch and configuration management for industrial control systems, and tabletop exercises that include insider scenarios.
- Competitive Edge: Offer combined cyber/physical risk packages tailored to chemical facilities that can be rapidly deployed where federal touchpoints are limited.
Security Training
- Risk Level: High
- Opportunity: Deliver training to fill the gap from reduced CISA engagement — including insider‑threat awareness, security operations, and emergency response training. Specific opportunities TBD pending solicitation language.
- Timeline: CISA still offers some training as of the dates in the Summary, but contact with stakeholders has been reduced following FY2024–FY2025 personnel declines.
- Action Required: Expand training portfolios, offer customizable on‑site and virtual courses, and align training outcomes with facility risk and regulatory documentation needs.
- Competitive Edge: Differentiate with scenario‑based exercises and certification paths that help facilities demonstrate preparedness to insurers, customers, and regulators.
Cross-Segment Implications
- The loss of federal terrorist watchlist vetting and reductions in CISA personnel create a direct dependency between Personnel Security and Vetting, Physical Security, and Security Assessments: without federal vetting, facilities must strengthen physical controls and assessments to manage insider risk.
- Reduced CISA on‑site assessments increase demand for private Security Assessments and Risk Management services, which in turn should feed into Security Training and Cybersecurity engagements to ensure remediation actions are implemented effectively.
- Chemical Manufacturing and Critical Infrastructure Protection segments are exposed to cascading supply‑chain and community risk if personnel‑related threats are not mitigated; this raises the strategic importance of integrated offerings that combine physical, personnel, cyber, and training solutions.
- Contractors that can offer bundled services (assessments + remediation + training + cyber/physical integration) will be well positioned to serve facilities seeking to replace or supplement federal support while CISA explores options to restore vetting capabilities.
Stop missing federal opportunities
Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.
Start Free Trialor see Intelligence Dashboard→

Cabrillo Club
Editorial Team
Cabrillo Club is a defense technology company building AI-powered tools for government contractors. Our editorial team combines deep expertise in CMMC compliance, federal acquisition, and secure AI infrastructure to produce actionable guidance for the defense industrial base.