Why It Matters

The Transportation Worker Identification Credential, known as the TWIC card, is the federal government's primary tool for keeping unauthorized individuals out of secure port areas. TSA runs background checks on applicants; the Coast Guard inspects facilities for compliance. As of August 2025, more than 2 million workers held the credential.

A GAO report published July 28 (GAO-26-107521) found the two-agency structure has produced tangible security gaps. The Coast Guard identified 888 TWIC-related deficiencies and 83 violations at port facilities between fiscal years 2019 and 2024, including instances of unescorted individuals entering secure areas. GAO also found a risk of people with revoked TWIC cards, specifically those on the Canceled Card List, still accessing MTSA-regulated facilities.

The coordination failures driving these risks are structural. TSA uses an ad hoc approach rather than a documented communication plan to share program information with stakeholders, who reported both declining engagement and delays receiving key updates. The Coast Guard collects deficiency and violation data during inspections but does not share or analyze that data with the field inspectors responsible for enforcing TWIC requirements. Coast Guard officials told GAO the data did not relate to areas requiring program changes, a rationale GAO rejected.

GAO made seven recommendations. As of the report's release, all seven are open, with no actions taken or planned by either agency.

Broader Context

The review was mandated by the Transportation Security Screening Modernization Act of 2024, which directed GAO to examine TSA's security threat assessment programs, including TWIC. GAO was separately asked to review other aspects of TWIC operations. The underlying program authority is the Maritime Transportation Security Act of 2002, which established the regulatory framework for unescorted access to secure port areas.

The seven recommendations span both agencies. The TSA Administrator is directed to develop a communication plan for relaying TWIC program updates to stakeholders (Rec. 1) and to coordinate with the Coast Guard through DHS on acquiring TWIC reader devices for inspections (Rec. 6). The Coast Guard Commandant is directed to share violation and deficiency data with field inspectors (Rec. 2), include deficiency data in performance measure reporting (Rec. 3), develop a method to mitigate risks from individuals on the Canceled Card List (Rec. 4), coordinate with TSA through DHS on reader acquisition (Rec. 5), and develop a plan for issuing final regulations specifying which facilities must have TWIC readers (Rec. 7). The Department of Homeland Security concurred with all seven recommendations.

Spot something wrong? Report an issue with this article