Reporting Chemical-Terrorism Vulnerability Information (CVI) Incidents

CFATS Announcement

As of July 28, 2023, Congress has allowed the statutory authority for the Chemical Facility Anti-Terrorism Standards (CFATS) program (6 CFR Part 27) to expire.

Therefore, CISA cannot enforce compliance with the CFATS regulations at this time. This means that CISA will not require facilities to report their chemicals of interest or submit any information in CSAT, perform inspections, or provide CFATS compliance assistance, amongst other activities. CISA can no longer require facilities to implement their CFATS Site Security Plan or CFATS Alternative Security Program.

CISA encourages facilities to maintain security measures. CISA’s voluntary ChemLock resources are available on the ChemLock webpages.

If CFATS is reauthorized, CISA will follow up with facilities in the future. To reach us, please contact

Under 6 CFR § 27.400(d), covered persons must notify the Agency of any unauthorized releases of Chemical-terrorism Vulnerability Information (CVI) and refer to the Agency any requests for access to CVI by persons without a need to know.

Chemical facilities and other entities or persons are encouraged to contact the Agency about any actual or suspected misuse of or unauthorized access to CVI. Information about such actual or suspected incidents may be reported to the CISA Chemical Security Inspector assigned to the area in which the incident occurred. See Chapter 10.0 of the CVI Procedural Manual.

In the event of any disagreement between the facility and the public official regarding the precise CVI to be disclosed or the method of disclosure, CISA encourages the parties to refer the matter to the CISA Chemical Security Inspector for resolution.

Contact Information

If you have questions or need the contact info for your local CISA Chemical Security Inspector (CSI), call the Chemical Security Assessment Tool (CSAT) Help Desk at 866-323-2957 Monday through Friday (except federal holidays) from 8:30 a.m. to 5 p.m. (ET) or email