SD COMPLY
SD Comply · Compliance Assessment Tool

Every TSA Security Directive requirement.
One file. Zero network connections.

A complete compliance assessment program for pipeline, freight rail, and passenger transit operators — every individual requirement of the five surface cybersecurity Security Directives, scoped to your operation, guided question by question, with the evidence trail an inspector actually asks for. It runs from a double-click and never sends your data anywhere.

264individually tracked requirements
5Security Directives, current renewals
0network connections — verifiable
1file. No install, no account, no cloud
3filing types generated — CAP, CIP, incident reports
file:///C:/compliance/sd-comply.html
Compliance dashboard with completion by directive and by sectionClick to enlarge
Why this exists

The directives weren't written for a four-person IT team.

TSA's surface cybersecurity directives are five separate documents with different requirements per sector, deadline clocks anchored to four different dates, and an annual renewal cycle that changes the text under your feet. Missing any of it is a finding.

01Five directives, renewed yearly

Pipeline, freight, and passenger requirements differ in ways that matter — the incident triggers, the response-plan objectives, even the reset-password rule are not the same document to document.

02Clocks everywhere

72-hour incident reports. 24-hour supplements. 7-day coordinator updates. 60-day notices. Annual plans, exercises, and reports anchored to approval dates nobody wrote down.

03TSA inspects your plan, not the directive

For the mitigation-series directives, the audit surface is your TSA-approved Implementation Plan. Drift from your own commitments and you can be non-compliant while every generic checklist shows green.

04"Prove it" is the real test

An inspector can request your asset inventory, firewall rules, diagrams, logs — even a 24-hour packet capture. The question is never whether you did the work; it's whether you can show it in five seconds.

Watch it work

From blank file to defensible program.

Real screenshots, real sample data, no mockups — this is the actual tool, which you can hold in your hands five minutes from now.

Setup wizard Questionnaire, unanswered requirement Questionnaire, answered with evidence Dashboard Gap register Incident report builder with the 72-hour clock
01
Built around how the work actually happens

Everything the directives demand, nothing you don't need to see.

Six areas below, numbered in the order you use them: scoping, assessment, deadlines, evidence, readiness, assessor layer.

01 — Scoping

Scoped to your operation before you answer anything

A three-screen setup interview asks the only question that legally matters — which directives has TSA notified you that you're subject to — plus a handful of scoping facts (shared accounts? PTC? a non-U.S. coordinator?).

  • A pipeline operator sees ~40–110 requirements, never the rail catalog
  • Conditional requirements scope out automatically, with the reason recorded — so the inspector's "why isn't this here?" always has an answer
  • Fully reversible: a mid-year TSA designation is a checkbox, not a re-assessment
Setup — 1. Identity & applicability
Setup wizardClick to enlarge
02 — Assessment

A guided questionnaire that speaks operator, not regulation

One requirement per screen: plain English first, the section cite as a footnote. Every screen tells you how to implement it in your environment — naming actual tools and configurations — and what evidence would satisfy it, down to "an attendance roster by position, because a sign-in sheet without positions is the classic audit failure."

  • Work any section in any order; "unanswered only" mode auto-advances as you go
  • Guidance adapts to your OT tooling and your IT stack — Microsoft shop or not
  • Marking a requirement non-compliant automatically opens a gap entry
Questionnaire — requirement detail
Guided questionnaireClick to enlarge
03 — Deadlines

A calendar that already knows your deadlines

Enter your anchor dates once — plan approval, last exercise, last assessment — and every derived obligation appears with its clock: annual plan updates, exercise anniversaries, biennial architecture reviews, amendment windows, the next renewal.

  • Overdue and due-within-60-days flagged automatically
  • One-click .ics export drops every deadline into Outlook, where deadlines actually survive
  • Standing duties — the 72-hour report, the 7-day coordinator update — listed so nobody has to remember them
Obligations calendar
Obligations calendar with an overdue itemClick to enlarge
04 — Evidence

Evidence by fingerprint — your documents never enter the tool

Drop a file on the register: it's hashed (SHA-256) in your browser's memory and the bytes are immediately discarded. What's recorded is the name, date, fingerprint, and where the artifact actually lives. Your firewall rules and network diagrams stay in your controlled repository — the tool holds proof they exist and haven't changed, never the documents themselves.

  • One artifact links across many requirements — the way real evidence works
  • Tagged against TSA's own inspectable-records list
Evidence register — SHA-256 fingerprints
Evidence register with hashes and pointersClick to enlarge
05 — Readiness

Inspection readiness, answered before TSA asks

The directives list exactly what TSA may request to establish compliance — inventories, firewall rules, diagrams, policies, logs, packet captures. The readiness view cross-references that list against your evidence register: green where you can produce it, red where you can't. Including the one that catches everyone: could you deliver a 24-hour packet capture at the OT boundary this week?

Inspection readiness
Inspection readiness viewClick to enlarge
06 — Assessor layer

For the assessor: the layer TSA actually inspects

An assessor view adds what a consultant needs and an operator doesn't: requirement IDs, candid commonly-failed commentary, advisory framework mappings (NIST CSF 2.0, SP 800-82, MITRE ATT&CK for ICS), and the Implementation Plan commitment layer — what your approved plan promised, next to what you actually do, with a drift flag that watches the amendment clock.

Assessor view — CIP commitment fields
Assessor view with CIP commitment fieldsClick to enlarge
Boardroom-ready in one click

A print-to-PDF executive briefing: completion, overdue items, filings due in 90 days, top risks. What you hand a GM who will never open the grid.

A real Excel workbook, generated on demand

Read Me, live-formula dashboard, full assessment, gap register — frozen headers, dropdowns, autofilter. Stands entirely alone; no app needed to read it. Zero lock-in.

Built for the renewal treadmill

When TSA reissues the directives each year, your file migrates: statuses carry forward, changed requirements are flagged for re-review, and the what-changed report is stored as a permanent audit trail.

Not a Microsoft shop? Covered.

Guidance defaults to Microsoft 365/Azure tooling; flip one setting and every affected requirement shows the capability actually required plus common equivalents — CrowdStrike, Splunk, Okta, Tenable, Veeam and more.

Gap register with the column that matters

Every gap carries description, dated remediation plan, interim compensating control, and the TSA-facing risk written the way an inspector would see it.

Honest status math

Scoped-out requirements leave the denominator entirely. "Not Applicable" requires a reason. The two statuses that legally require notifying TSA say so, loudly.

The filings TSA actually inspects

From assessment to the documents TSA asks for — generated, not retyped.

The mitigation-series directives require three approved artifacts — an Implementation Plan, an Assessment Plan, and an annual Assessment Report — plus timed incident reports and a dozen written policies. SD Comply builds each one from the assessment you already did, and refuses to produce anything that would certify a breach.

07 — Incidents

Incident Report Builder with the 72-hour clock

Log an incident with the moment it was identified — backdated to the real time, because that is when the directive's clock starts, not when you opened the tool. A live countdown runs against the absolute deadline; every "new information" entry starts its own 24-hour supplement clock.

  • Report fields are your sector's, drawn from the directive — five incident types for pipeline, four for rail; the 1570.203 dual-reporting sentence only where it applies
  • Paste-ready text for the CISA form, a one-click Outlook reminder with a 12-hour alarm, print-to-PDF
  • "Record as reported" judges within-72-hours or late and files the report into your evidence register automatically
  • It never submits anything — reporting stays a deliberate human act
Incident report builder — 72-hour countdown
Incident Report BuilderClick to enlarge
08 — Assessment plan

CAP coverage matrix, the Assessment Plan, and the annual report

The directive requires a third of your plan's measures assessed every year and all of them within three — and almost nobody tracks it. The matrix does: per-element assessment records across three years anchored to your approval dates, with the finding nobody sees coming flagged in red: elements never scheduled in any year.

  • Generates the Cybersecurity Assessment Plan as a Word document — and refuses while any element is unscheduled
  • Generates the annual report exactly as §III.F.2.e asks it: methods used, results per element, findings tied to their gap dispositions, unassessable elements disclosed rather than omitted
  • Planned assessments land on the calendar and in Outlook
CAP coverage matrix — three-year view
CAP coverage matrixClick to enlarge
09 — Implementation plan

A CIP skeleton that refuses to paper over drift

Every §III.A–E requirement becomes a heading with a paragraph built from its status, notes, approved-plan commitment and linked evidence. What the tool can't know is marked ⟦INPUT⟧; what the assessor must check is marked ⟦REVIEW⟧ — and where practice has drifted from an approved commitment, the draft carries a STOP instead of re-certifying the old promise.

  • Status table up front: pre-filled vs. needs input vs. drift
  • Implementation schedule from open gaps; delegations; the §IV.A records index as Section 8
  • Word format, hand-written — no library, no network
CIP skeleton generator
CIP skeleton generatorClick to enlarge
10 — Policies

The policies you're required to have in writing — and the ones you're missing

Eleven written policies and procedures are demanded by name, and they differ by sector (rail's criteria-based password policy is not pipeline's reset schedule). The checklist derives the list from the directive text and shows three states — on record, missing, and the one that causes findings: requirement marked compliant, no written policy on record.

  • Starter drafts for any missing policy: the regulatory basis, a checklist of what the directive requires the document to contain, roles pre-filled — and "skeleton" stated in the title, the first line and the footer
  • A starter draft never counts as evidence; only the approved policy you register does
Required policies checklist
Required policies checklistClick to enlarge
Records index (§IV.A)

Your evidence register re-sorted into Security Directive sequence — the index the directive requires when you rely on existing documents. Printable, and embedded in the CIP skeleton.

Every TSA inbox, by purpose

Receipt confirmations, coordinator details, and unable-to-implement notices go to different addresses — and they differ between rail and pipeline. The Contacts view lists the right one for each, with your coordinators and the 7-day update clock beside them.

Change history on every requirement

Who set which status, when, from what — the trail an inspector asks for when a status looks too convenient.

Compliance trend

A snapshot on every save; the executive briefing shows "61% → 84% since March" instead of a number with no direction.

Word documents with no Word library

CAP, CIP skeleton and policy drafts are written directly in the .docx format by the tool itself — the same zero-dependency, zero-network discipline as everything else.

Deterministic, inspectable, no AI

Every generated document is templates, rules and arithmetic over your own data. The same input always produces the same output, and there is no model to leak your SSI into.

The security case

Built for operators who don't trust software — correctly.

Your completed assessment describes your vulnerabilities. It should never live in someone else's cloud. So this tool isn't a portal, a platform, or a service — it's a single readable file, and every claim below is verifiable on your own machine in five minutes.

Zero network connections

No analytics, telemetry, update checks, external fonts, or cloud calls. Nothing you type is transmitted to TSA, a vendor, or anyone. Enforced by an automated test on every release of the file.

Your data lives in exactly two places

The client file you save where you choose, and a crash-recovery copy in your browser you can wipe with one button. Nowhere else. Ever.

Your documents never enter it

Evidence files are fingerprinted in memory and discarded. A stolen copy of your assessment file contains pointers and hashes — not your firewall rules.

Zero third-party code

No libraries, frameworks, or package dependencies. There is no supply chain to compromise and no upstream project that can be abandoned.

Not a TSA channel

The tool submits nothing to TSA. All submissions remain the deliberate, human, prescribed acts the directives require. SSI-aware handling guidance is built in.

No vendor to outlive

If the tool disappeared tomorrow, your record survives: an open-format data file plus a standalone Excel workbook with live formulas.

Don't take our word for any of it — the app tells you how to check
  1. Airplane-mode test — disconnect entirely; every feature still works, including Excel export.
  2. Network-tab test — open your browser's developer tools and watch: the request list stays empty.
  3. Read the source — it's one readable file. Have your IT person inspect it before anyone types a word.
And the limits, stated plainly, because trust pages that hide them are sales copy: the data file is readable text — protect it with your normal file controls (disk encryption, restricted folders); there is no login — anyone with the file can open it; one person edits at a time, with a merge tool to reconcile copies; and the requirement paraphrases are advisory — validate against the official TSA text before any submission. All of this is printed inside the app itself, on a dedicated About & Security page.
The demo is the product

No demo video. No sales call. Request the file, open it, and click.

The demo build ships with three fully worked sample operators — every applicable requirement answered to the standard we expect, deliberately not fully compliant, because the worked gap entries, drift flags, and evidence trails are the demonstration. Every view, every feature, freely explorable; nothing persists. Running a live assessment of your operation — with saving, your data file, and annual directive-renewal updates — is what the licensed build adds.

Pipeline / LNG

Both pipeline directives. Shows the forensic-memory requirement no rail operator has, the encryption rule with no escape hatch, and a non-U.S. coordinator handled correctly.

Freight railroad

Both rail directives. Shows PTC handling, an approved-plan commitment that drifted — flagged with its amendment clock — and a 17-artifact evidence register.

Passenger transit

The small-scope case: 48 requirements, no implementation-plan regime — and one live overdue exercise on the calendar, because that's realistic.

Start screen — three sample operators
Start screen with the three sample operatorsClick to enlarge
Pricing

Priced against one avoided finding, not against software.

TSA civil penalties run to five figures per violation per day. Every tier below costs less than the finding it prevents — and every tier keeps your data on your machines.

Licensed Tool

For operators with the staff to run their own program
$6,500 one-time, per operator
+ $2,500/year directive-renewal updates & migration support
  • The full tool, licensed to your operation
  • Every requirement of your applicable directives, scoped and guided
  • Evidence register, calendar, Excel & briefing exports
  • CAP, annual report, CIP skeleton, incident reports and policy starter drafts generated from your assessment
  • Annual directive-renewal updates — statuses carry forward, changes flagged for re-review
  • Onboarding session for your team
Ask about licensing
Most engagements start here

Guided Assessment

We assess, you operate
from $18,000 per engagement
One flat engagement, whichever directives apply to you
  • Everything in Licensed Tool
  • Full gap assessment conducted with you, requirement by requirement
  • Implementation Plan commitments mapped against actual practice, drift flagged
  • Gap register written to inspection standard — remediation plans, compensating controls, TSA-facing risk
  • Evidence register built and readiness check completed
  • Executive briefing delivered to your leadership
Scope an assessment
Fully managed

Managed Program

Your compliance program, run for you — by the consultant who built it
$3,500 per month retainer
Annual commitment · includes the Guided Assessment in year one
  • Everything in Guided Assessment, kept continuously current
  • Obligations calendar managed — plan updates, reports, and filings prepared on their clocks
  • Annual incident-response exercise designed, facilitated, and documented to directive standard
  • Assessment-plan schedule tracked (the 1/3-per-year coverage TSA expects)
  • Directive renewals migrated and re-reviewed for you, every year
  • Pre-inspection readiness runs, and support assembling records when TSA asks
  • Guidance on reportable incidents — including keeping the 72-hour clock met
Discuss a managed program
Every tierLicensed per operator · your data never leaves your machines · SSI-aware handling built in · no cloud dependency, ever · cancel and keep your records — the data file and Excel workbook are yours

One flat price per operator — no per-directive or per-site math. The managed program does not replace your own designated Cybersecurity Coordinator, which the directives require to be your personnel.

Questions operators actually ask

Frequently asked.

Not covered here? Ask directly — michael@securidigm.com

Does this send our data to TSA?

No. Nothing is sent anywhere, to anyone, ever. TSA submissions remain the deliberate email-based acts the directives prescribe — this tool prepares you for them and tracks them; it never performs them.

Where does our assessment data live?

In one file, saved wherever you choose — your own server, SharePoint, an encrypted folder. Plus a local crash-recovery copy in your browser that you can clear with one button. There is no cloud component to breach.

What happens when TSA renews the directives?

You receive an updated tool file. Open your existing data with it: statuses carry forward requirement-by-requirement, anything TSA changed is flagged for re-review, and the migration report is stored in your file as an audit trail.

We don't run Microsoft 365. Is the guidance useless to us?

No — flip one profile setting and every Microsoft-flavored recommendation appends the capability the requirement actually needs plus common equivalents. The directives are capability-based; no requirement anywhere names a product.

Is this a legal compliance determination?

No, and it says so prominently. It's a working self-assessment built from careful paraphrases of the directive text — the tool itself instructs you to validate requirement wording against the official TSA documents before any submission or inspection.

Does it write our CIP, CAP and policies for us?

It generates them as drafts from your assessment — the CAP and annual report almost completely (they are schedules and tallies), the CIP as a structured skeleton, and policies as skeletons that state plainly they are not finished. Every generated document marks what only you can supply and what an assessor must review, and none of them pretends to be approved. What you get is the end of the blank page and of structural mistakes; what remains is your judgment.

Is the free demo the full product?

It's the full interface with the full sample data — explore everything, verify every security claim. What it doesn't do is run an assessment of your own operation: creating client assessments, saving, and file import are licensed-build features, and licensed builds include the annual catalog updates when TSA renews the directives. The demo exists so your decision is informed, not so the decision is unnecessary.

Why should we trust a file over a "real" platform?

Inspect it. A single readable file with no network access and no dependencies has a smaller attack surface than any portal — and unlike a platform, every security claim it makes can be tested by your own IT person in minutes.

One file, by email

Get the tool and all three sample operators.

Open it, explore the samples, run the airplane-mode test. If it isn't obviously useful in fifteen minutes, delete it — it uninstalls by being deleted.

Request the demo file
Click anywhere to close