A complete compliance assessment program for pipeline, freight rail, and passenger transit operators — every individual requirement of the five surface cybersecurity Security Directives, scoped to your operation, guided question by question, with the evidence trail an inspector actually asks for. It runs from a double-click and never sends your data anywhere.
Click to enlargeTSA's surface cybersecurity directives are five separate documents with different requirements per sector, deadline clocks anchored to four different dates, and an annual renewal cycle that changes the text under your feet. Missing any of it is a finding.
Pipeline, freight, and passenger requirements differ in ways that matter — the incident triggers, the response-plan objectives, even the reset-password rule are not the same document to document.
72-hour incident reports. 24-hour supplements. 7-day coordinator updates. 60-day notices. Annual plans, exercises, and reports anchored to approval dates nobody wrote down.
For the mitigation-series directives, the audit surface is your TSA-approved Implementation Plan. Drift from your own commitments and you can be non-compliant while every generic checklist shows green.
An inspector can request your asset inventory, firewall rules, diagrams, logs — even a 24-hour packet capture. The question is never whether you did the work; it's whether you can show it in five seconds.
Real screenshots, real sample data, no mockups — this is the actual tool, which you can hold in your hands five minutes from now.
Six areas below, numbered in the order you use them: scoping, assessment, deadlines, evidence, readiness, assessor layer.
A three-screen setup interview asks the only question that legally matters — which directives has TSA notified you that you're subject to — plus a handful of scoping facts (shared accounts? PTC? a non-U.S. coordinator?).
Click to enlargeOne requirement per screen: plain English first, the section cite as a footnote. Every screen tells you how to implement it in your environment — naming actual tools and configurations — and what evidence would satisfy it, down to "an attendance roster by position, because a sign-in sheet without positions is the classic audit failure."
Click to enlargeEnter your anchor dates once — plan approval, last exercise, last assessment — and every derived obligation appears with its clock: annual plan updates, exercise anniversaries, biennial architecture reviews, amendment windows, the next renewal.
Click to enlargeDrop a file on the register: it's hashed (SHA-256) in your browser's memory and the bytes are immediately discarded. What's recorded is the name, date, fingerprint, and where the artifact actually lives. Your firewall rules and network diagrams stay in your controlled repository — the tool holds proof they exist and haven't changed, never the documents themselves.
Click to enlargeThe directives list exactly what TSA may request to establish compliance — inventories, firewall rules, diagrams, policies, logs, packet captures. The readiness view cross-references that list against your evidence register: green where you can produce it, red where you can't. Including the one that catches everyone: could you deliver a 24-hour packet capture at the OT boundary this week?
Click to enlargeAn assessor view adds what a consultant needs and an operator doesn't: requirement IDs, candid commonly-failed commentary, advisory framework mappings (NIST CSF 2.0, SP 800-82, MITRE ATT&CK for ICS), and the Implementation Plan commitment layer — what your approved plan promised, next to what you actually do, with a drift flag that watches the amendment clock.
Click to enlargeA print-to-PDF executive briefing: completion, overdue items, filings due in 90 days, top risks. What you hand a GM who will never open the grid.
Read Me, live-formula dashboard, full assessment, gap register — frozen headers, dropdowns, autofilter. Stands entirely alone; no app needed to read it. Zero lock-in.
When TSA reissues the directives each year, your file migrates: statuses carry forward, changed requirements are flagged for re-review, and the what-changed report is stored as a permanent audit trail.
Guidance defaults to Microsoft 365/Azure tooling; flip one setting and every affected requirement shows the capability actually required plus common equivalents — CrowdStrike, Splunk, Okta, Tenable, Veeam and more.
Every gap carries description, dated remediation plan, interim compensating control, and the TSA-facing risk written the way an inspector would see it.
Scoped-out requirements leave the denominator entirely. "Not Applicable" requires a reason. The two statuses that legally require notifying TSA say so, loudly.
The mitigation-series directives require three approved artifacts — an Implementation Plan, an Assessment Plan, and an annual Assessment Report — plus timed incident reports and a dozen written policies. SD Comply builds each one from the assessment you already did, and refuses to produce anything that would certify a breach.
Log an incident with the moment it was identified — backdated to the real time, because that is when the directive's clock starts, not when you opened the tool. A live countdown runs against the absolute deadline; every "new information" entry starts its own 24-hour supplement clock.
Click to enlargeThe directive requires a third of your plan's measures assessed every year and all of them within three — and almost nobody tracks it. The matrix does: per-element assessment records across three years anchored to your approval dates, with the finding nobody sees coming flagged in red: elements never scheduled in any year.
Click to enlargeEvery §III.A–E requirement becomes a heading with a paragraph built from its status, notes, approved-plan commitment and linked evidence. What the tool can't know is marked ⟦INPUT⟧; what the assessor must check is marked ⟦REVIEW⟧ — and where practice has drifted from an approved commitment, the draft carries a STOP instead of re-certifying the old promise.
Click to enlargeEleven written policies and procedures are demanded by name, and they differ by sector (rail's criteria-based password policy is not pipeline's reset schedule). The checklist derives the list from the directive text and shows three states — on record, missing, and the one that causes findings: requirement marked compliant, no written policy on record.
Click to enlargeYour evidence register re-sorted into Security Directive sequence — the index the directive requires when you rely on existing documents. Printable, and embedded in the CIP skeleton.
Receipt confirmations, coordinator details, and unable-to-implement notices go to different addresses — and they differ between rail and pipeline. The Contacts view lists the right one for each, with your coordinators and the 7-day update clock beside them.
Who set which status, when, from what — the trail an inspector asks for when a status looks too convenient.
A snapshot on every save; the executive briefing shows "61% → 84% since March" instead of a number with no direction.
CAP, CIP skeleton and policy drafts are written directly in the .docx format by the tool itself — the same zero-dependency, zero-network discipline as everything else.
Every generated document is templates, rules and arithmetic over your own data. The same input always produces the same output, and there is no model to leak your SSI into.
Your completed assessment describes your vulnerabilities. It should never live in someone else's cloud. So this tool isn't a portal, a platform, or a service — it's a single readable file, and every claim below is verifiable on your own machine in five minutes.
No analytics, telemetry, update checks, external fonts, or cloud calls. Nothing you type is transmitted to TSA, a vendor, or anyone. Enforced by an automated test on every release of the file.
The client file you save where you choose, and a crash-recovery copy in your browser you can wipe with one button. Nowhere else. Ever.
Evidence files are fingerprinted in memory and discarded. A stolen copy of your assessment file contains pointers and hashes — not your firewall rules.
No libraries, frameworks, or package dependencies. There is no supply chain to compromise and no upstream project that can be abandoned.
The tool submits nothing to TSA. All submissions remain the deliberate, human, prescribed acts the directives require. SSI-aware handling guidance is built in.
If the tool disappeared tomorrow, your record survives: an open-format data file plus a standalone Excel workbook with live formulas.
The demo build ships with three fully worked sample operators — every applicable requirement answered to the standard we expect, deliberately not fully compliant, because the worked gap entries, drift flags, and evidence trails are the demonstration. Every view, every feature, freely explorable; nothing persists. Running a live assessment of your operation — with saving, your data file, and annual directive-renewal updates — is what the licensed build adds.
Both pipeline directives. Shows the forensic-memory requirement no rail operator has, the encryption rule with no escape hatch, and a non-U.S. coordinator handled correctly.
Both rail directives. Shows PTC handling, an approved-plan commitment that drifted — flagged with its amendment clock — and a 17-artifact evidence register.
The small-scope case: 48 requirements, no implementation-plan regime — and one live overdue exercise on the calendar, because that's realistic.
Click to enlargeTSA civil penalties run to five figures per violation per day. Every tier below costs less than the finding it prevents — and every tier keeps your data on your machines.
One flat price per operator — no per-directive or per-site math. The managed program does not replace your own designated Cybersecurity Coordinator, which the directives require to be your personnel.
Not covered here? Ask directly — michael@securidigm.com
No. Nothing is sent anywhere, to anyone, ever. TSA submissions remain the deliberate email-based acts the directives prescribe — this tool prepares you for them and tracks them; it never performs them.
In one file, saved wherever you choose — your own server, SharePoint, an encrypted folder. Plus a local crash-recovery copy in your browser that you can clear with one button. There is no cloud component to breach.
You receive an updated tool file. Open your existing data with it: statuses carry forward requirement-by-requirement, anything TSA changed is flagged for re-review, and the migration report is stored in your file as an audit trail.
No — flip one profile setting and every Microsoft-flavored recommendation appends the capability the requirement actually needs plus common equivalents. The directives are capability-based; no requirement anywhere names a product.
No, and it says so prominently. It's a working self-assessment built from careful paraphrases of the directive text — the tool itself instructs you to validate requirement wording against the official TSA documents before any submission or inspection.
It generates them as drafts from your assessment — the CAP and annual report almost completely (they are schedules and tallies), the CIP as a structured skeleton, and policies as skeletons that state plainly they are not finished. Every generated document marks what only you can supply and what an assessor must review, and none of them pretends to be approved. What you get is the end of the blank page and of structural mistakes; what remains is your judgment.
It's the full interface with the full sample data — explore everything, verify every security claim. What it doesn't do is run an assessment of your own operation: creating client assessments, saving, and file import are licensed-build features, and licensed builds include the annual catalog updates when TSA renews the directives. The demo exists so your decision is informed, not so the decision is unnecessary.
Inspect it. A single readable file with no network access and no dependencies has a smaller attack surface than any portal — and unlike a platform, every security claim it makes can be tested by your own IT person in minutes.
Open it, explore the samples, run the airplane-mode test. If it isn't obviously useful in fifteen minutes, delete it — it uninstalls by being deleted.
Request the demo file →