Why It Matters

The U.S. Department of Homeland Security (DHS) estimates that if high-risk chemicals were weaponized, the impact could range from fatalities within the facility up to the equivalent impact of a nuclear explosion.

A Government Accountability Office (GAO) report, published Sept. 8, 2026, found that the federal government's ability to protect these sites has deteriorated sharply, leaving a vulnerability that the private sector cannot close on its own.

As part of a regulatory program, Cybersecurity and Infrastructure Security Agency (CISA) required facilities to vet their personnel and certain unescorted visitors for terrorist ties against the U.S. government's terrorist watchlist. Since then, chemical facilities have been solely responsible for identifying and mitigating their own security risks.

The problem: vetting against the terrorist watchlist is an inherently governmental function that private companies cannot perform independently. The loss of access to that process has left a gap in chemical facility security that poses substantial risks, according to the GAO.

The Big Picture

The regulatory program for high-risk chemical facilities was established by the Department of Homeland Security in 2007. As part of that program, CISA required facilities to vet their personnel and certain unescorted visitors for terrorist ties against the U.S. government's terrorist watchlist.

When the authorization expired in July 2023, high-risk chemical facilities became solely responsible for identifying and mitigating their own security risks. Following the lapse of authorization in July 2023, the program, including personnel vetting, was discontinued. As of May 2026, CISA said it was exploring whether the agency's SRMA authority could be used to fill the gap. That exploration was ongoing at the time the GAO report was published.

From fiscal year 2024 to fiscal year 2025, the number of CISA active personnel dedicated to chemical sector activities declined from 214 to 52. CISA acknowledged that personnel reductions have necessitated reducing or eliminating services, including most on-site facility assessments. The agency said it continues to offer services such as security training and cybersecurity guidance despite the staffing cuts.

The report found that the private sector could not replicate the vetting function that CISA had provided. The statutory authority that establishes SRMA responsibilities specifies that SRMAs are to implement security programs to assist stakeholders in identifying and mitigating risks to their assets and systems. Vetting against the U.S. terrorist watchlist is an inherently governmental function that the private sector cannot perform on its own.

The Bottom Line

GAO recommended that CISA implement voluntary options for chemical facilities to vet personnel for terrorist ties, and, if necessary, seek legislative authority to do so. The recommendation was straightforward: restore some form of federal vetting capability, even if on a voluntary basis, or ask Congress for new authority to make it happen.

DHS did not concur with GAO's recommendation to implement voluntary options for chemical facilities to vet personnel for terrorist ties. Despite DHS's non-concurrence, GAO stated it continues to recommend that CISA implement voluntary options for terrorist vetting. The status of GAO's recommendation is Open, with actions to satisfy the intent of the recommendation not yet taken or being planned.

Spot something wrong? Report an issue with this article